Jump to content

Recommended Posts

Posted

Hi All,

 

We are re-jigging our student permissions and im looking for some advice:

Firstly: we currently have permissions that get re-sent out each year - we are looking to lengthen that to the length of time at the school (with the right to refuse of course - yearly reminded). As we are a special school some of these children could be with us for around 15 years - I suspect that is too long to hold permissions - should we reask for permissions every phase?

 

Secondly: I am trying to work out if we need permission for each website where student data is held on. I believe (and feel free to correct me if I am wrong) that if we use a website for assessment purposes as our school way of working we don't have to ask for consent (i.e MIS to hold data, or something like Tapestry to hold assessment data for EYFS, iris for lesson observations). It is the other sites I'm concerned about. Would a statement in the permissions or online safety policy like *** School uses many websites in the course of educating, assessing, and aid our students? All websites that are used for this are risk assessed by the school, and only data required by these sites is uploaded, this may be names or names and birthdates. These websites include...... Education city, blah, blah.

 

Please note I am aware that specific sites-- like Seesaw do need specific permissions and will be getting this seperatley.

 

Thanks for help in advance

Posted

You need to set out a privacy statement where you explain why you are sharing the data - but you can do this in one document for all websites.

You'll need to say that the websites you are sharing data with are necessary for the running of your school, and you need to keep GDPR info from that website so that you are confident about their ability to manage your data.

 

You can't NOT share info with the DfE whether the students / parents like it or not - and we took the view the same was true of the other websites we use - so mymaths is essential for our maths teaching, so you can't opt out. No parent / student has questioned that.

 

We also decided to have one single photo / video permission - so for our website, or press articles - the photos will be un-named. We use "Edulink" so parents can request electronically to change this consent, and this is a field in SIMS - so staff can easily tell before events whether some studnets have to be kept out of photos.

 

[other schools have given a more bespoke level of consent, so photo consent separately for school wesbite, school newsletter, twitter, press... but we could predict just how many different pictures we'd need to take of the hockey team - one for the school website, then we change a student and take one for the school newsletter and so on....]

 

We publish the privacy statement on our website - so parents (or students) can also see what we've said - and what they are agreeing to.

 

So far - no problems....

 

Peter

  • Thanks 1
Posted
We currently have a GDPR Lead, as our service is one of those online ones. I don't have a login to ask myself, I wanted to see if I could get clarification before going through the 3 person process.
Posted

Most of the online services you use will involve a Data Processing Agreement. These will vary but the idea is that you need to get these reviewed by your DPO.

https://www.youtube.com/c/GDPRinSchools has arange of videos that could help you out here.

Remember, when you say 'permission' you are likely to be talking about the lawful basis of Consent. This is rarely the appropriate one when dealing with schools, and so you need to look at what the purpose is of using the different sites.

https://classroom.cloud/data-processing-agreement/ is a good DPA to have a look at for an idea of what questions you need to ask yourself and the vendor in question.

 

So, it is more a case of letting the DPO know what is being used, ensuring that the DP Lead is looking at DPAs to get the right information together and that any risk assessments are being done, where appropriate.

It is likely to be a case that your DPO is having this conversation with your DP Lead, but it might simply not have cascaded down to you. Ask your DP Lead what information *they* need so that it can be discussed with the DPO.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...