-
Posts
12,876 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by GrumbleDook
-
The school photographer is a data processor. You are deciding what is done, not the photographer.
-
Ask yourself this ... who is deciding that the event is run? Who has the final say in what data is collected and used? Unless this is a 3rd party hiring out your school to run a private function that it just happens to involve all your children ... that the school has *nothing* to do with ... The school is the Data Controller. I wouldn’t even say Joint DC ... as it is not compulsory to use this particular event company, if you say no to them taking pics because you will ... I can’t see any justification for them being Joint DC.
-
Who is the data controller?
GrumbleDook replied to Bigbird7's topic in Data Protection & Information Handling
Where there is no choice whatsoever (and you’ll be surprised about getting choice ... it is not always as cut and dried as the LA tells you) then you have the option of Joint DC, but a Data Sharing Agreement between you covers who does what with what, etc. -
It doesn’t matter who owns the equipment, the original pictures are taken under the instruction of the school ... the Data Controller.
-
Who is the data controller?
GrumbleDook replied to Bigbird7's topic in Data Protection & Information Handling
It is the legal entity ... in this case, the school. The LA are a Data Processor, following instructions given by the school. -
The school might use it for record or educational activity but you are transferring the data to a third party for them to use for their own marketing ... i.e. however they want to use it! Simple answer is no, they cannot use it. If they want to use it then *they* have to get consent from parents *and* children (depending on age) ... the other option is a contract to use the images and image rights of the children (which is signed by parents on behalf and possibly the child, depending on age) But that isn’t your problem.
-
Transfer student GCSE exam work to new school
GrumbleDook replied to muppet's topic in Data Protection & Information Handling
Interesting one. The recording has been made by school x of pupils of school x. The video is of an activity done as part of the curriculum to be shared with the exam body... Public Task would available at the lawful basis here? Or was it done under consent? The school will have decided who it can be shared with (Exam Board), but have they said they will share with anyone else? If not then go and ask the pupils / parents ... or inform them you are going to share (public task) but give the right to object. Do your due diligence on the school ... ask who will see the performance, how will it be stored ... Enter into an agreement with the school ... there are a range of ways you can skin the cat on this one but it does mean thinking about what you are doing, risks involved and so on. It may be that you share with exam board and then they share it to the new school. -
GDPR - When I'm off ill...
GrumbleDook replied to TomHD's topic in Data Protection & Information Handling
No, they do not need to give out medical information in this way. -
I've been asked for examples of BYOD policies in schools to help support a program with schools. I've got a handful of older references but don't have permission to share yet (looking into that), but do any fellow EG members have any that they could link to for me please?
-
Encrypted and then moved over encrypted tunnel is better, in the same way wearing a diver’s dry suit whilst walking in a corridor will keep you dryer then walking naked on the pavement ... (If there is risk that the windows in the corridor are left open and it is monsoon seasons then you realise the above is not being sarcastic but about risk management). And the reason the old file is left ... so you can check what was transferred. There are improved ways of doing this now though.
-
If the file is in a secured folder on the server then plain text or otherwise is a risk management thing. It is how it is transmitted that is the important question to ask. I don’t know the software itself and have spoken with them directly but ask them about secure transport and how that is managed.
-
Denis Norden: TV host and comedy writer dies aged 96
GrumbleDook replied to elsiegee40's topic in General Chat
An absolute genius for comedy and, like a few key others, the reason we have had such fantastic comedy in the UK for the last 70 years. -
The DPO role - personal liability
GrumbleDook replied to Ditto's topic in Data Protection & Information Handling
Yep, but again ... be aware if contract law and failure to complete contracts, etc. In risk management terms, some schools are looking to transfer the risk. You can’t. You are not even sharing the risk. You are reducing it ... or putting in a fallback. Both valuable and worth the time / money. -
Data sharing with NHS
GrumbleDook replied to Jollity's topic in Data Protection & Information Handling
The sharing may be Controller to Controller to allow them to comply with their legal obligations ... however you should complete a DPIA and ask for a copy of theirs so that you are taking due care when sharing data. If you do share data then it should be transported in a safe and secure manner. If that cannot be guaranteed then you cannot share. There is nothing that’s says *they* have to provide the method of transfer ... you could set up a secure pickup box that they have to use. It may be an inconvenience for them, but you have to be safe and secure. -
The DPO role - personal liability
GrumbleDook replied to Ditto's topic in Data Protection & Information Handling
