enjay Posted July 6 Posted July 6 Our Computing teacher would like students to use code.org but when you sign up, you have to specifically acknowledge that data will be shared with a company in the US and subject to US data access laws. According to their privacy policy, they are typically the data controller although they might enter into a separate data sharing agreement by which they'd just be a processor. The data would still be subject to the US access laws. How do we feel about that?! Should I allow the data sharing as it is very limited personal information anyway, or push back against the teacher and get them to select a different platform?
synaesthesia Posted July 6 Posted July 6 Put it to your DPO, it's their decision. I would personally push back and say please use something EU based though. 1
djm968 Posted July 6 Posted July 6 The key question isn't "Is the data going to the US?" It's: - "Is the transfer lawful, proportionate, necessary for the educational purpose, and low-risk given the nature of the data involved?" The ICO does not prohibit transfers to the US. UK GDPR allows them provided the transfer mechanism is appropriate and the risks have been assessed From a privacy perspective, Code.org is considerably better than many commercial EdTech platforms: It is a nonprofit educational organisation. It states it does not sell personal information. It does not run advertising. Much of the content can be used without creating accounts. Student accounts can be configured with very limited information. When schools provide student records, it says it will retain them as directed by the school. Get your DPO to do a DPIA - If your DPIA confirms that only minimal student data is being transferred and you can use pseudonymous accounts, I would be comfortable signing this off with documented mitigation measures rather than blocking
enjay Posted July 6 Author Posted July 6 Our DPO did a DPIA on them a few years ago and "failed" them because of the data location. I've asked them to review this, given they say they may take direction from the school (although the policy only mentions doing that for US school authorities not UK ones), and the data held is minimal. Also, as you say, a DPIA isn't a pass/fail thing, it's something to risk assess.
Ditto Posted July 7 Posted July 7 Ask your DPO to explain the UK-US data bridge works - or you can read yourself or geyt an AI summary - see https://www.gov.uk/government/publications/uk-us-data-bridge-supporting-documents/uk-us-data-bridge-explainer for starters. There's also a searchable database at https://www.dataprivacyframework.gov/list It is a movable feast and I believe the recent Supreme Court ruling in Trump's favour puts a potential spanner in the works, however EU is currently standing by it's 'adequacy' decision, but it is a complicated mess which is why I leave these things with the DPO, but push them to be up to date! 1
enjay Posted July 8 Author Posted July 8 16 hours ago, Ditto said: Ask your DPO to explain the UK-US data bridge works - or you can read yourself or geyt an AI summary - see https://www.gov.uk/government/publications/uk-us-data-bridge-supporting-documents/uk-us-data-bridge-explainer for starters. There's also a searchable database at https://www.dataprivacyframework.gov/list It is a movable feast and I believe the recent Supreme Court ruling in Trump's favour puts a potential spanner in the works, however EU is currently standing by it's 'adequacy' decision, but it is a complicated mess which is why I leave these things with the DPO, but push them to be up to date! Code's own privacy policy says they don't have EU adequacy! "The United States has not sought nor received a finding of “adequacy” from the European Union under Article 45 of the GDPR"
djm968 Posted July 8 Posted July 8 Code.org isn't registered on the official Data Privacy Framework List for the UK-US Data Bridge and Code.org operates as a non-profit educational organisation, so it doesn't fall under the jurisdiction of the U.S. Federal Trade Commission (FTC), making it ineligible to participate in the data bridge program. UK schools cannot therefore rely on the simplified data bridge and must use alternative safeguards. Your DPO will need to Complete a Transfer Risk Assessment (TRA) as part of the DPIA. 1
Ditto Posted July 8 Posted July 8 (edited) Yep. We looked at some software that was from a US based company. It fell throught because we have an SLT that can not separate investment from expenditure. The company was on the register so in some ways it made life easier and they even said they would consider setting up a UK AWS implementation to really make life better. In the end we went for a different product which SLT picked and after a 9 month attempt of getting it up and running, it was as weak as I predicted. $otherthings then interverned so it remains on hold as a project! Edited July 8 by Ditto 1
enjay Posted July 8 Author Posted July 8 4 minutes ago, mavhc said: Don't give them any PII, problem solved All code.org would get is students' names and email addresses. For me, this looks like a prime example of risk assessments but our DPO is taking a slightly harder line of "pass/fail" with the DPIA.
djm968 Posted July 8 Posted July 8 29 minutes ago, mavhc said: Don't give them any PII, problem solved This is sensible risk mitigation. I've not looked into user accounts for Code.org, but you might be able create student accounts using generic identifiers. For example, Name: Student 01, Email: [email protected]. Then you can tell your DPO: "We are pseudonymising the data and Code.org will only hold abstract strings. This will drastically lower the DPIA risk score.
enjay Posted July 8 Author Posted July 8 19 minutes ago, djm968 said: This is sensible risk mitigation. I've not looked into user accounts for Code.org, but you might be able create student accounts using generic identifiers. For example, Name: Student 01, Email: [email protected]. Then you can tell your DPO: "We are pseudonymising the data and Code.org will only hold abstract strings. This will drastically lower the DPIA risk score. The teachers would have to manage that, and the students remember their pseudonymised login (which also gives them the opportunity to "forget" it for homework purposes!). I'd prefer to use the sign-in with Microsoft which also limits what information is available to just names and email addresses. The code.org registration process asks for their age (mandatory) and gender (optional) but it's still relatively low risk - especially since you can't contact our students anyway.
djm968 Posted July 8 Posted July 8 Bottom line is it comes down to risk. Microsoft only passes the bare minimum data, usually the name and email address which means you will still be adhering to the UK GDPR principle of Data Minimisation.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now