Jump to content

ht6

Members
  • Posts

    87
  • Joined

  • Last visited

Everything posted by ht6

  1. You'll not be the first to sway opinion after consideration in relation to GDPR. Give me 2 weeks and I'll be back in the legal obligation camp again.
  2. I understand legal obligation as in "the DfE tell us we must do this". However, they don't tell you that O365 (et al) is mandatory, so you're using those services in the public interest, as in carrying out your duties of educating children in the public interest.
  3. Again, not a self proclaimed expert, but I'd say it's a public interest legal basis since you need those tools to deliver your teaching and learning, and if students revoked consent it would cause mayhem and would make you unable to carry out your business obligations. However, MyMaths is a data processor and therefore you need to ensure the correct contracts are in place and they themselves comply with the requirements of GDPR.
  4. Yes, I would say the consent stands so long as it was sought inline with the new requirements. I'm by no means a legal expert, but I would say I have a fair understanding of the new requirements. Us, however, used to seek photo consent as an opt-out and so are having to readdress our procedures to comply with new requirements. Just be transparent about it all, send a letter home explaining the new rules, how you are dealing with them, what it means, and where parents/students can find further information should they require.
  5. Hmmm I'd be tempted to go down the consent route for that - you don't need that photo information sending out to third parties for you to do a job (give kids an education). I think your safeguarding reasoning checks out, but when it leaves SIMS it's a different use of that data then.
  6. That's what we're debating, I say yes (in a nutshell). Also, I'd say any photos collected for educational reasons such as GCSE Coursework Evidence don't come down to consent - that legal basis is probably public interest.
  7. I didn't say the school's I've spoken to weren't making a conscious effort to comply, I merely said among the multitude of other things they have to do every day, they haven't got time to go round making up myths that give additional workload for no reason. I'm sorry, but if my privacy policies are adapted for children, accessible, and even mentioned in consent forms I don't know what transparency is. I think a sensible additional measure would be to cover such a topic in IT lessons, but sending a letter home at a predefined age isn't required. What age do you send it home? 13? 11? Who's to say all your students are ready to read something like that at 11 or 13? GDPR boils down to two things for me - proper policies/procedures in place, and good training. But no, it's definitely not about going round and asking who wants help with the toilet paper.
  8. I disagree, your policies are there for people to read should they wish. They will be publicly available and structured for the intended audience. I appreciate it might be wise to put on the consent form "please see our privacy notice for further information about how we will use this information" but sending a letter saying pretty much what your privacy notice says is additional work for no purpose. GDPR is about being transparent - you do that by making sure your privacy notices are right. GDPR is NOT about running around after people saying "ah, but, you know, well". Most of the school's I've spoken to haven't got time to worry about GDPR, and then I come on here (for the first time in years) and there's a bunch of people making up their own rules to do a job that isn't required.
  9. Or, you know, just include the fact that children have the right to revoke their consent in your policies, as stipulated by GDPR anyway. You're just giving yourself more work to do, there's absolutely nothing wrong with parental consent throughout a child's school life, as long as your privacy notices tell children of their rights.
  10. Ok, but I've already responded, posting sources, to counter these arguments. So parental consent provided for an 11 year old will expire when that 11 year old reaches the age of consent. GDPR doesn't define the age of consent, except (and this is explicit) for ISS. The ICO don't define the age of consent. The new data protection bill again doesn't define the age of consent, except (and again it is explicit in this) for ISS. Therefore, nowhere in any of these bits of literature does it state that when a child turns 13 (or 16) we need to seek consent again. So when does the consent end? Well, GDPR, the new data protection bill, nor any other relevant document I can find stipulate "parental consent is not valid when the child reaches their 13th birthday". Therefore, as far as I can gather parental responsibility comes in to play, which lasts up until their 18th birthday. I feel like I'm going round in circles a bit, apologies if I'm not conveying my points very clearly. I know what we're doing with consent (and the reasons why), and it certainly doesn't involve sending a new consent form out when a child reaches 13 (or 16, or whatever other number people want to fabricate in myth).
  11. What document, and what bit? You can't just say "it says in a document I've read somewhere" - show me where it says "all persons 13 or older must provide their own consent"
