Jump to content

jenatddm

Members
  • Posts

    117
  • Joined

  • Last visited

Everything posted by jenatddm

  1. Our response was here. Happy to discuss any of it, including what and why would you have us take down anything. Then a post to respond to the article being pulled, which included text approved by Al. But to be honest, phone would be easier if you want to go through, so can give you tel. no via PM if wanted.
  2. re 1. You're absolutely correct. This is why it says what it does and not that schools are "over-referring". The whole process needs transparency to identify where the 70% is, and where and why that % happens. re 2. Again, this is exactly the point. Staff (if children are using the systems under their watch) must understand the technology, and should be able to comfortably raise those concerns in school. It's why we're keen to get decent materials on this published, bearing in mind there are a wide variety of products on the market and not every one operates as NSDNA does -- and the blog doesn't talk about NSDNA (except the text Al approved) but is generic across the range of softwares in the sector. The concerns staff have are sometimes when a switch is made from one product to another. re 3. This is too nuanced for here, but again, bear in mind we're talking about sector wide improvements, not specific to one product. We have been told by schools we have researched, that around half use the software on personal devices and BYOD policy. Not all monitor only in school, or school hours. The caching question will be good to clarify for everyone too. re 4. It's very different for a child in a school -- different legislation, different rights, different risks, and power imbalance between an adult-child, and employment versus compulsory education and so on. It's important that schools understand that to be processing data fairly and lawfully. As I wrote, this is a challenging, complex area of data processing in the public sector, conflating important areas of safeguarding and child protection with the politics of Prevent. It sounds as though after the suppliers have vetted, it would be good to run draft materials by the Forum and you can take a look. Have a good holiday.
  3. It's not at all an irreconcilable position. Safe, fair, and transparent use of personal data should not be for any company providing tools that process children's data, especially in such sensitive and important work, with such a range of lasting consequences. I believe we'll have more in common than you think. For any company it's going to be a USP to offer good support to schools on anything data related given the challenges of GDPR. Improving consistent materials for schools, for families and children is going to be one positive part of that. See you next month.
  4. Al can verify how often I have asked NSDNA for just that this year, both written and face to face. We met and had a walk through of the product at Bett this year for example. But that's not what we were asked to comment on.
  5. Happy Christmas holidays everyone. I'm pleased to say we're meeting [myself and NetSupport] in January to have a chat in detail about this, and the product, as we've already discussed briefly several times in passing previously, at events for example. Regards this comment and article, for obvious reasons, we were concerned when the journalist approached us and reported the NetSupport DNA marketing manager as saying, "the company is planning a software update that will allow webcams to be activated in a student’s home." Al and I exchanged email, and he has subsequently reviewed and approved a statement that we posted on our website, so there are more facts in the public domain how the product works. More generally, we hope the whole area and use of these products will become much more transparent and informed in 2019. We are developing materials for parents and children to better understand it, and to help you in schools meet the fair processing requirements under UK Data Protection law / GDPR consistently. Some places have better policy, practice, and communications than others. The poll of parents we commissioned in February 2018 through Survation, showed poor understanding, and that 86% of parents with children in England’s state education system think that both children and parents should be informed of what the consequences are, if these keywords are searched for and flags created. This should be the bare minimum provided to families under GDPR rules on [risk] profiling, and we're pleased to get more engagement from companies, including NSDNA, to get improved understanding and consistency across the sector, what good should look like -- and put that into your hands for schools to use. Safeguarding-in-schools generated information, can be the trigger for staff to begin a Channel referral for children into the Prevent programme, and reporting statistics. 