Marshall_IT Posted June 14, 2013 Posted June 14, 2013 Hi, A quick plea for any guidance BECTA NAACE etc... I have been asked to allow someone from another school remote access to our MIS system to allow them to prepare some training for our staff.
BKGarry Posted June 14, 2013 Posted June 14, 2013 I would ask the Head to sign off on it, with a clear outline of the risks that could be involved and the DPA, and also get the other person to sign off about the information and the username and passwords and make sure they are shut down totally after a certain period. Ultimately the Head and Governors are responsible for anything under the data protection act
fiza Posted June 14, 2013 Posted June 14, 2013 Why do they need access to live data? Could you not set up a dummy database? We have done this for training purposes before.
Marshall_IT Posted June 14, 2013 Author Posted June 14, 2013 Thanks guys, I don't think a dummy database will do as this training is to be tailored to our exact requirements. What i'm thinking of doing is getting the person to sign our AUP for remote access and asking for their eCRB. Oh and obviously getting it signed off by the head.
Marci Posted June 14, 2013 Posted June 14, 2013 (edited) You MUST notify your Data Protections Officer. If they deem it a no-no then that's it, end of story. You're exposing sensitive private data to someone outside of the bounds of control of your company / school. If you do so without formally getting approval of your DPO, then your job is on the line for neglect of duty. A written contract will be required stating explicitly how they may use the data. Whoever it is that you're granting access to must also be registered with the ICO as a Data Controller. Edited June 14, 2013 by Marci
rpwillis Posted June 14, 2013 Posted June 14, 2013 What i'm thinking of doing is getting the person to sign our AUP for remote access and asking for their eCRB. Oh and obviously getting it signed off by the head. They may not have enchanced disclosure. You can only get an enhanced disclosure if you physically work with children on a weekly basis. And I think that it needs to be the same location as well. If you have access to all pupils information electronically, but don't physically work with them then you are not eligible for an enhanced disclosure.
plexer Posted June 14, 2013 Posted June 14, 2013 Whoever it is that you're granting access to must also be registered with the ICO as a Data Controller. Why? Ben
Marci Posted June 14, 2013 Posted June 14, 2013 (edited) Hmmm... thinking about it, no he probably wouldn't as his employer (the school) would be registered already as long as the training was booked with his employer rather than him as an independant, but as far as I understand it anyone handling / processing personal data has to be registered with the ICO. eg: If he was going to perform an analysis of the data contained in the MIS in order to tweak training to suit, that would constitute processing by a 3rd party. Edited June 14, 2013 by Marci
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now