Jump to content

Recommended Posts

Posted

Ok I am going round in circles on this.

 

Basically a company who is installing our electronic signing in system has requested a list of staff to add to the system before they bring it.

Is that ok to send? :confused:

Posted

I was once told by our bursar (she had data protection training) that names were not covered by the data protection act. However I have not checked this or had it confirmed by anyone else.

 

If the system stores any other information i.e. DOB, addresses, phone numbes - then no you can't release it without the individuals consent and they will have to wait until the system is on site.

  • Thanks 1
Posted

If the system stores any other information i.e. DOB, addresses, phone numbes - then no you can't release it without the individuals consent and they will have to wait until the system is on site.

 

This is incorrect.

Posted
This is incorrect.

 

The ICO disagree with you

 

Data Protection FAQs

 

: Can I use personal data for a new purpose or disclose it to a third party?

It depends. You should explain why you want to use an individual’s personal data at the outset, based on your intentions at the time you collect it. If over time you devise new ways of using that information, perhaps because of changes in technology, you will be able to use their personal data for the new purpose if it is fair to do so.

As you develop the goods and services you offer, you should think about whether your customers are likely to reasonably expect you to use their personal data to offer them these products. If you are unsure about this, you should explain your intentions and, at the very least, give your existing customers an easy way to opt out. If you intend to make a significant change to what you do with personal data, you will usually need to get your customers’ consent.

Individuals should generally be able to choose whether or not their personal data is disclosed to another organisation, unless one of the Act’s specific exemptions applies. If you did not make your intention to disclose information to a third party absolutely clear at the outset, at a time when the individual could choose not to proceed, then you will usually need to get the individual’s consent before making such disclosures

Posted
I think from the conference last year the DPA applies to any two bits of information which could be used to identify somebody. I.e having a full name does not count - as there could be multiple joe bloggs. But having the name Joe Bloggs and the DOB 12/06/2010 means you could pretty much certify its that person. Whereas just having the DOB you couldn't.
Posted
I think from the conference last year the DPA applies to any two bits of information which could be used to identify somebody. I.e having a full name does not count - as there could be multiple joe bloggs. But having the name Joe Bloggs and the DOB 12/06/2010 means you could pretty much certify its that person. Whereas just having the DOB you couldn't.

 

This is IMO, wrong. For two reasons. The DPA simply says information that can be used to identify a living individual. If your school sends me a list of names, I already have some information that you might not specifically have sent me, but that you should (must) assume I have. So we are not talking about any Joe Bloggs on planet earth, it is Joe Bloggs who works at X - and that will be enough to identify the majority of people at any school. However, even when dealing with much larger numbers (say many millions) where the vast majority of names might not be unique, there are names out there which are unique (and therefore identify etc). Personally, I wouldn't treat a list of names any different from a list of names + DOB + shoe size.

Posted (edited)

@ToyHeartsFan and @powdarrmonkey

You are both a little right and wrong.

 

Firstly, staff are not customers but employees. As part of their contract of work, you (or your nominated and authorised partners) will process their data on a regular basis and the school's entry in the ICO's Data Protection Public Registrar will cover the data sets, how they are used and who else will make use of them (though specific company names are likely to be held in an annex of your Data Protection policies as well as the Privacy Notice issued to children and parents (formerly called the Fair Processing Notice or FPN).

 

If the information is going to be used by the contracted company it makes no difference whether you release it to them prior to coming on site or not as long as you both adhere to the 8 principles ... that means ensuring that information is protected in transit, that it is held securely, that it is only accessed by those authorised to do so and that it will only be used for the specified purpose for which it was collected.

 

If they are purely asking for names of the staff (to set up user accounts?) then this is a reasonably amount of IL0 data (i.e. it will have no impact if released to the public domain) and should not be an issue ... partly because it will already be mainly on the public domain in a variety of forms. If other data is included (e.g. staff identifiers which are uniquely used by the school) then you have to make an assessment about whether there is additional impact but the uniqueness of user details could better be resolved over a phone call.

 

If you assess that the risk of *any* data being released incorrectly and misused is increased by the data being held in an off-site location. which you do not trust or cannot adequately assess, then yes, insist that the work is completed whilst the kit is on-site. As part of the contract of works to be completed with the company they should also be agreeing to abide by both your Data Protection policies and you understand theirs.

 

Also remember that when you share data you are not devolving responsibility for it ... you are *sharing* responsibility for it.

