Jump to content

GrumbleDook

Edu Supporters
  • Posts

    12,876
  • Joined

Everything posted by GrumbleDook

  1. The SAR is a request for personal data, not emails or other specific formats. If it is taking you that long to sift through and redact then you have a problem with emails. If we are talking about bullying, safeguarding, complaints and the like ... they will already be recorded elsewhere and so provided that data is sufficient. In fact, once the information is within your behaviour/safeguarding management system, the email is no longer needed. It should be deleted from the mailboxes of those involved (if there is a need for keeping it then the email can be attached as a file to the record!) and this both reduces the duplication of where data is held and looked for on an operational basis, from a data retention basis and from the position of having to deal with SARs.
  2. There are 3 distinct areas for this and I'll *try* to summarise as best as I can. 1 - contract agreements. Where software is expected to be used by an end user in an organisation, you will generally find that the EULA reflects this (or at least partially covers that it can happen and fudges the rest) but occasionally you will come across one that is adamant that the only want to deal with the end-user. In those circumstances, you have to consider whether any contract is enforceable with the end-user. At this point we can go into legal discussions about children and contracts, but the important point is that a valid contract with a minor (where it is permitted) is based on the minor having full understanding of the implications. Heck ... I don't understand half the EULAs I read! 2 - Personal Data. If the organisation requesting the data is doing it for their own purposes (so not even doing it because they have a DPA where they say that it is for the improvement of the existing product) then they are a data controller in their own right. If that is the case, under what lawful basis is data being obtained by them and processed? If agreeing the EULA then it could be contract or consent. We've just covered contract, so for consent you are going to have to get it from the parents, and if they say no then you have to have an alternative. If you have an alternative anyway, why are you still using this product? 3 - Telemetry. Stick 3 privacy professionals in a room and ask them a question and you will get 4 answers ... the common one being, "it depends!" ... and without a detailed review of exactly what telemetry it is, and for what purpose, then here be dragons. THis is why you need that DPA to give you the info. Realistically, I know schools will fudge it and find ways around it. Bulk acceptance of the EULA by finding a reg setting that makes it already accepted, blocking of the website to create accounts and blocking of telemetry data going anywhere ... but if you are doing that for a lot of software, why not spend the time with software that you don't have to fudge things with?
  3. I’ve been in contact with him and it is a legitimate request. I’ve also informed him of the more recent tribunal decision too and he is looking for the best way to gather it that is the least trouble all round. He might even drop in here but at least he understands that it is being discussed and the issue of forms has been a problem in the past.
  4. I couldn't find any reference to this so far, so thought I would share within here ... as it seems more appropriate for data protection than general internet stuff. https://brave.com/brave-search-beta/ How many of you will be looking at this for your schools? Please share with your DPOs that this is now available.
  5. Coming back to this (and thanks to the several folks who prodded), I think there is something that does need to be explained a bit more, about the reuse of data by EdTech/Tech companies and possible issues around it. This could be a looooong session and whilst I know I have covered some bits before I think it might be best to run a webinar on it. Would that be something people are interested in?
  6. You need to risk assess this. The gains you might have from a BCDR point of view could be issues from a data protection and security point of view. Devices can be replaced via insurance, data can be backed up. A lost or stolen laptop can be a bigger issue.
  7. We should all remember that any BCDR plan should be incorporated with the school’s critical incident plans. Making sure that it is not looked at in a silo is important. BCDR is also about managing impact, not just managing the tech.
  8. The NCSC materials are good for CyberSec but that is only a tiny bit of what you need for data protection training. You need to consider 3 areas. General awareness training for new staff and existing staff (they could be slightly different but you train new staff at induction, and not wait for the annual refresher). Role-specific training to support those dealing with SARs, records management (which includes data destruction), breach management, etc. Remedial training from where any reviews, incidents or DPIAs help you identify a need. I know a number of trainers that can cover this online and in person. DM me which is preferable and can suggest someone to you.
  9. I reckon it is EduSpecs, come back to have some fun!
  10. I definitely won't be able to make this one, unfortunately. Hope you all have fun though.
