Jump to content

rom1984

Members
  • Posts

    236
  • Joined

  • Last visited

Everything posted by rom1984

  1. It's obviously not required to send a letter home at a predefined age, the GDPR can't tell every organisation how to apply the law to their place of work. Each organisation needs to decide that for themselves. Your school may decide that a child can never be competent enough to decide about, for example, biometric data. The next school may think that by Year 11 the students will be competent enough. They may decide in the interest of fairness and transparency that they tell them about their rights in an IT lesson (great idea!) The next school may think that by Year 10 they are competent, but they are going to let students know via a letter of their rights. The next school may think that by Year 9 they are competent, but because it is in their privacy notice on their website they aren't going to say anything. If the school gets consent to process data in year 7, and by year 11 they decide that the child is competent enough to make the decision themselves, I personally think its fair to explicitly tell the child they are processing their data based on their parents consent and because they are now competent to understand the processing of the data, that they can freely make the consent/withdraw the consent themselves. Your school may disagree with this, that is fine. Every organisation will put procedures in place that they think helps them comply with the GDPR. Its not a case of your wrong and I'm right (even though I am - I kid!) . They are just options that a school can use to help demonstrate such principles as transparency, fairness, lawfulness etc. The example of the No USB's in a policy is a real life example, if a data breach happens via a USB drive and the organisation points to a policy to say that it says no USB drives the ICO won't give this much credit. They will ask the organisations questions such as how did you tell staff about this, when did you tell them, how often are they reminded, how regularly are they trained, are they aware of the GDPR, are they aware of the data subjects rights etc. This would be the same of anything in your policies, the questions would be similar.
  2. I actually did some GDPR training two weeks ago on consent and processing personal data and this was the exact type of example they used on how NOT to be transparent. If you think a 16 year old is not competent enough to make their own decision around their data then that's fine, your policies should reflect this. The schools that I have worked in, and dealt with, are really making a conscious effort to comply with the GDPR and I think that can only be a good thing. If you are dealing with special category data or children's data (or both!) then schools should really be putting effort into complying with GDPR, especially around security, transparencies and acting fairly. Thankfully my experience is opposite to yours.
  3. Yeah that sounds really transparent If you put something in your policies and you don't tell people about it, what's the point of even having it in your policy in the first place? It's the equivalent of putting "no USB drives for staff" in your polices but then never telling or training staff about it. The GDPR obliges a data controller to be transparent, putting something in your policy and then not telling someone about it isn't transparent.
  4. What are peoples thoughts on this as an easy solution; You processes data where as GrumbleDook says, you have to use consent (for example Biometric data). You get consent from the parent when they start in year 7 and this is recorded. The school decides that by year 11 children are competent enough to decide by themselves if the school can process their biometric data. You have an obligation to ensure the data you process is relevant, up to date and accurate. So in year 11 a letter is sent home addressed to the child to inform them that the school has consent to process their biometric data and informs them of their rights to withdraw their consent. That way the original consent was done in line with GDPR (i.e. explicitly consented) and the school is complying with their obligations to take reasonable steps to ensure that data is still relevant, up to date and processed fairly/transparently. Apologies to @Jamman960 feel like I've high jacked your thread!!
  5. I agree the GDPR, DP Bill ect doesn't explicitly mention age, other than for data processed for ISS. Apologies If I've caused any confusion! When talking about age of consent in the GDPR and DP Bill I was specifically talking about Article 8 as this is the only time the GDPR mentions a specefic age. When the ICO refers to a child they mean anyone under the age of 18. But, the ICO allows competent children to exercise their own data protection rights, after all the data belongs to them and not their parents. Schools need to decide at what age do they generally consider a child to be competent enough to understand their data protection rights. The GDPR/DP Bill does not give guidance on this. Schools can take article 8 and use that age to help them decide this but they don't have to. Ultimately it is up to each school to decide. If the school decide that a child isn't competent enough to understand processing data for biometrics until they are 18 then they will need to be able to justify this. Likewise if they decide at age 13 a child is competent enough, they will need to be able to justify this. The UN convention of rights provide that every child should be able to express their views and have them views taken seriously. Again the school would need to take this into consideration and if I child says at age 13,14,15 etc that they don't want their data processed (by way of consent), then the school should seriously consider it.
  6. I'm talking about GDPR Article 8 where they mention the specific age 16. I said the UK DP bill will lower this to 13. I then replied to say that I think it would be reasonable to gain consent at, for example, age 12yrs and 10 months because you would be applying with the spirit of the law and what it was intended for. This is something the ICO would look at when looking at a data breach, has the organisation tried to apply with the spirit of what the law intends. All this, as you have said, is around data processing relating to Information Society Services.
  7. That wouldn't seem practical or reasonable to me. I think at the beginning of each term if you identify any children that turn 13/16 in that coming term and gain their consent. (or the beginning of each month, 1/2 term etc). There would be times when the child is say 15yrs 10months and 3 days old but I would image the ICO would take into account that the school is endeavouring to apply with the spirit of the law and what it was actually intended for.
