Jump to content

jenatddm

Members
  • Posts

    117
  • Joined

  • Last visited

Everything posted by jenatddm

  1. If site uses G Suite Additional Services, what's the out-of-the-box state? 1. Am I correct to think Additional Services is on by default (YouTube, Blogger, Google Analytics). And that admins must turn these services off for users by accessing Additional Google services in the Google Admin console — or is it off by default? 2. DoubleClick on or off by default for staff and pupils (grouped as organisational units) (Believe they can be switched off by the administrator but what’s the out-of-the-box state?) 3. In practice, do you [and if you do how do you] get consent? If so, what are the options usually -- opt in, or opt out? From parents From pupils Opt in Opt out By each part of the service ie YouTube but not Blogger or is it all or nothing.
  2. US firms often have a poor grasp of what data protection by design and default" of article 25 of GDPR means and they may need to change their practice. Schools must carefully consider, is the personal data the app collects necessary and proportionate and is there a less invasive way of carrying out this task without infringing on the rights and freedoms of the people whose data it processes.
 
Seesaw collects personal data including their names, email addresses, and photographs. This information may be entered by a teacher or the student or populated from the student’s account with a third party sign-in service, such as their Google account.

<< are photographs necessary (not just a nice to have)?
<< is name *necessary* could a dummy be used?
<< does the teacher and child understand what Google collects and how the personal data are used if you use ggl sign on?

 We also collect comments on posts in your class journal which may be text, or if you allow Seesaw to access the microphone on your device, voice recordings. << biometrics sent to the US? Again does it pass the necessary test (not just a nice to have)? Seesaw collects messages that are sent and received in Seesaw by teachers, family members, and students.
<< They all need to understand what data are collected and have a suitable privacy notice.
 When you use Seesaw, we receive log data such as your IP address, browser type, operating system, device information, and your mobile carrier. In addition, we may receive or collect additional information such as the referring web page, referring search terms, and pages visited. If you are using Seesaw as a teacher, parent, or administrator, Seesaw may use your IP address to determine your approximate location for the purposes of sending you customized marketing and other information about our products.

<< customized marketing? Is this appropriate to send to parents? Is this excessive data collection (is IP *necessary*) and have you given parents an option of not getting this marketing?
 To help us analyze this data, we use a small number of third party services (such as Google Analytics and Fabric). 
 << Is the Ggl data use compliant? << They all need to understand what data are collected and have a suitable privacy notice.