  11. The problem is that it will still contain data the pupil was generating, including the class, activities, etc. The name may be different, but it is still the same pupil. This would not sort out the consent issue.
  12. Don't you mean, "What duck?"
  13. Google Workspace for education has a list of core services. For these, Google has previously confirmed that the data and any personal data is kept in the EEA (in Ireland) and not part of the blob sent to the US as per other Google and Google Workspace accounts. Google has also said that for these, Google remains a data processor as the school is the DC, and Google only processes for the purposes set out by the school. I'm sure the Google Edu members on here can dig out the relevant links. For the additional services, Google says that for some elements of these, they are also a data controller in their own right. They will take this data to the US and they will use it for things like targeting ads. These additional services are turned off by default from everything I have been shown and told so far, but this may not have always been the case. If you are using any of these additional services then yes, you are going to need consent, and you will need a backup plan if you don't get it. https://support.google.com/a/answer/6356441?hl=en is one of the support items I would suggest folk look at. As I understand it, but I have yet to had a cast-iron guarantee from Google Edu, turning off additional services for an account does not block it, only stops that account from being used for it. So you will get whatever messages you get when you go to a Google service without signing in. I'll be honest with you, I've been tempted to pull the exact same trick with the school that one of my children goes to. I have annotated the forms they send to us about consent and hit a brick wall at times as the priority is education (understandably so). There is a large chunk of politics around this and I would be remiss not to say that schools are still missing out on a lot of information that they need, there are minimal discussions between DfE and ICO, and the larger emphasis is on CyberSec with schools (for obvious reasons). That doesn't mean that you can be informed and prepared for when parents rightfully ask questions and take your schools to task. I know the Google Edu team work their socks off to get things right ... but their emphasis is also on education too. And yes, Microsoft has their own issues.
  14. The right to object is absolute, however the object does not have to be upheld, but we should remember that it is a right. You may legally be allowed to do something but if half your parents are complaining then something is not right. Remember that data protection legislation has its origins in human rights, not corporate law.
  15. This is a fair point. However, if after a review it has been noted that it is not the most appropriate lawful basis, you can start a DPIA as if you were starting afresh and look at the best option, engage with stakeholders, ensure all risks where covered and make sure it was transparent. You can’t just decide to change the lawful basis and not tell anyone or not change any safeguards you have in place.
  16. In the issue we are discussing ‘informed consent’ is not a relevant term. That one is to do with medical scenarios about treatment and not covered under data protection law (though it is closely linked to explicit consent for article 9 … processing of special category personal data). In this case, if you are not following the transparency principle when looking to gain consent it is a flawed request anyway.
  17. There is an issue about the normalisation of surveillance that predominantly occurs because of lack of correct assessment of risk and lack of communication. There are also issues around schools making life difficult for families that don’t agree with it. If someone doesn’t want biometrics used, then fine … that is what the law says.
  18. See my comments above, also have a long chat with your DPO. If your DPO needs any peer-review then I know many who can help. If you want a direct chat with me (or your DPO does) then let me know.
  19. Oh sweet $deity, where to start. 1 - Google Classroom is part of the core suite of Google Workspace for Education Fundamentals (https://edu.google.com/products/workspace-for-education/education-fundamentals/) and as such, they operate as your data processor. No data is taken or used by Google for their own purposes for the core suite. 2 - Ensuring the well-being and safety of your staff and children, the delivery of the educational curriculum, and the strategic and operational elements of the school form the core activities of your school. These are generally covered under public task, though other lawful bases could also comply. 3 - Consent for where data is processed as part of your core activities is generally not appropriate. Consent can be withdrawn and if that means the data subject is negatively affected, then the data controller has an imbalance of power, and consent should not have been used. 4 - When you are working with a data processor, they are exactly that ... a data processor, operating under your agreed instructions (that is why it is a Data Processing Agreement), and so Google, in the case of the school's core activities, is *not* a third party. A third party, although often used because it is a term within contract law, has a very specific definition within GDPR. It means someone who is not the Data Subject, Data Controller, Data Processor or a sub-processor. Effectively, they are a separate Data Controller who can also use the data for their own purposes. Please remember that this is the core services we are talking about (hosted in Ireland, not the US). Your Privacy Notice should not state that they are a third party (nor any other data processor or sub-processor) otherwise you can get people thinking you are handing the data here, there and everywhere! 