Jump to content

AndrewSharp

Members
  • Posts

    26
  • Joined

  • Last visited

Everything posted by AndrewSharp

  1. A survey of HR professionals suggests that a third have not yet implemented their retention policy so now hold data in breach of their company policies. HR could be exposing firms to potential GDPR fines | theHRDIRECTOR Give your shredder an end of term workout and ditch any HR paperwork past the designated retention date.
  2. That's right - under the new accountability framework, introduced by GDPR, all this should be in a privacy notice to data subjects so they don't have to look on the ICO site to find out what data is being processed. The public register of fee payers may also show DPO contact details.
  3. Dangerously simplistic and likely to lead to inappropriate data handling if trainees are led to believe that attempting to do good justifies any action including cutting corners on data protection. Both data protection and safeguarding are centred on the rights of the data subject and neither approach to doing the right thing should impede the other if we stay focused on that. There's certainly a need to share data with those who need to know within a school and with other agencies, and we've seen how poor communication can make things worse or fail to spot problems effectively. That data is sensitive, however, and the data subject is likely to be more vulnerable than most, so we need an even more careful approach than usual to ensure that data is shared appropriately and securely.
  4. An approach which may help, borrowed from marketing segmentation, is to consider what "persona" groups exist within your data subjects. Rather than seeing data subjects as roles (parent, student, staff member, governor, etc) and assuming that all people playing a role have the same needs and vulnerabilities, break it down in more detail in to groups for whom the need for transparency is different or for whom the impact of a breach is different. Seeing "separated parents" as a group then helps to focus consideration of risks and impacts for that group, just as seeing those with learning difficulties as a group aids the preparation of appropriate transparency notices. Some marketing segmentation models go as far as giving each persona a name and pen portrait - this helps discussion, as you can visualise the persona more easily and consider how your processing and notices affect them. I'm not suggesting that you label individuals, just make sure that you identify what persona groups exist within your data subjects and ensure that all relevant persona groups are considered when writing notices, carrying out impact analysis, implementing privacy by design etc. For any new processing, ask yourself whether this might impact different persona groups in different ways and whether any new groups are needed to match the possible impact of the processing.
  5. GDPR (Article 14)says that you should notify people from whom you did not obtain data directly about what you hold and why - broadly the same kind of transparency notice that you would provide to a data subject when collecting data, plus details of the source of the data. Contacting them regularly to check accuracy would also be a good test that ensure you have up to date information which will work when really needed. ICO guidance: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-be-informed/ Worrying to hear that the SIMS default is to share personal data with all primary contacts and that it took school office intervention to protect against what could have been a very serious breach. That needs analysis and remediation. You might log it as a near miss breach and then review how to minimise the risk, perhaps via a Data Protection Impact Assessment.
  6. In relying on Legitimate Interest to process contact data for marketing activities (and PECR implied consent to send the message electronically) beware, however, that parents can opt out of marketing purposes but not of public duty/contractual purposes, so you'd need to be able to determine which messages are which and apply your opt-out flags accordingly to those sent as marketing. You not remove a parent from all communications because they opt out of marketing, so you'll need to be sure that your messaging platform supports opt-out by message genre or that you can over-ride the marketing opt-out when sending a message to which it doesn't apply.
  7. There's the Rochester Grammar case which shows that data was lost and the school reported this to the ICO, but no record of regulatory action. https://www.bbc.co.uk/news/uk-england-kent-44371759 As for prosecutions in the schools sector, a former local education authority worker in an admissions team was prosecuted for misuse of data - https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2018/02/former-council-worker-fined-for-sharing-personal-information/
  8. Absolutely right, it's all about accountability and transparency under the new legislation. As with the recent prosecution of a medical practice receptionist, the individual has been prosecuted here and not the employer. Schools need to be sure that they have appropriate policies, have appropriate mechanisms to detect likely breaches and have evidence that they test and review policies and processes. Senior Leaders and governors should be monitoring this and leaving a suitable evidence trail as they would with safeguarding, health & safety inspections, etc etc.
  9. I think that resource calendar sharing is only needed if you want external people to be able to see status, internal users should be able to see availability and book without explicit sharing.
  10. You should see questions about capacity, whether repeating meetings etc are allowed. Did you create the room as a "resource" rather than as a standard user calendar? You can decide whether to allow anyone to book the room if it's free or whether their booking is treated as a request to be signed off by someone. I prefer the former - moderation can be a pain, so allow first come first served unless you have a particular problem. Here's how to create a resource calendar and control permissions -https://docs.microsoft.com/en-us/office365/admin/manage/room-and-equipment-mailboxes?view=o365-worldwide#set-up-room-and-equipment-mailboxes
