KWestos Posted July 14, 2008 Posted July 14, 2008 Just found out that the head of one of our departments has just purchased 2 external hard drives and just copied all the entire year 11 data to them. One for him and his sidekick. A couple of points: A) Is this legal (re DPA)? B) Even though some of these year 11 would have never been in his subject area for a GCSE, can he still do this (providing point A is legal in the first place)? C) He claims he is just having a copy of it, even though he knows we have a full backup and we always copy year 11 data to an external drive and put it in a safe. There are a few more questions but I'm that annoyed I can't be bothered to write any more questions. I have just found out. Our network allows teachers to view pupil areas so any teacher can do this if they chose. Where do I stand on this? Any help would be hugely appreciated
jsnetman Posted July 14, 2008 Posted July 14, 2008 I don't see a problem with this, what would be a problem is if he wanted to copy the data back and he had security permissions to do that. Teachers have the right to access the data for marking, the teachers are their legal guardians within school. I allow teachers who want to mark read only access to the year group they want.
KWestos Posted July 14, 2008 Author Posted July 14, 2008 But he has copied EVERYTHING! Not just work within his curriculum, but all curriculum subjects. He has not indicated what he will do with the data, how long he will keep it for, what he is going to do in terms of safeguarding the information - nothing! I find this quite irresponsible, especially when he can login remotely and see this data anyway.
jsnetman Posted July 14, 2008 Posted July 14, 2008 I agree it's a little strange if he intends to take it home but he may have some intense marking to do. here the kids are advised or taught to create subject folders and place say science work in the scince folder but this is very rarely the case and they just save it anywhere in their my docs folder. I would point out to him that due to DPA it was a little unorthodox or maybe even illegal for him to take it home. And yes it appears if he can remote login there is no reason to take a copy home.
srochford Posted July 14, 2008 Posted July 14, 2008 You could argue that he's done nothing different from what you do when you take backups. Provided that he keeps the data safe then there are no real issues (and depending on what the files contain there may be no issues anyway - a set of Geography essays with the name "john smith" on them probably don't constitute personally identifiable data) If he came to you on 1 October (say) and says "can I see the work for person X" would you still have it? Do you make clear to staff that you would still have it? Do they know how long you keep it for and will make it available?
KWestos Posted July 14, 2008 Author Posted July 14, 2008 If he came to you on 1 October (say) and says "can I see the work for person X" would you still have it? Do you make clear to staff that you would still have it? Do they know how long you keep it for and will make it available? This guy knows exactly how we perform backups, how long we keep them for, where we keep the tapes. He knows we keep pupil data for 5 years after they have left. Believe me, this person is clued up!
Ric_ Posted July 14, 2008 Posted July 14, 2008 Do you have a policy for removing data from site? You should have! Does this use comply with that policy? Was permission sought to do this? Who owns the data? What does he/she intend to do with it? It is a little odd... you just need to ask a few questions because until you do, you won't know if there is a perfectly innocent explanation.
plexer Posted July 14, 2008 Posted July 14, 2008 It's your responsibility to keep data safe unless he can prove what steps he will be taking to do this then I wouldn't allow it. In essence every member of staff could do the and you have a big problem on your hands. Speak to the schools data protection administrator. Ben
GrumbleDook Posted July 14, 2008 Posted July 14, 2008 A few issues with this ... 1 - There may be information in there that this teacher actually has no need to access Data Protection Principle 2 - Personal data shall be obtained only for one or more specified and lawful purposes, and shall not be further processed in any manner incompatible with that purpose or those purposes. I would query what the specified purpose is as someone already performs this task, and an administrative task at that (a breach of the 24 tasks?) 2 - Once the data is out of the system you do not know how it is going to be used ... I refer you to the following. Data Protection Principle 7 - Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data. You have no idea what he is going to do with this information and data ... the grey areas are that you have no idea what information is in there. Firstly, if it is going to be kept outside of school it needs to be encrypted. The data needs to be logged as to what type it is, how it is going to be used and details of how it is going to be securely deleted after it has been finished with. Secondly, the data controller for the school should have been notified that this is the case and your school should have had sorted out a data protection policy about this. Finally ... find a user that has personal pics in there, maybe even a database they have used for a project which includes the names, DoBs and addresses of other students ... then take it to senior leadership that when this gets lost and found by someone else that person knows where the student lives, what they look like and how old they are. If that doesn't scare them, then pointing out that as well as the teaching being culpable, so is the data controller, the Head and the Chair of Governors ... all of which will go to jail!
