-
Posts
12,876 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by GrumbleDook
-
Please don't presume media is exempt ... you require consent on this otherwise you affect LAC / former LAC / where court orders apply / a range of other personal circumstances As discussed on the other thread, you should not use LI for a core activity or where consent is the appropriate lawful basis. Publishing pictures of activities to the public is not a public task, strange as it may sound when first thinking about it … public task refers to the delivery of education / curriculum / care of the child and others at the school. School prospectus - please link to ICO guidance on this as it contradicts advice I have had (cinconsistencies do exist with guidance and contextual conversations within ICO ... which is how they improve their guidance)
-
GDPR - Managing consents
GrumbleDook replied to Jamman960's topic in Data Protection & Information Handling
Some of this you are confusing the right to be informed where the lawful basis is public task or legal obligation ("We are using your picture to identify if you are a hooligan") and consent to process ("Can we use your picture to take a register in an automated fashion?") Permission implies a reference to consent ... it is very hard to separate the two terms out. At the DfE hackday looking at retention and purposes we discussed consent forms for educational activities, and it got confusing. Even after we decided that we would call them permission slips (attendance on education trips in England does not require specific as there is statutory guidance on this from 2014, so processing any data related to this does not require consent either, it is a public task) it was still felt that it was very close in terms ... but saying "information notice to parents that also gives them a form to object to taking part in an educational activity that children could normally go on" is a bit of a mouthful ... so the common sense approach is use careful language but try to be clear and transparent. When you are clearly talking about permission to do something ... you are talking about consent. Where that permission is related to data you are talking about the lawful basis of Consent. -
GDPR - Managing consents
GrumbleDook replied to Jamman960's topic in Data Protection & Information Handling
@localzuk has captured pretty much everything … anyone would think that this is a discussion that has been going on for over 10 years now and he's read pretty much the same things I have and he is spot on with the tests ... necessity is the key one. @Edutech98 you have understandably, and possibly justifiably, argued that as a marketing tool there is a legitimate interest in using pictures of real children from the school doing things they will learn and experience at the schools ... and whilst LI is understandable you have to think which is the most appropriate lawful basis where multiple may apply. It boils down to the balance between LI and Consent. If you go down the consent route there is a fair balance of families and children that will be happy with this (I'll discuss the time periods separately) as it not only celebrates the activities of the school, it celebrates the activities of the children involved ... and whilst the use of this within a school environment can fall under Public Task, use on the website and social media would not ... hence consent. If you look at legitimate interest, then there will still be a fair balance of familes and students happy to promote the school (i.e marketing) as LI can be used as it is not a core function of the school ... but celebrating the activities of the child *is* a core function (as established as Public Task for use within school) and so LI *cannot* be used. So it boils down that this is purely for marketing. It is not a nessity for the school to use pictures of attending children doing real activities. It will fail as there are plenty of alternatives to this. Now, lets get onto the time periods on this. Again, we are looking at what is truly required and is it appropriate. If we are using Consent (which I think we have established is the applicable lawful basis) then we go back to the above 2 reasons for use of the pictures ... celebrating the school and celebrating the children. If the child is no longer at the school is it a requirement to celebrate them? Perhaps ... but not forever ... maybe for up to 1 academic year after they left? That would cover promoting success in the summer cricket tournaments during November ... when Cricket season comes round again, surely those pics would be replaced by new successes? Celebrating the school? Do you have to use those particular pictures? No ... not unless there is a particular outstanding achievement perhaps ... and in which case you can ask for specific consent from the family in the same way news outlets do ... to use and re-use the pic for x years ... up until the poin it is moved across to a public archive. And managing a Public Archive in school should not be attempted if the school is trying to use it as a way of keeping things to be used forever ... go and have a chat to the education team at the National Archives for guidance on that ... that is *very* special and you need to speak with archivists to truly understand it! So we come back to the idea of using LI. It fails on several attempts. If you try to use it then prepare to be challenged. -
GDPR - Managing consents
GrumbleDook replied to Jamman960's topic in Data Protection & Information Handling
I love this ;-) I'll talk about managing consent in a bit ... it is a pain ... when not done properly and without due consideration. It is also worth saying that a little pain up front is worth it to save a monumental hurt (to the child, the school or both) later on. -
As just mentioned … they are … and they aren't. And example would be where an incident has occurred where a non-resident parent has become a possible threat and information needs to be prevented from being sent to them. Under the requirements to pass on the educational record (a legal obligation) then the school should do so, but the protection of the child (also a legal obligation) would mean you don't. It is not that safeguarding trumps GDPR (I hate it when folk say that), it is just that a different legal obligation is held to be a higher priority on balance. It is a balancing act and will be a minority of cases where the balance of actions falls towards the student's request.
