-
Posts
12,876 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by GrumbleDook
-
GDPR - Managing consents
GrumbleDook replied to Jamman960's topic in Data Protection & Information Handling
And we have still to hear about where ISS fit within schools with respect to the age appropriate design code. -
GDPR - Managing consents
GrumbleDook replied to Jamman960's topic in Data Protection & Information Handling
Marketisation of education ... you mean we don’t already have that? (something for a completely different thread!) -
Because saying "don't do it" rarely works and you should have at least investigated technical and organisational measures ... and taken them where you can. Rdcuing risk vectors can be a fine art, but for something as general as this ... I think you are going about it the right way. USB sticks are a bad thing to put data onto ... so if you can eliminate a vector for data loss, then go for it. You have established the scenarios and know that organisational measures are unlikely to reduce risk.
-
Data Retention - Quickie
GrumbleDook replied to Simcfc73's topic in Data Protection & Information Handling
Just to clarify (as a query has been made), as an IRMS member I've volunteered, on a personal basis, to assist in updating the toolkit and if there are questions you can always send them in directly to [email protected] or find out more news (or even join) via https://irms.org.uk/news/ -
Data Retention - Quickie
GrumbleDook replied to Simcfc73's topic in Data Protection & Information Handling
This is where the DfE toolkit talks about the blurring effect. You need to remember that children have rights after they leave education to challenge activities that went on. The commonly agreed period is that this can happen up to 7 years after their 18th birthday (hence the 25 years) but that doesn't mean *everything* needs to be kept ... only where required or likely to be needed. Both the DfE Data Protection toolkit and the IRMS Toolkit for schools will be updated over the next few months, so let me and @maturelady know any questions you have (She is focusing on the DfE toolkit and I will work on the IRMS toolkit). -
I posted an updated in one of the other threads about this but will stick a summary here too. This is stepping on employment law now so I had a chat with the ACAS helpline. Unless a contract states what happens before the start date, then the start date is when the obligations and responsibilities apply as that is ... wait for it ... the start of the contract! This means that access cannot be given unless the member of staff has clearly shown that they have agreed to the school / organisation policies. That could be that the contract is updated to give them the status of 'volunteer' until they start as a paid employee, and it also means that you *have* to show that you have given any required training, etc. when giving access (this is part of GDPR demonstration of compliance). The same applies with safeguarding, H&S and so on. Just because someone is a volunteer it doesn't mean they have access to everything in the same way you don't let someone up the talloscope to change the lighting rig until they have had training.
-
Possibly battling with all the other questions that need looking at ... some DPOs are the equivalent of maybe an hour a week, others have a day ... so they rely on others to get answers to the questions and hand them over ... and that also takes time (get the questions out, get responses, review the responses, panic, calm, panic again, calm again and start asking questions about *WHY*).
-
Safeguarding information and GDPR
GrumbleDook replied to mjk's topic in Data Protection & Information Handling
I’ve just been reading this on my way home from holiday and was going to point folk to it. I’ve continued the discussion from other threads around safeguarding and data protection, and retention is another aspect. The important thing to always ask yourself is “what data do we need?” If that is something for a long term reason then you ask yourself to justify the limits, if you find there are legislative reasons or cases giving credence to your actions, then you have your answer ... but be prepared to justify it. -
Safeguarding information and GDPR
GrumbleDook replied to mjk's topic in Data Protection & Information Handling
Your logs / filters are step one. Information may be processed automatically be step two, recording as data of interest or to be sectioned, is done via the relevant safeguarding / behaviour system ... and that is a human decision. That data is then kept for the relevant and longer period. Emails and logs should not be used for long term retention. If you are then you need to look at retention facilities that are commercially available and do this properly. -
GDPR - Managing consents
GrumbleDook replied to Jamman960's topic in Data Protection & Information Handling
A few areas to consider in this. Re photos in public task for identification. Identification can mean on SIMS (important when logging behaviour incidents or needing to verify individuals at speed), on ID Cards (are they someone who is meant to be on-site?), knowing if they have particular needs (medical requirements such as needing epi-pens ... although this is processing special category personal data you still need a valid lawful basis under section 6 of GDPR ... and whilst other lawful bases are applicable too, public task is acceptable as you are already using it). The definition of a public task is for core activities. In November(?) DCMS issued a letter of guidance to all departments, to the ICO and other groups, pointing out that public authorities can only use LI for non-core activities. That means schools need to look at what their core activities are as set out by legislation and statutory guidance. And there is a lot of it. Marketing doesn't appear in there. I've spoken with one academy that, similar to how you have set out, that they have a responsibility to get bums on seats and keep the school funded by having a full intake. To some extent this is what the old requirement of a prospectus was for ... however ... If we look at the School Prospectus, take a look at this *old* article from Modern Governor (https://www.moderngovernor.com/school-prospectus-and-publishing-school-information-on-the-internet/) showing how long ago it changed that schools don't need one