1 in 3 of all referrals come from the education sector today, yet 70% of referrals into the Channel programme in 2017-18, resulted in no action for the individuals, so improvement is clearly needed somewhere in that process, to reduce over-referrals. We also get concerns from staff (and more rarely young people) usually where they feel it is not possible to speak up on their concerns on use of these software in school; on over blocking of content, on how to delete flags assigned to the wrong child, or flags created without real cause. We work [for free] with companies whose products are in use across the education sector, often going to sites, and we ask only for the coverage of direct travel expenses. Those who do, tell us they find it constructive and helpful. That doesn't mean they always like the answers, or our opinions, pointing out for example if products have not considered their lawful basis for product development, or lack of fair and required communications to families, and action is needed. We work with, and offer confidentiality to schools, MATs, [education] charities and others, willing to share their own issues, map data flows, testing-in-practice of their concerns (using a dummy student or staff profile), privacy policies, and Home-School ICT agreements that relates to these and any other software / personal data related topics. We will comment in confidence if and how to consider anything in your communications/text that may need updated, or any case studies provided. This makes for local improvement, but for us it is useful is to help feed [anonymously or not as preferred] into national improvements, such as input to the DfE GDPR toolkit, and our own wider work. If you want your school to contribute, you can send us your practical experiences, policies or questions which can help make improvements on any issue that can affect similar schools more widely. For example, to include in a new report we will bring out in 2019. Any companies named get to see the text in advance, and can also contribute text and changes. The UK is a large exporter of this kind of products, and with it we export the potential for both the good and bad practice. It has developed with little external scrutiny over the last ten years, and with increasing consciousness of data protection law, it is almost certain to get more scrutiny in 2019, nationally and internationally. So, with that, Happy Christmas holidays from me, all of us at defenddigitalme, and looking forward to the year ahead.
  6. The Controller determines the purpose and method of processing. So when the DfE pass data a school collected for its own purposes, which DfE gives on to a third party, the school is still the Controller of that data -- for the purposes for which the school collected it, *and* DfE then becomes the Controller when they require the data under a lawful basis and determine the purposes they collect it for, and it will be forwarded on for -- so DfE becomes joint controller *and* the third party if they then use it for their own purposes, not determined by the DfE -- could even also become joint controllers. Because the data are copies, not a single thing, you can end up having multiple joint-controllers of the same data -- each copy may be under the control of a separate body, for separate purposes. What fails today, is transparent communication of all those purposes to the child and/or parent. (and to the school in the case of the DfE distribution).
  7. LOL. You might need a change of law first and that would not be push back mainly from concerns over the rights of the child, but from those concerned about the marketisation of education.
  8. Quite right to say >> "No school *must* put children's photo on ID cards, Sims etc but the guidance suggests you could use public task." And this is why, while your lawful basis may be seen as part of a task a as a functional requirement not the exact thing that you are doing (safeguarding rather than 'use X photo on Y card'), there is also a Right to Object to consider, if using Public Task as its basis, which needs reflected in the DPIA and balancing test of the wants/needs of school, and risks to the child of processing the photo. To-date there is often over collection and over sharing of children's data in/and across education, incl photos. For example, a significant amount of photo sharing, especially with third-party apps, that is done on a very weak lawful basis that is neither lawful nor proportionate, and parents and children would have a strong right to object. Even G-Suite for education, can enable photo uploads as avatars, but then can also enable external viewing of that photo by outside parties if child posts comment on YouTube, or shares a Google doc for example. It's unnecessary. It will take time for app developers to work towards data minimisation principles of the DPA 2018 and GDPR, but I'd suggest where starting new contracts now, strive towards data minimisation to save future processing headaches.
  9. What's the current status anyone, please of a) support from Capita b) clarity of information what the current issues are and actions (that may be) required c) data issues?
  10. Thanks. What about API that extract data out regularly to third party software that uses the email -- ie ParentPay et al? - - - Updated - - - So phone numbers and email addresses only -- not address?
  11. Can you make an initial assessment of where your affected data may have been shared / passed on to third parties since the data were incorrect? [Trying to establish extent of where damage limitation may need considered (LA / MATs / DfE census / third-party researchers https://www.gov.uk/government/publications/dfe-external-data-shares ) and therefore where your corrections in your own data set may not be the only end point where error correction needed] Thanks.
