Jump to content

Recommended Posts

Posted

What do you do/think? Governors communicate with school usually by e-mail, this would be done in most cases over an un-encrypted mail service from an insecure private workstation. They are discussing some of the most delicate matters about school!

I am tempted to say they should have a school supplied laptop and mail service.

Posted

Probably!

Ours have a school email address, but they choose not to use it and so use their own. Bottom line is, as long as IT makes the school aware of the potential risks, it's up to the school to enforce it, or not.

Posted
That still leaves info on an un encrypted workstation. We are duty bound by the data protection act this would come straight back at you, wouldn’t it?
Posted

I think most schools approach to Data Protection is 'We'll worry about it when the ICO slaps us with a fine'.

 

I can't remember the exact details but I know some schools and local authorities were fined in the recent past. I find the problem is that we as IT professionals are responsible, but actually getting users - whether they're SLT, staff or even governors - to adhere to the rules is next to impossible.

 

We've got people who take sensitive data home on usb sticks, copy documents to personal devices etc etc. And that's aside from staff who leave themselves logged on to multiple machines on site, potentially allowing pupils access to staff/school data. All-in-all, not good really.

Posted
Pass what you've seen onto your Head Teacher and whoever your Data Protection Officer is on site. Failing that, does your LA have a Data Protection Officer?

 

That would certainly be the professional thing to do... but without going into detail, that course of action wouldn't work here. I don't believe our LA has a DP officer as such.

Posted
Doesn't matter if they exist or not, someone in the organisation is the Data Protection Officer if they want it or not. This is the person responsible for enforcing and creating the DPA guidelines in the school and most likely falls with the Head if all else fails. Remind him that DPA fines are also issued to offenders and those responsible personally, not just to the school. :)
Posted
I can't remember the exact details but I know some schools and local authorities were fined in the recent past. I find the problem is that we as IT professionals are responsible, but actually getting users - whether they're SLT, staff or even governors - to adhere to the rules is next to impossible.

Some LAs and councils have been fined, but to date, I don't believe there has been a single publicised case of a school being fined. As much as I hate to wish that on someone, until it happens we will all be facing an uphill struggle.

 

Whoever is the DP officer will be the fall guy if you are caught out. Schools are required by law to register individually, you can't just leave it to the LA, so legal buck-passing is out of the question.

Posted
Ok what about skydrive encrypted up and down but again device lets it down because if device stolen etc access to mail means access to skydrive account. Nominated person should be SLT position and have training but again real world - Do you even have a nominated DP person?
Posted
What do you do/think? Governors communicate with school usually by e-mail, this would be done in most cases over an un-encrypted mail service from an insecure private workstation. They are discussing some of the most delicate matters about school!

I am tempted to say they should have a school supplied laptop and mail service.

 

What e-mail service are they using? All of the popular e-mail providers secure their pages with SSL, unless you mean it's an internally hosted e-mail solution by the LA and there's no encryption whatsoever? I'd be more worried about users entering their e-mail and password without encryption onto a webpage.

 

Admittedly even e-mails sent from pages secured with SSL could be read in theory. E-mail isn't a secure form of communication and probably never will be!

Posted
All Governor’s use whatever they like (I wonder if it’s a shared family one ). The only way I can think of is to give them a laptop with encrypted drive and no access to USB etc. Plus a school e-mail account with only SSL access.
Posted
I would if could say that the information is private but on bound by the DPA as it should not contain personnel data as it policy that the governors are working on.
Posted (edited)

* Clears throat *

 

I have been a school governor for several years and am currently chair, so I have particular interest in this... especially with my eSafety hat on.

 

Governors do deal with confidential information, but the majority of what we do is in the public domain. Virtually everything can be requested under FoI if not already on the website. Governing body paperwork is sent out by snail mail or email and rarely contains information that would breach the DPA. Statistics, for example, are anonymised. We should not know the performance of individual students or staff members for example.

 

Every governor has reams of paperwork at home which, if left lying around, could embarrass the school. The email side of it is probably more secure than the paper.

