-
Posts
141 -
Joined
-
Last visited
Reputation
597 ExcellentAbout EdWhittaker

Personal Information
-
Biography
Teacher and behaviour manager in secondary schools for many years. Now supplying web-based services
-
Occupation
MD Edu. Software Company
-
Interests
Guitar playing, silverwork and stone setting
-
Location
Rochdale
Employer (optional)
-
Company Represented
Schools Data Services
-
Right to delete from backups
EdWhittaker replied to enjay's topic in Data Protection & Information Handling
In principle, yes. You would be advised on the basis of current legislation. However, one would have thought that, were things to be radically different then the advice would include the phrase "However, under GDPR ..." I think the important thing to note, though, is that there is no reason to believe that the ICO will not continue to take a reasoned and pragmatic approach to the issue of archived data when GDPR becomes law. -
Right to delete from backups
EdWhittaker replied to enjay's topic in Data Protection & Information Handling
Here is a link to the full document: https://ico.org.uk/media/for-organisations/documents/1475/deleting_personal_data.pdf -
Right to delete from backups
EdWhittaker replied to enjay's topic in Data Protection & Information Handling
I have spoken to the ICO about this and they do take a very pragmatic approach to the issue of deleting data from backups. Here is the advice: Putting information ‘beyond use’ "The ICO will be satisfied that information has been ‘put beyond use’, if not actually deleted, provided that the data controller holding it: is not able, or will not attempt, (my emphasis) to use the personal data to inform any decision in respect of any individual or in a manner that affects the individual in any way; does not give any other organisation access to the personal data; surrounds the personal data with appropriate technical and organisational security; and commits to permanent deletion of the information if, or when, this becomes possible. We will not require data controllers to grant individuals subject access to the personal data provided that all four safeguards above are in place. Nor will we take any action over compliance with the fifth data protection principle." Again my emphasis at the end there. So, as long as the backup is held securely and you undertake not to retrieve personal data deleted from the live system and the data will be overwritten at some point in the future, then no-one is going to jail. -
Latest Guidance on UPN
EdWhittaker replied to EdWhittaker's topic in Data Protection & Information Handling
Good point! We have a few schools in Wales. Can't see the advice being much different though? (help? How?) -
Following on from a thread started some time ago by GREED regarding the use of UPN by third party providers, DFE have finally come up some explicit advice on the subject. I'm afraid I'm a bit late coming to this, the new guidance was published middle of December. Anyways, if you've not seen it it's here. The relevant section is 2.2, which opens with "Where a school (or local authority) has entered into an agreement with a third party for the provision of an education related service or system then it will be permissible for the UPN to be used within those systems in accordance with the usual transfer controls." Hopefully this now puts the issue to bed.
-
GDPR IT Department - What should we be doing
EdWhittaker replied to dastrix's topic in Data Protection & Information Handling
Here is some clear, up-to-date advice direct from the ICO. I found it useful. https://ico.org.uk/media/about-the-ico/consultations/2014789/draft-gdpr-contracts-guidance-v1-for-consultation-september-2017.pdf -
GDPR & UPN use - Statement from Groupcall
EdWhittaker replied to GREED's topic in Data Protection & Information Handling
@GrumbleDook @GREED and everyone Ha, Sod's law in action. Shortly after I posted the above comment, I received this from DFE: "Thanks Ed and your comments below are useful. We are hopefully that an amended UPN guide will be made available on GOV.UK shortly and this should hopefully contain the clarification you request. The guidance has been updated and is currently undergoing final review and sign-off before publication." I have asked if they would be kind enough to give us a heads up when it's live. Hopefully can put this thread to bed, one way or another, soon. -
GDPR & UPN use - Statement from Groupcall
EdWhittaker replied to GREED's topic in Data Protection & Information Handling
I emailed Gary Connell at the DFE a week ago asking if he could make his clarification more widely available through, say, an update on the DFE website or something. No response so far. -
GDPR & UPN use - Statement from Groupcall
EdWhittaker replied to GREED's topic in Data Protection & Information Handling
okay, will do (not holding breath waiting for reply!) -