  12. https://ico.org.uk/media/for-organisations/documents/1136/taking_photos.pdf is from 2014, found here >> https://ico.org.uk/your-data-matters/schools/ and the ICO notes on the page they need to update it. Look at their newer guidance, and the DfE GDPR guidance (worked on with the ICO) p 23 which is explicit you need consent for photos online / or media / or marketing -- you can certainly get that en bloc, once a year for example but remember that it can be withdrawn at any time. Health data collection and any biometrics also need explicit, freely gven consent and must be possible to decline without detriment. (For wider ref) Photos online are not LI or public task -- (public task after all is reasonably narrow, not 'because your school thinks/ finds it necessary' but *required* by your statutory obligations as a school. No school *must* put children's photos online). And LI and PT both carry a right to object, which is then a balancing test and needs well documented to stand up. Every use of data and transfers to third parties, needs communicated up front, but up front need not mean immediately before-hand. If you have collected in advance and the purpose and distribution is unchanged it remains valid. Basically, as long as they would expect it, and aligned with what they already agreed to, your existing consent is OK. But it can't mix variety of purposes under a single 'consent banner, the 'required by school for safeguarding' versus 'to put on our website', for example -- which is conflating the lawful basis and uses.
  13. Good advice. But has anyone yet done any thinking and documented where the incorrect data may have been sent onwards outside school to third-parties such as developers, or other data collections by the LA, social services, DfE in census etc?
  14. See page 19 and page 23. GDPR and DP law is not everything, but PECR which has been the same for many years. https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/702325/GDPR_Toolkit_for_Schools__1_.pdf If you use a child's photo in a format considered personal data, in marketing materials including on social media and websites, without informing the parents / children and a pre-posting consent process, expect to lose if legally challenged.
  15. Sorry for the late reply (missed yours). I think we're saying the same thing, the difference being often it is not the school managing the data, now it's been sent to a third-party processor. Consent is not a valid basis for most data processing in schools > therefore you need another, which as you say is most often public task. I don't think I suggested pulling data, but there is certainly a pre-requirement to tell parents it is being shared. *That* duty existed under DPA 1998, principle 1, fair processing. Regardless that the same duty also exists under GDPR. This is probably the largest change management task that exists in the education sector today on data processing. The fact that few do it (pre notfication to parents of third-party data distribution) is not a reason not to start doing it lawfully. Further, the Right to Object (RTO) which applies to data shared under the public task or legit interest (and is not absolute, but is for consent, so say, photos for school marketing purposes), can only be exercised, if you know the data are being processed. And where there is an alternative and less invasive and lower risk way to do it. i.e. your health absence reasons can be phoned direct into the office admin, not sent via the servers of an Australian based app provider, the RTO should be upheld. Would be happy to chat more, if you think this is not right and also to get your input on the ICO Code of Practice consultation on Age Appropraite design. More info on RTO: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-object/
  16. According to Capita Services Director this afternoon, they have contacted those with whom they have contracts. It was then left to those LAs for example, to onwardly notify the individual schools. (I suggested this process needs further clarification). There is little new information on offer at the moment beyond what you have all collated here, and in your comments. They plan to provide an online FAQ tomorrow addressing many of them. --- I have a question: please can someone confirm to me how the UPRN interacts with address data changes since it is "automatically populated". I want to rule out that any new (incorrect) address updates would have generated a new UPRN, without need for verification / active validation. And whether these may have been indirectly affected. "From the 2016 to 2017 school census, the UPRN will be added as a voluntary data item to be returned alongside the full address (in either BS7666 or address line structure). The collection of UPRN should be relatively ‘invisible’ to data providers with the burden managed by the way addresses are processed within school systems. Schools are not expected to collect, or look up, the UPRN and instead this would be automatically populated within your school system when entering addresses if the OS AddressBase database is used as a reference. For schools and / or systems not using AddressBase there will be no change and they will continue to use either BS7666 or Address Line formats for submitting addresses."
