Jump to content

Recommended Posts

Posted

What do I need to know/do on this? Been asked by head to supply access logs etc for preliminary investigation into inappropriate teacher behaviour (it's quite serious and may involve someone losing their job if it's true).

 

We have no policy in place for this sort of thing yet :eek: I can obviously provide logs etc.. but what can I legally do/not do? as depending what info I give them (and it is pretty incriminating) could see someone losing their job..

 

Do they need to know they are being investigated?

 

help :(

Posted

Our policy is that if it data is officially requested by SMT, we supply it. We have clear notices at every login warning every user that their session is logged, and it is in the AUP that all staff receive with their logon details when they join.

 

If the user does have any legal right to know they are being investigated (and I'm not sure they do in an internal investigation), then it's almost certainly not your responsibility to notify them. In my view it is important that you play exactly by the book in these sorts of matters. Not having your own written policy does complicate matters in that respect. Are there any policies laid down by the LA that you could defer to?

 

Be sure you keep a separate record in your control of every request that is made and precisely what data you supply in response.

 

The golden rule of course is, if in doubt, consult your union.

  • Thanks 1
Posted

If you're doing an abnormal investigation. Delving in further than you have informed the you will / might do then it comes under the RIPA rules I believe.

 

I did the RIPA training our LEA put on, but they have changed their minds and decided all RIPA must be done by them. I would check that your head knows the official proceedure, and follows it.

Posted
You are being asked to do this by your head who must have their reasons to investigate. If you are unhappy about how to proceed it might be worth running this by your union rep. One thing that might complicate things is if you were having anything other than a professional relationship with the member of staff being investigated. If thats the case then it is probably worth bringing that to your heads attention before you proceed.
  • Thanks 1
Posted

I usually advise that you should ask for as many restrictions on their data as possible.

 

Eg. HT asks for "All Daves logs for the last month" - no thanks, smells like witch-hunt

 

Ask for:

 

* a limited date range - if there is an offence suspected, the accuser should know at least roughly when it has taken place

* a limited range of sites - if it is todo with a particular site, maybe all facebook logs would do for example?

* aggregate data - where possible you should try and provide data as charts or tables with limited drill-down

 

Ask whoever requires this data if they can limit it like that - this will mitigate risk to both of you.

 

HTH,

 

Tom

  • Thanks 1
Posted

Use this instance to write up an AUP to cover this for future reference.

 

What you should do is the following.

  • Make sure they are asking for specific information, not just generic info like bringing up last months records - try to get them to provide specifics, dates and times if possible
     
  • If no specifics can be provided, ask what sort of "filter" (eg facebook, myspace, bebo) you should apply to the search, as everything could be upto 50-60 A4 pages worth of websites
     
  • Make a copy of all logs pertaining to this person for the Headteacher
     
  • Keep a copy for your records should you be asked anything about this in the future
     
  • Make a copy for the member of staff involved, if he/she is smart he will want a copy of all paperwork
     
  • Do not inform anyone other than those who asked you to pull up the logs that you are doing this
     
  • Notify your union rep that you are unsure what consequences may come of this in terms of your job security (it should be fine but you never know when ANYONE is getting investigated)
     
  • Ask to remain neutral at all costs unless it is absolutely vital that you are bought into the investigation

 

That in theory will keep your nose clean and you will have covered all bases.

 

As I said, in future write up an AUP which will cover you, and give you a basis on which to operate in these situations. Thankfully I have never had to act on my AUP, but it is there just in case.

  • Thanks 2
Posted

As I seem to keep saying at the moment, get it in writing. Anything you have been asked to do by the head needs to be in writing so you exactly what you are being asked. Like others, all users are aware(even if they deny knowledge) that the systems are monitored, if you have instructions to provide details of a particular user you should be able to do that. You should inform the head however, if you discover something which needs to be reported that you will inform the appropriate people(for example your LEA if it needs auditing) and let them take over.

 

I have provided information on user logs previsouly and I provided exactly what was asked. It should be up to the SMT to determine if the users logs are worthy of discipline, and they can use your information to make up their mind.

