Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

garbage46

Members
  • Posts

    104
  • Joined

  • Last visited

Everything posted by garbage46

  1. I am late to the party as usual, in our responses to a SAR I always include a statement explaining our search criteria and justification along the lines of:
  2. Advice please: An out of area "Virtual School for Children Looked After" is asking us to share the GCSE results of a pupil. I have initially said no, because the results belong to the pupil so we need their consent etc. The Virtual School is insisting they need the results for their records. They are a local council with @xxxx.gov.uk email address. We anyone agreed that this personal data processing/sharing covered under "Public Interest" and/or "Vital Interests"? Thanks
  3. Has anyone managed to find a way to export grades which have been entered manually through the EDIT PI routine? i can see the results are there, and they appear of candidates statement of results etc I just want to be able to export all results to one spreadsheet
  4. Is your school choosing to take Friday 18th as an INSET? If so, for student attendance are you planning to edit the current academic year to add an additional INSET day? I am going to do this, but before I click go, is there anything that might go bang?
  5. Print to PDF. Redaction in Adobe Acrobat. Save as PDF. Email/Share encrypted zipped PDF.
  6. Adobe Acrobat has a pretty good redaction feature. It allows for text to be marked for redaction and then reviewed before being applied. Also give reassurance that redacted content is completely removed from the document, as in not hidden behind black boxes but actually removed from the document data. https://helpx.adobe.com/uk/acrobat/using/removing-sensitive-content-pdfs.html
  7. I might have not understood correctly, but how about using the query to "filter" the years: DECLARE @AcademicStartYear int = '2018', @AcademicEndYear int = '2021' SELECT txtAdmissionsStatus, COUNT(txtAdmissionsStatus) AS statusCount, intEnrolmentSchoolYear FROM [TblPupilManagementPupils] WHERE txtAdmissionsStatus !='' AND intSystemStatus=0 AND intEnrolmentSchoolYear BETWEEN @AcademicStartYear AND @AcademicEndYear Group BY txtAdmissionsStatus, intEnrolmentSchoolYear This should output txtAdmissionsStatus, statusCount, intEnrolmentSchoolYear Single, 500, 2018 Single, 400, 2019 Dual, 10, 2018 ... Then in the report matrix, columns grouped by intEnrolmentSchoolYear
  8. what does your current query output look like? Can you paste in the column header / field names here?
  9. Couple of things... 1. Do schools *need* to share personal data with PHE and NHS Test and Trace workers on request or if there is a suspect COVID case in school or does this fall with parents/carers? 2. Do any of you guys have a privacy notice for sharing personal data with Public Health England for the NHS Test and Trace.... a bit of Google searching found a standard template that appears to be being used by schools with links to "Catholic Multi-Academy Trust". https://www.stl-cmat.org.uk/cms/wp-content/uploads/2020/06/Covid19-Test-and-Trace-Privacy-Notice-staff-students-May-2020.pdf https://www.trinity.nottingham.sch.uk/wp-content/uploads/2020/06/COVID19-TRACK-AND-TRACE-PRIVACY-NOTICE-STAFF-AND-STUDENTS-JUNE-2020.pdf https://www.springfieldacademy.co.uk/news/detail/dlt-coronavirus-track-and-trace-privacy-notice-jun/ http://www.robertsutton.staffs.sch.uk/documents/Letters%20to%20Parents/2019-2020/2020.06%20-%20June/SRS-Privacy%20Notice%20for%20Coronavirus%20Test%20and%20Trace.pdf https://www.piggottschool.org/page/?title=Privacy+Notices&pid=150 (Half way down the page) https://www.rosehillinfants.co.uk/privacy-notice-and-data-protection/ (Half way down the page) HAVE I MISSED SOMETHING SOMEWHERE - LIKE A DfE TEMPLATE OR WHAT??
  10. Indeed. What I was trying to say is that we could do with a large organisation, like ASCL, to work with and convince the DfE, Ofqual et al that we should keep CAG and ranking confidential. Current guidance is just replying on existing exmeption rule for exam scripts. I believe this is something completely different, but let's wait and see
  11. Fingers crossed for some level of agreement, the exemptionrule I have used in the draft is for Freedom of Information requests but as a request to see CAGs and rankings would be a Subject Access Request with different exemptions that do not really fit - the best fit would be a stretch at some type of mental health / stress related harm for teachers or the one about "management forecasts", which could fit, if pushed hard enough... Disclosing CAGs and ranking would prejudice any future activities of a similar nature. What we need is for an organisation like ASCL to push for a non-disclosure rule/exemption or else it's going to generate a lot of work and a lot of difficult conversations that we do not want to have.
  12. I have also been considering how to respond to any SAR relating to centre assessment grades. IF we need to disclose information about CAG's then it might be best to have official CAG request forms ready.... but My gut feeling is that the grades and ranking submitted by the school should not be shared. If we are ever in a position where teachers will be asked go through the same process, say in Summer 2021, then the integrity of the process will be compromised. If teachers and heads of centre know that the grades they submit will or could be made public or disclosed to parents and students then they'll just inflate grades and point fingers at exam boards and the standardisation process when lower grades are awarded etc etc. I have started to draft a statement for non-disclosure. I have used the Section 36 expemtion for one FOI request previously, but not for a SAR.... but in the reasonable opinion of a qualified person (me) the same rules should apply to FOI and SAR in this case. see attached: CAG Draft.pdf