  8. The age proposed in the Data Protection Bill is 13 but this is currently subject to Parliamentary approval. I would stick with 16 to make life easier until the new Data Protection Bill comes into play. **Edified to avoid confusion - I'm talking about GDPR Article 8 here **
  9. Yep that's right You wouldn't need to reissue the whole document but it would be best practise to tell parents/students that you now use a new system (i.e Office 365), this is what we use it for and this is what data we collect. The requirement is more about transparency, so yeah you should tell staff/students/parents etc about any personal data that you pass to a third party so they are aware. You can still use legitimate interest in this case, as long as the school has a legitamte interest to do so that balances what the school wants to achieve against the personal rights of the individual. One test to apply to see if consent is more applicable is to ask yourself if the student/parent says they don't want their students personal data processed via Google, would you still do it. If the answer is yes, then you couldn't use consent and would need to use another lawful bases, for example legitimate interest.
  10. I think it might be a bit different for a parent just because it would be so obvious that the school would have the contact details of parents that you wouldn't need to be transparent because it is so implied that the school would have them details. Where as with an aunt, sibling, friend etc it might not be so obvious so it would be best practise to show transparency to contact the person just to check they are happy that the school have their details. I personally think the risk is pretty minimal though
  11. I think you'd need to show transparency towards the person who's personal data it belongs to so would be better to have some procedure in place that actual gets an affirmative yes/no from the actual person.
  12. I think the three areas you will need to think about are transparency, your lawful bases for holding the data and how excessive/relevant it is in relation to the purposes for which it was collected. Lawful bases: You may not specifically need consent, for example I suspect you are processing the data for a legitimate interest. Either way you would need to document on what bases you are holding the persons data. Transparency: The 3rd/4th person should know that you hold the data. So I think it would be reasonable to contact the person and ask them are you Ok that we have your data to be used for emergency contact. Excessive: You would need to be able to justify having 3/4 separate contacts. For example is it normal in an emergency that you can't get hold of mum, dad, grandparent etc. If so then document that as the reason for having the data. I suspect that even if you contact the 3 or 4th person, unless the person has parental responsibility you won't be passing over any sensitive information to them about the child- you would just be asking them to get in contact with the parent/carer and ask them to contact the school. I think if you cover the 3 things above I can't see it being an issue.
  13. No idea which way this is going to go! From what I've read I think he is using the right to be forgotten but also the principle that data must be relevant and up to date. Because the conviction is spent the argument is it is no longer relevant and he should be able to get on with his life as a rehabilitated person without the crime effecting his current life.
  14. This might help convincing staff too... https://iconewsblog.org.uk/2017/11/16/personal-data-must-be-safe-from-prying-eyes/
  15. The DPA and GDPR is specific to data controllers so the ICO wouldn't bring enforcement or prosecution against an individual. The things the ICO would look at when determining if the data controller was in the wrong would be are the correct procedures in place, how did the organisation tell staff about these procedures, did they do specific training, have they breached the policy before, if so what did you do etc. However, if the person makes a DPA Section 55 offence, then this is a criminal offence and the ICO could take action against the individual. For example if the person stole data from the school or shared personal information without authorisation (like the link below) https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2018/02/former-council-worker-fined-for-sharing-personal-information/
  16. If the school is the data controller and they still choose to use that supplier though, then the school would still be liable for any breaches.
  17. I'd either look on their website for their privacy policy or if it isn't online ask for it, you may find most of your questions are addressed in the privacy policy. Then if there are any areas that aren't addressed in the policy you can specifically ask them.
  18. The schools ICT Helpdesk System also asks them to enter their username and password over http. I wonder if the back ends authenticates to AD
  19. This will change slightly in light of GDPR but the general principle of taking a pragmatic approach will still apply. The guidance above was DPA guidance around the principle of not keeping data longer than necessary. The guidance was that if you delete data to be compliant with the principle of not keeping data longer than necessary, but it's still on the backup, then the ICO would take the approach that you have put the data "beyond use" and complied with the principle. However the GDPR now explicitly expresses that a person can have the right to erasure and the recital state that this covers any data that is processed. I think it's reasonable to follow this guidance until the ICO provide further guidance specific to GDPR.
  20. The way the ICO did it when they implemented it was to have a 12 month retention period. Then every month for 6 months they reduced it by a month to eventually get to 6 months.
  21. I work for the ICO and we get loads of calls from companies trying to sell us stuff to make us "GDPR compliant"
