jenatddm
Members-
Posts
117 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by jenatddm
-
First DfE video on GDPR
jenatddm replied to maturelady's topic in Data Protection & Information Handling
What's other people's views? -
Data protection census
jenatddm replied to tinkerbotsict's topic in Data Protection & Information Handling
You're right consent is not generally the basis for children's data collection in the school censuses, although it's not completely to disregard, given the sensitivity level of the new data to be collected, and their types - the Data Protection Act requires not only Schedule 2, but an additional criteria to be met of DPA Schedule 3. However, some data are in effect consnet based because they are optional and must not be ascribed, but only provided by the parent [or child]. ie ethnicity, service child, in-care, first language, country of birth, and nationality. So those items must be offered with choice, as 'refused' is an option. This specific case in the link, is the Alternative Provision census, and the changes only coming into effect for the first time from Thursday - collecting one of eight reasons for transfer out of mainstream education into an AP setting, incl. pregnancy, young offender, mental health - plus detailed SEND on a named basis. This is a new problem, because DfE / govt says it is the responsibility of LEAs to provide the AP census data through COLLECT to DfE, and yet LEAs have not told children and families who have been in AP provision at any time since January 2017, about the new data items that will be ascribed. The AP census guidance explains the changes, but the School Census guidance does not. But it is the School Census Guidance, not AP Census guidance that is provided to schools. Schools therefore can't tell the pupils leaving them, what the new AP census will collect. But no one seems to tell them after they leave / left either. They key part -- and I'd like your views -- is not what a document says, but what do data subjects understand, can they know who has been given their data that the school hands over, and how easy is it? A PN is not a get out of jail free card. It has to be meaningful. What we have seen so far, is almost none are. Schools tend not to explain this. While some have included a link to DfE's external data shares since 2016, many still simply say something like 'we are required to share some data with the DfE'. Each pupil’s information are sent to the Department, on a named basis, and added to a growing national database of 23 million people, the National Pupil Database (NPD). The data are identifiable at pupil-level, not anonymous, and stored forever. The information include name and address, date of birth, special educational needs, results across the educational lifetime from age 2-19 and more. We at defenddigitalme are concerned because from here, these identifying data -- not anonymised -- are given out to third parties; over 1,000 times as of May 2017, many for commercial re-use and even to newspaper and TV journalists without a child’s or parent’s permission. Given that the data have also been accessed by the police, and currently linked with the Police National Computer data, there has to be clarity on who will access the new young offender data, and why. See ICO on privacy notices and fairness, and why it matters: "the main elements of fairness include: using information in a way that people would reasonably expect. This may involve undertaking research to understand people’s expectations about how their data will be used; thinking about the impact of your processing. Will it have unjustified adverse effects on them? and; being transparent and ensuring that people know how their information will be used. This means providing privacy notices or making them available, using the most appropriate mechanisms. In a digital context this can include all the online platforms used to deliver services." -
Data protection census
jenatddm replied to tinkerbotsict's topic in Data Protection & Information Handling
It also collects information on if the privacy notice has been issued to parents and the response (typically Sought, No Response)" sounds intriguing. Not heard that before. You believe DfE collects information if a PN has been issued, proof the privacy notice has been properly sent and a response received? How does that work? -
Hi everyone - I'm looking to get a contribution to upcoming report (out on March 12th) from leading providers of CCTV, IPTV and Biometrics in education (door access / cashless payemnts / lockers / printers etc). How they are used, what works well, where they have concerns or want better clarity with GDPR - particularly as relates to "solely automated decsion making" and "profiling". Please can you help me by a) listing your suppliers or a few that you know are most commonly used? b) Secondly - who is the data controller / processor for you - does anyone in school have access all the time / on demand / provider only? c) Plus: any GDPR related questions to these types of data use in schools welcome. d) And finally - do you buy these providers in directly, or does your local / regional IT support 'broker' provider companies to schools - ie help me understand who has to understand how the product works and why, and how the data are used by whom. Any or all of the above useful, and hopefully if you have questions, we can get you some answers in return. Thanks.
