Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Hi guys, hope you can shed some light...

 

We send out our 'School Calendar' to all students, memebers of staff, parents and others (school bus drivers etc). Now, we have had a change to the powers that be and they have now published the full school roll in this booklet too. So, student names, form, house etc.

 

Is this ok? I'm not too 'hot' on this side of things and lady that normally deals with this (db admin) is off ill for a few weeks.

 

Quick responce would be tony the tiger...greeeeeeat!

Posted

I'd say if nothing else the fact that its sent to 'others' could be a problem. According to the BECTA advice:

 

Data protection legislation states that all those who hold personal data, whether on paper or electronically, must keep that data secure. This also applies to schools. Personal data is defined as any combination of data items that identifies an individual and provides specific information about them, their families or circumstances. This includes names, contact details, gender, dates of birth, unique pupil number (UPN) and so on, as well as other sensitive information such as academic achievements, other skills and abilities, and progress in school. It may also include behaviour and attendance records.

 

Suggests to me that the names, and some of the other information, being sent out to so many people might violate this, though I can't see any problem with the calendar.You can see the latest BECTA advice here: Becta Schools - Leadership and Management - Data protection - Data handling security guidance for schools

Posted

From the above post ... no, it is not ok without the permission of the data owners (the parents or the students themselves if they are over 12) and the people who receive the information are not allowed to share it with others.

 

If it is sent to the school bus drivers then they should only have information that is relevant to them.

 

The data you mentioned would probably hold the student full name and their for / house, thus giving an approximate age as well.

 

It is one of those areas that will probably be ignored or the rules will be twisted around slightly, but it is a fine line. I suppose by only including their initial and their surname it would reduce the amount of personal information, making sure that no pictures are available identifying these students (eg a whole class photo with names, etc) and removing those that do not want their names a school might consider they have gone through due diligence to reduce the risk until it is acceptable.

 

As long as the school is aware of the implications and the SIRO and Head have signed it off ... then you can say 'on your heads be it!'

 

Another area to take care ... if people are aware that a particular form / house contains only / mainly students with SEN then publishing who is in this form could be considered sharing SEN information.

 

I have had some more feedback on DP about use of UPNs for another thread ... this has reminded me to updtate that thread ... I'll try and do that later.

Posted

To be honest, the school I went to did this. Partly because the house structure was quite important and also because parents would tell you which kids to avoid ("don't play with those children, they are smelly and so are their parents!") but there was quite a bit of snobbery at the school ... which would go out the window as soon as we started playing with one another!

 

Or it would be a good way to find people that the parents know in other year groups ... often the older students were told to keep an eye and help someone settle in, and for younger students it gave someone they could go to if they had any worries ... soemthing that many schools are spending ages trying to formalise nowadays for peer mentoring!

 

It still has a place to some extent, and schools are going to have difficulties dealing with how to share this info.

Posted (edited)

There is definitely a dividing line about data sets, which is related to the number of items. As I understood from Becta's guidance, if the list is over 1,000 names, then it isn't legal to make it available in this way (even with permission).

 

If it is under 1,000 it may if individuals have given permission, and if it is unlikely that somebody could identify an individual from it. A list of names might be okay. A list of names & classes wouldn't be. Names & Houses - hmm, nice grey area!

 

You could try asking the question on the Becta Information Management>Data Security "Collaboration Community", that was set up to allow people to discuss the issues a couple of months ago. All 3 posts have had an answer ;)

 

Ray

Edited by rayfleming

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...