 

That said, I am in the process of getting our GB into the school's Google Apps, so that we can use Google Drive to store the paperwork rather than have Gigabytes of stuff clogging up our email accounts. The sharing and collaboration ofered by this will make life much easier... and hopefully more secure too.

Edited by elsiegee40
Posted
So what you are saying is governors do not deal with information that ICO would see as being part of the DPA?

 

I can only speak for my GB, but personally sensistive data is not part of the Governor remit.

 

In the last few years, I have been part of exclusion panels, interview panels, redundancy panels and an employment appeal panel. In all cases the paperwork was either brought to my home by the clerk, or I collected it from school.

 

Raiseonline data, league table information, general information on levels of progress made by groups of students may embarrass the school if leaked, but it is not subject to the DPA.

Posted
I am also a governor most of the content is as @elsiegee40 says public domain, minutes are posted on the website etc. We use School Leadership Systems which acts as a virtual office so documents are stored on there, I personally try not to print or carry out any paperwork from meetings as I like everything to be digital. Stuff that does get emailed as far as I am aware is not massively sensitive. Governors have recently requested school email addresses we use Office 365 so I am guessing they may start using our email system which I am fine with. All of them have signed or will be signing our AUP which includes items about data protection. I guess it depends on how your governing body operate.
Posted
I like the sound of Googles 2 step sign on. I have never used 365 does this have similar? But if it’s on your device and that is not encrypted then still against ico advice. Oh yes I spent many years as a governor. Just love the punishment.
  • 1 month later...
Posted

*inserts my 2p*

 

If everything GB are writing is accessible through a FOI request, then that means they have to surrender their personal email accounts for data trawling surely?

 

Im pretty sure if gov knew this they would quickly start using official school supplied accounts.....

Posted
*inserts my 2p*

 

If everything GB are writing is accessible through a FOI request, then that means they have to surrender their personal email accounts for data trawling surely?

 

Im pretty sure if gov knew this they would quickly start using official school supplied accounts.....

 

No. We don't have to surrender our personal email accounts for FoI. The Gb has to provide the information requested... that is not the same thing at all. A member of the public can't simply ask to see everything in a Governor's inbox betweeen certain dates. They could request specific information which might include email content, but that doesn't require us to hand over our accounts.

Posted

All of our Governors have exchange based school email accounts and have had for years. They're told to use them and mostly do, especially as the school will only send to that address. However, lots of them use mail clients like Gmail and outlook/outlook.com and have unified inboxes which leaves us not much further forward than personal email accounts. Plenty also download to their phone - if set up properly, that's fine, because when they set up the hosted exchange system enforces a remote wipe capability as part of it. I have suspicions that some use work arounds too, such as forwarding from mail clients - they can't set up forwarding rules in the hosted exchange. It was reported to me that at the last FGB meeting when they were talking about storing documents a governor said "I could just share them with you - I've got them all on Dropbox anyway". :suicide:

 

I've had words and data security is an agenda item at the next meeting...

 

Having said all that, I think it is worth mentioning that we need to make it easy and straightforward for Governors to be contacted and for them to receive all the documents they need to perform their role. Lots of our Governors can't access webmail at work and don't necessarily log onto a PC every night when they get home. We can't just shout about DP without providing a workable solution.

Posted
I can only speak for my GB, but personally sensistive data is not part of the Governor remit.

 

In the last few years, I have been part of exclusion panels, interview panels, redundancy panels and an employment appeal panel. In all cases the paperwork was either brought to my home by the clerk, or I collected it from school.

 

Raiseonline data, league table information, general information on levels of progress made by groups of students may embarrass the school if leaked, but it is not subject to the DPA.

 

Almost all of what we send is not subject to DPA, but quite a lot is sensitive and I would venture that some comments and individual opinions are definitely tempered through the drafting process and are edited before a publishable version is reached.

 

Should this be in General Chat?
Probably not any more - sorry, partly my fault.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...