Jump to content

jenatddm

Members
  • Posts

    117
  • Joined

  • Last visited

Everything posted by jenatddm

  1. Feedback summary from the GDPR readiness in UK schools survey is ready. First, thank you to everyone who took part. The 35 responses are summarised here. I am leaving the survey open, because we can still include your feedback in ongoing discussions, and highlights will be included in the broader sector report we're bringing out next month. With only 35 it's not a large enough sample to be statistically robust, but it's a helpful snapshot. Staff views on GDPR readiness in schools.pdf Please complete the survey here if you still want *your* views included and have not already done so >> https://www.surveymonkey.co.uk/r/GDPR_support Questions? For any questions or feedback on the summary, please ask here on the forum, or email [email protected] If you have any questions or queries about the survey please address them to jenatddm The anonymous responses you provide will contribute to building: A summary of what support the education sector still needs in order to have confidence in their GDPR readiness Aggregated feedback to give policy makers at the Department for Education and Information Commissioner’s Office Findings for a free report to be published next month, coordinated by defenddigitalme and to be launched at an event in the House of Commons Better understanding of the breadth of technology commonly used in schools today A picture of why consistent guidance is needed on data protection and privacy to deliver clarity, consistency, and confidence to schools and developers
  2. >> tbh doubt you'll get many as ppl 'a rush of requests under the right to be forgotten' because few know that so much data is held and exported -- what they don't know they can't ask. Regardless, right to erasure can't see applying in school at all. Almost all data schools hold is statutory. Retain as long as statutory need. Then delete (including ensuring where there has been onward distribution) or anonymise (by which I mean by UKAN standards, not 'take off the name' or pseudo). What might change in future is the indefinite retenton for re-use current practices -- the forever retention by DfE and onward sharing of data like reasons-for-exclusion (theft, violence) to third parties like press and businesses who don't have a clear 'necessity' for processing (as opposed to they'd *like* the info) given the possible interference with a child's confidentiality. But won't affect school holding it for the necessary purposes. How long they can be reained for today seems to vary though. RTBF -- delisting from search won't matter much in schools.
  3. Curious what SIMS (and other MIS) offer today by way of SAR capability and what it will look like in future. They're not replying to my requests so if anyone wants to send me data-free screen shots I'd be *really* appreciative. Can you view what data items have been sent out of the system and where it went? Or get a bulk report of whose data was sent to a single provider, and which children were left out? (if you start using a new cashless payment system for example).
  4. Now I understand why not a single exam board has replied to my query on their policy and practice and GDPR readiness for report. It's all so **** there is hilarity in waiting to read each new example of bad practice you all have to put up with. Would like to include this as case-study (anonymised) please, unless you have any objection?
  5. Perhaps setting out the bare minimum of the ICO guidance as others set out in this thread and the risks to data and reputation might help > British councils hit by nearly 100million cyber-attacks | Daily Mail Online Would more guidance specific to schools be helpful on this?
  6. Rather than an ad-hoc decison, what does your privacy / data protection impact assessment say? If you've not done one, then you could, as if you were considering buying it for the first time. As part of that you balance necessity and proportionality, against infringements of rights and freedoms. Then you have a decsion which can be accounted for and as needed under GDPR (and current DPA 1998) Not every school is the same. https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/accountability-and-governance/data-protection-impact-assessments/
  7. The school can only 'require' what is legislated for, and beyond that the borders of what systems a parent/child can ask not to be part of, are less clear. Where for example however a school has passed information out of the SIMs (for which the school is the controller), the school would remain the controller or joint controller (i.e cashless systems). This is one topic we believe there needs to be UK-wide clarity on from the ICO, because what is the boundary of "required" as it's not at all clear in practice and affects who is accountable for it. (much of our current work). PS if you've not already done so, pls consider doing the survey and add this question into the end "what have we not asked" question in the survey and we'll include it in upcoming report FAQs. (Average completion time so far, 9 minutes >> Please complete the survey here before 12:00 midday on February 14th >> https://www.surveymonkey.co.uk/r/GDPR_support ) Thanks.
  8. We've some really useful responses and will be included in report coming out on March 12th and discussed at this event, but would really like to get more contributions, so the survey is still open and extended until next Wednesday or until we get 100 replies. Thank you! Please complete the survey or encourage colleagues or friends at other schools to do so, here ideally before 12:00 midday on February 21st >> https://www.surveymonkey.co.uk/r/GDPR_support This survey is to help us understand your GDPR readiness in UK schools*, and help you get more support where needed. We'd like you to contribute to a picture of GDPR readiness in education in the UK, by taking part in this online survey. It should take no more than 10 minutes to complete, there are 25 required questions. There are also optional questions at the end to help support the breakdown of analytics. This is only for state-funded educational organisations for any children age 2-19. This survey is not intended for the independent sector, except state-funded Alternative Provision and pre-school private settings. The anonymous responses you provide will contribute to building: A summary of what support the education sector still needs in order to have confidence in their GDPR readiness Aggregated feedback to give