Jump to content

Recommended Posts

Posted (edited)

What do others do in regards to satisfying the need to gain consent from Parents for the use of services like Canva etc?

Have you added it to existing consent forms for example the video and photo consent or some other way for example in acceptable use policies? 

Edited by gpjt
Posted
2 minutes ago, sigma said:

We block sites until parental consent has been obtained where necessary.

 

How is the parental consent gained? 

Posted
13 minutes ago, gpjt said:

 

How is the parental consent gained? 

 

Not my problem, it's for teachers to do.   😄 

 

I believe they use Parentmail or whatever.  I know that's not exactly a useful reply.

 

I think it helps focus the mind on what sites are appropriate for the age group.  We don't have a sixth form but still have teachers wanting pupils to sign up to sites where the minimum age is 18 "because edu".

  • Like 1
Posted

Don't rely on consent for things that are* core school functions (as in, they're not optional) or the agreed mechanism that helps fulfill that functions.

 

If the DfE says "you need to share attendance data with us via Wonde", that's not based on consent.  If the school has Microsoft 365 as their established way of working, that's not based on consent.  If the school needs to store a photo of Jimmy such that they know what he looks like (and can provide that to the police should he steal just the one swan), that's not based on consent.

 

*as in, a headteacher would agree with that definition.  If it's just Geoff wanting to try out the latest shiny widget with the children and the HT doesn't know WTF he's up to, that's one thing.  If it's "we as a school have decided to use Platform A for purpose B", then you don't rely on consent.

  • Like 3
Posted
12 minutes ago, pete said:

Don't rely on consent for things that are* core school functions (as in, they're not optional) or the agreed mechanism that helps fulfill that functions.

 

If the DfE says "you need to share attendance data with us via Wonde", that's not based on consent.  If the school has Microsoft 365 as their established way of working, that's not based on consent.  If the school needs to store a photo of Jimmy such that they know what he looks like (and can provide that to the police should he steal just the one swan), that's not based on consent.

 

*as in, a headteacher would agree with that definition.  If it's just Geoff wanting to try out the latest shiny widget with the children and the HT doesn't know WTF he's up to, that's one thing.  If it's "we as a school have decided to use Platform A for purpose B", then you don't rely on consent.

 

As long as you have a DPIA, should be covered.

Posted
5 hours ago, pete said:

If it's just Geoff wanting to try out the latest shiny widget with the children and the HT doesn't know WTF he's up to, that's one thing.

 

Its always Geoff...   At least, that's the context I was referring to.  

Posted

Am I right in thinking that some of this is US based, not UK? I'll try to cover both.

In the UK, when EdTech solutions are used for the education, pastoral care or running of the school, then those vendors are being used as data processors and through an intermediary (i.e. through the school who is the data controller). This means they do no count as Information Society Services and so are not covered by the Children's Code (Age-Appropriate Design Code) in the UK. Where the school is the Data Controller and processing the data under their official authority or in the public interest, then the lawful basis is likely to fall under public task (under art. 6 of GDPR ... I'll leave art. 9 for the moment to keep it simpler). 

 

In the US, at the moment the efforts to introduce variations of the Children's Code have been centred on commercial/consumer rights and not where it is applied to schools/direct education.

The US also doesn't have the range of lawful bases that we get under GDPR, and so you have the need to get Parental Consent for children under the age of 13 if the school wants to use edtech. As far as the vendor is concerned, they don't need to see it for each student, and as far as the school is concerned they can list everything they want to use and just ask once to cover them all. There are some issues with this last one as the lack of granular records can be problematic but I've seen it done in a variety of ways. For COPPA, the FTC do make amendments and the most recent ones do clarify about de-identified data, reuse by vendors and a few other bits ... and COPPA 2.0 is still not close to being passed ... so you get the MIS being used to record that a form has been sent in, a Google/MS form being used, of a few apps that do send a request to the parents on behalf of the school and so on. 

 

The simplest way is a form, providing the purposes for using data, what data it actually is and who will be doing it for you. Ask for agreement, keep the record and on you go. Some schools record each year, some do it only once. The risk cannot be passed onto the EdTech vendor, it is down to the school (or District) to make sure it is being recorded correctly.

 

This is a vast simplification and there are some variation out there, so I tend to say to UK folk to speak to your DPO and to US folk to speak to your District.

  • Like 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...