 

As others have said, it is not your responsibility to inform people they are being investigated, you are only being asked to provide some information. If you are uncertain about anything contact your union, document everything and make sure you get all requests in writing(email is fine)

  • Thanks 1
Posted
further to tech_guy's repsonse, if it is a criminal investigation then the machine in question should be isolated so noone can touch it until authorised people can investigate it(I think?)
Posted
I had a similar issue here. I spotted the problem and had a word with the individual (probably wrong but wth!) It didn't stop so I told the Dep Head who asked me to have another word! Before this happened the HT got wind of it and asked for logs. I said I felt uncomfortable doing it. He was fine with it and got someone from the LEA in to investigate and advise. I would suggest you ask your HT to do likewise. If for no other reason that it will leave a bad taste if you do it.
  • Thanks 1
Posted

Get the request in writing.

 

Amazing how people get selective memory when the mucky stuff and lawers get involved.

 

If they do loose their job, you can bet someone will be looking for a way to blame others.

 

Don't let them have reason to blame you.

  • Thanks 1
Posted

Treat it in the same way you treat things like CCTV logs.

 

What is the reason the information is required?

What date / time ranges is it required for?

Who will the information be shared with? (unions, the LA, etc)

Once the data is handed over will there be signatures, etc.

Is there a log kept of who looks at this data?

 

There should be satisfactory answers to all of this for you to go ahead. If there are not satisfactory answers then the data may be laughed at should it go to tribunal and you need to remember that you are protecting yourself, the Head and the school.

  • Thanks 1
Posted
further to tech_guy's repsonse, if it is a criminal investigation then the machine in question should be isolated so noone can touch it until authorised people can investigate it(I think?)

 

If thats the case you will also need to document things like:

 

date and time you were asked to remove machine

 

date and time you did remove the machine

 

explain any significant difference between the times eg teacher did not have laptop in school

 

was the machine in use when it was removed?

 

how was it in use?

 

How you isolate the machine is also important. somebody will probably have to sign a police statement documenting its isolation and who could have had access to it. The police will need to be sure the trail of evidence is maintained. so if it is in a safe in the heads office. The key to the safe and the office should not be in the possession of one individual.

  • Thanks 1
Posted
What do I need to know/do on this? Been asked by head to supply access logs etc for preliminary investigation into inappropriate teacher behaviour (it's quite serious and may involve someone losing their job if it's true).

 

We have no policy in place for this sort of thing yet :eek: I can obviously provide logs etc.. but what can I legally do/not do? as depending what info I give them (and it is pretty incriminating) could see someone losing their job..

 

Do they need to know they are being investigated?

 

help :(

 

 

You don't need to tell them they are beeing investigated. It's the job of the HR Department.

 

You are following the instruction of a Senior Manager and you have to do what he is requesting. And like Nephilim and Tom suggest ask for detailed informations (range, time) on what type of logs you have to retrieve

 

Monitoring Staff Behaviour:

The laws relating to monitoring your employees | OUT-LAW.COM

  • Thanks 1
Posted

To everyone who has replied, A1 advise as usual, thanks for the help.

 

Obviously I cant say whats going on, will just have to see what pans out over the next few weeks given the advise :)

Posted
A key thing that I have stuck to is that if I am to do stuff like this, I require a third party to be watching whilst I do it. ie. if the head wants me to get logs, then someone on SMT should be watching whilst I am doing it, so as to show I'm not doing anything bad myself.
  • Thanks 1
  • 3 weeks later...
Posted

As an RBC we keep logs of all internet traffic that goes through our wires, but you have to be very careful when giving logs to people upon request. Unless you have an AUP in place signed by the user that they acknowledge that their internet use will monitored and logged, you could be in breach of one of three acts, the Human Rights Act, the Data protection Act and RIPA. Under guidelines issued by BECTA, if your SMT was asking me to give them the logs in these circumstances without a signed AUP in place, I would have to refuse.

 

Regards,

 

Andrew

  • Thanks 2
Posted

I agree with ayoward on this.

 

According to the Data Protection Act any data related to an individual can only be used for the purpose for which it was originally collected and the individual must have consented to its collection in the first place. You would normally have them sign an AUP to that effect before they got access to the system. Since you don't have prior consent from your users, I don't think you can legally disclose the log data.