timzim Posted July 14, 2008 Posted July 14, 2008 I disagree that taking away the entire folder is necessarily a DPA problem since most, if not all, of the data would not be classified under the act as 'personal information'. find a user that has personal pics in there, maybe even a database they have used for a project which includes the names, DoBs and addresses of other students Sure, this would be 'personal information' but then the DPO should be making sure that this sort of stuff isn't available on a shared drive, and that kids (and teachers) aren't keeping databases of others' addresses/DOBs/etc in the first place. That in itself, regardless of whether the info is copied out onto CD, could be a breach of the act. Maybe the teacher is just too busy to copy out and rename each and every folder that he/she needs? I know that our kids have the most disorganised home folders and finding a particular piece of work can be a tedious and lengthy process.
Grommit Posted July 14, 2008 Posted July 14, 2008 But he has copied EVERYTHING! Not just work within his curriculum, but all curriculum subjects. He has not indicated what he will do with the data, how long he will keep it for, what he is going to do in terms of safeguarding the information - nothing! I find this quite irresponsible, especially when he can login remotely and see this data anyway. We have the same problem with teachers leaving and copying the entire shared staff folder and their entire departmental folders
PiqueABoo Posted July 14, 2008 Posted July 14, 2008 If that doesn't scare them, then pointing out that as well as the teaching being culpable, so is the data controller, the Head and the Chair of Governors ... all of which will go to jail! You mean fib? Not a strong interest of mine so someone probably knows better, but I thought DPA stuff usually ended up with errant organisation writing a couple of hundred lines on how good they'll be in future. I'd be suprised if there's been any serious criminal proceedings unless unless it was something like someone caught selling police records etc. Anyone?
GrumbleDook Posted July 14, 2008 Posted July 14, 2008 No fib ... The last round of press releases from the ICO are not words of gentle badgering ... 25 June 2008 HMRC and MOD data security breaches Richard Thomas, Information Commissioner, said: ‘I will be taking formal enforcement action against HMRC and MOD following the serious data breaches that have occurred. Someone is in serious smelly stuff and that can mean heavy fines, loss of job, further investigations or doing time. We can talk about scapegoats or being made an example of, but central Govt workers now know that if they make a mistake they will be punished under the letter of the law, and that letter will be big and heavy. That same message is now being pushed out to all Govt agencies and they are working damned hard to make sure there are things such as audit trails for data access, encryption facilities, and documented policies and procedures. I suppose we should all be happy to wait for the wake up call of someone being banged away (worst case scenario), heavily fined (the individuals are liable, not the employer for this), sacked or investigated further due to the nature of the data that was taken off-site / lost ("Now why did you have the names and addresses of all those children you do not teach, along with the details of their favourite sports and so many pictures of them in PE kit?") Personally ... I'm opting for the idea of protecting myself from a screw up by someone else.
GrumbleDook Posted July 14, 2008 Posted July 14, 2008 I disagree that taking away the entire folder is necessarily a DPA problem since most, if not all, of the data would not be classified under the act as 'personal information'. Yes, it is a very grey area ... the problem is that the person copying the data off doesn't know what is on there and is not following some very basic principles. Sure, this would be 'personal information' but then the DPO should be making sure that this sort of stuff isn't available on a shared drive, and that kids (and teachers) aren't keeping databases of others' addresses/DOBs/etc in the first place. That in itself, regardless of whether the info is copied out onto CD, could be a breach of the act. In a recent discussion I had about this I was told that we should examine what data we hold, consider how it is classified (this is a job being done by a number of Govt agencies in more detail at the moment), and consider who has access to it. A medium risk piece of information on its own might be fine, but when you put together a number of pieces of information it may then become high risk ... it is not a single piece of data we should worry about but how the streams or blocks of data can then build into something more. This is why thigns like Shibboleth are being used within RBCs now to connect to other VLEs and services ... anonymise as much as possible and control the rest yourself! Maybe the teacher is just too busy to copy out and rename each and every folder that he/she needs? I know that our kids have the most disorganised home folders and finding a particular piece of work can be a tedious and lengthy process. The problem is that the teacher is 'backing up' the work ... and someone is already employed and authorised to do this under the retention and use of data. It is not within their remit to do it and is also an administrative task, so they are already failing to follow union guidance. How many more things do they need to break before someone raps them on the knuckles and says *Oi!!!! No!!!!*
timzim Posted July 15, 2008 Posted July 15, 2008 I think we have to be careful about what we regard as 'personal data' and what the DPA classifies it as. The Act is very clear that (to quote): "“personal data” means data which relate to a living individual who can be identified— (a)from those data, or (b)from those data and other information which is in the possession of, or is likely to come into the possession of, the data controller" In a school this is talking mainly, but not exclusively, about data in the MIS or which has been extracted from the MIS. The DPA does not apply to students' coursework. If you disagree have a read through your own school's entry on the DP Register - not a single word about coursework or plagiarism or any of that sort of thing. The DPA is about protecting personal information about pupils (and staff) - exam results, disciplinary data, personal details, financial information, health, etc - and preventing it from being seen by all & sundry. Some might argue that coursework should be protected from plagiarism/altering/etc - I agree, but this has nothing whatsoever to do with the DPA. If a teacher was running loads of reports from SIMS and taking these home then I'd be concerned, but I think we need to get things into perspective - taking kids' work home to mark is what teachers have been doing since education started.