IAPP have some fantastic courses and CIPP/E looks like it will cover most areas that will end up in the DPO certification accredited by some Supervisory Authorities ... but it is heavy going. I’m doing the reading for it at the moment and it can be heavy going. It probably could go into a different thread but as we are talking suitability of DPO I think it is still relevant. We have to remember that certificates are a momentary thing, some courses are pretty much the same cost no matter which sector you come from (10% on a £1900 course means nothing if the school is struggling even to cover your expenses to get to London / Birmingham / etc.) and there is no accreditation yet (so be wary of ‘certified’ courses when it comes to GDPR) There are courses to go on to get a certificate, courses to get knowledge, courses to be peer-recognised ... and this gets combined with experience to make the right person for the role. There are people on LinkedIn who have done a mass of courses or run courses and in general there are a few that seem to stand out. 2040training always get a massive seal of approval within DP / IG circles as Tim Turner has a concise and precise knowledge of what he is talking about. ActNow and Amberhawk are always well received. IAPP courses are in depth and serious ... and everyone I’ve spoken with say they have great trainers. Anyone who can show operational experience combined with MIS and records management courses, or FoI training, will be gold dust for you. Realistically, a lot of schools will make do until the right person comes along or the skills are brought up to speed. -
The DPO role - personal liability
GrumbleDook replied to Ditto's topic in Data Protection & Information Handling
“Firstly, the GDPR does not provide for any specific liability for the DPO. However, the Art. 29 Working Party addresses this issue in its Guidelines on Data Protection Officers of 13 December 2016. These guidelines state that the controller or the processor remains responsible for compliance with the data protection laws, and accordingly it will be up to the controller or processor to demonstrate compliance, regardless of how much autonomy the DPO is granted. Therefore, even though the DPO is responsible for assisting the controller or processor in monitoring the internal compliance, the DPO is not personally responsible for any non-compliance with the GDPR. In addition, the GDPR further clarifies that the DPO should not be dismissed or penalised by the controller or the processor for performing his or her tasks” https://www.lexology.com/library/detail.aspx?g=ef6f8142-9283-4a98-be5f-54d1054fd646 Written late last year but still a good explanation. Of course, this does not absolve DPOs from competency claims under their contract but that is employment law ... e.g. the DPO maliciously and wilfully withholding or falsifying information. It will be case law the makes a point on all this ... If anyone is a DPO there are membership groups out there you can speak with such as NADPO or DP Forum UK. -
New Edugeek Users - Introduce yourself here :)
GrumbleDook replied to tarquel's topic in General Chat
Good to see you back. Chat to @ZeroHour about the old account.- 4,289 replies
-
- assistance
- background
-
(and 2 more)
Tagged with:
-
Student Request for filming
GrumbleDook replied to DrCheese's topic in Data Protection & Information Handling
Personal use ... GDPR does not apply, but there is no guarantee how it may be used in the future ... so no! -
SAR - Medical records
GrumbleDook replied to Simcfc73's topic in Data Protection & Information Handling
The information has probably not been gathered by consent so the age of digital consent is not relevant here ... as a private school I would judge that it is contractual obligation (under article 6) and purposes of preventive or occupational medicine (under article 9 - special category data) ... but get your DPO to look at the DPIA on this. As such, the parent is the legal carer of the child, and the contract is with them (including as the legal carer of the child) and has rights to medical information ... unless an exemption is applied ... and they have to be justifiable. "Not being comfortable" ... that is going to be a hard case to argue. I would suggest that the nurse consults with her professional body on this as they will have plenty of experts looking at the exemptions. -
SIMS photos / Legal basis
GrumbleDook replied to jonathan.lees's topic in Data Protection & Information Handling
It is an interesting one with using Legal Obligation as the lawful basis, but remember that there are other legal reasons that may affect what happens with pictures. Nothing 'trumps' anything else ... it is all information that helps in the decisions made about why you do things in a certain way. To some extent, the right to object it a way of raising a flag that other things have to be considered. Whilst it is considered the school might consider it a right to restrict ... but the whole point is that the school considers it and what the impact is ... and can then justify the decision if ever pushed to do so. I've floated out the above to other DP folk and will see what they come back with. -
SIMS photos / Legal basis
GrumbleDook replied to jonathan.lees's topic in Data Protection & Information Handling
If the photos are being taken where the lawful basis is public task or legal obligation, then the parent is raising the right to object, not withdrawing consent. The school would review the request and identify whether they uphold or reject the request. Where the lawful basis is legal obligation (e.g. a photo attached to medical requirements would help identify if someone uses an EpiPen) then this is going to be rejected. Where it is as part of a classroom display, then the school might uphold the right to object as there as personal reasons behind it, or they might reject it as they see a clear benefit for the child being treated the same as other children. Where a student is in a group photo the school would make an assessment of this before photos are taken (on a personal note, this is an objection I have raised and has been upheld) and children are even known to get involved in helping with this. A group photo but the child hides their face with their hand, holds up a mask ... there are way around it. Or they simply are not included. Where pictures have already been taken, then that needs to be logged and handled carefully. Your MIS is often the best place to capture that information. -
SIMS photos / Legal basis
GrumbleDook replied to jonathan.lees's topic in Data Protection & Information Handling
It could come under legal obligation or Public Task ... but remember that if you then use the photos for other things you have to have a lawful basis along with a justifiable purpose.
