jenatddm
Members-
Posts
117 -
Joined
-
Last visited
-
NetSupport DNA, Telegraph Article.
jenatddm replied to Lone_Rider's topic in Network and Classroom Management
Our response was here. Happy to discuss any of it, including what and why would you have us take down anything. Then a post to respond to the article being pulled, which included text approved by Al. But to be honest, phone would be easier if you want to go through, so can give you tel. no via PM if wanted. -
NetSupport DNA, Telegraph Article.
jenatddm replied to Lone_Rider's topic in Network and Classroom Management
re 1. You're absolutely correct. This is why it says what it does and not that schools are "over-referring". The whole process needs transparency to identify where the 70% is, and where and why that % happens. re 2. Again, this is exactly the point. Staff (if children are using the systems under their watch) must understand the technology, and should be able to comfortably raise those concerns in school. It's why we're keen to get decent materials on this published, bearing in mind there are a wide variety of products on the market and not every one operates as NSDNA does -- and the blog doesn't talk about NSDNA (except the text Al approved) but is generic across the range of softwares in the sector. The concerns staff have are sometimes when a switch is made from one product to another. re 3. This is too nuanced for here, but again, bear in mind we're talking about sector wide improvements, not specific to one product. We have been told by schools we have researched, that around half use the software on personal devices and BYOD policy. Not all monitor only in school, or school hours. The caching question will be good to clarify for everyone too. re 4. It's very different for a child in a school -- different legislation, different rights, different risks, and power imbalance between an adult-child, and employment versus compulsory education and so on. It's important that schools understand that to be processing data fairly and lawfully. As I wrote, this is a challenging, complex area of data processing in the public sector, conflating important areas of safeguarding and child protection with the politics of Prevent. It sounds as though after the suppliers have vetted, it would be good to run draft materials by the Forum and you can take a look. Have a good holiday. -
NetSupport DNA, Telegraph Article.
jenatddm replied to Lone_Rider's topic in Network and Classroom Management
It's not at all an irreconcilable position. Safe, fair, and transparent use of personal data should not be for any company providing tools that process children's data, especially in such sensitive and important work, with such a range of lasting consequences. I believe we'll have more in common than you think. For any company it's going to be a USP to offer good support to schools on anything data related given the challenges of GDPR. Improving consistent materials for schools, for families and children is going to be one positive part of that. See you next month. -
NetSupport DNA, Telegraph Article.
jenatddm replied to Lone_Rider's topic in Network and Classroom Management
Al can verify how often I have asked NSDNA for just that this year, both written and face to face. We met and had a walk through of the product at Bett this year for example. But that's not what we were asked to comment on. -
NetSupport DNA, Telegraph Article.
jenatddm replied to Lone_Rider's topic in Network and Classroom Management
Happy Christmas holidays everyone. I'm pleased to say we're meeting [myself and NetSupport] in January to have a chat in detail about this, and the product, as we've already discussed briefly several times in passing previously, at events for example. Regards this comment and article, for obvious reasons, we were concerned when the journalist approached us and reported the NetSupport DNA marketing manager as saying, "the company is planning a software update that will allow webcams to be activated in a student’s home." Al and I exchanged email, and he has subsequently reviewed and approved a statement that we posted on our website, so there are more facts in the public domain how the product works. More generally, we hope the whole area and use of these products will become much more transparent and informed in 2019. We are developing materials for parents and children to better understand it, and to help you in schools meet the fair processing requirements under UK Data Protection law / GDPR consistently. Some places have better policy, practice, and communications than others. The poll of parents we commissioned in February 2018 through Survation, showed poor understanding, and that 86% of parents with children in England’s state education system think that both children and parents should be informed of what the consequences are, if these keywords are searched for and flags created. This should be the bare minimum provided to families under GDPR rules on [risk] profiling, and we're pleased to get more engagement from companies, including NSDNA, to get improved understanding and consistency across the sector, what good should look like -- and put that into your hands for schools to use. Safeguarding-in-schools generated information, can be the trigger for staff to begin a Channel referral for children into the Prevent programme, and reporting statistics. 