Jump to content

Data Protection - Can we send out a directory of parents to other parents?


Recommended Posts

Posted (edited)

Basically, I am fairly sure this is against data protection but can't find the bit that basically says it. Deputy head wants to send out a parent directory to all parents in a year group, this is to contain all address and phone numbers of all in this year (so they can ring round and organnise parties, etc etc). Is this allowed without consent? To add to it, a member of staff is also a parent so effectively we'd be publishing the teachers address and phone number too...

 

Cheers

 

Just noticed the typos in the thread title - sorry (i'm not stupid honest...)

Edited by Ben_Stanton
Posted
If you print it out, and give the hard copies then the data protection act may not apply - but I'm pretty sure that sending that information out electronically is definatly against the rules.
Posted

Data protection act does apply to hard copies; you absolutely must get consent before you do this.

 

The school I used to work had a field in the database effectively saying "address not for publication" so it's quite easy to just print those who are happy to share their info.

 

You've almost certainly got some children where there are court orders preventing access by one or both parents - you could end up not just possibly breaching some bit of the DPA but being directly in contempt of court!

Posted
If you print it out, and give the hard copies then the data protection act may not apply - but I'm pretty sure that sending that information out electronically is definatly against the rules.

 

IIRC this kind of loophole was only present in the 1984 Act. The current legislation being the 1998 Act.

  • Thanks 1
Posted

mpe is correct; the Data Protection Act applies to all personal data held by the organisation, including data not stored electronically, and even if it was never stored electronically in the first place. Those last two parts were a key measure included in the 1998 revision of the act.

 

If you send such a directory out without the explicit consent of each and every person on it, it is most definitely a breach of the Data Protection Act.

Posted
mpe is correct; the Data Protection Act applies to all personal data held by the organisation, including data not stored electronically, and even if it was never stored electronically in the first place. Those last two parts were a key measure included in the 1998 revision of the act.

The relevent issue is data regardless of how it is stored. (Including using data storage methods yet to be invented.)

If you send such a directory out without the explicit consent of each and every person on it, it is most definitely a breach of the Data Protection Act.

Even if you get this you will also need to specify this use on your registration with the Infomation Commissioner's Office.

 

In addition there's also the matter of where the money to do any of this would be coming from.

  • Thanks 1
Posted

For our pupil directory, our PTA send out a specific request letter for information. (Actually we send the letter for them using parentMail, but that's as far as it goes)

 

If the form isn't returned, the family is not included. We never ever use data given to the school as contact details.

Posted

As Steve pointed out you may also have families at refuges and if so you would not only be putting that family in serious risk but maybe 10 to 20 other families not even at your school.

 

Russ

Posted

I'm not an expert at this sort of thing, but why would a school provide names and addresses of parents for parties without an educational benefit what-so-ever.

 

Parents would need to give explicit consent to be part of the directory and would have let them opt into the directory rather than to opt.

 

It's to be a child protection issue if this data got into the wrong hands. It would be a big no from me, if I was asked that question here.

 

BTW is this a primary or secondary school were talking about?

 

Thanks

Posted

No just plain no... say the parents got a hard copy (either printing or by post). What then happens if its thrown in the bin? it goes outside... some dodgy people may find this info and put it to all soughts of misuse.

 

It's a bad idea, with very little benifit (pros) and huge dis-benifits (cons) and add to that lots of risks (cons that could or couldn't happen).

 

p.s yes i've been on a prince2 training course :cool:

Posted

Slightly off-topic but ... PRINCE2 ... always make me think that it is describing the pint-sized singer ... the artist formerly known as Prince but is now known as Prince ... doesn't that make him Prince2?

 

Back to the thread.

 

1 - The school has the right to use the data from the student and parents only as required to complete the purpose of the school, educating the student and ensuring the safety of the student whilst In Loco Parentis. It does not have the right to hand the information to any party that has not been explicitly granted access. The common form of granting authority for this is the Fair Processing Notice. Unless all parties agree this with all parties it cannot be done.

 

2 - The entry with the ICO describes how the different classes of data will be used, defining the appropriate use. You can bet it does not have a section stating it will share it with external groups who may have no requirement for it and a group which you cannot stipulate how they will use the information either (8 principles of Data Protection apply in bucket loads at this point).

 

3 - Common sense rules apply. Tell the Deputy that if you are going to do this then you should also give out all home addresses and contact details of staff to the parents too. I wonder how quickly the opinion changes.

Posted

While this has been an interesting thread on data protection (thank you all), I think there's a larger issue here, namely that DH slept through their CP training or just doesn't have any common sense and probably can't be trusted not to lick a frozen lamp post.

 

How can they even be *asking* this question?

Posted

Other posters are quite right, as far as I understand it. Now our parent directory was launched in response to a parent who brought in her son's previous school's directory. Secondary school; each class photographed with form teacher; names, addresses, phone numbers and emails of all parents and teachers shown. This directory was used very heavily to manage and run events to support the school, and was publiched as a matter of course, supported by some parents advertising their companies or whatever. This of course is totally impossible here under the DPA, but the experience (in the USA) was, she explained, wholly positive.

 

What we've done is to get parents to sign a consent form; all that we disclose in the directory is that John Smith's parents and Mr Mike Smith and Miss Jane Jones, their phone number (landline or mobile to taste) and the area where they live. This seems to be sufficiently informative to be useful and sufficiently anonymised to do the job, with signed consent. The complaints we've had have been from parents who didn't sign the consent form and were therefore omitted! We get the data from the MIS (which also has the consent recorded), tidy it up, check it and then send that to the parents' association who actually print and distribute.

 

Seems to work. In anything like a sensible world I'd far prefer the US version.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...