  13. You could be proactive and ask each of your feeder schools for ranked teacher assessments in core areas? <- see what I did there Teacher assessments having always been a thing in Primary schools, especially at end of EYFS for GLD and end of Y2 for KS1 outcomes and usually for KS2 too. DfE will probably just ask for a judgement based on Expected Standard. Below Standard, Working Towards, At Expected, Higher Standard etc and scrap the progress measures... With the lack of scaled scores from KS1, this years prgress measures for KS2 SATs were going to be a car crash for the DfE before they decided to cancel exams....
  14. Pupils connecting adults who are not school staff via webcam sounds well dodgy from a safeguarding perspective, espcially when you throw in potential recording of video! Has this been run past your DSL and or safeguarding lead?
  15. A bit late to the conversation, but we dealt with a similar request which resulted in thousands of emails. I was able to import the .PST files into one mailbox in Outlook. Next we sat in a meeting room with a projector and went through the emails one by one, tagging them using categories like "not the subject", "not in scope", "to be redacted", "to be released" etc. This took a few days, but nowhere near as long as we first thought. Once than process was finished I Exported the "to be redacted" emails to pdf and we use Adobe Acrobat Pro redaction tools. We need to sort out our email retention rules. Fingers crossed we do not receive many more SAR like this one. Working in a MAT, I dread to think how many emails would be returned if a bloke named "Mark" made a SAR.
  16. How would you classify a pupil's exercise books and the work inside them... Is the content of an exercise book a pupil's personal data and therefore within the scope of a SAR? Would parents/carers be entitled to request the books be sent home? What if the books contain personal data of other pupils including photos - would it be time to get out the redaction tools? But then what if the books are still be used on a daily basis....
  17. My current understanding, following conversations and possibly conflicting advice from ICO, is: Pete is mentioned and is identifiable. Steve and Dave know who the Pete mentioned in the email is. With the additional context of the email addresses others from the same school would be able to identify Pete. "Pete has asked Mike to bring some samples of work" is Pete's personal data because it relates to something Pete has done. It is also Steve's personal data because he wrote the email and made the statement. My uncertainty is: Disclosure could be in breach off Steve's data protection rights. Should this or any similar email be including in a SAR from Pete? I am leaning towards no... Is this really personal data under the definition of a subject access request?
  18. My head hurts... Steve sent an email to Dave: Pete makes a SAR to see all emails containing his personal data. The email above has Pete's personal data, yes? How do would you respond, choose you answer from the following options: (a) it is exempt because it is work related and for general business purposes. (b) it is exempt because it is the personal data of Steve, Pete and Mike so disclosure to Pete would be in breach of DPA rights of Steve and Mike? © it should be disclosed with redaction of red text (d) only blue text should be extracted and disclosed (e) other.. please explain
  19. Is there any guidance or case law on what is a manifestly unfounded or excessive subject access request? Thoughts on what is excessive in terms of number of documents and emails to refuse a non-vexatious SAR.... 10,000 emails? 25,000? 100,000? Are there any examples you have found that establish criteria for refusal to comply with SAR unless the scope is reduced?
  20. Indeed! A poor choice of words there.... I think I'll make an edit to the previous post to emphasise exemption. This paragraph from the DP1 guidance helps further explain the exemption element;
  21. What are you thoughts on parents/relatives collecting exam results for pupils who cannot make it in to school on 22nd August? Has anyone already got a system in place? Would a letter of consent be enough?
  22. I realise I am late to the party but thought this was worth sharing.... hopefully someone finds this useful. When the police make a request for personal data in relation to the prevention and detection of a crime, the prosecution of offenders or to protect the vital interests of a person then GDPR does not apply an exemption rule can be used to disclose personal data without breaching DPA or GDPR***edit: see post below***. BUT there is an official form that must be completed stating the name of the data subject, reasons why personal data is requested (see above) and then the personal data required. The request should explicitly state the request is in relation to one for the above reason (prevention, detection, prosecution or safeguarding). I believe, even with the form completed, it would be a school decision to release the information - but the release would be lawful. The form used by Lancashire Police is called a DP1 form, I will attempt to attach some screenshots of a blanked out version along with the guidance notes.
  23. just out of interest, where is source information from? is it available as a csv somewhere?
  24. Do you need a Power BI Pro license to publish and share dashboards like this?
  25. I agreed with @Meldrew - if photos are for identification then you can link that to safe guarding therefore Vital Interests basis. Here is an example of a short provicy statement I wrote for an academy in our Trust for transition data collection forms: This is the photo consent section of the data collection form:
×
×
  • Create New...