GrumbleDook Posted July 15, 2008 Posted July 15, 2008 To make things clear, data held within students' home areas may contain a number of identifying items that are deemed personal. These range from their name, their date of birth, their registration group and classes they are in, their address, details about their family, photographs of themselves. They may also have the above information about other students too. Some of this may be in personal documents, some of it may be contained with classwork, coursework or homework. Whilst there are no specified data classes for types of work, when a mechanic asks what type of car you have you don't just say 'one with wheels' ... you talk about the engine, the parts of the engine, perhaps the CD player, the electrics (and the components of the electrics) ... it is similar with student home areas ... we cannot just say 'coursework' ... we have to consider what that coursework contains. As I have previously mentioned, it is often not the individual items of data that are the issue, but the collective data. Now ... the OP is pretty clear that the person taking this data is doing so to just have a copy of it without specifying what he is going to do with it, how he is going to store it, where it will be stored and when it will be destroyed / deleted. They are doing something outside of what the unions would say is their normal remit. If it is just the DPA side of the arguement you don't agree with, then fine .. we can agree to disagree ... and we can wait until the new guidance comes out. If it is the coursework side of things ... I still struggle to understand why any teacher has access to *all* the work a student does, not just for their particular subject anyway!
elsiegee40 Posted July 15, 2008 Posted July 15, 2008 Like grumbledook, I cannot understand why a teacher in a secondary school has access to pupil home drives. If a teacher has access, they can copy files. These files could be modified and submitted instead of course-work actually done by the pupil. I think exam boards would take a very dim view of this. "It wouldn't happen here" is not an excuse. With external exams "it COULDN'T happen here" is the only way. In primary schools, things are different. SATs don't require course work... however, personal data could still be on the Home drives and teachers, while having access, should still be bound by an AUP not to make copies of the data.
timzim Posted July 15, 2008 Posted July 15, 2008 I can't understand why a teacher shouldn't have access to pupils' work. Are you saying they can't take written work home either? They could change that. Are you saying that all teachers are cheats until proved otherwise? Do network managers have a monopoly on righteousness?
jsnetman Posted July 15, 2008 Posted July 15, 2008 I agree with Timzim, and I guess he is a teacher and I'm a NM. At the end of the day the teachers are the legal guardian of a pupil when they are in school. If a teacher is altering work well thats a problem for the teacher and the school. We as NM's/Techies are there to advise and can point out problems with taking data home, but at the end of the day the head and SMT decide school policy.
GrumbleDook Posted July 15, 2008 Posted July 15, 2008 Why do an ICT teacher need access to the student's Geography coursework? Why does a Biology teacher need to see what the student did in History? Why does a RS teacher need to see what they did in Graphics? If you give teacher access to student areas it should be relevant to their subject. If you are going to allow direct access for a teachers to their subject work then each student has a folders specific to each subject. These are folders are viewable by all but only contents only accessible by that department. This is how many VLEs / Learning Platforms work ... you have access to *your* students for *your* subject. Some schools may also wish to have a 'personal' folder where students can stick no-work stuff that is not accessible by teaching staff ... but may be by their form tutor. All folders are accessible by tech support staff ... but it is their job to look after it all.
