Jump to content

maturelady

AFK GNU
  • Posts

    91
  • Joined

Everything posted by maturelady

  1. Hey @edugeekers I've told the DfE that schools are desperate for guidance on GDPR from them and ICO. They asked me to gather a list of the top issues schools are facing so they know where they can help. Do I go back to the DfE and say 'well actually just a handful of schools feel they need help from the DfE' This isn't a voice its a whisper! Yes I am telling you off! Please say something even you agree with another person's post.
  2. I agree a deputy head can be DPO provided he/she is not a direct decision maker for systems that process personal data. Likewise a school governor or any other senior member of staff. Please add to my request for things to ask the DfE - I need as many cries for help as possible. If I get only a few they may just say 'schools don't seem to need help - not many are asking' http://www.edugeek.net/forums/data-protection-information-handling/188681-lets-get-our-voice-heard-dfe.html
  3. It has been stated absolutely that GDPR will be fully implemented and the law is currently passing through parliament at the moment. If we trade with Europe we have to. In addition other Commonwealth countries are looking to change their DP laws to match GDPR. Sorry @StevieM there's no way out.
  4. I think everyone would agree we would like the DfE to provide us guidance and clarity on GDPR. I have found someone who is genuinely listening to our concerns about GDPR. I would like to co-ordinate a 'voice' into DfE about the areas where that guidance is most needed. Here’s my top 3 issues…what are yours? The more replies we get the more compelling our cry for help. The DPO - who is the best person to take this role in school and how will this person be funded? Legal basis for processing - when can't a public funded school use 'Public interest' as a legal basis for processing? SARs - what data should and shouldn't be included in a SAR? Keep them coming please. I'd like to get back to the DfE as soon as I can.
  5. Sadly one of the authorities I mentioned to you @GrumbleDook have been instructed 'from above' to NOT offer the service. They were really keen too. They have been told that there is too much risk. I despair! Let us know if you know of any LAs in England, Wales or N Ireland offering a DPO service. Scottish schools are different, the LA not the school is data controller - the buck is 100% passed north of the border.
  6. I'm investigating the costs associated with schools implementing GDPR. Does anyone know of the costs relating to engaging an outsourced DPO? What do these people offer in terms of understanding what goes on in schools? Has anyone got any quotes? Your thoughts on what is being offered? It would be good to share this with others, rather than guessing what should be charged. Thanks
  7. I think we need to be very careful as we're into uncharted territory assigning what is the legal basis for processing data. @GrumbleDook and I spend a lot of time in this area and I think @GrumbleDook would agree with me that there are so many unknowns still to be clarified. I think its fair to say that a school is a public body, carrying out a duty for the public interest, ie educating children. Thus it would follow (in my opinion, and only my opinion, as no one has said Yes you are right or No you are not) that everything which is done in schools which can be classed as a normal task or processes in the education of children the data processing can be classed under the public interest umbrella. Attendance, progress tracking, school meals management, teaching and learning, keeping kids safe and informing parents, in my opinion, are tasks that are normal in school and therefore the data used has a legal basis for processing in the public interest. Inviting parents to barn dances would not (in my opinion) as neither would Ski trip communication, taking photographs or selling school uniform. We need so desperately directions from the DfE but as yet there are none. The regulations are quite simple to understand, setting them to a school context is the challenge. Whatever you do you are going to have to justify your decision and saying 'this guy on Edugeek said so' wont carry much weight. Please be assured that we at GDPRiS are pressurising ICO and DfE for more information and you have my promise as soon as we know anything we will share it with you.
  8. If what you say is correct MathsWatch does not come anywhere near today's requirements and regulations. These are clearly laid out - here's one site that outlines what is required https://www.amityweb.co.uk/blog/is-your-website-legal Today you can take the risk using a company that does not meet regulations, on 25th May 2018 it will be illegal for you to use them. I would not expect any company yet to be publishing how they are GDPR compliant although I would hope that they will be letting their customers know that becoming compliant before 25th May 2018 it is of the highest priority for them.
  9. I'm nowhere nearly as knowledgeable as @GrumbleDook but I'll answer any questions as best as I can while he takes a break.
  10. Yes, it’s all conjecture until we see the final act and I was merely stating possibilities not fact. What is clear though, a fixed age has never been suggested to be part of legislation before as it is here. In view of all these considerations, we will legislate to allow a child aged 13 years or older to consent to their personal data being processed. In the past there’s been ‘suggested’ ages and very woolly statements. As for using public interest as legal basis for processing, it’s a minefield. Take the standard text messaging service – a school could argue, correctly in my opinion, that communication with parents regarding attendance, progress, behaviour is the public duty of a school and therefore the data may be processed legally as being of the public interest. However if the school uses the same messaging service to tell parents about the school fete or barn dance – this is definitely marketing and consent needs to be sort. The data map for the same data fields for the same processor needs to carry 2 legal basis for processing. Welcome to my world!