-
The OP has said that there is a legitimate reason for this request and it has been upheld, and this is a perfect example of a school taking into account situations, making decisions, getting them checked and sticking to them. It would be done on a case by case basis and it would have to be justified. Just because the school has said yes in this one instance it *does not* mean they will say yes for others. That said, when I posed this to one of the Data Protection groups the following came back pretty sharp from a member in Leics. "https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/489901/Parental_Responsibility_Advice_for_School_January_2016.pdf Page 8 of the document linked above suggests other legislation overrides the wishes of your student:- Under The Education (Pupil Information) (England) Regulations 2005, schools are required to provide access to, or copies of a child’s educational record to parents upon request. Therefore, if the school were to abide by the request of the natural parent they would be in breach of their obligations under education law. To note: under the principles of the Data Protection Act 1998 (the DPA 1998), children and young adults can assume control over their personal information and restrict access to it, should they be of sufficient age or maturity to exercise their will in this matter. However, this control is not extended to cover information which is held within a pupil’s educational record. Parents are entitled to request access to, or a copy of their child’s educational record, even if the child does not wish them to access it. This applies until the child reaches the age of 18. This is however, subject to information that the school could not lawfully disclose to the child him/herself under the DPA 1998 or in relation to which the child him/herself would have no right of access under that Act.3 For example: a non-resident parent who has limited contact with their children, contacts the school to find out how well they did in their exams. Neither the children nor the resident parent wishes to share that information and informs the school of this. The school refuses to release the information on the basis that the children are sufficiently mature to have control over their personal information. The school has therefore breached education law by failing to provide information to which the non-resident parent is entitled." I cannot see anything specific from DPA2018 that would affect the 1998 intepretation, even on the right to object as there is a legal obligation to comply with the above act. It might sound like fence sitting ... but it really is a case that you need to take into account other legislation and statutory guidance when these decisions are made.When in doubt, seek advice from your DPO and professional legal advice.
-
GDPR - Managing consents
GrumbleDook replied to Jamman960's topic in Data Protection & Information Handling
Photos on the website require consent though I would be interested to hear why you think they would be Legitimate Interest. Photos around the school could onlybe used for public task if was being used for the education of that data subject, or whilst they were there ... what benefit is there to the data subject in it continuing to be used once they have left? -
GDPR - Managing consents
GrumbleDook replied to Jamman960's topic in Data Protection & Information Handling
Generally it would be as per your retention schedule and as per the retention period specified on the relevant consent form. For students who have left ... if you don't still have a relevant consent form then get the pictures off straight away! For student who are leaving ... it depends on what was on any cosent form ... and this is another push for granularity here. If they say "remove my photo" then they mean all of them unless they are obviously being specific ... also remember that you have a duty to uphold their data rights and are a public authority. Be helpful and ask them the question of which photos ... there are two reasons for this. If you are trying to trick them to save work then it will be both publicly bad for the school and a dim view will probably be taken by ICO. Secondly ... if you are not helpful you are going to end up with them asking where all their photos are ... and that is a SAR ... so more paperwork! And managing assets ... yes, managing pics will be a pain in the backside. Let me know if you ever find a good solution! -
GDPR - Managing consents
GrumbleDook replied to Jamman960's topic in Data Protection & Information Handling
This is usually done as the school as data controller for the children and the school / partner as joint data controllers for the parents. -
[sims] Urgent Capita SIMS Data Issue - Issued by childrens services
GrumbleDook replied to vikpaw's topic in MIS Systems
Sorry for not responding sooner on this, but we are chatting to look at the best way of helping customers and members. There have been notifications and that is part of a separate discussion. I'll feed back later today. -
A lot of consent forms are written as such that if you take part, then you are granting consent ... or rather, by granting consent they can now take part. It might not be the case in your school but a substantial number still don't understand the difference. It might also be that I am happy for a pic to be on the newsletter but not on twitter, or on the website but not on FB. The chances of pictures of family being found by birth family on the school website are small, but the chances on FB are higher. At that point some schools start talking about, "well, tell us which ones you don't want us to use..." and them you have to explain again about this becoming opt-out, not opt-in.
-
[sims] Urgent Capita SIMS Data Issue - Issued by childrens services
GrumbleDook replied to vikpaw's topic in MIS Systems
Better than quoting Hear'say! -
And then parents like me come along and say the lack of granularity means my son/daughter generally has 2 choices ... take part in everything and the pic can be used or take part in nothing. Consent cannot be forced and should not disadvantage the data subject. If it means not being able to do school events, that disadvantages children.
