Jump to content

Are we are breaking any data protection or laws by ID smart cards with SIMS photogra


Recommended Posts

Posted

I think I know the answer to this but I’ve been asked to do a bit of research, so thought I’d ask the experts.:D

 

Are we are breaking any data protection or laws by letting the School catering company issue ID smart cards with SIMS photographs and names on to the students for them to buy lunches etc? Data sent to catering company on password protected ZIP

 

Should we have parental consent for this?

Posted

Yes you need parental consent.

 

As long as the catering company is also registered to use personal data and is compliant with the necessary regulations, a password encrypted zip file should be sufficent to transfer the data to them.

Posted
Yes you need parental consent.

 

As long as the catering company is also registered to use personal data and is compliant with the necessary regulations, a password encrypted zip file should be sufficent to transfer the data to them.

 

Word of warning, default zip encryption is very weak and I doubt would be considered secure. Use a zip program (7Zip) that supports AES 256bit at least.

Posted
+1 for 7zip it's really not difficult to crack a zip password, especially files zipped with the Windows integrated zip manager

 

I feel a challenge coming up.....

Posted
Feel free, the fact is that failing to use the strongest form of encryption reasonably available to you is never a good idea, but if you want to challenge it go for it
Posted

Do we really need parental consent as the photo is only on the ID card and destroyed from there printing system once card is printed? The photo is already stored in SIMS/Frog/AD so should we need parental consent for that in the first place?

 

Photo is used just to stop them stealing each other’s cards and using them to pay for there dinner?

Posted

You need parental consent because you are sending their child's photo along with identifiable data outside of the school. Internal systems are different, they are there to help staff identify students who they are working with on a daily basis, once you send data to external companies you need consent.

 

Just send out a letter explaining why you are sending out the data and that the third party company (I presume!) comply with all the necessary data protection laws and good practices.

Posted
Feel free, the fact is that failing to use the strongest form of encryption reasonably available to you is never a good idea, but if you want to challenge it go for it

 

I didn't mean to challenge it in that way :)

 

I meant I thought it might be fun to create a passworded zip, and see who can crack it.

Posted
I didn't mean to challenge it in that way :)

 

I meant I thought it might be fun to create a passworded zip, and see who can crack it.

 

Go for it, I've had a few beers and I'm feeling a challenge lol ;)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...