 We also use third party conversion tracking services only to understand if a teacher signs up for Seesaw after seeing an ad for Seesaw on a platform like Facebook or Twitter.
 << Is the Facebook or Twitter data use and tracking compliant? << Data subjects all need to understand what data are collected and have a suitable privacy notice fro all processing, including by the third parties involved. For one app -- this seems like an awful lot of unnecessary collection and use and might involve the family in marketing, profiling and tracking. Let's say: approach with caution.
  3. Oh dear. I would love a list of what you think is broken. PM open. Then they might wish they'd taken our calls over the last 18 months when we start pointing it out. They need to get a move on and *not* pass any bills for providing a legally compliant service on to their customers. And yes Capita, I mean you and every other SIMS provider. The GDPR was passed in April 2016. Practical SAR, audit and data usage reports need to be possible. There's nothing but excuses for not having been proactive since then.
  4. Suppliers *have a legal obligation to process in a legally compliant manner or should expect to pack up business*. End of. If they start processing data illegally on May 26 send 'em our way. They need to pull their finger out.
  5. You must bring any new uses of an individual’s personal data to their attention before you start the processing. (current law as well as GDPR) I suspect your new intake data collection happens long before September - more likely May or June start as well, no? To get started, do you know what needs to be in the privacy notice and how many you need? i.e make sure all your data collection and processing and their legal bases are clear. List where data are optional vs required? Retention periods? Where it's for pupil data, they will need to be understandable to children not only written in clear and plain language. Workforce, governors, and public using the website are separate. Do you inform how DfE, LA, MAT processes data or just say "we pass data on to the DfE". Purpose of the processing and the legal basis for the processing, retention period etc. I'm sure you've seen the ICO guidance already: https://ico.org.uk/for-organisations/guide-to-data-protection/privacy-notices-transparency-and-control/privacy-notices-under-the-eu-general-data-protection-regulation/ If not already done, you might try user-testing with the PTA and/or governors. We could review if you post a current non-identifiable version and/or future to-be draft.
  6. Thanks for the link. "People don't distrust technology until someone starts creating things like this PDF and waving their arms", is not the upset and harm that many children and families experience unfortunately. You don't see it as an issue as it's not been brought to your door perhaps, but that doesn't mean it doesn't exist. I'm glad that for you they do not. Do contribute if you want to write something (even if anon) for report. PM open.
  7. Can't see anything there that is obvious how filtering and monitoring work, but perhaps I'm missing it? [schools are the data controllers, so we need a consistent communication approach across UK form each school; but I agree it's a good site so in addition to school level, perhaps together we could get a good simple explanation written and ask SI.org.uk to post it on their site?]
  8. Some schools say home access is possible (can be required for homework) to the school network. Some install on BYOD. Not everyone limits to school network at least according to what schools have told us via FOI.
  9. God knows we've tried. Every provider has refused to date, to have transparent discussions or reply to questions. Anyone welcome to PM me if you would be happy to write a paragraph for report how it does at your school because everyone we have asked are not talking about it. (And wearing my parent hat, so has my child's secondary school. It's not explained at all in the parent-child-school agreement. all it said is "I understand my Internet use will be monitored." (By staff? By a system? How - I asked, and have asked twice since in 18 months, still nothing.) The point is exactly this -- parents shouldn't have to "sit down and discuss with some one in IT" over a IT used in schools, and you shouldn't have to be in that position either. Policy and consequences should be public to access, easy to read, on a school website. Transparent to the person involved as both current Data Protection law and GDPR require, and most schools fail to meet.
  10. Filtering and blocking are very different from monitoring, screen content storage, web cam control. How much time are pupils unsupervised by staff -- it sounds like it's a lot, perhaps more than parents would expect. What should be transparent is in the web monitoring at very least is the process, how what works, why, and what the consequences are. "If you search for this type of content, we will know and you'll be in front of a panel to explain yourself." The chilling effect on health related searches and teen issues is real, and familiar in any surveillance culture. Where do you draw the line what school can do in the name of safeguarding, and have no parental objection allowed? Some have active webcam use. Some have home use. Some have most hits in the summer holidays.
