Jump to content

Recommended Posts

Posted

We are currently looking to retain an external support company on a contract to provide technical support when the in-school technician is not available.

 

The salesman of our preferred company said that they will store admin credentials to the system or not as requested by the school. I think for the support to be effective we need them to have that access. He said they did not normally have anything formal in a contract about confidentiality of school data, but that this could be arranged.

 

It seems to me that to meet our obligations to protect pupil data, I ought to be looking to have them agree to something like our AUP for staff, but a bit more tailored: putting the obligation on them not to remove school data from our network or look at anything not required to perform their job. Do other schools using external support do something like this? Does anyone have a model for such an agreement I can refer to (or borrow if necessary)?

Posted

It very much how you intend to use this company. They obviously need some sort of admin credentials (unique to them... not access to any of your logins) , but whether you let them have that and disable the login when they don't have access... or whether you only let them have the password under a "sealed in the safe" scenario depends on how frequently they need access. If you're talking about covering for a tech on holiday or off sick then the password and login setup will probably be different to if you're getting them to provide cover on days when a part-timer isn't working, for example.

 

The contract does need to have some sort of data confidentiality clause in it... but going as far as making individuals sign AUPs seems a little pointless. It is a company that you are employing, the employees may change; it is the company's responsibility to maintain things in line with the Service Level Agreement set out in the contract. Unless you have experience of drawing up this kind of contract, I would strongly advise that the contract is dealt with by someone who has this experience like the school business manager and that that person takes legal advice.

 

@GrumbleDook may be able to offer more advice

  • Thanks 1
Posted
I ought to be looking to have them agree to something like our AUP for staff, but a bit more tailored: putting the obligation on them not to remove school data from our network or look at anything not required to perform their job.

 

"Something like an AUP" but for a business - So a contract, then? Does their contract with you for this support not specify something of this kind? If not, the obvious answer is to amend it so it does.

Posted

Ok ... this is where you get a person with legal credentials to deal with it because of the following

 

1) Any 3rd party who may have the same permission / ability to process your data as that held by your schools staff need to be treated as if they are *at least* school staff, and have a corresponding contract.

 

2) Their data protection obligations *have* to be, at least, as high as yours when it comes to processing data. It may be that it has to be higher (i.e. they take even more technical or organisational controls to cover this than you do.)

 

3) Any contract where you are giving a company access to your systems (which means they have access to your data) *has* to have a section about data processing and data protection.

 

4) If an external party is a sub-contractor (which they effectively are) then you are sharing data with an outside source and this should be included in your Privacy Notice (the replacement for the Fair Processing Notice).

 

At this point, go and talk to your LA legal and finance teams who will help you out with this. If you are no longer part of an LA (or never where) then you need to go to whoever your school gets legal and contractual advice from.

 

The above points should be a starting point for questions you want to ask the company involved.

 

If you *really* want to have a think about it ... go and have a look at how things like this are dealt with in your MIS contract ... it is usually covered *extremely* well ... and should give you an idea about how complex and legal it can be.

  • Thanks 4
Posted (edited)

Thank you, Grumbledook that is a really helpful starting point. I will ask whether we can talk to our legal advisers on this.

 

Since making my original post, I have now received their actually contract text. It does include a section saying they will not "remove or copy" any of our data off-site without our permission and that it will be encrypted (according to specified standards) and securely erased afterwards if they do. It is brief.

Edited by Jollity

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...