Jump to content

Bigbird7

Members
  • Posts

    91
  • Joined

  • Last visited

Everything posted by Bigbird7

  1. Looked at this a couple of weeks ago and the catalogue available seems very limited. I randomly checked 50 or so books from our library and not one was available!
  2. Absolutely a DPIA should be carried out and it should have been thought of as part of the procurement process not an afterthought. Not only is this a new system, but also one that will process high volumes of data and special category data.
  3. In the DfE guidance on mass testing in secondary schools it mentions a template privacy notice specifically for testing. Has anyone managed to find this?
  4. I've heard good things about the Evolve accident book system http://www.edufocus.co.uk/pages/evolve/accidentbook.asp
  5. The ICO have recently published a couple of audit reports on academy trusts, available here https://ico.org.uk/action-weve-taken/audits-advisory-visits-and-overview-reports/ They are only summary reports but interesting reading nonetheless. A couple of key points come through - staff training/awareness and data sharing practices.
  6. Anybody with PR can put n a SAR for their child no matter their age. Who you should respond to depends upon the competency of the child (usually deemed to be over 12) but should be treated on a case by case basis. If you are confident the child understands their rights then the response should be to the child, however the child may give their consent or if it is evidently in the best interests of the child then the response is to the parent.
  7. Yes, any personal information you hold where an individual is identified is requestable by a parent, no matter the source. Safeguarding records are not automatically discounted but you must go through a redaction process to remove anything that identifies another individual and anything that could cause harm by passing it on.
  8. I read it as any close family member who is being tutored by a member of staff or any family of exams staff, so we will need to survey our staff to get the information and pass it on to the awarding bodies. The exam regs are a legal requirement so that’s our legal basis.
  9. Does anyone have any thoughts on the JCQ general regs 2018-19, page 11 5.3 d) and the sharing of data to exam boards for family members of staff sitting exams, even if it’s not at your centre. https://www.jcq.org.uk/Download/exams-office/general-regulations/general-regulations-for-approved-centres-2018-2019 Whilst sharing of information with the exam boards will be covered in our privacy notices, this won't be extended to family members. As it’s extended to other centres we won’t even currently hold the information.
  10. Possibly, they may also not have finished their review yet! I know of two breaches reported to the ICO back in June and July and the schools have heard nothing back yet.
  11. I attended a Level 1 safeguarding course for a school that I'm a governor at last week, given by the LA safeguarding lead. At no less than three times the trainer stated that safeguarding overrides data protection. i tried to push the data protection is safeguarding point and that the two should always be considered together which did seem to be accepted. If this is a consistent message being given to schools by safeguarding trainers then DPOs face an uphill battle!
  12. Contact is obviously very different to access to the child’s data which should be controlled by knowing who has PR. With regard to the original question it would be unmanageable to get consent from the additional contacts. Our solution was to add some wording on the data collection form to put the onus on the parent completing the form to ensure that they had told the contacts that their details were being passed to the school and why. We reduced the data we were collecting to just a name and mobile number. We also reduced the number of contacts we were asking for. It’s not a perfect solution but we’ve reduced risks as best we can.
  13. Annex 8.1 of the DfE Toolkit has a summary report of an ICO advisory visit https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/747620/Data_Protection_Toolkit_for_Schools_OpenBeta.pdf
  14. Apologies! In lots of schools in my area the catering company not only provides the food but also the staff to serve it. If that's the case then those staff need the allergy information.
  15. If the catering company provide the service directly to the children, as is the case in many schools, then there would be a need to associate the medical information with the child
  16. Many schools are now facilitating this on a parents evening, that way the forms never leave the school. You won’t get everyone but it’s a more reliable way of updating as many details as possible.
  17. Agree with most of the others here, no risk to the data subjects so no need to report to ICO. Record on your own systems, making sure that you put things in place to prevent a recurrence.
  18. It's a hypothetical one based around something that happened in the past and came up in a discussion around a DPIA for the current system. The LA process the payroll, then print and deliver payslips to school via Royal Mail(!), on one occasion these were lost and never found. This would now be a reportable breech hence the original question on who is the data controller and therefore responsible for reporting to the ICO. As a side note the process of going through the risk assessment has made the school think about it's practices and will hopefully get the LA to improve it's systems or perhaps look elsewhere
  19. I think you are probably right they are free to choose, but I get the impression that many don’t realise it.
  20. That was my view too. What I can’t get my head around is that the school has no choice but to use whoever the LA says for particular services, such as payroll. It is therefore not determining the manner of processing
  21. In a maintained community primary school where the LA is the legal employer and determines things such as who the school uses to run it's payroll, who is the data controller? Is it the school, the LA or are they joint data controllers? Im thinking of a particular scenario where there is a breech involving pay slips and who is responsible for reporting that breech.
  22. The recommendations from an ICO audit are available in the DfE toolkit Annex 8.1 https://www.gov.uk/government/publications/data-protection-toolkit-for-schools
  23. We have covered special category data in our data protection policy, with details of what we process, our legal basis, retention, etc and extended this way beyond what is defined as special category to include all of the sensitive data we process (FSM, PP, etc). This is also covered in plain english on privacy notices. I've heard that following an ICO audit a school has been advised that it needs a separate policy for special category data, I don't know if the school had covered it in it's DP policy or not. Has anybody come across this, and if so does anybody have a policy I could have a look at.
  24. Odds on favourite in my view too
  25. The ICO are unlikely to give you a straight yes/no answer on this or indeed anything else. The standard response is that it is for you to assess your own risks and act accordingly
×
×
  • Create New...