Jump to content

GrumbleDook

Edu Supporters
  • Posts

    12,876
  • Joined

Everything posted by GrumbleDook

  1. There were companies doing this 10 years ago ... and they worked with LAs or Govt groups to deal with this ... that’s why Becta gave out advice 10 years ago. Compliance has been a growing sector for some time. And police officers have always been told to justify their requests where I have worked ... but I am aware that this has not been the standard position for many schools even now! I think the message in all this has become a bit warped in the conversation. The police requesting the information (i.e. ad-hoc data sharing) will have a purpose. They will have legislation to support this (as already mentioned) giving it a lawful basis. When the request for information comes in they should explain this. When the request comes in the school should consider whether they should agree to it. They also have to consider how long they will take to complete it. There may be safeguarding issues (get it done immediately) or it may be part of a longer request. Police are used to filling in forms. They won’t object. If in doubt speak to your DPO. If there is an issue speak to *their* DPO.
  2. Nope, it worked teh same under DPA98
  3. Firstly, inform people what the purposes are, that the lawful basis has been updated and start the exercise again. If the purpose has expanded then you need to review and inform. Be prepared for objections but make sure you have your decision documented.
  4. As someone who has to meet a lot of people throughout the year ... and someone who can be terrible for faces / names ... this sort of thing is so useful. LinkedIn has been my saviour on so many occasions.
  5. I can understand your position, but it might be the school's position that *all* staff should be easily identifiable ... The website, that is more difficult to justify, but internally within the school ... all staff should be identifiable, but I am aware that the size of the school is a factor here.
  6. Yes, all the stuff that analysts used to do in their heads but can now be done on a wider scale. That is why Privacy by Design is such an important principle.
  7. Thanks for the responses so far ... So, we have that you need a purpose ... we've had one good example - for safeguarding reasons. To expand this a bit more ... schools have responsibilities to make sure that parents, children and visitors know who to approach should there be a concern. To see and ID badge you need to be fairly close to a person but if you have seen their pic on the noticeboard in reception, or even on the website (the purpose is the same ... it is just the place where data is published is different ... but you can review this as a whole) then there is a better chance the right person will be recognised and approached. Safeguarding is part of the school's responsibility so it clearly fits within Public Task as a lawful basis. So ... no consent needed. That's not to say staff can't refuse. This is the right to object, and whilst not an absolute right, consideration may be needed (adults who have escaped abusive relationships may not want their pic on the website, but fine on a noticeboard in reception). There are a range of possible purposes ... Allowing parents and children to identify staff (Note what I mentioned about ID cards. One company I know stopped using lanyards after complaints that the ID Cards ended up situation smack bang in the middle of cleavage, and that was linked to many people being very uncomfortable about the situation on both sides) Allowing parents and children to identify staff roles and teams (important for DSL and so on) Supporting parental engagement Professional standing (photos on website) and there can be more. Once you have these you look at the relevant lawful basis ... Public Task is a general one ... but LI could be used (you need to do an assessment on this) and then Consent. Risk assessments can help with the breadth of where images are used and what you do when you need to uphold the rights of individuals. Does that help @DrCheese ?
  8. Safeguarding is a very good purpose. In a previous response we had SLT and safeguarding team ... so a good example. Why would people need to know them? (And apologies for leading people through this ... just trying to demonstrate the process that is needed).
  9. You don’t always need consent if it is personal data. If you did you would have pupils refusing to have their attendance recorded or have detention details sent to parents. Or staff refusing to have performance management recorded. What is the purpose of having photos in reception?
  10. Ask yourself what is the purpose behind having the photos there. Then ask if there is an applicable lawful basis. If others would like to give responses I’ll feed back tomorrow.
  11. You need a purpose and a lawful basis. If you have these, presuming consent is not the lawful basis, then informing data subjects is key.
  12. You can set up specific retention schedules and have the default one delete emails after x days/months/years ... If something needs to be kept for longer, then the member of staff selects the relative retention schedule. You can even have one called 'recorded' that members of staff can apply to an email once the information in it has been recorded in the relevant (and correct) place ... and have that set to delete after 7 days (the email is no longer needed, after all). I have tried prodding MS a few times about explaining these features to schools but have had nothing back. I've spoken with a few MS Partners, who are happy to explain a bit more ... perhaps I should go and see what they can do.
  13. Nope, I'm looking at all schools ... the issue with non-state schools is how you deal with some specific risks due to different legislation applying and the varied approach to relying on the contract with parents for things.
  14. As part of contributing to the continued DfE resources around Data Protection, both EduGeek and ANME have agreed to have members look at areas around IT Services, what they access, how they work and any pinch points where risk might be a significant factor. IT Support (whether an individual working part time within a school, a small team, a larger group across multiple schools or even as commercial IT Services) can be veritable gods within schools, with access and control over key systems and functions. When someone needs things changing in the MIS who do they ask? Searching mailboxes for missing documents? Checking what students have been doing on the internet? Controlling access to confidential folders? Domain admins, sysadmins with root, holders of master keys and alarm codes … the list goes on. And with great power comes great responsibility. What are the checks and balances that we put in place to manage this? Do we document those or do we do it in our heads and on the fly? I think we all know that answer to that. This group will look at particular roles they perform in schools and see which could be considered to have risks associated to them. We will then use the ICO DPIA form (or one of their choosing) to break down how it could be formally reviewed and measures / risk management plan could be put in place. It also means that formal acceptance of risk can take place, giving a level of support / comfort to IT staff. These will then be exemplar / templates that the DfE can point people towards and reference. Contributors will be mentioned as the members of this group. For EduGeek members to join this group, please message @ZeroHour or @Dos_Box with your details. They will short-list and then give you access to the relevant areas. For ANME members, you will be given advice on how to join over on the ANME site. The deadline is Tuesday 18th June Places are limited and so the best cross-section of applicants will be involved. It is open to all, but experience of making decisions on risk would be beneficial.
  15. Is there much else to say on this? Someone uses your systems then they have to considered a paid employee, a volunteer or a visitor. They should only have access to systems that are agreed for their particular role and should sign to say that they abide by any policies / procedures. It needs to be guided by contracts where possible, 'volunteer agreements' and by agreement of policies / procedures.
  16. Many thanks to @Dos_Box and @ZeroHour for inviting me down to speak. I'm glad someone spotted the wittertainment reference ;-)
  17. To paraphrase the late, great Roy Castle .... "Education, Education, Education is what you need. If you want to be the best, if you want to beat the rest, education is what you need!" I talked about the constant drip feed of reminders to staff at the conference last week. That single 30-60 min session they do once a year within Inset is not enough. ICO do posters, we do posters ... there are lots of things that can help.
×
×
  • Create New...