GDPR & UPN use - Statement from Groupcall
EdWhittaker replied to GREED's topic in Data Protection & Information Handling
No, indeed that is true. However, what we have received from the DFE is a very clear clarification of that guidance. If anyone chooses to disregard that clarification, which to my mind is unequivocal, then that is of course their prerogative. -
GDPR & UPN use - Statement from Groupcall
EdWhittaker replied to GREED's topic in Data Protection & Information Handling
@GREED and everyone: Further clarification from DFE has been received by a colleague as Follows: "I do not believe the advice above contradicts the currently published guidance but do accept that specifics about sharing UPNs with software suppliers is something which is not explicitly covered within the current guidance. The Department have already planned during the coming months to review the current UPN guidance in collaboration with sector representatives (particularly concerning the advice about adopted and looked after children) and therefore we will feed your concerns into that process to provide a coordinated single update to the overall guidance. From a legal perspective, it should be noted that currently there is nothing specifically set out in data protection legislation which specifies how the UPN should be used other than the usual provisions of the Data Protection Act 1998 that apply to all personal information and therefore the UPN guidance provided by DfE is driven by policy for which I am the owner. I therefore have the authority to confirm that, from a DfE perspective, it would be permitted to make UPNs available to a third party who are processing data on your behalf for the purpose of providing your school with an education service / system in accordance with the usual transfer controls. However DfE have no involvement in the particulars of agreements between individual schools and third party software suppliers and therefore, ultimately, it would be a matter for you as data controller to make an informed judgement as to the appropriateness of sharing in this circumstance. So, in summary, as owner of DfE UPN guidance I can confirm that there is nothing in there that would prevent sharing UPN with a third party software supplier who are processing data on your behalf for the purpose of providing your school with an education service / system. However, ultimately, it would be a matter for your school as data controller to make an informed judgement as to the appropriateness of sharing in this manner." Gary Connell Head of Operations Education Data Division (EDD) Department for Education So, now we know. -
GDPR & UPN use - Statement from Groupcall
EdWhittaker replied to GREED's topic in Data Protection & Information Handling
Well, it's not actually as simple as you make out. When there is a commonly agreed alternative with a consistent format across all MISs then we'll use it. And... er, you effectively have a UPN by another name so, as Grumbledook noted earlier, doesn't that put you back to square one? Anyway, not being rude or anything, but sounds like you don't want the responsibility of making a decision. Not everything in life is cut and dried; sometimes we have to use our skill, training and judgement. -
GDPR & UPN use - Statement from Groupcall
EdWhittaker replied to GREED's topic in Data Protection & Information Handling
The problem is that the DFE have NOT said no. They say that the decision is ultimately down to the data controller, provided they are satisfied that suitable conditions and precautions are in place. Third party applications can viewed simply as extensions of the school MIS. Ok, the data may not actually physically be on the school premises (but then neither is it with some MISs); but data security aside, to all intents and purposes it might as well be. I say this because the service provider has no rights on the data, they can't just do with it whatever they want. Data is coming out, being processed in a defined way, then returned. Because the the guidance from DFE is not explicit and concrete it can be interpreted, and indeed misinterpreted, according to whatever axe you have to grind. If you really don't want providers to use the UPN, then you could argue that; if you don't mind, then you can argue that as well. However, for my money, any disinterested, impartial reading of the guidance would come down on the side of there not being any specific interdiction on the use of the UPN. There, see, I said it. -
GDPR & UPN use - Statement from Groupcall
EdWhittaker replied to GREED's topic in Data Protection & Information Handling
I'll be interested to see what they say. When I have contacted the ICO in the past their advice has usually been along the lines of 'Well, it depends ...' and 'Well, that's up to the data controller ...' so it'll be interesting to see if they come with something more concrete.
