Jump to content

Recommended Posts

Posted

As a school, we check everything that is flagged as "safeguarding" every day, so that appropriate action can be taken if necessary. It is very rare for us to find anything that is not a false positive, and mostly it is a "bad result" from a perfectly legitimate search because of poor filtering categorisation, and we record as such. In the event of a subject access request, we cannot have inaccurate records stored against pupil's names which would be the case if we relied on the automated filtering output directly. Our safeguarding alerts are 99.9% garbage, even after I've taken steps to mitigate as many FP's as possible.

 

As a result of a high profile media case, it appears that "making" indecent images can have a wide legal definition.

 

The Crown Prosecution Service says

 

it can include opening an email attachment containing an image;

downloading an image from a website to a screen;

storing an image on a computer;

accessing a pornographic website in which an image appears in an automatic pop-up window;

receiving an image via social media, even if unsolicited and even if part of a group;

or live-streaming images of children.

 

I am concerned that this wide ranging definition could be legally problematic for any staff checking filtering results in the event that any of the above conditions were met, possibly even for the filtering companies that supply the urls to us.

 

Thoughts?

Posted

The CPS's information there is clearly from someone with no expertise or input other than perhaps prosecution. For years I assumed "making" referred to taking the original photographs or manipulating them, however the term is just too loosely used. And indeed it *could* have implications, especially as you point out things like automatic pop-ups to which the user may have absolutely zero control over. Even we, with the best filtering systems known to man short of turning off the internet can not 100% guarantee that our users or indeed we are safe from them; just mitigate the risk.This is why it is absolutely imperitive to log everything we do; every change we make to the filtering system whether it's a URL whitelisted or blocked, why, if it was in reference to an incident whether it's safeguarding related or not (most of it will be behaviour/class control).

Even currently I don't log false positives that come through; perhaps I should be, even if just to show due diligence in checking context, why's and what fors. We of course then run into the risk of more paper than work, but maybe a necessity.

 

On an aside, the language needs clearing up. The oxford dictionary has a clear definition on "Making" so it shocks me to this day that these supposedly vastly intelligent legal folks continue with the use of language in this way. I mean why can't it be differentiated? Manufacturing, distributing, viewing, manipulating etc. Not difficult to understand, each may have a different level of severity. The so called definition you've said comes from the CPS there basically classes 99% of us as child predators...

  • Thanks 1
Posted

'making' in this context just means copying in this context (copying from the wire to memory, disk or rendering).

Presumably the police forensics are excluded from this definition when they clone a phone, I guess the same would apply to those storing copies assuming they have the legal basis to do so. I doubt it's been tested in court.

Posted (edited)

I am concerned that this wide ranging definition could be legally problematic for any staff checking filtering results in the event that any of the above conditions were met, possibly even for the filtering companies that supply the urls to us.

 

Thoughts?

 

Yes. If your computer downloads it (in the technically pedantic sense) while checking a suspicious link you are within scope of this law.

 

Our filtering/monitoring platform uses language that increases in "alarm" based on what it evaluates the severity of the material to be. Anything that crosses a threshold isn't reviewed, but instead escalated to the CP Lead who will call the student and have them review (verbally, not in the ocular sense) their own browsing/chat history.

 

Stay well well away from anything that might cause your computer to access these types of images.

 

This is also why (generally) the urls of CSAM and Extremist materials are managed at a trans-national / regional level . Your filtering provider should not be sharing those with you. In the UK they operate under the following codes of practice, which are derived from work by the US and EU.

 

https://www.gov.uk/government/publications/online-harms-interim-codes-of-practice/interim-code-of-practice-on-online-child-sexual-exploitation-and-abuse-accessible-version

 

https://www.gov.uk/government/publications/voluntary-guidance-for-internet-infrastructure-providers/voluntary-guidance-for-internet-infrastructure-providers-on-preventing-terrorism-online-accessible-version

Edited by psydii
  • 2 weeks later...
Posted

We had a meeting with a few officers from East Mids Special Operations Unit a couple of years ago and they referenced the possiblity that just viewing the image in a capture could constitute an offence, unless you take reasonable measures to ensure the material isn't accessed or shared by anyone else other than the police. ie, Don't show your boss/head/DSL to ask for an opinion on whether it needs to be reported. You should either report directly or inform DSL that it needs to be reported but you can't show them. This guide from Securus forms the basis of the way we handle these situations: https://securus-software.atlassian.net/wiki/spaces/SSKB/pages/328020/Guidance+for+Printing+Copying+or+Emailing+Captures

 

Thanks,

  • Thanks 2
Posted

It took me a minute, but I have had it suggested that this is the document to read:

(nb, this does not constitute legal advice from me or my employer!)

 

https://www.cps.gov.uk/publication/memorandum-understanding-between-crown-prosecution-service-cps-and-national-police

 

This indicates that there's a decent amount of "good guys" protection. Be sure if you do discover something you suspect may be illegal that you report it to the IWF as soon as practically possible (particularly if it is hosted on the internet somewhere) and that you make as few copies as is necessary (I would say clearing your browser cache would be a good idea, just for the sake of completeness)

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...