  11. Well its official then! GDPR will stand after Brexit and more. For those that want to read the official release here it is: https://www.gov.uk/government/news/government-to-strengthen-uk-data-protection-law https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/635900/2017-08-07_DP_Bill_-_Statement_of_Intent.pdf However this has to be the scariest statement in the release: In view of all these considerations, we will legislate to allow a child aged 13 years or older to consent to their personal data being processed. The full impact of this is not yet clear. Most data in schools will be legally processed under the Public Interest umbrella - that's good, kids can't stop standard personal data flows. However, it is now clear that any child over 13 is a fully recognised data subject and thus all rules apply. So the student not the parents must be informed of what, where, how and why their data is used and they can be given the opportunity to challenge its use. Data check sheets will need to go to students first not parents. ...and a question I can't answer - does the legal basis for public interest data processing pass on to the parents or can a student of 13 say? "I know you can process my data without my permission to do things in school but you don't have my permission to share it with my parents." I dare not think of the consequences were this to be true. Your thoughts and comments please
  12. @LukeRowberry I doubt anyone is compliant at the moment and I would not expect to see compliance statements emerging until the New (calendar) Year
  13. The bottom line on all of this is accountability. If you can justify that selling uniform is a part of the public interest banner then its OK. I personally have reservations about that but it will be every school's own decision. Their DPO will advise them if they believe their justification is sound. Remember the decisions you make will only be challenged if you are investigated. Whilst I cannot say this with 100% certainty but if an organisation has carefully thought and DOCUMENTED its decisions about how personal data is legally processed the ICO must take this into account when deciding the outcome of the investigation. I believe schools are in a much, much better position than many private organisations. Protecting data has been in our 2nd nature. GDPR brings a lot of common sense and things we already do. Its the proof and documentation where effort is needed.
  14. Sorry @enjay - I didn't mean you were hung up on consent - many of the threads are. There will be times where consent is needed and Yes you are right if consent is required it will be more painful. I think it would be valueable if we expand this thread to listing when we think consent is required. I'll kick off: Payment systems (that's the one I know best) - if you use your payment system to collect money for anything other than the standard processes in school, ie dinner money and curriculum related trips and I believe most schools will, then consent will be needed. Many schools sell uniform, resources, tickets to productions, etc - it would be difficult to justify these under the public interest tag. Messaging system - if these are used only for standard school related communications then provided you can demonstrate that's all you do its OK. However if you bombard parents with messages about non-essential school issues parents could be justified saying these are not under the public interest umbrella and therefore their consent is required before you send them
  15. I think people have become too focused on the consent bit and less on the reason for sharing data. Number one priority is that you and your 3rd party are lawfully processing data. In my earlier post I have explained what these are. You MUST be able to assign a lawful basis for processing data. In many many cases as @GrumbleDook says you will be able to demonstrate a lawful basis for processing which does not request gaining consent. However your data audit is much more than just establishing the lawful basis for processing. You must demonstrate why you are processing, where this happens, when including your retention of this data and how by ensuring the processing whether its you or a 3rd party are carrying it out compliantly. I am working on advice regarding privacy statements for schools, I will create a template and will publish this through this forum in the next few weeks. That is the place to say who, what, why, when and how.
  16. 3rd Party Suppliers I cannot stress enough how important it is for any 3rd party to which you send personal data of any kind demonstrates they are GDPR compliant. On 25th May 2018 it will be illegal for you to use any that are not. Very few will be compliant for sometime but get assurances that they are working on it.
  17. GrumbleDook is spot on! Here’s a bit more though on consent and the legal basis for processing Non- explicit consent will no longer be acceptable. However, you need to consider that for much of the data processed in school consent may not be needed. That applies to both staff and pupil data. Get your head around 'what is the legal basis for processing data' then the muddy waters become clearer. Here’s the basis for legal processing: 1 Consent of the data subject This is the obvious one - someone has given you consent to use their data 2. Processing is necessary for the performance of a contract with the data subject or to take steps to enter into a contract Staff are contracted to school and you can’t fulfil that contract, ie pay them, without a payroll package. 3 Processing is necessary for compliance with a legal obligation Schools have a legal obligation to send data to the local authority and/or the DFE and other bodies. 