policy makers at the Department for Education and Information Commissioner’s Office Findings for a free report to be published next month, coordinated by defenddigitalme and to be launched in the House of Commons Better understanding of the breadth of technology commonly used in schools today A picture of why consistent guidance is needed on data protection and privacy to deliver clarity, consistency, and confidence to schools and developers Please complete the survey here ideally before 12:00 midday on February 21st >> https://www.surveymonkey.co.uk/r/GDPR_support How the information you provide will be used The survey is anonymous. If you want at the end of the survey, you can choose to provide contact details for follow up questions or clarification, or to have your explicit question answered directly to you or aggregated it may be included in the FAQs in the report. Contact details are optional. We will not use any of the metadata from the survey, such as IP address, for any purpose. We are interested in general findings. The questions and aggregated answers and percentage scores, but no identifying comments, will be published on our website for full transparency after they have been reviewed. Two volunteers on behalf of defenddigitalme will have access to the answers and any identifying information you do provide. Any contact data volunteered, will not be used for any other purposes. For any questions please ask here on the forum, or email [email protected] If you have any questions or queries about the survey please address them to @jenatddm *Please note question 15 on the survey is for schools in England only due to the different way pupil data is shared there compared to the rest of the UK.
  9. Hmmm. The Nudge Unit requested them from DfE to match with national pupil data. I wonder if then they have them direct from GL Assessment, or perhaps it was a fishing exercise? Source National pupil database third-party requests [TD="bgcolor: #deebf7"] DR170621.02 [TD="bgcolor: #deebf7"] Behavioural Insights Team Ltd [TD="bgcolor: #deebf7"] The CAT4 suit of tests is used throughout England to measure a wide range of pupils’ skills, predicated around spatial reasoning. This allows teachers to identify a pupil’s various strengths and weaknesses, their true learning potential, as well as recognising whether a pupil is “underachieving” in their Key Stage, GCSE and even AS/ A Level exams and mock exams. It can also help teachers in target-setting. The KS2, GCSE, AS/ A Level grades will be used as Indicators, that are then combined with the CAT scores, to provide schools with information that investigates the relationship between verbal, non-verbal , quantitative and spatial tests and attainment in English, mathematics and science for the above mentioned exams, in addition to searching for a correlation between backgrounds (e.g. free school meals, gender, ethnicity) and attainment.
  10. Thanks. So if you change ethnicity field to refused today, for child that's been in sims for 2 years, does it not permit you to keep history today?
  11. You're spot on. The right to refuse is another separate point. The question could have been separated out to profiling OR automated decison making, but what we're trying to identify is either. What needs clarification I believe in guidance is where we draw that line, because although the teacher may use the CATS score - if they cannot assess that the CATS score is accurate, ie.the algorithm are not transparent and errors can be spotted by the teacher - then that is not enough. But then we get far along into the detail of DP and systems design and lots of unknowns as yet. And the next question is if the CATS scores are being passed on to govt at DfE level, and they are doing behavioural insights analysis on them at pupil level, or start joining with other data sets, where do we draw the line with a right to refuse? Thanks for asking. I *really* appreciate comment and criticisms as both help get me beyond my knowledge and we need as much 'on the ground' applied thinking in this report work as possible.
  12. What I'd (possibly mis)understood from "Granular deletion of pupil data = Summer 2018" (let me know if so) is that there was no way at all to delete data for individuals. But if it's only that there's no 'bulk' way, then you're fine to carry on as you do so far. Of course you are. No one is suggesting you need "delete a Year 11 leaver in May/June" - carry on with today's lawful retention periods. The thinking shouldn't be what do we need to delete - it's what do we need to hold? The principle is data minimisation. It's just like today - if you need the personal data and the reason for holding, has a fair and lawful basis, and respects the essence of the fundamental rights and freedoms, is necessary and proportionate you hold it securely etc etc - then you're right, why would you want to delete it? There is no absolute right to erasure broadly speaking. It's based on an evaluation of all the above, but this is not legal advice, and each will vary and be different in diff schools. If a school holds onto data you don't need and has no basis for holding now, then that shouldn't be held under the DPA 1998 either, not new to GDPR or the DPA 2018 as will be. So that needs work now, not connecetd to GDPR delivery dates. Presumably you/schools have some consistent reference point for retention periods now (is it online and might you share it if so? Could be useful for others too), or is it only scattered in various legislation and guidlines? If so, we should see if we could get that sorted out. Presumably you have deleted data in the past that you no longer need and have no gounds for processing. Carry on as is until you have a better tool. But the tool cannot justify unlawful processing just because it's not well designed.
  13. no. You shouldn't use technology that isn't compliant by design and default (article 25) "by default, only personal data which are necessary for each specific purpose of the processing are processed." but it sounds as though you ahve a way to delete, just it is slow, not bulk. You need to look at retention periods and if you meet them, then no you don't need it yet anyway. And if you can do ad hoc as needed, then presumably it works for now. For example - if someone asks you to delete ethnicity or nationality it should be replaced and overwritten with refused. So the field still has data, but historical content removed.