  11. I agree one thing that is missing is consistent training and guidance, but as often seems the way, a huge technology solution can be misapplied trying to fix what are nuanced human issues. If one system appears to be filtering and monitoring appropriately, and then a new system is trialled which has a significant spike in flagged words, but no more issues in reality, it could indicate it is indeed the fault of the technology in the second provider as over-sensitive by deisgn. There's questions and concern in some communities in particular how SWGFL works when its website -- for a product in use by children -- says re Online Terror Content, "... attempts are proactively monitored with unique links to Police and expert support in an emergency." So when questions are asked and there's no answers offered, it simply builds mistrust, rather than ensuring a sensible, proportionate approach to safeguarding. Parents should have been involved in this DfE policy introduction from the start, and should be at school level, but it's the exception rather than the norm.
  12. "Nobody is checking kids' browser histories outside of school concerns" may be true for you. It's not elsewhere. If you think it should not be monitored at home and outside school hours, then we agree. It's why there needs to be guidance to have consistency across the sector. Delighted to hear your processes are transparent. Clearly of the 1,004 parents in survey if 86% want it to be and it's not, they might not be in as good a position as you. My own child's secondary school is just one school, but my own experience is it has refused point blank to explain to me how this works which we asked when we were given the agreement to sign, we asked what it was we were being asked to agree to. We're still waiting over a year on. The primary simply has never mentioned that they monitor and there is no agreement, but know that they do as well. Schools monitoring pupils in loco parentis is exactly why they shouldn't keep the whole process opaque, but in partnership with parents and full transparency of consequences. If we met, you'd know I'm a very reasonable and practical person. But the number of questions we get on this from teaching staff, shows there are concerns how it operates very differently across the sector, without enough clear policy and guidance how.
  13. This is where it gets interesting. Art 9 makes it prohibited to process these things, unless one of the Art 9(2) applies. None do, 2(j) is a higher bar and especially because there is no confidentiality applied on distribution from the DfE - they give it out as identifying data at pupil level, there can be little regard for siilar standards to professional secrecy, so it has to be consent based. I think schools will have to record it at consent based, also has therefore clear legal basis for retraction and removal at any time -- which is why things like ethnicity have a basis for refusal at all. (And biometrics must be). We're in process of asking around, and will keep you posted.
  14. It's not what you or I *think* they should have, but they do have rights that need respected. How we all balance those between right to be kept safe, their best interests, right to freedom of expression, right to participation, right to digital access, right to equality and non-discrimination, and right to privacy is the hard part. We genuinely have teachers upset their children are flagged for nothing. That's a pressing issue, that should(?) be an easy fix if there were a technical option to do so, and guidance how and when it was appropriate to do so. "potentially valid concerns at home." Um, yes. And if you can help us at all with the 1-10 we would be genuinely grateful. There needs to be much more fairness and consistency in what companies and policy decide how to operate, as well as what parents get told.
  15. This level of intrusion into home life even for the sec./intell services, has more oversight, due legal process, and transparency.
  16. Answer the questions. Solve the real issues above. Teachers are really unhappy with children flagged as a suicide risk, or potential gang risk, who is not. Some people seem very keen in all our research, that parents and children are explicitly not "clued-up". And yes, SWGFL et al, needs to answer the questions.
  17. Great to see something for parents (and children?) too. Lovely style and upbeat tunes! Remember biometrics, and that consent means genuinely there must be an alternative on offer. (Side note, 38% of parents asked recently who said their school was using biometrics, said they had not been offered any choice -- which means it's not consent, and therefore not lawfully processed today). Subject access rights and parental rights to access the Information Record are useful to separate too as they have different legislation, but don't apply to all schools equally. Looking forward to see what comes out from DfE on SAR at national level, and expectations of suppliers to enable data usage reports to help schools meet SAR at local level. The biggest gap IMO for many will be that the parents have little idea what schools hold and process today, and for example, the National Pupil Database needs a whole explainer of its own. (which may come later). [FYI survey stats on parents' starting point]. Looking forward to see what's next.
  18. It doesn't change much compared with your existing legal basis today as per sensitive data, in so far as they need to meet tests of necessity and proportionality if collected under substantial public interest (not just 'want' or 'helpful to have') and does not effect fundamental rights or freedoms or cause distress. Today, under existing law, and will also be under GDPR, ethnicity (and country of birth, and nationality, language) can only be consent based (you are obliged to ask for it to fulfil the legal duty via DfE regs, and 'refused' is possible answer, and must not be ascribed by school) [see Census guidance section 5.3]. Biometrics can only be consent based (as today, plus any parental/guardian objections must be respected, Protection of Freedoms Act 2012). Also today -- adopted from care [5.3.20], service child indicator optional [5.3.10] and collected only on a consent basis in census submission. Same will be true of religion, and union membership (for staff).