  11. rom1984 - you're right that PECR always requires consent, but there's a difference under PECR between marketing to prospective customers, where specific consent is required, and offering additional similar products/services to existing customers via soft opt in. The ICO's guidance on PECR, which governs email and SMS marketing is summarised as "You must not send marketing emails or texts to individuals without specific consent. There is a limited exception for your own previous customers, often called the ‘soft opt-in’., Details can be found at https://ico.org.uk/for-organisations/guide-to-pecr/electronic-and-telephone-marketing/electronic-mail-marketing/ You're also right that there's a particular challenge for not for profit organisations. This is most commonly encountered when they want to use data for fundraising. For example, taking an entertainment example, you attend a show at a not for profit theatre and they then want to approach you for a donation. Fundraising isn't a similar product or service to the originally purchased item so the soft opt in doesn't apply. Many not for profit organisations now seek a separate consent to keep supporters up to date with projects and related fundraising activities, which schools could do on the admissions form "we'd like to keep you up to date with our new library project, supported by fundraising, and other similar projects...". Looking at the lawful basis for processing under GDPR, Legitimate Interest "is likely to be most appropriate where you use people’s data in ways they would reasonably expect and which have a minimal privacy impact" says the ICO at https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/legitimate-interests/ Marketing was specifically mentioned in GDPR as a possible purpose for which Legitimate Interest might be appropriate, along with fraud prevention and others. Note, however, that a Public Authority, which includes a state school, can't use this basis for anything where that task is already covered by their duty as an authority. The school doesn't, I suspect, have a statutory duty to inform parents about most of what is in a typical newsletter, so couldn't rely on Public Task, but it can argue that it has a legitimate interest in doing so. A Legitimate Interest Assessment can be used to record the possible impact and whether the balancing test of the school's interest vs the data subject's right to privacy is met.
  12. If you feel that this project would disclose personal data, particularly in a way or to people that would be unexpected, then I'd suggest that you carry out a Data Protection Impact Assessment and discuss it with your Data Protection Officer (who should have a template for a DPIA, or you can download one from the ICO website athttps://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/accountability-and-governance/data-protection-impact-assessments/ Whether you need parental consent probably depends on what your existing policies, in particular your photographs policy, say.
  13. There are six lawful bases to choose from. Contract would be the logical lawful basis for communications about payments. This prevents opt-out as you need to communicate as part of delivering the contracted services. Consent or Legitimate Interest would be suitable for messages which might be considered marketing. In either case the parent can opt out if they wish. The key is to ensure that the lawful basis, or bases if there are multiple purposes, is clear when you collect the data, so refer to it in a privacy notice and perhaps on the admissions form where it is collected and make sure that it's also clear on your Record of Data Processing for each purpose. PECR (which covers electronic communications) permits contact with existing customers, but not new prospects, about products or services similar to those already purchased without prior consent as long as an option to opt out was provided when the data was collected and in subsequent communications (known as a "soft opt in" or "implied consent"), so you may choose to rely on Legitimate Interest for marketing similar services to current parents.
  14. I'd suggest that you check the standard staff contract - it should include a duty of confidentiality and a requirement to return any school property on leaving which you can refer to in a conversation or letter from their line manager (probably the Head) to ask the bursar to return any school equipment or data. This shouldn't be news to the outgoing Bursar, as DPO they should have been auditing that this process is working effectively. It's unlikely that your bursar is a good candidate for DPO, so the school leadership should consider appointing someone who a) isn't directly involved in decisions about data processing and b) who has the necessary data protection expertise and access to regular training, or better still outsource the role to an independent specialist (declaration of interest - that's what we do).
  15. There are certainly exemptions from GDPR concerning serious harm data and child abuse data in Education, but these are exemptions from right of access rather than total exemptions from any GDPR rights. See https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/exemptions/#ex30 A Data Protection Impact Assessment sounds like a structured and emotion free way forward in the circumstances outlined in the original @Decision post - examine the purpose of sharing information about vulnerable children, who it needs to be shared with, what risks this carries, the impact of it reaching unintended people, how effective communication will be measured, etc.
  16. Odd that Internal Audit are looking at this rather than your Data Protection Officer? The DPO should be reviewing compliance regularly - checking that policies are being complied with and that required records are in place, monitoring whether they are effective, etc. The ICO site lists the functions of a DPO, including conducting internal data protection audits, at https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/accountability-and-governance/data-protection-officers/