but need to publish information on their website - https://www.gov.uk/guidance/what-maintained-schools-must-publish-online is the present guidance (including link to relevant act) and also links to what is needed for free schools, acedemies and colleges. In there there is no requirement to show pictures or show activities that are part of pitching the suitability of the school ... no chance to say you *have* to show that you have all the latest tech, show children having fun in your swimming pool with retractable roof or to show that you get visited by Olympians. The requirement is now to state facts to get people to look at the school ... everything else is not a requirement but ... well ... marketing. You have fulfilled your Public Task already ... you don't *need* to have lots of pics. Once you have established this then it leaves you asking how you can comply with the guidance as it stands *and* also with DPA2018. By gaining consent for media and marketing at the beginning of the year use you can continue to use that basis for events and, as you describe, you give continuing notice to families as events continue ... allowing families to raise their right to object. That would indeed reduce the amount of paperwork you do as a result. The downside is that if a sizable number of families exercise this right it starts to look like you are putting an opt-out solution in place ... and as we know, opt out is a no-no. There is also the risk that some events can only be participated in if consent is agreed. I know that there have been explanations from other members that *they* would never allow it to be aused that way ... who is to say everyone in the school will continue with that. Once in place ... it is there and hard to avoid. This is one of the reasons why the law talks about consent being unambiguous and not providing it should not disadvantage the data subject. From personal experience, and from collectively talking with adoptive parents/guardians or parents who take more care over online footprints, this is a real and present issue. And so the balance falls down to working out what can be a general consent and what is done on a case by case basis. For a prospectus, this is a perfect example. You gain permission from a parent / child. There is a reasonable understanding that this is a long term thing. They can't just change their mind. Effectively it becomes a stock photo ... and so some schools even consider the generation of stock photos and recompense for families ... and at that point it becomes processed under contractual obligations ... and the school has *way* more control. And this is just touching on it ... and not going into some of the other areas I've raised in the various threads. Of course ... if the DfE was to determine that marketing to get bums on seats was an required activity of a school, it would change things in a number of ways. You might get push back from those looking after the rights of children though. -
GDPR - Managing consents
GrumbleDook replied to Jamman960's topic in Data Protection & Information Handling
I've PMed as this is boiling down to the interpretation of a piece of guidance that was published a number of years ago and has a number of areas that can be challeneged in reference to GDPR/DPA2018. Until that is updated or clarficiations given (which could have wider impact on other public authorities when considering what is core / non-core) we have two positions. 1 - Take the existing guidance from ICO on face value and run with it (whether because it is published advice or because it is felt that the existing guidance does not require a change in approach under GDPR /DPA2018) 2 - Look at the guidance and consider the other factors that the recent change of legislation has introduced, and look at how to change as a result. Both EduTech98 and I have put positions out there, so there is not much else to be covered on it right now that I can see. If people want to discuss particular aspects of point 2, then happy to ... but there is little to benefit right now on discussing the differences in positions of 1 and 2. -
GDPR - Managing consents
GrumbleDook replied to Jamman960's topic in Data Protection & Information Handling
And this is where I am trying to fathom out what on earth this discussion has been about. If you are using the picture online to market you must either be doing it under consent or LI. Marketing is not a Public Task. You've said you are not using LI so that only leaves consent. The above statement pretty much confirms that and you appear to be recording that on block? But then you are giving them notification of individual use and allowing them to raise their right to object ... which needs to be recorded ... and as part of this you must tell them how long it will be used for, either as part of that discussion or as set out in your retention sechedule. No, just several hundred ... and if done thoughtfully, it wouldn't be several thousand ... just once a year, with ad-hoc additional events for a handful of students at a time. I have been called far, far worse ;-) -
The context is that this is done with the family / child having given consent to this use and are being notified that it is done. Responded to in the other thread. Please remember that other legislation has an impact when doing your impact assessment of this. Please understand that some pictures used in the day time during lessons (behaviour charts, birthday charts) are items that may have risks associated with them, depending on what else the school uses that classroom for, who can see in etc. It is a risk-based approach. Saying that parents can request it ad-hoc means you are enforcing opt-out ... this is not legal. And as for thousands of records ... wow, imagine that ... a school having to manage lots of bits of information about individuals, like name, address, medical information, behaviour, friendship groups, attendance, permission to attend and take part in activities ... Anyone would think there are solutions out there that can help with this? Difficult does not mean you should avoid things. I really do think you are missing that fact that this is a risk-based approach and that guidance should not be taken in a silo but understand as part of the wider picture. An open question to you now ... have you taken all of this to your DPO or is this from your DPO?