5 - Google has a raft of additional services. If you select these as being available for your data subjects, then Google are also a Data Controller in their own right. For these, you do need Consent. The additional services are not turned on by default and this is because Google knows that they should not be. If you, as a school, turn them on ... then it is your responsibility to sort consent and notify parents/children that there data is being shared with Google for Google's own purposes ... and link to information from Google too. The above applies to Microsoft and their partners, and a host of others too. If the data is only used at your instruction, then why are you asking for consent? There will be times it is relevant (pictures on websites, etc.) or a legal requirement (biometrics), but most schools should look at public task. It is even covered as such in the DfE guide on data protection. Yes, I know a lot of educational tools talk about consent and 13, especially those US-based or delivering to the US. COPPA has a section that covers this and it is relevant to US schools, not UK. The requirement for consent is due to the way the it is worded and conversations with the FTC have shown that the only lawful basis available in the US under COPPA is Consent, and that is either provided by the user, their parents directly or via the school on behalf of the parents. Consent also has a slightly different meaning too, but not by much. If you see a DPA that mentions COPPA as the basis of the agreement, tell them you need it framed within GDPR terms. You also need to get them state where any other organisation they work with is a sub-processor (operating under your instructions still) or a true third party (and taking the data to use themselves). The former is good, the latter is to be avoided except for in specific circumstances (some elements of research, etc.) So, back the original problem. If you are using a curriculum tool, and the data is only ever processed under your instruction, then do not use consent unless there is a specific requirement to do so (images, biometrics, etc.).
  20. Biometrics always requires permission for children as it is also subject to the Protection of Freedoms Act 2012, as mentioned in the above guide from DfE.
  21. Firstly, it is not the data subject's data ... there is no ownership of it in that sense. The LA has every right to have it and process it, and to subsequently share it with other data controllers who have a need for it. There is a clear purpose for that sharing and an appropriate lawful basis too. Yes, you would get a significant amount of that data via the CTF and other information sources, but the LA has put the work into structuring it in such a way that it is beneficial to you, the school. The effort would need recompense as a result. Can you do the work yourselves? Quite probably. Have you (i.e. your school) considered the need for this? They should have and should have planned a way they are going to sort it. Is £100 a fair price? When LAs provide a service they are not allowed to mark significant profit on it, so they will have planned how many they think will take up the offer, worked out how much it costs to provide the service in the first case and then priced it accordingly. Some LAs will provide their schools with this automatically as it is part of the service they get. Many Academies *won't* get this service unless it is already covered in any service you have agreed with them. LA schools are likely to agree that Academies should not get stuff for free from work the LA schools are effectively paying for. Think of it as something that needs a guess about time and support your school would invest in gathering this, against what the cost is from the LA.
  22. As a Mac Evangelist … I’m now at the point of agreeing that there is little reason to stick with the Macs for what you are doing. I like GarageBand, just as I like Logic, but it is no longer the best of breed that made such a difference. Unless you have some very specific things you want to do, or have educational schemes of work that require Apple kit (which is possible) then there are other things that will work out as good but cheaper. To be honest, I just use GarageBand on my iPad or iPhone now instead if I want to play about. Any trimming or cleaning gets done in audacity now. No need for Macs And you cannot know how sad that makes me feel. The other thing you lose is a different OS being used and some different ways of working. If the lab is only ever used for a few lessons though, then hard to justify that as a reasonable area of impact. [emoji24]
  23. Good to hear the team were helpful (and the fix looks good too). I'll have a chat with Charlee and drop you a line. Always interested in feedback.
  24. I love all three!!! If it is a tie, does that mean we get all three?
×
×
  • Create New...