Jump to content

AndyCrow

Members
  • Posts

    52
  • Joined

  • Last visited

Reputation

115 Excellent

About AndyCrow

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

  1. Dear Client We are writing to inform you, as the data controller, of a potential data breach that has occurred involving data processed by Single Central Record Ltd, acting as the data processor. We are committed to maintaining the highest standards of data protection and transparency, and it is in this spirit that we provide you with the following details. Description of the Incident On 17th August 2025 we were notified by Intradev, our external software supplier, that a part of their system had been subject to unauthorised access. The incident itself occurred around 31st July 2025. Intradev confirm that certain files that relate to personal data were copied from their systems. Our own network and servers were not compromised. We are actively investigating why Intradev had copies of some of our data in their systems. Nature of the Data The data potentially affected by this breach includes personal identification information. At this stage, we are conducting a thorough analysis to determine the full scope of the data involved. From our assessment so far, the scope of the data appears to be limited to an audit table used to record certain changes or actions made in the Single Central Record. Potential Impact The potential impact on the data subjects may include identity theft. We are actively assessing the situation to understand the extent of the impact and will keep you informed of any significant developments. Immediate Actions Taken Upon discovery of the breach, we immediately obtained a report from Intradev detailing the nature of wthe breach. We have undertaken a review of our own systems, which have not been affected. Although we are not the data controller, we have been pragmatic and made a report to the Information Commissioner's Office (ICO). Next Steps We recommend that you, as the data controller, consider reporting the matter to the ICO and to notify potentially affected data subjects. You can report the matter to the ICO on their website https://ico.org.uk/for-organisations/report-a-breach and contact them for advice on 0303 123 1113. We will do our best to assist you to address this situation and mitigate any potential harm to the data subjects. Should you require more detailed information to fulfill your own data controller obligations, please contact us. We are prepared to assist you in assessing the full nature of the data upon your request. Contact Information For further communication regarding this matter, please contact us on [email protected] or 0151 606 5101. We are available to discuss any concerns you may have and to provide additional information as it becomes available. We take this matter very seriously and are committed to resolving it promptly and effectively. Thank you for your attention to this urgent issue. Sincerely, SCR Team
  2. Much of GDPR is about risk and accountability. If you and the DPO highlight and document the potential risks involved in this new process then the ultimate decision should be with the Governors. If she can prove that the risks are minimal having produced a DPIA,(it is a new process) then the Governors may give them the go ahead. When the risks are accessed I would be surprised that it would get the green light.
  3. I would also add that you should make sure have explicit consent for the use of the pictures on the website. Some parents may be happy for pictures of their children to be around the school for example, but not happy for them to be on websites, school brochures or social media platforms.
  4. Most pupil information from your Primary school should be passed onto the next school they join. Your school doesnt need to keep most of it...and certainly not for 25 years. As previously stated, there are exceptions to this are things such as accident records, SEN etc The IRMS provides excellent guidance for schools to follow https://irms.org.uk/page/AcademiesToolkit. The school should have a retention policy signed off by Governors and any queries and decisions on deleting or keeping data and the timeframes decided should be made by them and your DPO. I would suggest waiting to be instructed by them before next moves.
  5. There would be a good argument not to disclose the letter on the following basis. https://globaldatahub.taylorwessing.com/article/sars-under-gdpr-ico-guidance-and-uk-exemptions "The DPA18 states that you may only disclose the information about the third party where they have consented to the disclosure or where it is reasonable to disclose the information without their consent. DPA18 sets out that what needs to be taken into account when assessing whether or not it is reasonable to disclose third party information includes: The type of information you would disclose. Any duty of confidentiality you owe to the other individual. Any steps you have taken to seek consent from the other individual. Whether the other individual is capable of giving consent. And Any express refusal of consent by the other individual. Essentially the decision involves balancing the competing rights of the individuals involved. Case law (which remains relevant under the new regime) suggests that the controller has a wide margin of assessment and a wide discretion as to which factors to treat as relevant. In a 'tie-breaker' situation, presumption will fall in favour of non-disclosure but this view is not replicated in the ICO guidance."
  6. Yes GDPR is all about accountability and to that point the ultimate responsibility rests with Governors then SLT. Obviously every school is different but there should ideally be one one centrally run data mapping template that lists the various processes within the school, the different products used, lawful bases for processing, where data is stored etc. Again in the ideal world this is overseen by the DPO but compiled by the area of the school using the process. This is a task in the first place but then relatively simple to update. In terms of teachers wanting to subscribe to websites with student details, this should not be yours or their decision. They should seek approval from the Head or whoever is responsible for DP in the school. Reading a Privacy Notice does not mean that it satisfies a DPIA. Not sure if this covers all of your points but you really should chat with your DPO.....its their job!
  7. As @GrumbleDook says its a cultural change that is needed within the school. It is definitely not purely an IT issue. 95% of data breaches we see are from human error not IT issues. Staff need understand that data protection is part of Safeguarding, because the loss of data relating to a child could be very harmful. Stress that whilst you are doing your part of the job in keeping systems secure etc SLT need to ensure policies and procedures are followed and that regular training takes place.
  8. This is a very good example of why a DPIA should be completed. Whilst the company stresses that they comply with COPPA and FERPA, which indicates they are trying to maintain good practices, they need to comply with GDPR for UK and EU data subjects. Their Privacy Notice is not compliant with GDPR and provides insufficient details. The school should ask the company for their Data Processing Agreement with the Terms and Conditions as part of the DPIA process. These will need to be assessed. The fact that they are selling their service into the EU and dont seem to have offices here means that they need an EU Representative and they have chosen someone in Austria for that purpose. Going back to my previous point. Once the DPIA is completed and reviewed by the DPO, the Governors should make a risk based decision as to whether you should use the product or look for a similar product.
  9. Theoretically all of the outside agencies and service providers should be named however this is obviously a very long list. That said the school should have a document listing all the processes and processors that you engage with. If the Privacy Notice has been written by your DPO and signed off by Governors it is their responsibility. In preparing the policy and sanctioning the various products DPIAs should have been carried out to prove that they are accountable to any possible risk in the processing the data. Its not OK just because its Education as guidelines need to be followed and I don't think you are being paranoid. Perhaps a quite word with the DPO or whoever you report into to confirm that they are happy with what you are being asked to implement.
  10. Any new service should have a DP Impact Assessment conducted before it is installed. In this instance the process will flag that the product isnt GDPR compliant. Your DPO will then make their comments on the suitability of the product. At this point the decision to use it or not should be with the Governors. If they decide it is worth the risk then it's their decision and any repercussions will rest with them.
  11. Following on from @GrumbleDook@s point. The process should not be purely an IT issue. The DPO should provide the template with the questions, the area of the school that want to introduce the new product/process should fill in the document ( as they are using it) and IT should be asked only in specific areas. The DPO will then read and give the OK if all is fine and ask for Governors to sign off.
  12. As long as you're not an Independent school you should have a DPO . They should be able to give you the correct info.
  13. As others have correctly stated you do not need consent for this process. You have a legal obligation to maintain parental records of your pupils and so as long as the data is stored securely and then only used for specific reasons and retained for the length of time stated in your policies, it is fine. This information should be on your school's Privacy Notice so that parents understand why the data is collected. As previously stated your DPO should have this covered.
  14. Following the comments re. Zoom, is anything really safe? #GDPR #data protection https://www.scmagazineuk.com/critical-vulnerability-microsoft-teams-lead-data-theft-just-looking-picture/article/1681503
  15. Hi. The retention periods will vary depending on what type of data you are referring to. For example School Records of a pupil will vary from the time you keep staff employment records. You should first ask your DPO for a copy of the schools's Data retention schedule or failing that look at the IRMS guidelines. https://irms.org.uk/page/SchoolsToolkit
×
×
  • Create New...