4 Processing is necessary to protect the vital interests of a data subject or another person An interesting one this – a school can argue that in many cases data is processed to ensure child is safe and well cared for. 5 Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller This is the one schools will rely on the most. Teaching kids in a school is in the public interest and therefore data may be processed to ensure the school functions effectively 6 Necessary for the purposes of legitimate interests pursued by the controller or a third party, except where such interests are overridden by the interests, rights or freedoms of the data subject. As a silly example - you may decide to process data regarding which football team students support because you legitimately want to offer red cakes and blue cakes at lunch time and want to know how many to bake. That’s OK. However, if you physically partition the students or say Man Utd supporters can only have red cakes you would fall foul of the law. Saying all that the data subject must still know Where, What, Why and When their personal data is processed.
  18. Appointing an external DPO will be expensive but if you can find someone inside school - ie someone that is not involved in decision making for data management then time will be your biggest expense. Remember the DPO is overseeing compliance not doing it, to get systems in order will still need you guys. Getting you GDPR compliant and then keeping you there will eat up a lot of time. ...and when someone is doing this who is doing their job.
  19. I am trying to find if there is any funding for GDPR implementation in schools. I have asked a number of local authorities under the freedom of information about funding for GDPR implementation in the authority. I've had 1 reply. Here are the questions and answers: 1. How much of local authority budget in 2017-2018 has been allocated for resources to ensure the authority meets its GDPR statutory requirement by May 2018? xxxxx County Council has allocated up to £179,000 of budget for 2017/18 to the GDPR project. 2. How much of this budget has been allocated to schools? None of this budget has been allocated specifically to schools. You may wish to ask your authority. However if only £179K has been allocated for all services in this authority it will not scrape the surface. We'll keep looking - anyone found any?
  20. I thought it may be interesting to share with others the level of support, information, courses or even funding your LA, MAT, Service Provider, 3rd party processor has offered for the introduction of GDPR. What communication have you received about the changes? Have you been offered any courses to understand GDPR better and if so were they free? Are you being contacted by professional organisations that would not normally support schools? If you have been given any costs could you share them? What are your 3rd party data processors saying about their plans? Once we have a good selection I'll collate a spreadsheet and share - save you reading every post.
  21. Great question @meadowgirl with no real answer. I'm really keen on family history and I can see records of my ancestors everywhere including government archives. Would my great great grandmother really want me to know she went into the workhouse? Here's ICO's guidance https://ico.org.uk/for-organisations/guide-to-data-protection/principle-5-retention/ If you can justify keeping it you can
  22. I'll answer the first 4 as they are easy! Does GDPR replace, supplement or work alongside DPA? GDPR replaces DPA although much of the DPA is still in place Does GDPR just apply to data held electronically? No any Data Protection Law is about all personal data. However the reason GDPR has been introduced is because so much personal data is stored, and often used unlawfully, electronically. In the context of schools, what constitutes an organisation (ie individual schools or LA?) and should the Data Controller be local or at LA level, given the requirement to be "Suitably qualified and an expert in DP law"? Any organisation that is registered with ICO (and all schools should be) identifies who is the data controller https://ico.org.uk/about-the-ico/what-we-do/register-of-data-controllers/ I am thinking that a whole school information audit would be a very useful exercise, recording types of data, how long it is kept for, why it is kept, where it is kept and how it is tagged for searching purposes. I agree 100% that an audit should be done as it would be difficult for you to demonstrate compliance without it. However be warned it wont be a 5 minute job!
  23. Excellent move. Thank you For those that don't know I'm working with a group of well known school focused developers to create a platform which will pull everything GDPR related in one place to show a school is GDPR compliant. We're trying to take the sting out of this huge directive that's coming our way. Those that know me will be pleased to hear that I have nothing to do with the actual development but my role is to be the company guru on all things GDPR related and ensure the platform manages this correctly. If I'm not sure I take legal advice which was the case in one of my previous posts on Edugeek. In my previous life I was the Founder and MD of the UK's largest schools' payment system. Those of you that know me from then, know I'll help freely wherever I can. There's an awful lot of mis-information being banded about regarding GDPR. This will be a great place to get things right.
  24. You are spot on @vikpaw but here we are tut tutting a university. Does this sort of thing go on in schools? I don't need to answer that!
  25. The point here is that a message was sent out containing personal data, unencrypted which allowed anyone to read the contents. Even if it reached the right people this message broke every rule today let alone when GDPR comes our way. I'm guessing such a dreadful event will result in an ICO fine - at least it will be this year's rates not next years.
×
×
  • Create New...