- 1 reply
-
- biometrics
- cctv
-
(and 3 more)
Tagged with:
-
This is where I would like Smoothwall et al to post the legal basis for processing they understand they operate on today and explain if there is any change expected under GDPR. If Internet access is 'tick here or no access' it's not consent based. (Even if "consent" is in the title of the parent/pupil home agreement.) What I believe is unclear, and must be clarified for schools and parent/children, is who can refuse what and why. i.e. can a school impose home monitoring 365 days a year. Can a parent / child refuse the imposition of software on BYOD. Can parent/child refuse filtering/monitoring and school still permit Internet access by child. If not, can school refuse child access to the Internet in school, and on what legal basis vs school opinion. Collecting questions you want answered right now and will be used in discussion: please add here near end in coments in section "IT questions from current schools in practice" starting on page 18. and I'll edit them into body of text anonymously - unless you tell me you *want* to be named. Thanks.
-
Sharing DPO Role with GDPR
jenatddm replied to Wubbalubbadub's topic in Data Protection & Information Handling
The question is probably less who can we farm it out to, but rather, do IT professionals have the necessary DPO professional's skills? Hats off to all who have both. This is perhaps helpful to some. From Tim Turner's InfoLaw blog his thought is that, "Very few schools need a full-time DPO." He's drawn up a guide, "for those organisations seeking an external, contract-based Data Protection Officer. It is designed to help the small, non-expert organisation to choose the right DPO consultant. You can find it at this link, in the downloads section of my website." -
Our GDPR Timeplan for comment!
jenatddm replied to kennysarmy's topic in Data Protection & Information Handling
What do you typically do about children's personal data on staff personal devices? Are there contract terms or employment rules to cover this, and are tehri revision a step in the planning, or is everywhere different? -
Our GDPR Timeplan for comment!
jenatddm replied to kennysarmy's topic in Data Protection & Information Handling
This is great to see action planning! You know your site and why you can't have the DPO in place and responsible for leading this now. The three things I'd suggest are to support how you chnage from current (non GDPR compliant) to future (compliant) process and actually make sure that you can maintain good practice easily in future - and - have a way of demonstrating accountability and practice as will be needed by your DPO: 1. As you do any audit now, a)write down any processes in the school that have significant personal data transfers involved. I.e Staff hire, Pupil Admissions, School Census, NHS NCMP visit, Begin a new third party contract (cashless system/biometrics/CCTV/sign up class for new app) and b) for the data parts of the process, draw up a flow chart of the process where and when it happens, and where there is accountability for the data transfer, communication to data subject, ways to correct. audit etc. Draw in the people / roles involved of who must do what in each process. 2.Plan beyond May 2018. Include a review with all staff and audit again, how is it going? And take one or two processes each month after GDPR and ask staff to review what they do now after GDPR, compared with the model process. Are there gaps? Anything unclear? Are privacy notices clear? 3. Incorporate documents into future new staff onboarding / training. I'm happy to help with drawing up and review if anyone uses this and wants to. We'll be including 'global GDPR process maps' (For adapting to loacl needs) in our free report to come out in Spring and if anyone wants to help us review them and spot what we are missing, I'd be thrilled. -
Very little if any data processing in schools is consent based. Most processing is on a different legal basis. Children don't use the Internet in school on a consent basis, they can't revoke it, and you require them to use certain services for teaching. That's bot consent. Consent as a result of GDPR remains generally unchanged based on capacity in law, not GDPR. The change through Article 8 is only for most Internet /online services ("Information society services" not counselling or preventative services) targeted at a child, and it is not exactly consent of the child, it is rather the the age at which parental consent is no longer required. Any cosnent based processing will have to still make other legal considerations, like "best interests of the child" test. Default is not a good word to use. It is advisable that all data collection from a child should involve a parent. And for example, it is a legal obligation for biometrics in schools >>Protection of Freedoms Act 2012.
