jenhet Posted March 1, 2018 Posted March 1, 2018 We are expected to use a personal e-mail address for school business. I have set up a separate gmail address for school use, but am uncomfortable using a non-official email address for school business. Despite repeated requests for school email addresses to be set up, I can’t convince management that this is necessary. Does the new legislation make it legally unacceptable?
djrscally Posted March 1, 2018 Posted March 1, 2018 Technically no but in practice very likely yes. You have no way to set up the controls and protections that are really needed to safeguard personal data being dealt with via email, no way to audit your staff to check their compliance with your policies. I would open a new discussion with management that says they're almost certain to have liabilities down the line arise from this. Check the ICO's "Actions we've taken" pages for fines to schools; they're almost exclusively for messing up personal data via email; without a managed system you're going to be blindsided by that at some point, it's practically certain. 1
hardtailstar Posted March 1, 2018 Posted March 1, 2018 We are expected to use a personal e-mail address for school business. I have set up a separate gmail address for school use, but am uncomfortable using a non-official email address for school business. Despite repeated requests for school email addresses to be set up, I can’t convince management that this is necessary. Does the new legislation make it legally unacceptable? Not sure if it makes it legally unacceptable but there is a whole host of moral issues there. Do teachers contact students with their personal email?
RLR Posted March 1, 2018 Posted March 1, 2018 Not sure if it makes it legally unacceptable but there is a whole host of moral issues there. Do teachers contact students with their personal email? This might be something. We have a lot of peri music teachers that come in to teach students specific instruments. All these peri music teachers have to have a school email address to be able to email their students. This way we can monitor/audit it. A few of the peris are annoyed that we do this and say other schools don't do it but I think it's something that is needed to be done so we have a trail of communication.
mthomas08 Posted March 1, 2018 Posted March 1, 2018 I'm sure this isn't correct way of doing it at all. We are told that it's recommended to use school email for all related emails to the school. Not to use personal ones to store work etc. We are even setting up the Governors to use school email. If there is a breach or sensitive information sent around and that data is on a 'personal' email account.......... Sorry but I consider this a 'risk' and although not punishable... unless there is a breach because it's on personal email and not a work one.
Popular Post elsiegee40 Posted March 1, 2018 Popular Post Posted March 1, 2018 As @GrumbleDook will no doubt say Noooooooooooooooooooo!!!!!!!!!!!!! Office 365 and Gmail are available free for schools there is no excuse! How can you comply with current Data Protection and Safeguarding law if everyone is using their private accounts, let alone GDPR?! Your school MUST maintain control of its data. It MUST be able to defend itself if there is a Safeguarding incident. You cannot do either with private emails. Who knows where personal information is being stored and ends up? How can you tell who said what to whom if you’re using private email? I’d say this school needs to go straight into Special Measures 7
strawberry Posted March 1, 2018 Posted March 1, 2018 If they won't listen, force the issue. Close the account because you are receiving unwanted emails. Open new one, cause inconvenience. . Much better demonstration of why this is a terrible idea than a CP breach.
GrumbleDook Posted March 1, 2018 Posted March 1, 2018 And breathe and relax ... 1) by using a system not under the control of the school, the school would not be able to control what happens with personal data that goes to it. Whilst ICO will explain that it is the school’s decision ... this is on the understanding that a true risk assessment is taken and recorded ... and this would clearly by very high risk ... and hard to show compliance. 2) safeguarding wise ... stop!!!! Protect yourself from possible allegations. This is not where you want to be. I think most people have covered off the issues you face but I would echo @elsiegee40 that this would raise significant safeguarding concerns should Ofsted ask ... raise to your DSL, and the relevant governor working with DSL. 3
fiza Posted March 1, 2018 Posted March 1, 2018 Which School in this day doesn't have an official email system? How do parents email the School if they need to?
SchoolFibre_Paul Posted March 1, 2018 Posted March 1, 2018 Why is the school objecting so much to this? Office 365 is free for education use. I know of a lot of schools (mostly secondary however) who have official email accounts for pupils, staff and governors. I do think there is an issue with Data Protection here, if not, it's a very grey area to be in it. I personally think Ofsted would have a field day with this should it come to their attention during a visit. This is since the school doesn't have control of the data and it cannot be monitored. Both of which can lead to a whole host of issues. Let's say a teacher and pupil have been messaging inappropriately, it cannot be monitored easily. But if it is all kept "in-house" it could easily be reviewed. In addition to this, you have the issue with spam emails (you would have to implement individual rules on each account to block a domain etc).