Edited by GrumbleDook
  • Thanks 1
Posted

Do you have a staff list on your website?

 

If so just point the installer to your website and then they are obtaining information available in the public domain.

 

As most schools and businesses have a staff list/directory available online this would assume that providing a list of names only is acceptable.

Posted
This is IMO, wrong. For two reasons. The DPA simply says information that can be used to identify a living individual. If your school sends me a list of names, I already have some information that you might not specifically have sent me, but that you should (must) assume I have. So we are not talking about any Joe Bloggs on planet earth, it is Joe Bloggs who works at X - and that will be enough to identify the majority of people at any school. However, even when dealing with much larger numbers (say many millions) where the vast majority of names might not be unique, there are names out there which are unique (and therefore identify etc). Personally, I wouldn't treat a list of names any different from a list of names + DOB + shoe size.

 

I didn't think about the school name, but what I mean is if somebody left a print out of a spreadsheet with a list of names on (and no other information such as school name etc) then it would not be covered under the DPA, as the majority of that information is available in the big wide world.

Posted
I didn't think about the school name, but what I mean is if somebody left a print out of a spreadsheet with a list of names on (and no other information such as school name etc) then it would not be covered under the DPA, as the majority of that information is available in the big wide world.

 

I don't believe 'Majority' would cut it. We have a duty to data subjects as individuals and pleading that most of the information was OK won't protect you from the single line of information that is not. I'm not even sure you can argue that your duty is absolved if the 'information' is 'public domain'. First, "the information" consists of the entire list - which if it is the names of people working at your establishment in alphabetical order of surname, is likely to be entirely unique to your establishment (so unless you have previous breaches is unlikely to be public domain). Second, even if information is already in the 'public domain', you do not know if that is because it was intentionally put there by the individual or it was put there perhaps by another data breach. And none of that will affect your registration (the stated reasons why you hold data on a subject), nor is there a get out clause in treatment of an individuals data "well, hey, everyone knew that" - at least not that I am aware of.

 

Just to (try to!) be clear, I'm not saying that the data cannot be sent, just that a list of names without any other information is not a special case and should be treated as you would treat any request for personal data. You might share it with suppliers because your registration allows you to do that as part of conducting the business of the organisation, but you should not assume that a list of names is somehow exempt from DP.

Posted

Everybody's name is in the public domain if they are born in the UK, all i have to do is walk into a public records office and look, the bit that then makes it unique is if you have a second piece of information such as DOB is there as you can then find the exact record needed.

 

Yes an entire list of names is probably unique to your establisment but if there is nothing to bring it back to your company/school, for example if that list was lost in scotland and the school was in cornwall your not going to be able to trace the list back easily.

Posted (edited)

@GrumbleDook

“Firstly, staff are not customers but employees”

I’m not sure this makes any difference although it would help if the ICO referred to them as data subjects rather than customers. I believe the section I highlighted still applies i.e. to release data to a third party you need the consent of the data subject.

 

“entry in the ICO's Data Protection Public Registrar will cover the data sets, how they are used and who else will make use of them”

 

Yes this is the problem. If the sign in system was already in place and the third party was listed in the schools entry with the public registrar when the data subject signed their contract / became a customer there would not be an issue and the OP would not need to ask if it was ok to release the information. But he wants to release information to a NEW third party that the data subjects have yet to approve and that is not listed in the schools entry with the public registrar.

 

 

“it makes no difference whether you release it to them prior to coming on site or not”

I see where you are coming from with this so really the third party should show the school how to import the user data and they shouldn’t actually be given the data at all.

 

“ensuring that information is protected in transit” – encrypt it

 

“that it is held securely” – How can you do this without auditing the third party?

 

“that it is only accessed by those authorised to do so” The data subjects have not authorised the third party and how can the school ensure the third party does not release the data to others?

 

“that it will only be used for the specified purpose for which it was collected” – The data was not collected for the signing in system, the signing in system is being installed after the data was collected.

 

 

 

@pcstru

Our bursar who is the one that has had data protection training said names were ok but I see your point. If say a website listed the names of its customers then I would say that was a breach so there is a very fine line and its best to err on the side of caution.

 

 

 

@sparkeh

You must be dizzy from all those circles and probably need to lie down – lol

At the next staff meeting why don’t you turn up with a list of staff names and ask them to sign it if they are ok with you sending the data? Any people that don’t can then get added once the system is installed.

 

 

 

 

EDIT - Oh and just to be pedantic if the names included their title i.e. Miss, Ms or Mrs you would be releasing two bits of information i.e. their marital status as well as their name...