  22. This is the ICO's guidance on CCTV, section 5.1 covers the administration of the CCTV system. https://ico.org.uk/media/for-organisations/documents/1542/cctv-code-of-practice.pdf In terms of the actual GDPR, the "rules" so to speak are in Article 5 (f) "processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures" How you interpret "appropriate security" is obviously up to each separate organisation and will be different every time. However, if there is a breach the ICO will ask you to show what security measures you had in place to protect the data. I'd personally think that some kind of log of who is authorised to make the request would be seen as "appropriate security". Your DPO/SLT/Governors/Network Manager should always be able to satisfy themselves that they have put in appropriate security measures to protect any system the processes personal data. The ICO will then balance what security measures you have put in place against the breach (looking at things like what the data was, how sensitive it was, the damages to the invidual, what you could have done to prevent it etc.) As a starting point the ICO would look at basic ICT security principles, so Integrity, Availability, Confidentiality and Privacy of the data. This will be the starting point and you should be able to show that you have addressed each of these for all of your systems the process personal data. The one thing that I would say, is that personal data of children is thought of as very important within the ICO and what ever procedure you do put in place, the ICO would take into consideration that the data is of children when balancing the weight of the breach.
  23. Hi All, I've got the go ahead to draft up some guidance on the ICO's position in relation to backups. I'm going to do it in the form of a questions & answers piece or as a blog post depending on how it turns out. Has anyone got any specific questions that they would like seeing addressed in it. I've got some ideas from @enjay 's thread (see http://www.edugeek.net/forums/data-protection-information-handling/185799-right-delete-backups.html) but wanted to do it as a separate thread so I can just easily pull out the relevant bits. The things I had in mind are; GDPR's position on backups The lawful bases for processing the data vs the right to erasure Questions around right to erasure - the ICOs' position on this Encryption Requirements Data Retention expectations Backups to the cloud Privacy by Design (for manufactures of backup appliances and for Network Manager types that are responsible for developing systems, procedures, infrastructure etc) Tape Backups - how are they different, what the ICOs position is VSS Backups - Thinking around does the ICO expect you to basically break the VSS to delete the data, if not what is the ICO's position, retention periods of VSS Virtualised infrastructures vs Physical - how does this change the expectations of the ICO @GrumbleDook I think you said in the other thread you gave the ICO some questions to address - could I pinch them off you either via PM/email or on this thread? I've obviously got to be quite broad because the guidance will be for all organisations so I might not be able to include specific nuanced examples but I'll try to cover the general expectations of the ICO. Thanks all!
  24. Yep that's a fair point, on seconds thoughts I think your right the supplier will determine how they collect the data (i.e they give the school the order form and tell them how they want it). But I think the school defiantly sets out why they need to process the order, they are mandating that parents have to go to that specific shop and order the specific uniform. I think it would be different if you said you can buy any grey jumper and black pants then you wouldn't be involved. But as you have said, because you are saying the parent must go to that shop than you are determining why the person is in the shop processing the order. Sounds like your on it with the rest of the other bits!
  25. 1 - this is a tricky one I'm not 100% sure off, might be a call to the ICO helpline. This is my own thoughts on it thinking out loud... The school is determining why they are processing the order (to provide a school uniform), they are also determining how they are processing it - i.e they provide an order form, collect the form, they manage the handing over of the cheques, they provide details on how to go directly to the supplier. That straight away says to me the school is the controller and the supplier is the processors. You would have to think about the lawful bases that you are processing this data too. You couldn't collect this data on the bases of consent because the parents has no choice. They either hand over their personal details or their child can not go into school. So I think it would be the school that would need to determine on what bases they are processing the data which further suggests they are the controller. At the very very very least the school would need to find out how the shop is protecting personal data because the school is forcing parents to give the shop their details. If the shop comes back and says they process data on their laptop and its not encrypted, this should scream alarm bells and the school needs to decide are they happy forcing parents to give personal details to a company that doesn't have basic protection procedures in place. If they decide they are happy with doing this, they would unquestionably hold some responsibilities, and I image quite a high level of it. 1b - I don't think it would because of above. Because you are thinking about other methods to collect the data I think this further suggests you are the controller too, the school is determining how the data is collected whether it be order form, online, direct with the supplier. 2 - I think in this example the ICO would look at Article 5 of the GDPR and ask did the school act fairly and reasonably in the matter. So for example they would ask you to show documentation on how you assessed the risks of using the specific company. You could then provide them a contract or an agreement that said the third party agreed that all the credit card details they kept were encrypted, the credit card details were pseudonymised etc etc. If the breach was then just human error by someone from the third party, then the school can show that the issue was with the third party controller. If the third party comes back and says we don't encrypted our credit card details, and the school still chooses to use that supplier, then the school would share some responsibility. 3 - I think this is similar to the above. Because you are basically giving the parent no option but to hand over their details to a company, you must have at least an obligation to check that the company is handling the data properly. I think the main take away point is that the school needs to act fairly and needs to be able to show it acted fairly. If you give the parent no option but to hand over their details to a third party in order to access a part of the schools curriculum, then it is fair of the parents to presume that the school has checked that the third party handles personal data properly (see Article 5 of the GDPR for what I mean by handled properly)
×
×
  • Create New...