Jump to content

Recommended Posts

Posted

So we've recently starting moving all of the staff/student accounts across the academy to a new email domain - all three schools using the same domain, and sharing one big massive address book.

 

I'm curious, from a DPA standpoint, if this is ok?

 

I know none of my vendors (I'm data manager) will allow me access to the lower school's data, citing DPA (something we're looking at fixing by assigning an academy level data manager - hopefully me).

 

but is there any issue with email addys?

Posted

How are you guys linked?

 

Only my opinion, but surely you're either a trusted link e.g. Can share emails/data etc, or you aren't linked that well then no-one should have access to manage your email accounts (As in surely there's one bod overall managing the emails etc?) Or are you still using individual email systems just one domain?

 

Steve

  • Thanks 1
Posted

It's all office365 - one domain, three seperate schools - we all still have our own networks, databases, etc - we're looking at linking all three sites together, but the current plan is to hire one top network guy, one top data guy, and then work from there getting the three sites actually linked - and two guys managing the emails - one for the lower two schools, one for the upper

 

To be honest, I don't personally see an issue with it, but I was asked by someone, and figured I'd ask you all here, as you'd be more likely to know the answer. Personally, the only issue I'll have with it is all the similar names we have across the three schools, and knowing I'm emailing the right person (staff or students to be honest)

Posted

So Mr IT in one school can forward all other emails to themselves anyway :p (Currently I mean) would say that's a pretty huge DPA issue unless they're all under one management etc which then I can't see the data being a problem either.

 

Steve

Posted
So Mr IT in one school can forward all other emails to themselves anyway :p (Currently I mean) would say that's a pretty huge DPA issue unless they're all under one management etc which then I can't see the data being a problem either.

 

Steve

I'm confused about what the actual issue is here. Is the issue that somebody/a group of people could potentially access mailbox data for all three schools? Or, is the issue that other schools can see pupils and staff names in the address book? If so, you could tidy that up I imagine by using address book policies?

  • Thanks 1
Posted
I'm confused about what the actual issue is here. Is the issue that somebody/a group of people could potentially access mailbox data for all three schools? Or, is the issue that other schools can see pupils and staff names in the address book? If so, you could tidy that up I imagine by using address book policies?

 

If it's one email domain under O365 but used by three schools, surely one has access to control/view/read/etc others emails? Or is there a way of doing that in O365 with 1 domain being used for 3 seperate accounts.

 

Steve

Posted

To be honest it depends on the structure of the trust.

 

If you are a single trust with Academies that operate within that trust and adhere to a central entry in the ICO registrar, then the test under the DP principles will be based around whether there is a need to use the data.

 

If there are collaborations between the schools, at staff and learner level, then the data is being processes appropriately but it should be reviewed on a regular basis.

 

If you are a Multi-Academy trust where you are individual entities who operate collectively, then there are more hoops to jump through and then yes, the introduction of central staff to deal with certain things is correct.

 

Of course, if in doubt then the ICO helpline can provide advice on this.

 

There are ways of locking down O365 to prevent the address book and people picker seeing as much, or publicising they can see as much ... and then you have transport rules to control who can send emails to the various accounts ... a lot of configuration but doable.

  • Thanks 1
Posted

Thanks

 

I talked to our NM last night, and apparently he did the setup, and has handed over the responsibility to the lower schools' NM, which makes sense, as our NM leaves at the end of the year.

 

We are three entities with ICO (I looked at our ICO records last year to make sure we were reporting everything we used), I'll suggest to our NM today that maybe we can use the rules you mention above for the time being to limit who sees what in the address book, and then when we move to a central system, review it then.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...