  17. Ouch. I don't imagine that the DSL is also a data protection expert and qualified to make the assertion that safeguarding wins. As DPO you've been appointed to advise whether their actions are compliant with data protection legislation. There are parallels between data protection and safeguarding, not least in the approaches which will embed them effectively by raising awareness and managing risk. It's unlikely that posting notices on a board in a room not used by all staff who need to know, but also used by people who don't need to know, is the most effective way and measurable way to communicate important information to those who need it. Can the school provide evidence that those who need to know do and that those who don't need to know don't? Safeguarding includes not exposing vulnerable students to undue risk, so a Data Protection Impact Assessment to look at how information about those students, which might include special category data, is being managed would be an appropriate mechanism to consider alternatives and record how the school has decided to act. Should the school decide to ignore the DPO's advice, then that too should be recorded. As DPO, do you report regularly to the Governors or to the Head?
  18. GDPR Article 14, which covers information to be provided when data is processed which was not obtained direct from the data subject, sets out what you should notify to the "other contact" so that they become aware that you're holding about them. If the contact details include an email address, this would be relatively straightforward and you could point them towards your privacy notice to explain what data you hold and why. A text message with a link to the privacy policy might also be practical for mobile numbers without email too. The nominated contacts then wouldn't be surprised to get a call or message from the school when it's important and will know that they need to keep their details with you up to date. The provisions don't apply where the data subject already has all the information required, which you might hope the parent has conveyed to them when they agree to be an emergency contact, but I wouldn't rely on that if it's practical to provide a privacy notice. Nobody seems to be doing this yet, though - I've not had a single Article 14 notice personally and I don't believe that there are no organisations who hold data not collected from me.
  19. Hi Nick, TLS 1.2 certainly ticks the "state of the art" box, as Microsoft are making this their standard and are dropping earlier versions, so you can record in your DPIA that you've adopted a widely used method. https://support.microsoft.com/en-gb/help/4057306/preparing-for-tls-1-2-in-office-365
  20. GDPR doesn't set out specific security measures, so there is no general "sufficient for GDPR" and this has to be considered by data controllers on a case by case basis. What GDPR requires is that the measures that you take should be appropriate to the perceived risk. You can examine risk and record your decision with a Data Protection Impact Assessment, which you should then review with your DPO and keep on record. Consider what data you are sending, whether it is all essential for the purpose (could it be reduced, pseudonymised, anonymised, aggregated?), what risk transmission of that data carries and how best to mitigate that risk. It sounds like you're talking about sending personal data outside your organisation, so ensure also that you've recorded the basis on which you do this, whether it's a controller to controller transfer or a controller to processor transfer, and, for the latter, how you've established that the processor will handle the data securely.
  21. GDPR Article 9(2) provides that special category data can be processed for the purposes of preventive medicine in some cases - that might apply here, but check with your DPO. Vital Interest can only be used when the data subject is incapable of giving consent, so doesn't fit this situation as the parents could give consent in advance. If in doubt, do a Data Protection Impact Assessment to record how you will share the data and how it will be protected and to record how you reached a conclusion. Make sure that this provision of data and requirement to protect it is reflected in the contract with the caterer. Check also that use of data in this way is included in your privacy policy too so that parents know how you will use it.
  22. Sounds like a policy review might be in order too unless this was purely a lack of understanding of the existing policy. Is there a policy which makes it clear to staff that they may not install new applications or begin new processing methods without this being reviewed and has that been made clear through INSET and other mechanisms? A review to determine whether a full DPIA is needed, and to record the decision, as well as a review of the processor contract would be among the minimum actions before starting to use a new way of processing personal data. That's too much detail to cover in an INSET, as most staff won't be involved, but all staff need to be aware that changes to processing personal data require planning by suitably qualifies staff.
  23. Your payroll processing agreement with the LA should state clearly whether they see themselves as Processor or joint Controller. In the hypothetical scenario mentioned, printed payslips lost in the pos to the school, data was in transit when lost and the schools is the party able to detect the loss and, as controller, would need to log this and decide whether to report to the ICO based on the risk to individuals. If the LA became aware of a breach then, if they're your Processor, they must report this to the school as Controller.
  24. As others have pointed out, the risk to data in transit is likely to be one pupil at a time with a paper system, but bear in mind also that keeping records on paper makes it harder to protect the information against accidental loss and harder to ensure that you know what information you hold and where. There's a risk of duplicate records getting out of step and of difficulty in responding to an access request. Whatever route you end up choosing, keep a record of how you reached the decision by considering the risks and methods to address them and seek advice from your Data Protection Officer.
×
×
  • Create New...