Edited by ToyHeartsFan
Posted

@ToyHeartsFan

 

There is a difference between customers and employees, and this will be reflected in your Public Register entry. The use of data sets specified within the data classes is not reliant on specifying named companies in that document, but on the general information on how it will be processed and the fact that it will be shared with 3rd parties / partners / agencies for those processes / reasons.

 

An example would be to say that personal information will be used to create, control and allow access to systems under the control of the school and agreed partners. You then specify who those partners are in the Privacy Notice for parents and children, or within the contract of employment or other school policy documents for staff. The privacy notice is an information dissemination route as are the policies. You may consult whilst making decisions about appropriate choice of partners and review the entries in the Public Register (consultation is frequently done by the Governing Body to ensure it fits in with policies and the policies fit in with the entry) but it is not about consent.

 

If you wanted to use the data for a purpose other than one already specified in both the Public Register and the school policies then yes, consult and gain consent where needed. This is why you will see many entries in the Public Register that seem rather vague and open ended ... you will see inclusion of use of personal data for marketing, research and so on ...

 

Yes, the difficult thing is ensuring that the 3rd party is following your own stringent rules about managing and handling data. Some of this does not have to be done via an audit but by the contract of works between yourself and the 3rd party. If they state in the contract that they will do X to allow them to comply with the laws of the land and your polices and they fail to do it, then you can be said to have taken reasonable action to ensure the DPA (and its 8 principles) have been followed. You can look at this as a way of then taking legal action against the 3rd party to cover any liabilities you have incurred as a result of any breach ... and so on.

 

This is why a long period to time (and a fair chunk of money) is spent on frameworks ... to cover areas like this off so that when schools sign into them (since a number of LAs don't do it on their behalf anymore, of course) then the responsibility of dealing with this is shared with not just the 3rd party but also with the framework creator (e.g. a regional group, DfE, etc).

 

My apologies if I wasn't clear enough about those aspects in my original reply. As always, if a school is concerned about their responsibilities then they should gain formal legal advice (i.e. all my advice is given with no acceptance of liability!)

Posted

Oh and just to be pedantic if the names included their title i.e. Miss, Ms or Mrs you would be releasing two bits of information i.e. their marital status as well as their name...

 

Not pedantic enough! Ms does NOT convey marital status - that is the whole point of it...

Ms Witch..:)

Posted
Not pedantic enough! Ms does NOT convey marital status - that is the whole point of it...

Ms Witch..:)

 

"Ms. derived from the female English title for all women, Mistress"

 

Does that mean its Mistress Witch? :getmecoat:

Posted
"Ms. derived from the female English title for all women, Mistress"

 

Does that mean its Mistress Witch? :getmecoat:

 

And not forgetting those staff who choose to remain with their pre-marital name for professional reasons also keeping 'Miss' too.

Posted

I have to say I am heartened that the DPA talk I gave at last year's conference has been remembered!! I m alined up for the same opening slot this year as well. After that I'll be opening for Bon Jovi (in my dreams).

 

This is one of those lovely grey areas that solicitors will take lots of money off people to argue both ways!!

 

First things first, your duty of care to the information. If this were me, and I was unsure, I would treat the information as sensitive, until proved otherwise. So, firstly, I would ensure that the target organisation is registered with the ICO (easy enough to do online).

 

If they're not, don't send the info, just tell them to get registered (as it's a legal requirement if they hold personal data, and are a business).

 

If they are registered, I would consider this data use pertinent to the individuals job role, and so be happy to send it. I would encrypt in transmission though. I would also ask (nicely) about the target companies data protection training, and access to the data.

 

Data comes under the DPA if a living individual can be identified. I would think that knowing someone is a teacher as school 'X' and their name would be enough. In transit though, if it's only a list of names, it may not fall under the act. I would still treat the data as if it is though.

 

Short answer - yes the data maybe covered, and treat it as though it is, but this sounds like a proper use for the data, so you would be OK using it for this purpose.

 

I hope to see a lot of you at the conference - come over and say 'Hi'.

Posted

Thanks for everyone's input.

I checked the companies ICO registration, quizzed them on their DP procedures, encrypted the document and sent it.

 

*deep sigh of relief*

Posted

Data comes under the DPA if a living individual can be identified. I would think that knowing someone is a teacher as school 'X' and their name would be enough.

 

Some people can be (uniquely) identified JUST by their name.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...