-
Data Protection Act Report stage 11/12/17
jenatddm replied to Ditto's topic in Data Protection & Information Handling
Amendment to Article 8(1) is a code of practice for children using Information Society Services based on consent Article 6(1)(a). How much schools' online activities policy is based on consent? There was also an introductory amendment that's only relevant for children and pupils up to age 19 in education (Amendment 117) at end of p25 and top of p26. https://publications.parliament.uk/pa/bills/lbill/2017-2019/0074/18074-I.pdf If interested, take a look and I would be interested in your opinions in shaping something to be useful for schools. Background thoughts on it here. The Debate is here. -
"Not that I think we would not comply" - stop - ask yourself, what is the school's legal basis to give those data to any third party? This seems a surprising request, to say the least, both from the POV they should already have those data if it's Public Health England and it's not a school's responsibility (time / cost). There *is* a new NHS child health programme, but no one can just come long and say "send me all your cildren's names and other personal data" and be OK even if it 'sounds legit'. Send nothing, and lots of questions to be asked. Legal basis - yes you need to know the piece of legislation that permits you to. What's the purpose. Where's the documentation. What's the secure transfer mechansim. What's the retention and destruction plan. Where will it be stored. Wil they onwardly share with others. What data will they link it with. What communication materials and privacy policy do they provide for you to give to parents and pupils. How do you deal with refusals?
-
Implementing Cashless Catering and data issues
jenatddm replied to Seb1780's topic in Data Protection & Information Handling
Not necessarily true. If the software enables any information or data transfer to the software company, they are also data processors and might be controllers if they make autonomous decisions what they do with thsoe data. -
Implementing Cashless Catering and data issues
jenatddm replied to Seb1780's topic in Data Protection & Information Handling
enjay it's not about complaints but handling data legally (and ethically). If your catering option is biometric [which I don't know] there's a legal requirement to offer and respect parental and pupil choice under the 2012 legislation. You need to meet data protection, child rights law and privacy obligations, it would also be good to encourage good aplied and ethical practice. Is there a free-for-all when starting to use an app in the classroom at teachers' will, or do you have an assessment process - is the app safe, secure, transfering personal data outside the EU, and what will become necessary, ethical - for example targetting kids with a bait-and-switch approach of paid premium option out of school later. There's some absolute trash out there reportedly using "AI" for example. Google, Mathswatch etc we can help you with, if you want to give me a full list, but that audit is something your DPO needs to be doing *now* ahead of May 2018. Where do they store personal data, what's the legal basis for every use of data. Each third-party transfer may ahve more than one basis or thing to think about. Photographs for example, might be hard to show a necessary legal basis for a homework app, but OK for building access. But all biometric data needs special consideration. -
Implementing Cashless Catering and data issues
jenatddm replied to Seb1780's topic in Data Protection & Information Handling
("Impose" is also imposed not only on catering co. but on parents and children. Do you give *them* an option? It is their personal data, after all, not school's. Tip: AVoid what our school did. MIS should not extract and send to third party cashless co. without explicit permisison fisrt to set up accounts.) Needs more information --hence the questions-- before you can decide where the controller and processor roles are. Other locations using Biostore /similar systems in past have been part-funded by the NHS and pass the children's data on to the Health Authority (or as was). That made them a joint-controller, so each situation needs detail as it ay not be obvious. There are shared responsibilties in any processing. Unless their systems never touch any of your data, can't see how they will avoid being processors, and possibly joint-controllers if purchase-profiling is not at your request, but by their design for example, and is not part of school's duty as public authority. Some relevant parts of GDPR Records of Processing - shared duties https://gdpr-info.eu/art-30-gdpr/ Joint Controllers https://gdpr-info.eu/art-26-gdpr/ Responsibility of the Controller https://gdpr-info.eu/art-24-gdpr/ Processor https://gdpr-info.eu/art-28-gdpr/ Security of processing https://gdpr-info.eu/art-32-gdpr/ need to demostrate accountability https://gdpr-info.eu/recitals/no-74/ -
