Little-Miss Posted October 3, 2011 Posted October 3, 2011 Yeah i know its pretty much common sense but i'm trying to help the admin girls. Last year i found out that for free school meals, information such as names, addresses and NI numbers were sent over email just as an attachment. I wasn't impressed. More so with the department for letting people do that without giving them any guidance on encryption etc. Now, am i being massively paranoid or do i have a point?
witch Posted October 3, 2011 Posted October 3, 2011 No, you aren't being paranoid and yes, you do have a VERY GOOD point. Where were they being sent and why did they need all that info anyway? 1
penfold_99 Posted October 3, 2011 Posted October 3, 2011 No, you aren't being paranoid and yes, you do have a VERY GOOD point. Where were they being sent and why did they need all that info anyway? The LA would need the information so they could check the entitlement of the parent to a benefit. A lot of LA staff (not all) believe that if they are emailing another county based/school email is doesn't go outside the council network and is secure. There are a few LAs looking to handle the FSM entitlement checking service automatically via SIF, which would remove issues like this. You are good to be paranoid. 1
Jawloms Posted October 4, 2011 Posted October 4, 2011 I'd say you're not being paranoid because to me that means worrying about something you don't need to worry about. Student info going over email IS something to worry about justifiably! 1
pete Posted October 4, 2011 Posted October 4, 2011 Welcome to finding out most data protection blunders with your data are committed (or initiated by) the LA and associated orgs. 1
Earthling Posted October 4, 2011 Posted October 4, 2011 No, you're not being paranoid at all. But that doesn't mean They're not out to get you. 2
Netman Posted October 4, 2011 Posted October 4, 2011 Here you go... Sensitive personal data means personal data consisting of information as to - (a) the racial or ethnic origin of the data subject, (b) his political opinions, (c ) his religious beliefs or other beliefs of a similar nature, (d) whether he is a member of a trade union (within the meaning of the Trade Union and Labour Relations (Consolidation) Act 1992), (e) his physical or mental health or condition, (f) his sexual life, (g) the commission or alleged commission by him of any offence, or (h) any proceedings for any offence committed or alleged to have been committed by him, the disposal of such proceedings or the sentence of any court in such proceedings. More here: Key definitions of the Data Protection Act You can also order some publications from the ICO site - useful for handing out to staff... 1
witch Posted October 4, 2011 Posted October 4, 2011 So sending out names and addresses unencrypted is OK then?
Netman Posted October 4, 2011 Posted October 4, 2011 So sending out names and addresses unencrypted is OK then? No probably not, but the OP asked in the title what is 'sensitive data'. There is a difference in the DPA between 'Personal Data' and 'Sensitive Data' and how you are supposed to handle them... The Data Protection Act 1998 states, “Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.” This requirement involves a judgement as to what measures are appropriate in particular circumstances. IMO, I would say encrypt to be on the safe side, but it's all shades of grey rather than black or white... 1
Little-Miss Posted October 4, 2011 Author Posted October 4, 2011 Glad its not jsut me then. Its awful. Guessing i just encrypt/password protect it and ring them to give them the password.
Little-Miss Posted October 4, 2011 Author Posted October 4, 2011 Sensitive wasnt the correct word to use i suppose, but you got my point....
CAM Posted October 4, 2011 Posted October 4, 2011 Our LA has a central mailserver for everyone in the borough who is signed up to their E-Mails service and is considered inside the wider LA network. If we want to send E-Mails to other government organisations or schools, we can use a service called CJSM which is heavily encrypted and has a zero tolerance no messing around policy. Downside is the recipient also needs to have a CJSM address. I think it stands for Criminal and Secure Justice Mail.
Little-Miss Posted October 6, 2011 Author Posted October 6, 2011 Ok, so my colleague rings the department to tell them what i had said and that she is going to zip and password protect the file and apparently the women on the phone was not impressed saying we are the only school wanting to do this and all others have sent there's normally and wanted to know who i was and why i was saying this. lol So is there a part of the DPA i can quote to this women. It's ridiculous. Why cant they just write a list of can's and cant's (yeah i know there are grey areas)
featured_spectre Posted October 6, 2011 Posted October 6, 2011 You go Kaz, u r fully in the right on this one and stick to it. 1
teejay Posted October 6, 2011 Posted October 6, 2011 Pick out some bits from this, for instance: Example An organisation holds highly sensitive or confidential personal data (such as information about individuals’ health or finances) which could cause damage or distress to those individuals if it fell into the hands of others. The organisation’s information security measures should focus on any potential threat to the information or to the organisation’s information systems. I would say a list of people with free school meals falls into this category under individuals financial information as it indicates that they are on a low income. Also: Computer security Computer security is constantly evolving, and is a complex technical area. Depending on how sophisticated your systems are and the technical expertise of your staff, you may need specialist information-security advice that goes beyond the scope of this Guide. A list of helpful sources of information about security is provided at the end of this chapter. You should consider the following guiding principles when deciding the more technical side of information security: Your computer security needs to be appropriate to the size and use of your organisation’s systems. As noted above, you should take into account technological developments, but you are also entitled to consider costs when deciding what security measures to take. Your security measures must be appropriate to your business practices. For example, if you have staff who work from home, you should put measures in place to ensure that this does not compromise security. The measures you take must be appropriate to the nature of the personal data you hold and to the harm that could result from a security breach. As it's straightforward and no additional cost to password protect an Office document or use 7-Zip to stick the data in a password protected zip file, then I would say that is the minimum expected nowdays of any organisation. 1
Little-Miss Posted October 6, 2011 Author Posted October 6, 2011 I know its madness! Thanks for the pointers. In these situations i lose the ability to get my point across!! Not a massively confident person, as you can tell i doubt myself a lot lol!!
hsimpson Posted October 16, 2011 Posted October 16, 2011 There are a few LAs looking to handle the FSM entitlement checking service automatically via SIF, which would remove issues like this. Indeed, SIF would remove issues like this, it supports HTTPS and client authentication and the UK data model contains objects which allow you to transport Free School Meals SIF Implementation Specification (UK) 1.3 - SIF UK
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now