  12. The spirit of the law? You are all making laws up to make your life more difficult! Need photo consent? Parental will do until the child is 18. Need biometric consent? Parental will do until the child is 18. Nobody has provided any hard fast legislation (or proposed legislation) that says otherwise.
  13. Who has mentioned 16? Because the last time I checked a child is a child until 18 in this country, and yes GDPR mentions 16 as the age of consent but ONLY for ISS, therefore it must still be 18 for all other services/needs.
  14. So reading the actual bill: Child’s consent in relation to information society servicesIn Article 8(1) of the GDPR (conditions applicable to child’s consent in relationto information society services)—(a) references to “16 years” are to be read as references to “13 years”, and(b) the reference to “information society services” does not includepreventive or counselling services. Again, this is relating to ISS - not the concern of a school. The more I get in to this the more I think people are trying to make a square peg fit in a round hole, and I don't get why considering it's not for ease.
  15. The main elements of the bill are: Set the age from which parental consent is not needed to processdata online at age 13, supported by a new age-appropriate designcode enforced by the Information Commissioner. Again - not sure what "online data" has to do with our biometric data, this doesn't fit.
  16. Well that's not the question, because from what I gather this is only for ISS - the lovely world of facebook etc. So my understanding is this might be 13 so kids can create their own twitter, but ultimately they are still a child and their parent's consent is enough. Yes, they can revoke their parent's consent, but if they don't then it is still valid throughout their school life.
  17. Also, where does it state that the age of children's consent is 13? I understand the UK may lower it for ISS but a school doesn't fall in to this category?
  18. Hi all, been a while but searching for some SIMS.net functionality and stumbled on this thread, thought I'd better post to give my side of the 13+ debate. Nowhere in the GDPR does it state that from 13 consent lies with the student. Added to the fact the ICO state a consent gained at entry (Year 7 say) is valid until leaving (Year 11 say) unless revoked. Children are still children at age 15, and therefore parental consent is still valid. Under GDPR there are rules in place (Article 8) on consent for information society services - doesn't apply to schools wanting to use photograph the last time I checked. Therefore, the old rules in the protection of freedoms act still applies as far as I'm concerned - parental consent is valid up until 18, however, from 13 (or younger if you deem the child to be sensible) can revoke parental consent. So a parent can say "sure, it's fine to take biometric registrations of my child" till they are blue in the teeth, but if the child refuses then that is a valid case of revoked consent. If the parent consents for a 15 year old child, and the child goes willingly through the process, it's all valid. https://ico.org.uk/media/about-the-ico/consultations/2013551/draft-gdpr-consent-guidance-for-consultation-201703.pdf ^^ Page 26 Protection of Freedoms Act 2012
  19. Little update: I've run system state by itself on the troublesome server using BE and it flew through - about 40 minutes. See what happens again tonight when the full runs, but hopefully it's flushed the issue out.
  20. Once or twice (or half a dozen times)
  21. Having a strange problem with a BackupExec server, BE 2012, Server 2008 R2. System State backups take around 10-12 hours, only been happening last few weeks - nothing has changed that I can point to in that time. The server it's happening on has the BE agent running, two other servers with agents and the server with the main client are all fine and have system states of around an hour. I've tried removing the agent from the server, also deleting the job from the main client and recreating it all. No errors on VSS writers or anything, and I tried a system state using Windows Backup today which took a little over an hour. I've had a good old search about the net and can't find anything to help me towards the next step to fixing it. I was beginning to think the issue was with the VSS services or something OS related, but after carrying out a quicker system state today it's apparent the problem is BackupExec related. Anyone got any ideas?
  22. It's a totally separate line and all, so not sure that sort of setup would work for us. I've wondered about the possibility of configuring the NAS as iSCSI though, that way the Backup Exec server could see it as a local drive - only issue with this is as far as I'm aware Backup Exec doesn't do delta (changed data only) so would be copying more data up across.
  23. That's one of the bits I've stumbled on - couldn't see where it offered system state though
  24. Thanks, just had a play with that - it requires a local HDD (other than the one I'm backing up) to temporarily store data on. We don't have a spare, and don't want to bottleneck the network by choosing a network drive as we'd be looking to run it on multiple servers.
×
×
  • Create New...