ht6
Members-
Posts
87 -
Joined
-
Last visited
Reputation
35 ExcellentAbout ht6

-
You'll not be the first to sway opinion after consideration in relation to GDPR. Give me 2 weeks and I'll be back in the legal obligation camp again.
-
I understand legal obligation as in "the DfE tell us we must do this". However, they don't tell you that O365 (et al) is mandatory, so you're using those services in the public interest, as in carrying out your duties of educating children in the public interest.
-
Again, not a self proclaimed expert, but I'd say it's a public interest legal basis since you need those tools to deliver your teaching and learning, and if students revoked consent it would cause mayhem and would make you unable to carry out your business obligations. However, MyMaths is a data processor and therefore you need to ensure the correct contracts are in place and they themselves comply with the requirements of GDPR.
-
Yes, I would say the consent stands so long as it was sought inline with the new requirements. I'm by no means a legal expert, but I would say I have a fair understanding of the new requirements. Us, however, used to seek photo consent as an opt-out and so are having to readdress our procedures to comply with new requirements. Just be transparent about it all, send a letter home explaining the new rules, how you are dealing with them, what it means, and where parents/students can find further information should they require.
-
Hmmm I'd be tempted to go down the consent route for that - you don't need that photo information sending out to third parties for you to do a job (give kids an education). I think your safeguarding reasoning checks out, but when it leaves SIMS it's a different use of that data then.
-
That's what we're debating, I say yes (in a nutshell). Also, I'd say any photos collected for educational reasons such as GCSE Coursework Evidence don't come down to consent - that legal basis is probably public interest.
-
I didn't say the school's I've spoken to weren't making a conscious effort to comply, I merely said among the multitude of other things they have to do every day, they haven't got time to go round making up myths that give additional workload for no reason. I'm sorry, but if my privacy policies are adapted for children, accessible, and even mentioned in consent forms I don't know what transparency is. I think a sensible additional measure would be to cover such a topic in IT lessons, but sending a letter home at a predefined age isn't required. What age do you send it home? 13? 11? Who's to say all your students are ready to read something like that at 11 or 13? GDPR boils down to two things for me - proper policies/procedures in place, and good training. But no, it's definitely not about going round and asking who wants help with the toilet paper.
-
I disagree, your policies are there for people to read should they wish. They will be publicly available and structured for the intended audience. I appreciate it might be wise to put on the consent form "please see our privacy notice for further information about how we will use this information" but sending a letter saying pretty much what your privacy notice says is additional work for no purpose. GDPR is about being transparent - you do that by making sure your privacy notices are right. GDPR is NOT about running around after people saying "ah, but, you know, well". Most of the school's I've spoken to haven't got time to worry about GDPR, and then I come on here (for the first time in years) and there's a bunch of people making up their own rules to do a job that isn't required.
-
Or, you know, just include the fact that children have the right to revoke their consent in your policies, as stipulated by GDPR anyway. You're just giving yourself more work to do, there's absolutely nothing wrong with parental consent throughout a child's school life, as long as your privacy notices tell children of their rights.
-
Ok, but I've already responded, posting sources, to counter these arguments. So parental consent provided for an 11 year old will expire when that 11 year old reaches the age of consent. GDPR doesn't define the age of consent, except (and this is explicit) for ISS. The ICO don't define the age of consent. The new data protection bill again doesn't define the age of consent, except (and again it is explicit in this) for ISS. Therefore, nowhere in any of these bits of literature does it state that when a child turns 13 (or 16) we need to seek consent again. So when does the consent end? Well, GDPR, the new data protection bill, nor any other relevant document I can find stipulate "parental consent is not valid when the child reaches their 13th birthday". Therefore, as far as I can gather parental responsibility comes in to play, which lasts up until their 18th birthday. I feel like I'm going round in circles a bit, apologies if I'm not conveying my points very clearly. I know what we're doing with consent (and the reasons why), and it certainly doesn't involve sending a new consent form out when a child reaches 13 (or 16, or whatever other number people want to fabricate in myth).
-
What document, and what bit? You can't just say "it says in a document I've read somewhere" - show me where it says "all persons 13 or older must provide their own consent"
-
The spirit of the law? You are all making laws up to make your life more difficult! Need photo consent? Parental will do until the child is 18. Need biometric consent? Parental will do until the child is 18. Nobody has provided any hard fast legislation (or proposed legislation) that says otherwise.
-
Who has mentioned 16? Because the last time I checked a child is a child until 18 in this country, and yes GDPR mentions 16 as the age of consent but ONLY for ISS, therefore it must still be 18 for all other services/needs.
-
So reading the actual bill: Child’s consent in relation to information society servicesIn Article 8(1) of the GDPR (conditions applicable to child’s consent in relationto information society services)—(a) references to “16 years” are to be read as references to “13 years”, and(b) the reference to “information society services” does not includepreventive or counselling services. Again, this is relating to ISS - not the concern of a school. The more I get in to this the more I think people are trying to make a square peg fit in a round hole, and I don't get why considering it's not for ease.
-
The main elements of the bill are: Set the age from which parental consent is not needed to processdata online at age 13, supported by a new age-appropriate designcode enforced by the Information Commissioner. Again - not sure what "online data" has to do with our biometric data, this doesn't fit.