  17. Hi, you mention finding and manually fixing the issues. What effect do you think this has on transfers of your pupil data incl name and address made to others, ie. school census (mid Jan 2018 and again in mid May) and entire end of year new school data transfers ? ie year 6 data sent to secondary school? Shocking if Capita knew months ago and didn't flag it.
  18. Sounds sensible decision, and worth noting in case others are doing similar, nothing changes on this under GDPR. (Now UK Data Protection Act) compared with Data Protection Act 1998. This type of activity using that level of personal data, should only ever have been done on a parental consent basis. BR.
  19. There is no statutory 25 year retention period for pupil data regardless of format. For each data *type* there are no statutory periods. For *purposes* there may be. For example, processing a child's name and photograph for local press purposes does not have the same legal basis (consent), as processing it in your MIS (public authority / public task). The retention periods for each are different. But it's the same chilld's name and photo. If not read already, the DfE advice could be useful; and they're accepting written feedback for next versions, until June.
  20. Nothing changes under GDPR. You should have a legal basis for holding data now, and the same basis from 26th May.
  21. Are parents "authenticating" an account already set up -- or consenting (which is not likely valid legal basis in school) to their details being shared with the company? Authenticating sounds like the account has already been sent their details and they make it active. Whether or not they want to use an account, parents need told *before* the data is shared with the third-party. Ditto ParentPay et al.
  22. Did this get resolved? ICO did a joint session at Academies Show last week with DfE. Consent under GDPR is literally about only valid as a legal basis for processing for marketing use of photos by schools, and not much else at the moment, unless you decide you will make things optional. (See p19/20) For example: Google Ts&Cs say additional services are consent based, but they are not as it's unlikley it's freely given, and parents are not explained how ads and tracking work and data are used. We're yet to meet a school in which they are. Consent unlikely to be an acceptable legal basiss for processing where school really wnats the child to, as it musty not disadvantage them, and must be freely given and able to refuse. Rarely valid for a public authority. Rarely valid for children. Because it's not valid where power imbalance means "freely given" is under any pressure at all to do so. There is no universal "age of consent" in GDPR. Article 8 does not apply in schools because you operate apps on a statutory basis not consent. Consent *is* required for any biometrics because of the legisation in Protection of Freedoms Act (2012), not GDPR, and one or more parent can object up to 18 no matter what child says, and child can object no matter what adult says. Basically default is object for biometrics with active opt in. Can opt in if consent is freely given, and able to withdraw at any time.
  23. Thanks -- all advice and comments help my understanding -- (now wearing a parent hat, what I don't get, is how my own 11 yo can watch and comment on pop videos on a home computer logged into her school user Ggl account.)
  24. There's lots of incorrect information being given in presentations by companies that are making money out of consent solutions. Be careful. There is lots of confusion on consent under GDPR. Get some data protection legally qualified advice but hopes this helps. Consent only applies where you have no other of the six legal bases for processing and only where it is freely given, can be refused and withdrawn at any time without effect to the service provided. And it cannot be a basis for processing where there is any imbalance in power in the relationship between organisation and data subject (school and pupil/parent) -- almost nothing will be consent based except you should already be using it -- biometrics. Consent is legal obligation for biometrics and an alternative must be offered (England: Protection of Freedoms Act 2012) and required for Youth Services 13+. Consent in Article 8 of he GDPR at age 13 is *only* for Information Society Services targeted at and used by a child, and only where consent is the basis for processing. If your children's access to GSuite, apps etc are all optional and can be refused, then you can ask for consent. If they're not -- and clearly they are not -- there is no consent process. See the GDPR threads in the forum for lots of discussion on this and ICO and get your data protection officers guidance. https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/applications/children/
  25. Thanks -- for the access to Youtube and Blogger, is there any opt-out or opt-in choice for the children/parents? Basically trying to work out how this is easiest presented to schools compared with what you do now. Addtnl services must be consent based even today according to Ggl terms -- which means isn't tick-box but freely given, can say no -- and therefore I'm looking to understand what effect it would have if schools are not doing that today, and what a consent form would look like.
×
×
  • Create New...