1 in 3 of all referrals come from the education sector today, yet 70% of referrals into the Channel programme in 2017-18, resulted in no action for the individuals, so improvement is clearly needed somewhere in that process, to reduce over-referrals. We also get concerns from staff (and more rarely young people) usually where they feel it is not possible to speak up on their concerns on use of these software in school; on over blocking of content, on how to delete flags assigned to the wrong child, or flags created without real cause. We work [for free] with companies whose products are in use across the education sector, often going to sites, and we ask only for the coverage of direct travel expenses. Those who do, tell us they find it constructive and helpful. That doesn't mean they always like the answers, or our opinions, pointing out for example if products have not considered their lawful basis for product development, or lack of fair and required communications to families, and action is needed. We work with, and offer confidentiality to schools, MATs, [education] charities and others, willing to share their own issues, map data flows, testing-in-practice of their concerns (using a dummy student or staff profile), privacy policies, and Home-School ICT agreements that relates to these and any other software / personal data related topics. We will comment in confidence if and how to consider anything in your communications/text that may need updated, or any case studies provided. This makes for local improvement, but for us it is useful is to help feed [anonymously or not as preferred] into national improvements, such as input to the DfE GDPR toolkit, and our own wider work. If you want your school to contribute, you can send us your practical experiences, policies or questions which can help make improvements on any issue that can affect similar schools more widely. For example, to include in a new report we will bring out in 2019. Any companies named get to see the text in advance, and can also contribute text and changes. The UK is a large exporter of this kind of products, and with it we export the potential for both the good and bad practice. It has developed with little external scrutiny over the last ten years, and with increasing consciousness of data protection law, it is almost certain to get more scrutiny in 2019, nationally and internationally. So, with that, Happy Christmas holidays from me, all of us at defenddigitalme, and looking forward to the year ahead. -
The Controller determines the purpose and method of processing. So when the DfE pass data a school collected for its own purposes, which DfE gives on to a third party, the school is still the Controller of that data -- for the purposes for which the school collected it, *and* DfE then becomes the Controller when they require the data under a lawful basis and determine the purposes they collect it for, and it will be forwarded on for -- so DfE becomes joint controller *and* the third party if they then use it for their own purposes, not determined by the DfE -- could even also become joint controllers. Because the data are copies, not a single thing, you can end up having multiple joint-controllers of the same data -- each copy may be under the control of a separate body, for separate purposes. What fails today, is transparent communication of all those purposes to the child and/or parent. (and to the school in the case of the DfE distribution).
-
GDPR - Managing consents
jenatddm replied to Jamman960's topic in Data Protection & Information Handling
LOL. You might need a change of law first and that would not be push back mainly from concerns over the rights of the child, but from those concerned about the marketisation of education. -
GDPR - Managing consents
jenatddm replied to Jamman960's topic in Data Protection & Information Handling
Quite right to say >> "No school *must* put children's photo on ID cards, Sims etc but the guidance suggests you could use public task." And this is why, while your lawful basis may be seen as part of a task a as a functional requirement not the exact thing that you are doing (safeguarding rather than 'use X photo on Y card'), there is also a Right to Object to consider, if using Public Task as its basis, which needs reflected in the DPIA and balancing test of the wants/needs of school, and risks to the child of processing the photo. To-date there is often over collection and over sharing of children's data in/and across education, incl photos. For example, a significant amount of photo sharing, especially with third-party apps, that is done on a very weak lawful basis that is neither lawful nor proportionate, and parents and children would have a strong right to object. Even G-Suite for education, can enable photo uploads as avatars, but then can also enable external viewing of that photo by outside parties if child posts comment on YouTube, or shares a Google doc for example. It's unnecessary. It will take time for app developers to work towards data minimisation principles of the DPA 2018 and GDPR, but I'd suggest where starting new contracts now, strive towards data minimisation to save future processing headaches. -
[sims] Urgent Capita SIMS Data Issue - Issued by childrens services