3s-gtech Posted March 1, 2018 Posted March 1, 2018 Is this a thread bump from 1998, or is your school seriously that much out of touch? DP is one thing, bit safeguarding and PREVENT are quite another - this needs to be dealt with and soon. 3
LeMarchand Posted March 1, 2018 Posted March 1, 2018 If nothing else, some official bodies will only send mail to certain accounts. Our local child protection team recently told us that they would only send to [email protected]er and not head'[email protected]. (They initially said it had to be @school.sch.uk, but backtracked).
jdoyle Posted March 1, 2018 Posted March 1, 2018 Just a snippet from the ICO guidance re FoI requests and work use of private email addresses "In order to avoid the complications of requesting searches of private email accounts, and other private media, records management policies should make clear that information on authority-related business should be recorded on the authority’s record keeping systems in so far as reasonably practicable. It is accepted, that in certain circumstances, it may be necessary to use private email for public authority business. There should be a policy which clearly states that in such cases an authority email address must be copied in to ensure the completeness of the authority’s records. In this way, records management policies will make it easier for public authorities to determine whether information is held and to locate and retrieve it in response to requests. If the information is contained within the public authority’s systems it can also be subject to consistently applied retention and destruction policies. " https://ico.org.uk/media/for-organisations/documents/1147/official_information_held_in_private_email_accounts.pdf 1
jmak Posted March 1, 2018 Posted March 1, 2018 I agree with all of the above. Most of it is advice for the school (for you to pass on). In terms of what you need to do, I would refuse point blank to use personal email for any school business. That's to protect you, not the school.
TwistedHelixis Posted March 1, 2018 Posted March 1, 2018 Just wondering how you make sure a teacher does not have school related data when they leave. Imagine what data someone like the deputy head or office staff could have in their emails. All my schools also insist that the governors use school supplied accounts.
elsiegee40 Posted March 1, 2018 Posted March 1, 2018 Just wondering how you make sure a teacher does not have school related data when they leave. Imagine what data someone like the deputy head or office staff could have in their emails. . There’s a thread on that topic in this forum somewhere. And I agree OP has a real problem with people holding onto data after they leave.
RobD Posted March 1, 2018 Posted March 1, 2018 I agree with what everyone else says here but at the same time imagine someone moaning their email is broken and just shrugging and saying "speak to google".
elsiegee40 Posted March 1, 2018 Posted March 1, 2018 I agree with what everyone else says here but at the same time imagine someone moaning their email is broken and just shrugging and saying "speak to google". Fortunately gmail doesn’t break very often. We used it at my last school without incident. Many schools do. Same goes for office 365
enjay Posted March 2, 2018 Posted March 2, 2018 Just wondering how you make sure a teacher does not have school related data when they leave. Imagine what data someone like the deputy head or office staff could have in their emails. Exactly the point I made yesterday to an ex-staff member who now works for an organisation providing 1:1 support to some of our students. They need the data now but they don't need it when the child finishes their exams in a few months. A school-controlled email address is the only way you ensure this.
speckytecky Posted March 2, 2018 Posted March 2, 2018 Wow, @jenhet, I wonder how many other schools are in the same position? Your job there sounds doubly difficult and I'm left wondering if they have allowed you to advance from Server NT and Windows XP yet as well!! Seriously there are, as ever, many fabulous answers here that point us all in the right direction. Reading through them I'm left wondering about a chink I see in my own school's GDPR armour; that being Governor's email. When the fabulous Andy Ratcliffe set up our O365 in 2014 we added all Governors and the Clerk as addresses and duly let them know they had the addresses but to date, they have steadfastly refused to use them.
enjay Posted March 2, 2018 Posted March 2, 2018 (edited) Reading through them I'm left wondering about a chink I see in my own school's GDPR armour; that being Governor's email. Your school may be different, but when I raised that very question with the HT, she said the Governors don't need school email addresses because the only information they receive over email is public record. Anything sensitive is handled verbally in the meetings. The Chair of Governors has a school address, that's it. Edited March 2, 2018 by enjay 1
RLR Posted March 2, 2018 Posted March 2, 2018 All our governors have a school email address with 2 Factor authentication setup (as well as all our staff). 1
speckytecky Posted March 2, 2018 Posted March 2, 2018 That makes a lot of sense. Out of curiosity, how did you manage to win that particular argument? I've got a couple of staff who can't even manage complicated passwords! All our governors have a school email address with 2 Factor authentication setup (as well as all our staff).
elsiegee40 Posted March 2, 2018 Posted March 2, 2018 Governors, as I have said before, shouldn’t be dealing with identifiable personal information. They work at a strategic level and should never be working with data for an individual, Thus, while there may be a confidentiality problem, there is no DPA/GDPR risk. The exception is those that serve on Behaviour (Exclusion) Panels and Staff Disciplinary Panels. In most schools these are, mercifully, few and far between and the vast quantity of paperwork is usually a photocopied file. It’s far too big to email. The third case is those on a pay committee and, again, it’s relatively straightforward to sort this out without school emails for governors. We have secure logins via the school website to get all governor ‘paperwork’. We do not have school emails. What’s emailed does not include sensitive data. You cannot escape governors processing electronic data on home computers and your governor terms need to address how governors dispose of both electronic and paper data they receive from the school. 1
RLR Posted March 2, 2018 Posted March 2, 2018 That makes a lot of sense. Out of curiosity, how did you manage to win that particular argument? I've got a couple of staff who can't even manage complicated passwords! We had a small data breach (not IT related I'll add!) so we can win most arguments when it comes to security and locking things down. Luckily, all our teaching staff have 1:1 iPads so we can use the Google Authenticator app as 2 factor. Requires a phone number to setup initially but after that they can use the authenticator app. We're even thinking about doing students now as they have 1:1 iPads also. Not sure if this'll work though.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now