 

Most importantly -> "Unauthorized disclosure of personal data attracts personal criminal liability", so be careful.

Posted (edited)

I agree with some points raised here but disagree on others.

It really depends what the basis for the request is.

 

If it is simply becuase the Head suspects he's got loads of music in his home directory, or was logging on to the HT's pc, or for some other kind of flimsy reason, then I would either not give the information, or just give the raw basics that I felt comfortable with.

 

If however, the HT is asking as it is a potential Child Protection issue or other legal issue which is being internally / externally investigated then I would say one thing - co-operate.

This individual might one day be able to turn round and attempt to use data protection laws against you, but there is not a court in the land that would uphold such a case when the actions were supporting the investigation of a higher offence.

Edited by mb2k01
Posted
That may be, but there isn't a decent lawyer in this country who wouldn't make sure the evidence was inadmissable if the Data Protection Act had been breached/hadn't been followed, so the case wouldn't even get to court if that was all you had.
  • Thanks 1
Posted

I'm not sure that I accept the inadmissable evidence scenario....

...but then I work in IT, and am only an observer/semi-geek of Law! :)

Posted

I have been involved in a situation that was difficult.

 

The person involved was caught by students and they reported to us. We knew the person involved very well too. The students ended up telling a member of SLT before we could which sort of saved the agro.

 

What you may want to do as has been mentioned is to keep a log of what you did when and what you presented. It could be in 6 months time you are asked about this and need to refresh your memory.

Posted

What you have to remember is a court of law upholds the law. It is not interested in what is just or fair or even the right result. It is there to enforce the law as is written, or use precedent to determine the appropriate legal result.

 

If you breach the Data Protection act, you are in breech of the law of the land. Your reasons for doing it may be taken into account at the sentencing stage, but are unlikely to offer you much protection from having the case brought against you in the first place.

 

If in doubt, don't take the risk.

Posted
What you have to remember is a court of law upholds the law. It is not interested in what is just or fair or even the right result. It is there to enforce the law as is written, or use precedent to determine the appropriate legal result.

 

If you breach the Data Protection act, you are in breech of the law of the land. Your reasons for doing it may be taken into account at the sentencing stage, but are unlikely to offer you much protection from having the case brought against you in the first place.

 

If in doubt, don't take the risk.

 

You'll find that the law is written with protections in many cases. Various defence clauses to be taken into account. This is done before the sentencing stage. It should be taken into account when the case is passed to the CPS, and then if it still ends up in court, it should be presented as an argument to the court by your legal representative.

 

Also, a court upholds the law, but in some circumstances it can get back to Hansard, and look at what the law was *intended* to do - not just how it is written - but this requires for some aspect of ambiguity to exist, and lower courts will not often allow it.

 

Also, remember that the courts are required to balance the laws of the UK with the provisions of the Human Rights Act. And if the latter overrides the prior, they can (although it is very rare, if it has been done at all yet), declare the law to be incorrect. It is also a case of balance. Do the rights on one side outweigh the rights on the other (hence the measuring balances on Lady Justice).

 

So, it can be there to uphold what is just, right and fair. It is just very rare...

 

If in doubt, refer it to your managers. If they try to get you to do something you feel uncomfortable with speak to your union legal bods. They will be useful for this sort of thing.

Posted (edited)

Legal defences, to my knowledge, do not include "because I thought it was the right thing to do". You are much better to seek advice.

 

As localzuk rightly says, just be wary of doing anything without clearing it with your manager and legally qualified people with experience in data protection laws. Get any and all advice given to yout in writing as it can often be difficult to prove anything said orally.

 

The Human Rights Act is one of the laws you are actually trying to breach by disclosing the data.

 

As a general rule, regarding anything data related, seek legal advice first. You could ask your manager but without going to someone who knows the law on this area, you are potentially risking a legal case against you.

 

I might have a law degree, but I would be reluctant to make any decisions on what to do, as it is quite possible the law has changed since I studied it!

 

I would advise against following any advice given on internet forums regarding the law, unless the person giving the advice is a practicing solicitor or barrister. You are always best to seek legal advice.

Edited by mwalpole

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...