  19. << Please write to your MP briefly and tell them that. We think you need guidance and that the ICO should provide it. There is a proposed amendment to the DP Bill which would require the Information Commissioner to write a Statutory Code of Practice in consultation to give guidance how to apply GDPR in education. (Consultation would be open to everyone, schools, industry etc) It would not create any new rights, or obligations, just set out *how to apply GDPR in practice* and explain some of the more complex expected standards, in context for the education sector. Why we believe it is needed is set out in detail here, including as s imply, as Lord Jim Knight said in the House of Lords Second Reading, "Schools desperately need advice on GDPR compliance to allow them to comply with this Bill when it becomes law.” Write to your MP (you can use this is easier https://www.writetothem.com/ ) Tell them who you are, why you are writing (in support of New Clause 16 to have a Statutory Code of Practice in the Data Protection Bill for schools), and why it matters to you. The sooner the better.
  20. The main issue of the web monitoring and keylogging (not filtering) is utter lack of transparency and fair and lawful processing, aside from the baked-in issues that Prevent has of its own. Constructive solutions sought for: 1. Legal basis outside school hours. [see ]Oral evidence - Children and the internet - 11 Oct 2016 2. Legal basis of excessive data collection. 3. Genuine error rate is opaque and system providers have little incentive to be transparent about it. Teachers concerned enough to contact us saying they have children who search for something uncontroversial, system flags it, and system only allows to make a 'note', that it was an error, but not delete the error. And that a move from one system to another create sudden spike in the volume of flagged words, which are all nothing to be concerned about — so the system should not be flagging them. 4. Security researchers warned Impero twice of serious flaws but the company has reportedly failed to fix them. 5. Collecting someone else's web searches and content in-and outside school hours and assigning the results of monitoring to the child’s record (i.e. a parent or older brother or classmate prank) 6. Opaque direct contact with police without trusted teacher intermediary. 7. Behavioural effects are unresearched but there’s qualitative feedback that it has a chilling effect on safe searches for sexuality, health, teenage development questions. 8. Necessity and proportionality of web cam access to take photos of the child; and risk of misuse. 9. 50% of schools that have responded to us impose on Bring-your-own-device which is opaque level of surveillance of personal property, active wherever logged in to school network and some at all times regardless of network. 10. Lack of transparency to parents and children of the consequences of the web content monitoring and keylogging. 84% of parents in survey said they believe they should be informed which keywords get flagged, and 86% want to know what the consequences are — but do not currently know.
  21. Updated version including changes made from your feedback. Many thanks.http://defenddigitalme.com/wp-content/uploads/2018/03/Staff-views-on-GDPR-readiness-in-schoolsv5.pdf
  22. routine profiling "or" automated profiling in same question, and may not always be an "and". Thanks for flagging I'll make clearer.
  23. The calcs are right and you're also right that if anything's unclear we can add some explanation. What isn't possible to show is where people change their mind or give inconsistent answers, and the number is small, so the % changes by 2.86% for each one person's answers in this, which is why bigger surveys are statistically significant and this one is not -- as we say in intro, this is nothing more than a flavour of what is needed and collecton of views. But ones that are pretty consistent with what we hear across the sector. Let me know please too, if you think the conclusions need different things suggesting as a result? That's what will get read (first). In detail to answer you, first they're two separate questions so people can answer as they choose to and change their mind in each one. In Question 24 there are 27 ot of 35 (or 77.14%) who answer "what's missing" (today for the future) is an assigned DPO role. In Queston 3 there are 26 out of 35 who reply, either they do not yet have an assigned DPO role (54.29%) or do not have plans to have one place by May (20%)= total 26. (74.29%) In Queston 3 two reply don't know. One of the "don't know's" in Q3 answered "what's missing" is an assigned DPO role in Q24. Second, any question that adds up to over 100% shows it was possible to have multiple answers -- ie the data protection responsibilities today are often split between multiple people on the same site -- you're right that the % total is therefeore is meaningless, but it's a useful indicator of the types of people currently assigned the duties, in each type of role of its own. I'll add a note, thanks for pointing it out. (It's why I shared here first to get these criticisms and improve it for outside readers, so genuinely, thanks for asking!) [ATTACH=CONFIG]47869[/ATTACH][ATTACH=CONFIG]47870[/ATTACH]
×
×
  • Create New...