Implementing Cashless Catering and data issues
jenatddm replied to Seb1780's topic in Data Protection & Information Handling
The catering company have said "there are no data protection issues because it's all on site" and BioStore have said "it's all in your MIS so it's your responsibility". Questions: For school: 1. Are you going to adopt the Biostore biometrics applications 2. Which data items precisely will be extracted from the MIS and does each one meet the test of 'necessary' and why (don't just accept "Biostore wants it") 3. Who owns (and has access to content and responsibility for security of) each server involved 4. Is there a direct data flow to the catering company and/or to Biostore from school and/or flow back For catering co: [cough] 1. You have employment data, as well as customer/client data even if you don't store pupil data. Suggest you get some Data Protection advice. For Biostore: 1. What personal and other data does the POS equipment collect from a child - item by item basis 2. What personal and other data does Biostore extract and how often from the MIS 3. What sensitive data do you collect, process and retain / analyse or otherwise process (biometrics, ethnicity, photographs) 4. What payment data are collected from payers (holders of parental responsibility) 5. Where are these physically stored and shared 6. Are data stored on the 'controlling cards' 7. What in-house or third party analytics do you run on the data and what is its retention and onward use policy (for example of the purchase profiles) 8. What is the retention policy for each and how is future destruction managed For all: 1. what is the legal basis for the collection or processing for each data type (i.e. personal / biometrics / financial) 2. who stores and shares with whom, feedback (what is that exactly) on what has been bought ("eaten" unproven) on what legal basis are parents told what has been bought or other associated data 3. Is it possible in your part of this chain that personal data could be compromised (lost or leaked through malicious hacking, system outage, theft, human error) > If yes, who would contact the ICO and who would contact the individuals affected? 4. Who will document any necessary security and consent procedures for each part of the chain 5. Who will document pupil / parent communications for each part of the chain 6. Who is responsible for pupil / parent subject access requests 7. Who is the responsible DPO (children merit special protections under recital 38 and large scale monitoring and profiling, required)? 8. Who is responsible for assuring destruction of all personal data gathered for these purposes, when, and how is it communicated to pupils/parents at that time? Re: "this obligation would include getting explicit permission from all those 13 and over when the new legislation based on GDPR come into force." Note: there is no legal duty in this area that is age related under current DPA. 13 is likely to be the age at which parental authorisation for the collection of personal data will be required for information society services, excluding preventative or counselling services, where consent is the legal basis for processing. (GDPR article 8) This is an area in which both pupils and parents need involved at any age. If biometrics involved, note requirement to have informed both holders of parental responsibility / parents, and active consent from one and lack of active objection neither as well as child necessary. (Protection of Freedoms Act 2012) I'd suggest all taking a look at this ICO page if not already done so, and decide the legal basis for each data processing activity: collection, copy/share of MIS data, flow, storage, processing (including any profiling of the child whether by biometrics or on what has been purchased over time), retention period and destruction. What I can think of for now. I'd love to keep in touch on this one, and see what the outcomes and replies are. We could build a flow diagram from it, with decision points and if yes> if no> steps, which would be helpful for others I believe. -
As you might imagine we have ongoing discussion with ICO and DfE about their privacy notice template. Questions: 1. Do you think these privacy notice templates can be easily understood by a child? (Note that "concise,transparent, intelligible and easily accessible, using clear and plain language, in particular for any information addressed specially to a child" is a Data protection legal obligation) 2. Do you understand from this, that the Department for Education will give children and workforce identifiable and sensitive personal confidential data (not anonymous) to commercial companies, journalists, charities, think tanks and researchers without asking for consent? 3. Therefore, do you think these privacy notice templates are useful?
