I would guess it's a totally automated system. This is how my employer does it and they have 30k accounts to make, the data is there but its never disclosed to IT staff.
That said, the student record itself contains it and anyone with legitimate cause to look that up has it. This is dealt with by some principle 1 statements on the learning agreements.
I'm against it as I don't think it makes a particularly good password. Particularly as most of our students' passwords are therefore all over Facebook already. That doesn't bode well for in-class security if they don't change it quick enough (ie. between the account being created and their first login, at which they are asked to change).
Ian
-----Original Message-----
From: This list is for those interested in Data Protection issues on behalf of Tim Trent
Sent: Tue 10/08/2010 17:31
To: [log in to unmask]
Subject: Re: [data-protection] percolation of DoB - is this OK?
I'm going with "Fairly (and lawfully) processed"
It is not fair to distribute your date of birth because it was not intended to be processed for this purpose. An exception might be if the DOB is not ever revealed to anyone except you during the password reset process (ie is by a totally automatic system and is one way encrypted as the password on the access control system)
On 10 Aug 2010, at 16:48, Mark van Harmelen wrote:
> Hi all
>
> One would think that I could type words without sending an email... let me try again
>
>
> Working sometimes for a university, I was a bit shocked when I received this in an email....
>
> The password ...... I have reset that to be your date of birth in the form YYYYMMDD.
>
>
> ie my DoB is in the central HR system, it then gets passed to a central IT system, and local departmental system administrators can access that information. They cunningly use a user's DoB as a password when resetting passwords, in order not to mail passwords around in plain text.
>
> But isn't my DoB my personal data that should be safely guarded by the HR department?
>
> If someone can quote chapter and verse to me such that I can get our uni's data protection officer to change things, then that would be great.
>
> Thanks
> mark
> All archives of messages are stored permanently and are available to the world wide web community at large at http://www.jiscmail.ac.uk/lists/data-protection.html
>
> Selected commands (the command has been filled in below in the body of the email if you are receiving emails in HTML format):
>
> Leaving this list: send leave data-protection to [log in to unmask]
> Suspending emails from all JISCMail lists: send SET * NOMAIL to [log in to unmask]
> To receive emails from this list in text format: send SET data-protection NOHTML to [log in to unmask]
> To receive emails from this list in HTML format: send SET data-protection HTML to [log in to unmask]
> All user commands can be found at http://www.jiscmail.ac.uk/help/commandref.htm and are sent in the body of an otherwise blank email to [log in to unmask]
>
> Any queries about sending or receiving messages please send to the list owner [log in to unmask]
>
> (Please send all commands to [log in to unmask] not the list or the moderators, and all requests for technical help to [log in to unmask], the general office helpline)
>
Tim Trent - Consultant
Tel: +44 (0)7710 126618
web: ComplianceAndPrivacy.com - where busy executives go to find the news first
personal blog: timtrent.blogspot.com/ - news, views, and opinions
personal website: Tim's Personal Website - more than anyone needs to know
Important: This message is private and confidential. If you have received this message in error, please notify us and remove it from your system. This email and any attachment(s) are believed to be virus-free, but it is the responsibility of the recipient to make all the necessary virus checks. This email and any attachments to it are copyright of Meadowood Associates, owners of Compliance And Privacy, unless otherwise stated. Their copying, transmission, reproduction in whole or in part may only be undertaken with the express permission, in writing, of Meadowood Associates, at Meadowood House, 30 Redditch, Bracknell, Berkshire, RG12 0TT.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
All archives of messages are stored permanently and are
available to the world wide web community at large at
http://www.jiscmail.ac.uk/lists/data-protection.html
If you wish to leave this list please send the command
leave data-protection to [log in to unmask]
All user commands can be found at http://www.jiscmail.ac.uk/help/commandref.htm
Any queries about sending or receiving messages please send to the list owner
[log in to unmask]
Full help Desk - please email [log in to unmask] describing your needs
To receive these emails in HTML format send the command:
SET data-protection HTML to [log in to unmask]
(all commands go to [log in to unmask] not the list please)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
---------------------------------------------------------------------------------------
Please consider the environment before printing this email.
---------------------------------------------------------------------------------------
This email and any attachments are confidential and intended solely for the use of the individual to whom it is addressed. Any views or opinions presented are solely those of the author and do not necessarily represent those of Liverpool Community College or associated companies. You must not, directly or indirectly, use, disclose, distribute, print, or copy any part of this message if you are not the intended recipient.
The message content of in-coming emails is automatically scanned to identify Spam and viruses otherwise Liverpool Community College does not actively monitor content. However, sometimes it will be necessary for Liverpool Community College to access business communications during staff absence.
Liverpool Community College has taken steps to ensure that this email and any attachments are virus free. However, it is the responsibility of the recipient to ensure that it is virus free and no responsibility is accepted by Liverpool Community College for any loss or damage arising in any way from its use.
---------------------------------------------------------------------------------------
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
All archives of messages are stored permanently and are
available to the world wide web community at large at
http://www.jiscmail.ac.uk/lists/data-protection.html
If you wish to leave this list please send the command
leave data-protection to [log in to unmask]
All user commands can be found at http://www.jiscmail.ac.uk/help/commandref.htm
Any queries about sending or receiving messages please send to the list owner
[log in to unmask]
Full help Desk - please email [log in to unmask] describing your needs
To receive these emails in HTML format send the command:
SET data-protection HTML to [log in to unmask]
(all commands go to [log in to unmask] not the list please)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
|