GrumbleDook Posted July 15, 2008 Posted July 15, 2008 I agree with Timzim, and I guess he is a teacher and I'm a NM. At the end of the day the teachers are the legal guardian of a pupil when they are in school. If a teacher is altering work well thats a problem for the teacher and the school. We as NM's/Techies are there to advise and can point out problems with taking data home, but at the end of the day the head and SMT decide school policy. The problem is Timzim doesn't think there *is* a problem with taking the data home. The school is In Loco Parentis and each member of staff (not just teachers) have a duty under this. One of those duties is to ensure that the students rights are upheld. That includes who has access to information about them. Part of the problem is that some people are happy to turn a blind eye to the fact that student home areas contain an array of personal information. This worries me more than a teacher taking stuff home actually. It makes me believe that people don't really know what data is held and where? Out of interest ... who here is the DCO for their school and has their name in the annals of the ICO's paperwork?
jsnetman Posted July 15, 2008 Posted July 15, 2008 Interesting article in light of this thread BBC NEWS | Education | Teachers 'put pupil data at risk'
timzim Posted July 15, 2008 Posted July 15, 2008 FYI I'm the NM and not a teacher (although I was once but then I got a real job ). I can't see that there is a problem with teachers taking data home in principle although I agree that taking the entire student folder tree home is not only unnecessary but probably also a little bit suspicious, and I also think that the reason given (i.e. no reason) was pretty poor. I'd certainly be doing a bit of investigation myself in the same situation. However, I don't see anything wrong with staff having access to pupil folders. How else are they going to mark the work? And why do they need to have access to every sub-folder of each pupil's home folder? Erm, they don't but it would take me about a month to set individual permissions for each sub-folder and I've better things to do with my time. Anyway, what exactly are they going to find if they have access to all pupil sub-folders? Teachers are professionals (like it or not) and have a fairly rigid professional structure and registration to ensure they comply with certain standards. What do we NMs have? Do we have a professional body to which we all must belong & which can strike us off if we transgress? Apart from a CRB what guarantees can we give that we will access & protect data in a professional & discrete manner?
contink Posted July 15, 2008 Posted July 15, 2008 Erm... this seems to stumbling into a more detailed issue that veers towards data privacy within school rather than the more worrying issue of data being taken off-site. I would have though that within school the teaching staff are responsible for and in charge of the children. Irrespective of their role or subject, as a teacher I'd have questioned why they shouldn't be able to access the data. Perhaps not be able to modify the data but certainly access it. Otherwise what you're suggesting is that: a) children be totally organised and putting their Geography work in a folder marked Geography. b) setting up ACL's so that the geography department can access the geography folders c) deal with the fact that children will use their file system to hide stuff from teachers once they work out they can. d) make network managers some kind of demi-god that can access anything. which begs the question why we should have access to their work either. Point D. is probably most poinient in all of this... By what right do we say teachers can't be trusted or shouldn't have access when they are argueably more legally responsible for the children than we are. Just playing devils advocate and to clarify, some numpty hauling all the data off site and not clearing the proper hurdles just beggars belief for all the reasons stated above.
pallen Posted July 15, 2008 Posted July 15, 2008 I dont think the point being made that NMs are demi gods. But rather that it is in your interests as someone who looks after the network(and data contained) that procedures are in place and people follow them. VLEs can be setup for pupils to submit work for teachers of their chosen subject, which can by pass the need for teaching staff to access pupils folders. I think the point being made is that the teacher is *probably* not the best person to decide how they should access and store this data. As GD points out, if they copy personal information which then gets out, who is respsonsibile for this breach in security? If the NM can put into place a procedure which allows the teaching member of staff access to the work they need, and keeps security of data for the school, surely thats what they should be aiming for? If a teacher wants a copy of relevent work then surely the school could come up with some policy and procedure which would allow the teacher to only access the work they need. Not a global access to everything? @Contink - teachers shouldn't have to be trusted with data, they should have an account which only allows them access to things they need. If you are employing a Technical person to perform backups, why does the teacher need to do it also? Teachers are responsible for the pupils, but in my experience here, they are not interested in the legal responsibility of what you should and shouldn't do with the school network. Hence many many complaints when I removed software we didn't have licences for when I arrived:rolleyes:
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now