Maybe we should think about how we make schools spaces of freedom for our children rather than turning them into the next panopticon.
Maybe we should think about how we make schools spaces of freedom for our children rather than turning them into the next panopticon.
The fact that we have kept a part of middle-age inside our modern societies keeps fascinating and frightening me.
I see these things as my basic human rights. And nobody should accept having them restricted.
In the country where I live the school has the authority by law to be more restrictive and enforce their own rules. Which I see as necessary to some point. But I think we should teach kids and teenagers to make decisions on their own and take responsibility for their actions. And not just enforce arbitrary rules.
It was my first lesson in dealing with unjust authority and that most authority relies on the principle that most people under it will do as they say most of the time.
A useful lesson and after that I saw asking to use the bathroom as a courtesy because I was going either way.
It destroyed my fear of and respect for arbitrary authority instantly so I look back on it as a good thing today. I realised that rather than my peers turning on me on a shame basis they turned on the teacher because it was going to be them next.
It also positioned me well for dealing with the somewhat backwards ideals in my own childrens’ school.
it was one of those things that chipped away at my respect for authority - it didn't destroy it, but still dinged it. Peers still turned on me - no one thought "it could be me next". We were 7/8(?) - I'm not sure most people could reason that far ahead vs living in the moment.
What sticks with me is that we had an announcement earlier (few days or weeks earlier?) that no bathroom breaks would be given out because a few kids had 'abused the privilege' (stayed out of the room longer than they should have). So... someone else violates a trivially stupid 'rule', and my own life is negatively impacted, which is wholly unjust. That was my takeaway, which has stuck with me for ~40 years. I still remember a couple of the kids who'd been 'abusing' that privilege beforehand, and remember what impact they and that teacher had on me that day and beyond.
They use that ridiculous methodology now. For example my eldest's entire class was held back at the end of the day for 15 minutes due to one child's behaviour. Unfair and her ASD younger sister relies on her to get home and had a complete panic and breakdown over the routine change. Teachers surprisingly never available for comment after such things due to the layer of bureaucracy over everything. Formal complaint raised, pushed to the very end of their own self-inflicted process every time they screw up!
Going from Swedish to American high school felt like stepping back to elementary school in regards to personal freedom and trust.
First to set the base, in general in Sweden you have all your classes with the same 25-30 instead of different groups every period. From 7th grade we had our own schedule complete with periods without lessons where we would just hang out, walk around or go to the library and jump on the computer. In high school this ramped up even more. Loitering as a concept doesn't exist in Sweden.
To accommodate this the design of schools are completely different. The endless hallways don't really exist, instead there are areas between the classrooms with sofas, tables and whatever to enable people to hangout or study together. My school even had a café open all day. Doing group projects is the epitome of this, we'd show up at the start of the class for attendance and then take off to the library or some other place.
Contrast this with America. Hall passes to go to the restroom, hall monitors. We even had CCTV surveillance in the entire school building. If you would show up late you could be sent to the cafeteria and forcibly miss the class and have to write some essay about how wrong you were. How can a person learn to take care of themselves in such an environment?
This isn't even talking about the pledge or national anthem over the PA system.
Sorry for the rant.
Back to the topic on hand, from what I've read on Swedish news about it everyone involved generally was positive. No more the annoying wait while taking attendance. For the parents it was no different, even before this system they still immediately got a text if the kid didn't show up for class.
The questions raised by the DPA are relevant and my guess is that this will continue to be explored but with more caution towards how the data is processed to comply with this ruling.
I am French, I live in Japan. My criticism applies to these two countries as well. Within European progressives, Scandinavian countries are seen as having a really different educative system and we are wondering what we are waiting before stealing it!
On the topic at hand, I am sure it is very convenient. That's the problem: maintaining privacy is a bit less convenient, but it is important, which is why it is good government do not allow people to trade short-term convenience for longer term privacy erosion.
That's not the issue (at least as I see it).
The big questions in my head include "Who's storing the biometric data? How are they securing it? Who has authorized access to it, and what processes and mechanisms are n place to ensure they only use it in authorized ways? What are authorized uses of the data? How is it ensured that authorized uses will ot be increased in scope? What process or mechanisms are in place to detect attempts or successful cases of some authorized 3rd party obtaining that data? What penalties are there for unauthorized use of the data and to whom will they be applied? What penalties are there for inadequately securing the data and to whom will those be applied? What processes mechanisms or policies are in place to ensure unauthorized access or failures to secure the data are detected and disclosed? How are those processes mechanisms or policies measured to ensure they're working?"
Pretty much _anyone_ dealing with EU citizen's data should already have the answers to those (and related) questions written down. (If you do not, think about how sure you are that the answer to those " .. to whom will the penalty be applied?" questions will not be "Who's responsible for the data breach? Oh, that'd be Barrin from the dev team. Here, let me give you his full contact details and their HR file! BTW, they'll be fired and marched out before close of business, might be best if you call them on their personal cell phone."
- Data and analysis was done at a server in the class room (locked in a cabinet) - All parents signed a consent form before the trial started. - All data was erased after the trial ended.
The Swedish DPA decided that:
1. Consent is not valid of there is a power difference between the subject and the requester. 2. They should have documented a PIA (Privacy impact assessment). 3. They should have contacted the DPA before starting the trial.
Parents should be able to consent on behalf of their children and retraction should come from parents as well.
This used to be considered common sense but not anymore.
Good! Some progress at least.
Ignoring reality for the sake of ideology isn't progress.
By that logic, next a doctor will refuse to vaccinate an 8 year old because the child refused to give consent.
Exactly what stuff the parents can consent to is the real question and should be argued properly and not treated as any kind of "common sense". Things that are necessary for the safety of the children - like vaccines - yes. Other things are on much more shaky grounds.
Well (as you said - and thankfully) not any more.
I try to refer questions of consent to my kids, but in this case the question wasn't asked, they just said "hold your hands out" and went ahead.
I don't think minors can retract parental consent, but IMO schools should accommodate an individual's personal consent if practicable. Indeed schools should where possible be advocating for pupils before their parents if necessary (things like a tutor contacting a parent to request consent on a child's behalf).
Aside: I heard security staff make an exchange suggesting they'd chosen a particular person to search "because you like doing the $ageGroupIdentifier", which might have been innocent but came across as wholly wrong.
What’s the use case? Automatic student registration? If it is, and I can certainly imagine some HR consultant going “weeeeeell we can squeeze five minutes of extra education in if we remove this teacher-student interaction of registration, that’s a gazillion hours of extra education a year!”. I know this is a strawman of my experience, but it’s frankly the only way it would happen at my place. Which would be crazy considering the primary focus of Schools in Scandinavia is to educate democratic citizens, and automating something as meaningful as presence registration is damaging to that focus because the “AI” won’t be able to have a conversation about the usefulness of attendance.
So I absolutely agree with you. This is completely crazy, but what I really wonder is why no one asked “why?”.
"Microsoft says it. We believe it. That settles it."
Really, there's no other option: Even if they magically got the ability to audit source code, the whole point of a cloud service is that the code can be changed at any point. Even if you extract a promise from Microsoft that the code won't be changed... well, see Figure 1. You're operating on trust that Microsoft will abide the agreement, and trust that you'll be able to magically tell if they don't.
As far as the GDPR goes it actually didn’t have a huge technical impact on the public sector. We’ve had stricter local laws for decades, and have build our systems accordingly. We also don’t track you for advertising. So for us the GDPR has mostly been a bureaucratic change, and you’ll notice that’s also the majority of violations. It’s not that data aren’t protected, it’s that no one knows where the contract is, or that we haven’t documented elaborate procedures for whatever. 95% of the GDPR impact on the public sector had been law and legalisation. So the GDPR actually doesn’t impact O365 94 public cloud at all as long as you go to iso27000 certified vendors who provide privacy shield or whatever it’s called these days.
That’s not to say that we aren’t debating public cloud. Because we are. This has more to do with national laws though, we have war-time contingency plans from the cold-war era. Like I said, we had much stricter policies before the GDPR was even a thing.
The issue is that it makes public cloud illegal, but we can’t operate the most digitalised public sector in the world without public cloud. So far everyone is moving to AWS and Azure, pretending the flawed bureaucracy will eventually go away, but our politicians and national digitalisation agency has been refusing to give any meaningful heading, so who knows?
At some point though, someone is going to ask if the privacy bureaucracy is really worth the money it’s costing. At our place you could hire 10 extra teachers a year, just to cover the bureaucratic processes that don’t actually increase security, because a contract or a nice incident plan isn’t actually going to stop anyone from hacking you.
Especially considering that kids have poor judgement, tracking things in school that could be in any way used later against the individual is dangerous.