jenatddm replied to vikpaw's topic in MIS Systems
What's the current status anyone, please of a) support from Capita b) clarity of information what the current issues are and actions (that may be) required c) data issues? -
[sims] Urgent Capita SIMS Data Issue - Issued by childrens services
jenatddm replied to vikpaw's topic in MIS Systems
Thanks. What about API that extract data out regularly to third party software that uses the email -- ie ParentPay et al? - - - Updated - - - So phone numbers and email addresses only -- not address? -
[sims] Urgent Capita SIMS Data Issue - Issued by childrens services
jenatddm replied to vikpaw's topic in MIS Systems
Can you make an initial assessment of where your affected data may have been shared / passed on to third parties since the data were incorrect? [Trying to establish extent of where damage limitation may need considered (LA / MATs / DfE census / third-party researchers https://www.gov.uk/government/publications/dfe-external-data-shares ) and therefore where your corrections in your own data set may not be the only end point where error correction needed] Thanks. -
GDPR - Managing consents
jenatddm replied to Jamman960's topic in Data Protection & Information Handling
https://ico.org.uk/media/for-organisations/documents/1136/taking_photos.pdf is from 2014, found here >> https://ico.org.uk/your-data-matters/schools/ and the ICO notes on the page they need to update it. Look at their newer guidance, and the DfE GDPR guidance (worked on with the ICO) p 23 which is explicit you need consent for photos online / or media / or marketing -- you can certainly get that en bloc, once a year for example but remember that it can be withdrawn at any time. Health data collection and any biometrics also need explicit, freely gven consent and must be possible to decline without detriment. (For wider ref) Photos online are not LI or public task -- (public task after all is reasonably narrow, not 'because your school thinks/ finds it necessary' but *required* by your statutory obligations as a school. No school *must* put children's photos online). And LI and PT both carry a right to object, which is then a balancing test and needs well documented to stand up. Every use of data and transfers to third parties, needs communicated up front, but up front need not mean immediately before-hand. If you have collected in advance and the purpose and distribution is unchanged it remains valid. Basically, as long as they would expect it, and aligned with what they already agreed to, your existing consent is OK. But it can't mix variety of purposes under a single 'consent banner, the 'required by school for safeguarding' versus 'to put on our website', for example -- which is conflating the lawful basis and uses. -
[sims] Urgent Capita SIMS Data Issue - Issued by childrens services
jenatddm replied to vikpaw's topic in MIS Systems
Good advice. But has anyone yet done any thinking and documented where the incorrect data may have been sent onwards outside school to third-parties such as developers, or other data collections by the LA, social services, DfE in census etc? -
GDPR - Managing consents
jenatddm replied to Jamman960's topic in Data Protection & Information Handling
See page 19 and page 23. GDPR and DP law is not everything, but PECR which has been the same for many years. https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/702325/GDPR_Toolkit_for_Schools__1_.pdf If you use a child's photo in a format considered personal data, in marketing materials including on social media and websites, without informing the parents / children and a pre-posting consent process, expect to lose if legally challenged. -
GDPR - Managing consents
jenatddm replied to Jamman960's topic in Data Protection & Information Handling
Sorry for the late reply (missed yours). I think we're saying the same thing, the difference being often it is not the school managing the data, now it's been sent to a third-party processor. Consent is not a valid basis for most data processing in schools > therefore you need another, which as you say is most often public task. I don't think I suggested pulling data, but there is certainly a pre-requirement to tell parents it is being shared. *That* duty existed under DPA 1998, principle 1, fair processing. Regardless that the same duty also exists under GDPR. This is probably the largest change management task that exists in the education sector today on data processing. The fact that few do it (pre notfication to parents of third-party data distribution) is not a reason not to start doing it lawfully. Further, the Right to Object (RTO) which applies to data shared under the public task or legit interest (and is not absolute, but is for consent, so say, photos for school marketing purposes), can only be exercised, if you know the data are being processed. And where there is an alternative and less invasive and lower risk way to do it. i.e. your health absence reasons can be phoned direct into the office admin, not sent via the servers of an Australian based app provider, the RTO should be upheld. Would be happy to chat more, if you think this is not right and also to get your input on the ICO Code of Practice consultation on Age Appropraite design. More info on RTO: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-object/