-
GDPR Responsibility in your school
jenatddm replied to prad-ucs's topic in Data Protection & Information Handling
Remember it is expected that the DPO reports to the highest management level of your organisation. It requires that they should have professional experience and expert knowledge of data protection law. This should be proportionate to the type of processing your organisation carries out, taking into consideration the level of protection the personal data requires. Adequate resources must be provided to enable DPOs to meet their GDPR obligations. The DPO’s minimum tasks are defined in Article 39: To inform and advise the organisation and its employees about their obligations to comply with the GDPR and other data protection laws. To monitor compliance with the GDPR and other data protection laws, including managing internal data protection activities, advise on data protection impact assessments; train staff and conduct internal audits. To be the first point of contact for supervisory authorities and for individuals whose data is processed (employees, customers etc). Reference WP 29 Guidance on DPOs and the ICO guidance on DPO and governance. -
Let's get our voice heard in the DfE
jenatddm replied to maturelady's topic in Data Protection & Information Handling
Hi - this is the reason I joined the forum and had offered to in other threads, and have already been gathering your questions and concerns so far since May, as well as those of academics, child rights groups, teachers and parents in one place - all been /being / to be asked of the DfE and the ICO. I've had several discussions with Grumbledook to support your company work too. Forum members can read their examples and questions asked from the forum included in this. It's work-in-progress and report to come out once UK Bill is final.(expected Jan 2018). Anyone can add and contribute comments to include case study questions, not only read, But for schools very little of 1,2, 3 above should be new. Your current legal basis for processing, and Subject Access Request reqs. are very unlikley to change compared with today. Where we see is trickier as regards profiling for example, are the relatively new technologies in schools, such as apps and safeguarding, where the tools involve third party processors, and where the boundaries of necessity, proportionality and questions of retention lie. Even then GDPR is not likely to change this much, but it seems many in schools have not paid attention to data protection reqs. or clear legal basis and fair processing on their introduction so far. The DfE is not going to catch this up for schools, and the ICO has already published guidance over several years for the education sector. For schools, our report will discuss applied edTech and school processes and policies and offer suggestions how you need to apply these in practice, but if you're using it now, you should know your current legal basis for the data collection and any onward distribution. If your school honestly doesn't have a qualified, trained data protection resource to ask or access (even if shared across schools / MAT / LA which is also fine under GDPR), then you should raise this as a critical risk, and ask whether your school would be OK with having no trained First Aider. Meeting requirements of data protection law is not an optional extra. https://docs.google.com/document/d/10KD1adCAeWXG_5SioUNBSzu-yfsNdIdtlj5xlOqbIFQ/edit?usp=sharing Note 29/7/2017: This is a collaborative working file which does not set out to address all GDPR issues or offer answers. It is intended to present collated questions from, and for, applied practice, gathered throughout 2017 -- from education practitioners, schools, child rights’ advocates, tech third parties, discussions and events -- for anyone who needs to obtain consistent answers as UK derogations become clear, or where a national approach may need thought out at policy level, and regulators may need to offer opinion and guidance. Many thanks to all contributing. For direct questions or contact please use Twitter direct message @Defenddigitalme or email jen [at] defenddigitalme.com- 35 replies
-
- 4
-
-
- data protection
- dfe
-
(and 3 more)
Tagged with:
-
You really need your responsible DPO to do this but there is not really any such thing as a firm 'being compliant' as it depends on how your organisation, your students' personal data, parents/students communication, and the company and their processsing interact, and that is not fixed. Questions you need to be asking include, What age are the children from whom the data will be collected? What do you mean when you say 'profiling'? Are you planning on using the free or paid version? What data are collected? On what legal basis will you collect and process each of those data? What processing do you expect the company to do? What is their security set up? What is their data retention and destruction policy?
-
GDPR & UPN use - Statement from Groupcall
jenatddm replied to GREED's topic in Data Protection & Information Handling
Added as a question to the file we will submit for review by ICO and DfE, and in preparation for our report https://docs.google.com/document/d/1...it?usp=sharing FFT is an interesting case for many reasons, not least there is no clear legal basis for linkage of the data FFT gets from schools to data they receive from the National Pupil Database, and its indefinite retention as a merged dataset. -
GDPR & UPN use - Statement from Groupcall
jenatddm replied to GREED's topic in Data Protection & Information Handling
There is no 'official guidance' from DfE other than that which was published nationally in 2013. It is explicit: Quote page 7 of 19 https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/270560/Unique_Pupil_Numbers_-_guidance.pdf [my underlining] "The UPN must be a ‘blind number’ not an automatic adjunct to a pupil’s name. It must be held electronically and only output when required to provide information to the LA, central government or another school/academy to which the pupil is transferring." What has been explained to participants on the forum differs between who you speak to at DfE, and the ICO. It seems sensible that the ICO and DfE need to agree a position in light of the questions raised, and we are recommending to them both, that the DfE guidance is updated accordingly with regard to GDPR. -