-
This is more about employment law than GDPR. To be able to handle and process data on behalf of the Data Controller a relationship needs to be established. For volunteers this will be based around things like the AUP and signing agreement to other policies, and for staff it is the employment contract. The contracts have start dates but *may* have other things in there to say the relation starts from the point of signature on an unpaid / volunteer, reasonable basis. It has to say this as the school cannot ask for lots of work to be done whilst employed by someone else. There is also risk about using devices from the old school to do work for the new school. Generally I would suggest schools do a DPIA on leaver / starter processes and update processes / documentation / contracts as a result (get it written that it will be done in September to allow you a chance to review what did or didn’t work well?) I’ve added it as an idea for the next iteration of the DfE toolkit, but that will be too late for this year.
-
Pretty much what @Ksavage413 has said. Within Records Management and data retention schedules, there is a requirement that data is always accessible, meaningful and that you can uphold the rights of the data subject (as and when they apply, considering exceptions and other factors). As systems evolve or are replaced, data collected, stored, processed and archived should have continuity to it, as a break in continuity would mean a break in access and/or integrity ... which are, in turn, breaches of GDPR. Simple example. If you retain data in the form of an MIS archive, then make sure you have the software to access it. If you back up to tape and have a 25 year retention ... do you still have that DDS2 drive?
-
A few things ... the cloud hosted version has to comply to GDPR as data subjects involved are EU Data Subjects. Secondly, for the school hosted version, you are Data Controller and data processor ... you set it to comply with your retention schedule. If you need to keep ticket information (including user details) then you keep it. Look at the purpose for processing ... in this case to manage and run IT services within the school. Then look at the lawful basis for processing ... if you don’t manage IT what would happen? So many thing to put in here but first would be your own GDPR compliance as you couldn’t ensure the security of data within the school ... that bit is a legal obligation How long do you need it for? 1 year after the ticket is raised? 2? 5? It is up to you but justify it. Do you need to keep the user associated with it? What do you record? Incidents? Problems? Tasks? If tasks does that include setting permissions on different systems? Would you need to know that after an employee has left (yes ... look at both limitations and historic allegations), so you are starting to understand that you need to keep info for a certain period of time. It might be that you opt to ‘change’ the name of the user with the service desk as a way of anonymising ... maybe 3 years after they left employment? Remember that it is your school that assesses it and makes a judgement call. For students ... again? Do you want to delete users and tickets or just anonymise? Change the names? DB changes? There are ways.
-
I spotted Elementary will be dropping off NowTV in a month so decided to give it a go. Now I’m thoroughly hooked.
-
Supposed records management term that annoys people who work in records management, from what I've seen
-
GDPR CCTV clip to parent
GrumbleDook replied to leegcvcc's topic in Data Protection & Information Handling
This is always an interesting one. I've seen it argued that this is a public task. As crimes range in what they could cover, it can and will cover forms of assault, and this comes under safeguarding ... vanadlism is a form of criminal damage and the school has a duty to protection public investment. I've seen that challenged and schools back down, but i've also seen schools say that no, this is what our risk assessment has come out with ... and the general response is 'OK, that is your decision.' It then falls down on what protections are put in place about the information, how transparent you are (how many schools want to be open about the risk of vandalism or assault at their schools). Also remember ... Legitimate interests ... safety of students and safety or property ... core activities ... public authorities ... There is another reason why you might not show other children. If the incident being reviewed has a chance of needing to be reported to the police, then you don't want to introduce possible risk to witnesses. Items that are public interest as above, coud also be arrestable offences. -
New Edugeek Users - Introduce yourself here :)
GrumbleDook replied to tarquel's topic in General Chat
I’m not allowed ... apparently it is frowned upon to have a side line in selling 3D specs. Also telling people who complain about it being to dark yo just open their eyes a bit more is also not good.- 4,289 replies
-
- assistance
- background
-
(and 2 more)
Tagged with:
-
GDPRis Data Breaches
GrumbleDook replied to Jaymate's topic in Data Protection & Information Handling
Evening. I’ll drop you a DM in the morning with some good news. -
New Edugeek Users - Introduce yourself here :)
GrumbleDook replied to tarquel's topic in General Chat
That has just made me launch iWittr for the first time in ages.- 4,289 replies
-
- 1
-
-
- assistance
- background
-
(and 2 more)
Tagged with:
-
Have a look at the NCSC site for Cyber Essentials and Cyber Essentials Plus. Definitely worth it.
- 2 replies
-
- 2
-
-
- compliance
- gdpr
-
(and 1 more)
Tagged with:
