Jump to content

Recommended Posts

Posted

Hi Everyone,

 

I was just wondering if any MATs out there use dedicated SCR software? I am looking to set this up us, but there are so many options. We currently use SignInApp and they have an add on for SCR creation. Or there is https://onlinescr.co.uk/ or we could even use the add-on for MyConcern called 'Sentry'

 

Does anyone have any experience with these, to offer an opinion?

 

TIA

Posted

We use SCRtracker (scrtracker.com) which has now become part of Sign In Solutions and is now known as Sign In Central Record.

 

So that might be a good fit ?

Posted
We use SCR Tracker. Seems to do the job.

 

Thanks for your reply. Isn't SCR tracker now part of SignInApp? -https://www.signincentralrecord.com/

 

I do like the look of their software, and at £350 a year I feel it is fairly priced.

Posted
Thanks for your reply. Isn't SCR tracker now part of SignInApp? -https://www.signincentralrecord.com/

 

I do like the look of their software, and at £350 a year I feel it is fairly priced.

 

We use SCRtracker (scrtracker.com) which has now become part of Sign In Solutions and is now known as Sign In Central Record.

 

So that might be a good fit ?

 

yup - no noticeable difference in the actual software yet.

Posted
Thanks for your reply, do you use this MAT wide for each school? or would it be £350 per school per year?

 

MAT wide

 

Things might have changed, but we purchased for three years for 10% discount.

 

Cost was per school based on pupil headcount, so starts at ~£350 for each school and we get the Central Team for free.

  • 6 months later...
Posted (edited)

Former MAT COO and DPO here.

 

We had a major failure in our SCR management process that resulted in the Trust's schools being rebrokered. I'm very familiar with the SCR software market and the wider data protection issues having spent 2 years working with the DfE on related issues.

 

There are 2 big issues to be mindful of that a number of SCR providers are offering:

 

1. Social media reference checking: This is a major risk area that exposes the Trust to legal action on the grounds of discrimination. There have been 2 big legal cases against MATs on the grounds of hiring discrimination and both times the Trust lost. The latest KCSIE highlights that "as part of the shortlisting process, schools should consider carrying out an online check," however it does not stipulate this to be social media and it provides no framework to follow.

 

Under UK employment law, it's highly advisable that any school get consent from candidates prior to any check of social media. For one, it's critically that any checks are carried out on the correct accounts. Get the wrong account, or a spoofed account, and the school could be in big trouble. Once schools begin looking at any candidate's online activity, this falls under GDPR and is protected. A candidate can request a SAR and have full visibility on what the school checked and how they used that information.

 

The school (and Trust) need a robust policy when it comes to vetting online activity as this isn't covered by default in the Safer Recruitment process.

 

The Equality Act 2010 protects an individual's characteristics include (but are not limited to) age, disability, gender reassignment, race, religion or belief, sex, and sexual orientation. If a school rejects a candidate based on social media content that reveals or pertains to any of these characteristics, they could be at risk of a discrimination claim.

 

I've seen some SCR providers offering in-depth social media 'reports' in which they've pulled a single post and labelled it "potential hate speech," or pulled up posts from when the candidate was under 18. There's no audit trail on how they found that post and whether that account has been verified to belong to the individual. If that information is used to discount a candidate from an interview process, 9 out of 10 times, that will break Equality Law. The penalties are huge, you're talking 6 figure payouts typically.

 

Rolling that out across a Trust and devolving that process to business managers (who typically apply for vetting checks) is a massive risk. Until the DfE provider more guidance and protection for schools, it's too big of a risk to take.

2. Adding contractors to a SCR: There's no legal requirement to do this, and while it seems like common sense, it raises process and GDPR issues. A school is required to ensure contractors are vetted correctly when they're undertaking regulated activities or they're in the school unsupervised, however most contractors don't fall into this category. Once a contractor is added to a SCR, the school typically captures a lot of personal identifiable information. Under GDPR, once the contractor is finished, a school can only hold this type of information for 28 days unless they have a demonstratable reason why it must be held longer. "In case the contractor returns" is not a viable reason, however I've already seen a number of schools building their 'bank' of contractor information in their SCR thinking it's saving time if they ever return. This simply isn't allowed, this data must be deleted. Having a visitor management system directly populate a SCR isn't advisable as most schools have no awareness of data deletion requirements for non-employees.

Edited by FenderJay
Improved clarification
Posted

I would suggest that the comment from @FenderJay about contractors is itself not a perfect view either. As with all data processing, you need to look at it on a case by case basis. If you have a contractor that attends site very regularly (eg. photocopier engineer that visits the site monthly for example), then having them in the SCR is not problematic from a GDPR point of view. If you are adding someone who comes to the school once a year to do the water legionella testing, then that's not really sensible to do as a year is a long time to hold data for no real reason.

 

There is also no legal definition of a time period to hold data for - so saying "28 days" is not accurate either - that is a judgment call by you as an organisation, and as with a lot of GDPR related decision making is down to your risk assessments and own processes - you simply need to document why and be reasonable in your decision making process. Remember also that the guidance for retaining visitor logs is at least 6 years.

  • Thanks 1
Posted (edited)

It's a complex area and I agree with what you're saying @localzuk.

 

I contributed to this thread as my main concern is that I've seen 2 companies advertising to schools that they "must" now add all contractors to their SCR, and that social media checks are a statutory part of Safer Recruitment (they're not).

 

To clarify a little further, with contractors, the key factor is what data you're capturing. Personal identifiable information is protected under a different legal framework and it can't be held for the same period that contracted employee data can be. As long as you're holding a business address (and not a personal address) and you're not retaining DOBs, you're ok to retain that information.

 

It's correct that there is no legal definition of 28 days. However when it comes to personal identifiable information, this is considered best practice and has been established in a number of legal cases in the UK.

 

It's ultimately about minimising your risk exposure as a Trust. My experience is swayed as I've spent a number of years working on policy in the Academies Programme. I've a seen a number of issues that have resulted in rebrokerings and legal action around compliance, data and staffing. In almost every instance, the Trust had acted in good faith but they didn't understand the legal frameworks they operated within and had fallen foul.

Edited by FenderJay
  • 2 weeks later...
Posted
Nobody is recommending a visitor management system directly populating a SCR, contrary, the recommendation is that SCR records for repeat or regular contractors are populated in the visitor management system to flag any missing or expired checks that may be required when they visit as an 'Approved contractor' at point of entry.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...