If anyone has questions that are still unclear due to data protection changes, please do keep posting here, and if they are of broadly applicable interest and it would be useful to have national policy / ICO clarifications, I will add them into this collaborative working document, for discussion and to get their views. Clarifications / recommendations / any still open questions will be included in a report to be published in autumn. Anyone can add comments into the GDPR google doc which is open to all https://docs.google.com/document/d/10KD1adCAeWXG_5SioUNBSzu-yfsNdIdtlj5xlOqbIFQ/edit?usp=sharing GDPR should mean more of good practice for those who have it today, and offer clear direction for improvement where there is not. Unless you currently ignore current Data Protection principles and laws, it's unlikely very significant change will be needed. The GDPR won't explicitly change where consent is or is not needed compared with today for children, except on Internet services that collect personal data. Take a couple of practical scenarios: for example on fingerprinting in schools, if your school does not clearly state that biometric solutions are optional and must be consent based, yes, you will need to change policy and practice, but that's to process data to meet today's legal basis, not [only] GDPR driven. And that's not only about a consensual process from children, but must involve those with parental responsibility. One area we think clarity is needed for schools for example, is regards your legal basis for the necessity of data collection as part of a school's authority to process data, vs requiring the method of how that data is collected. (Reporting absence app for example, over a phone call or email). The GDPR offers a good opportunity to review all current practice, and if improvement is needed, a reason to make change. Schools that have good practices and treat parents' and pupils' data fairly, should be confident they can carry on as is, and where practices are not in line with good data protection practice and law, changes needed must be clear so that the DPO can explain them to decision makers, and change can be made as easily as possible. For that everyone needs a common understanding. We are trying to support the sector by getting awareness of your real-life practical questions in front of policy makers, and show up gaps that we know of. We want to ensure ICO and DfE guidance will be clear and consistent, and that everyone can apply it in practice, in confidence, with common understanding for Data Controllers and Processors (suppliers and schools) to know their responsibilities, and for Data Subjects (parents, staff and students) to understand theirs, and their rights. Share your practical scenarios if you need support, and we'll make sure they get addressed. The DfE will always defer to ICO for recommendations on your practice. The ICO does plan to issue more guidance. It's important for people not to worry right now, but to be taking positive action to do a data audit, take stock to know what data you have, where, why, and on what legal basis.
-
Not at all, my goodness, it's not scary. There was never any question of "kids [can't] stop standard personal data flows". "So the student not the parents must be informed of what, where, how and why their data is used and they can be given the opportunity to challenge its use" is not correct. Data subjects [Parents, staff, and pupils in this case] need to continue to be informed of all data processing for it to ahve a legal basis, just as today, Principle 1 of the current Data Protection Act. Consent is not a matter of age, even in existing law, but of capacity. This GDPR Article 8 age, where parental consent is required is NOT for all data processing, but personal data collected by information society services i.e. online applications. And only where consent is the legal basis for processing. It will change little for schools. Consent rarely applies as a legal basis for data processing in schools, and for example on school census data is only 4 items: country-of-birth, nationality, ethnicity and first language, just as it already has done to date. Until you see the draft bill, you cannot make any further assumptions on implications. There is no "age of consent" for generic data processing in GDPR. It is likely only to be pushed as such, by companies that want to sell a consnet solution, which for schools is likely to be unnecessary, and certainly no one can no yet unless you have seen the UK draft legislation, and how it will be finalised. Our comment: Comment on Data Protection Bill DCMS Statement of Intent
-
Dear All - work-in-progress collaborative doc is here, and open for contributuons. It is shared between academics, legal-, data protection-, and child rights' specialists, as well as regulators and more, and open to all. As yet, it does not intend to offer answers (some are known, some are unknown) but it aims to capture and highlight some of the applied, and perhaps the slightly more tricky thematic areas, under the relevant aspects of the GDPR. especially those which may mean a change or review of current policy and/or practice in schools in education in England today. It is not everything by any means. But it's open to all for comment, and open for suggestion for other things that are missing. It's welcome to be shared widely, and you can post questions to me via comment, email, here, or DM on twitter. Or comment here. There will be some legal unknowns until some of the UK interpretations are defined in the coming UK legislation to finalise the derogations, and there is more to come that is not expected from the Article 29 Working Party until December on consent. Work-in-progress. Feel free to join in. It will contribute to a report on data privacy and protection in education, with a view to GDPR readiness. (Full link: https://docs.google.com/document/d/10KD1adCAeWXG_5SioUNBSzu-yfsNdIdtlj5xlOqbIFQ/edit# )
- 14 replies
-
- 3
-
-
- data protection
- faq
-
(and 3 more)
Tagged with:
