Jump to content

crimsonspanner

Members
  • Posts

    8
  • Joined

  • Last visited

Reputation

40 Excellent

About crimsonspanner

Personal Information

  • Occupation
    Fixer of privacy and security problems
  • Location
    Down Under
  1. This is a very good question! I can say having looked into this before in the UK that the likes of Facebook DO NOT own the photos once their uploaded. However, the uploader will have granted royalty-free and non-exclusive rights to reuse the photos globally so bear that in mind. In reality this permits them, for example, to allow global users to see those photographs if you have so permitted. This is obviously the way Facebook works and you can control to a certain extent through privacy settings in the relevant application. Importantly, when you delete those photos from the likes of Facebook, you are ending that IP license thereby revoking any rights they had. Handy when you consider you might have a parent withdrawing consent at some point - which they have every right to do.
  2. Forgive my candour, but it's a very minor issue. In the grand scheme of things, there will be FAR greater data protection risks to concentrate on than this inside a school and this is the message I'd be relaying back. Provided: 1) you have a solid contract with the service provider (tick - MS have a comprehensive GDPR-compatible contract) 2) have ensured that the photo won't get shared with externally bound emails (tick) I'd say you have taken reasonable measures to safeguard the personal information in question. So, this now becomes more of an acceptable use issue with the students and that is the lens through which I would be reviewing this matter.
  3. THIS. Ultimately, your DPO should be involved at the start of a project while it can still be influenced (go on, tell me you're the DPO lol). Also, I believe Data Loss Prevention is available in Office365 which covers SharePoint, OneDrive (which is powered by SharePoint) and Teams. Well worth looking into.
  4. Just to add my 2c. It could be argued (rightly in my opinion) that the exam boards and the school are in a joint controller relationship as the exam board will no doubt be using and making decisions on how some of that personal data is processed. This clearly puts a shared interest on both parties. Legal semantics aside, they have a duty to get with the times - something everyone should remind them of at any given opportunity or we will not see change. I think back to my own experience of teachers sending dance videos of 11/12 year old pupils from a girls school in our MAT to an exam board. Sending an unencrypted USB over regular mail with that content on board is simply unacceptable. Add a fretting teacher to the mix who just wants the information submitted on time, and you have a dangerous cocktail. My advice would be encrypt and courier.
×
×
  • Create New...