  14. Thanks Enjay some useful corrections made as a result, as none will affect any of the answers already given by contributors. (many thanks all, really interesting and great questions coming in too!!) q19 is relevant to GDPR because of the significant implications for consent and software installations dependent on ownership. q20 Added option for school-managed q21 clarified to add additional option for "no profiling or automated decsion making", >> some of the options listed are not automated decisions<< yes but all are profiling and question pertains to either q25 lists MyMaths twice, some options don't make sense -- thanks well spotted, changes made, feel free to criticise further to make clearer if needed. Thanks all help much appreciated.
  15. Shoddy date delivery given they will make your controler function unable to comply with legal obligations from May, and the GDPR has been in place for two years. Since Capita SIMS so far refuses to engage with us - despite various email and phone attempts in last 12 months, not a good look tbh - perhaps those who have them as suppliers can ask them how they plan to enable you as controllers to fulfil GDPR SAR obligations, right to rectification, and retention managment without audit functions? And make clear on asking, that you will publish the reply. If they refuse to reply, let us know. Individuals have the right to access their personal data and supplementary information. The right of access allows individuals to be aware of and verify the lawfulness of the processing. Schools may be controllers but Capita has new obligations as a processor too. Under the GDPR, individuals will have the right to obtain: confirmation that their data is being processed; access to their personal data; and other supplementary information – this largely corresponds to the information that should be provided in a privacy notice (see Article 15 - ref p43 http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679&from=EN). including the recipients or categories of recipient to whom the personal data have been or will be disclosed, rights to correction, and to obtain the source of where data came from that was not provided by the data subject (ie. ascribed by school or other third parties in SIMS) The GDPR also includes a best practice recommendation that, where possible, organisations should be able to provide remote access to a secure self-service system which would provide the individual with direct access to his or her information (Recital 63). We’d also like to discuss their data plans for health data in SIMs via the parent lite app.
  16. Yep, their data team ppl. hadn't read it last July even. Like many others. But let's not focus on gaps. If you also acknowledge schools need guidance, I hope we could get a consistent note together on what is needed and present it to DfE and ICO (as above off piste) and ask MPs to support a simple clause in the Data Proection Bill to require ICO to deliver that code of practice for consistency and clarity and confidence across the sector. Do email me if you want to help shape via jen at defenddigitalme.com
  17. Sure, agree apologies bit off piste but just ging further along the line of replies of finding out and how to best deliver guidance what ppl want to know. I guess the point is not to produce good videos per se, but help school staff deliver better data practice. I'd like to hear your views, you have my email, but also more views than only you two, as I think what's misisng is a consistent and clear guidance accessible to all (a code of practice). IMO the videos should be tied into themes and practical guide "how to" not just "what to" do. But there's perhaps a conflict for you if it should be free to all, not trying to sell a product. The headings mentioned in the film are unclear, it's a bit wooly. What headings should a school be pulling out of this for mapping? They should appear on the screen, and have an accompanying download document. That's gist of the feedback I gave DfE.
  18. Sounds good.
  19. Still unclear what's the alternative to 'every school should have a nominated, conflict-free, resposible DPO.' 1. Tell me in a paragraph what the law should say instead of what it does now. How would it change the status quo for the better. 2. What are your "almost impossible hurdles"? 3. What we're working on is guidance to support. I believe the ICO needs to issue a code of practice specific to education so as to give clarity and confidence to both schools and suppliers, and enable children, parents and staff to know their rights and any limitations, and schools, staff and providers to know their own rights and their responsibilities. If you were to want *this* ICO guidance to be specific to education, what woiuld be different, added or missing? https://ico.org.uk/media/about-the-ico/consultations/2172913/children-and-the-gdpr-consultation-guidance-20171221.pdf Then see page 25-26 amendment 117 and see if that would cover it or needs something else>> https://publications.parliament.uk/pa/bills/lbill/2017-2019/0074/18074-I.pdf Interested in all your views on this.
  20. You can't easily lobby against something that's part of the law which is supposed to bring improvement on the status quo, without an alternative. What's the alternative?
  21. Great. Sounds really exciting! Will pop by.
  22. No, not all personal information are equal. Ethnicity like nationality, for example, can only be distributed on consent basis. UPN has restrictions. If your school does enable SAR and distribution tracking, we'd love to see it and champion it as good practice. Yet to see a school or SIMS that can with a decent pupil/parent report.
  23. Do you know what "the usual transfer controls" are? If so, I'd be pleased to see a copy. As the 2017-18 census guidance states, "subject to Data Protection restrictions". Of course that means that any third-party supplier that uses the UPN must be able to provide a SAR to pupil (and/or parent) on request, and school needs to be able to facillitate telling pupil/parent excatly which third parties have got it and retention periods, purposes of use, etc.
  24. Tony what's missing is who is that film for? the audiece is totally unclear and without accompanying guidance to action, unlikely to make much helpful difference. As I told Ian, I'm looking forward to seeing guidance on privacy notices and SAR, and being told what the Department plans to do about their own policy on those.
  25. Hence one of my feedback comments to DfE asked who is funding DPO support, and I suspect why they won't want to make more of a thing of it. But you all could.
×
×
  • Create New...