Hi all,
Wonder if someone can help me with this. As background, we are a small managed service provider working out of Herefordshire with about 40 primary/secondaries on our books.
Our Local Authority has engaged with The Contact Group to provide a Virtual School for LAC children within our county and a number of our managed schools have their data extractor installed on their on-premise SIMS servers. SIMS is managed by a 3rd party company and not by ourselves.
Prior to May 2018 we were auditing our schools to ensure everything we knew about was in its proper place for GDPR and we came across an issue with the Contact Group data extractor. The log files for the data extractor on the SIMS server (c:\program files (x86)\Contact Group\Data Extractor\Logs were flagging up personal data. When we checked the logs, it seems that the data extractor was logging in plain text, the names, addresses and parent/foster carer names and contact details of all the LAC within the school. That is, all the data that was used to populate the Virtual School was recorded in plain text in the log files.
This was of a major concern to us as the SIMS server has shared access between us, the company that manage SIMS, Capita to need to remote in from time to time and also every other Tom, Dick and Harry it seems that need to drop another data extractor on the SIMS server from time to time. We always install these ourselves wherever possible but we are not always told this is going on.
Ordinarily, this data would be protected from within SIMS itself to which we don't have access and neither do many other 3rd parties but as soon as it is moved out of SIMS and dropped into plain text on the SIMS Server system drive then it becomes much more visible. Technically, it also contravened the then Data Protection Act in terms of processing personal data, you must ensure that you leave it as secure as you found it.
We raised this with The Contact Group, who after some persistence, agreed that it needed to be addressed and that they would removed personal information from the logfiles as it should not be required for telemetry troubleshooting. I also asked for logging of personal data to be moved to the cloud alongside the virtual school application (for auditing of personal data collection) and a number of other changes that I do not need to go into here. I was told that this would be carried out and we would be told when this work was finished. Despite being cc'ed in on every email, our Local Authority Head of Virtual School was silent in all regards.
I did not hear anything back so we have checked again. The data extractor has been updated and although the majority of personal data does not now appear in the logs, the full name of the LAC subject still appears in plain text. They have now also put in a log rotation to delete old logs (prior to May some of our school accumulated nearly 2 years of this data) but there are still logs for the last 5 days visible.
My question is simply should I accept this as a solution or push it back?
EDIT: The reality is that anybody using the Looked After Call solution would be affected in the same way so asking should I accept it is a closed question. The Contact Group have other hosted solutions/services but they all use the same extractor so there may be other information in the logs for these also but I only know of Looked After Call. I would be interested to know if anyone else has found personal data recorded in their data extractor logs.