-
GDPR - Managing consents
GrumbleDook replied to Jamman960's topic in Data Protection & Information Handling
Erm ... you have been talking about marketing to parents ... PECR would be an item of legislation to be taken into account when evaluating purpose and lawful basis. The data subject whose picture you used, if used for marketing (as you insist it is ok to do so without consent) would also need to know that you are following the rules with regards to where that picture may go, what context it is used for ... how are you doing that exactly? -
GDPR - Managing consents
GrumbleDook replied to Jamman960's topic in Data Protection & Information Handling
You can request that formal archives do not retain a copy of your website, you can state they can only do it for x years and you can also work with National Archives to have a public archive ... I would suggest the latter first as they truly are experts in this area. -
GDPR - Managing consents
GrumbleDook replied to Jamman960's topic in Data Protection & Information Handling
Wrong. You need to have it in your retention schedule. You also need to be able to justify continued use. Even if you tried to claim for marketing purposes ... you market against what the school does. If you have a picture of a science lesson and the currciculm changes so that lesson does not happen in that way anymore, if H&S changes what can be done, if the layout of the room changes and is no longer a true reflection of what the school looks like ... you are no longer following the original purpose. Please don't say "but the ICO said" as the ICO will also say read the rest of the act. -
GDPR - Managing consents
GrumbleDook replied to Jamman960's topic in Data Protection & Information Handling
Appreciated And this is where there is conflict on ICO guidance. This is an area where an update is needed perhaps and it even contradicts what happens when completing DPIAs. When you do your impact assessment you can look at you the purpose, where data will be used, the lawful basis and a raft of other items ... where there is are legal requirements that can affect the purpose this *has* to be taken into account and the legislation around safeguarding is part of this. At this point, most schools will struggle to do anything but opt for using consent. I'll raise to ICO again on this as it doesn't uphold the rights of the individual. Whether it is a 'waste of school resrouces' is unimportant. Many feel that way about H&S, but it is there for a reason, and what might appear as common sense can sometimes be ignoring other factors as it makes it too difficult. -
There are lots of examples where laws appear to contradict one another which is why we have a range of tests that can be used to assess where the core requirements lie. They do try to update all relevant and linked acts to refer to or amend those acts when new legislation comes in ... but sometimes the intracacies are a tad insane ... and as much as we might joke about lawyers getting paid silly money, this is the reason why.
-
And this is where the nuance comes in. I do not know the issues with this specific case, and to some extent we are talking hypotheticals here, but where a child has a non-resident parent and where there is a possible threat (not yet taken to court but police involved) access to data about the pupil could result in information about gaining access to that child which could result in coercion and jeopardise a police case. An instruction would not have come from the courts on this matter but from the child as there is a risk of harm or distress. If the child and resident parent are fleeing from the other parent due to domestic abuse, then the non-resident could use information in the educational to find the child and other parent. If there is a risk of a non-resident parent taking the child overseas for an arranged marriage and information int eh educational record shows items that may help them (educational record showing high academic achievement may be requested by the other family to show suitability). And there will be a myriad of other minor scenarios that relate to the protection and welfare of the child that are covered under other acts of law. So, the balance test comes in ... and it is not that safeguarding trumps GDPR ... GDPR says you follow all the appropriate laws ... and the law says you do the balance test looking at risk of harm to individual agains the request of another.
-
Transition Photos
GrumbleDook replied to Gongalong's topic in Data Protection & Information Handling
I don't know … some schools seem to label children so early in their educational life! ;-) (interesting to note that by having the yellow dot you are publicly showing there is a medical interest in a child … which is special category personal data!) -
Transition Photos
GrumbleDook replied to Gongalong's topic in Data Protection & Information Handling
Yes, it would be compliance with legal obligations or public task when looking at safeguarding (KCSIE is the guidance you would reference in the first instance) but some children may have Vital Interest applicable as well (nut allergies, vulnerable groups, etc.) but as legal obligations and public task would also apply to them, you would wonder why make a special case. Hospital schools, PRUs, Special Schools may look at things differently though. -
Classrooms, they can be public areas but are generally controlled access. Where they are used for public activities (e.g. they are hired out) then they should be treated as public areas ... this can be managed though by having pictures in places that can be covered up, locked away, etc. It just depends on your school and the situation. Anyone would think that this is why people keep saying that data protection is about risk assessment. And yes, I heartily disagree about bundling all web and social media in together ... and again it is about risk. For some families, the risk where the picture is on the school website is small ... it can increase on twitter ... but can become high on Facebook. This is the data protection and safeguarding element of the argument. Because there are different levels of risk that *should* be treated separately. However, where some schools tie in all their social media together ... a news item on the website is automatically fed to facebook, which subsequently sends out a tweet ... then the risk is a single one across the park (i.e. high for affected families) and so only one box for consent is needed And yes ... I disagree with schools who approach it this way as it does disadvantage some children ... that is an education arguement though, not a data protection one.
