Jump to content

Recommended Posts

Posted
We are expected to use a personal e-mail address for school business. I have set up a separate gmail address for school use, but am uncomfortable using a non-official email address for school business. Despite repeated requests for school email addresses to be set up, I can’t convince management that this is necessary. Does the new legislation make it legally unacceptable?
Posted
Technically no but in practice very likely yes. You have no way to set up the controls and protections that are really needed to safeguard personal data being dealt with via email, no way to audit your staff to check their compliance with your policies. I would open a new discussion with management that says they're almost certain to have liabilities down the line arise from this. Check the ICO's "Actions we've taken" pages for fines to schools; they're almost exclusively for messing up personal data via email; without a managed system you're going to be blindsided by that at some point, it's practically certain.
  • Thanks 1
Posted
We are expected to use a personal e-mail address for school business. I have set up a separate gmail address for school use, but am uncomfortable using a non-official email address for school business. Despite repeated requests for school email addresses to be set up, I can’t convince management that this is necessary. Does the new legislation make it legally unacceptable?

 

Not sure if it makes it legally unacceptable but there is a whole host of moral issues there.

 

Do teachers contact students with their personal email?

Posted
Not sure if it makes it legally unacceptable but there is a whole host of moral issues there.

 

Do teachers contact students with their personal email?

This might be something. We have a lot of peri music teachers that come in to teach students specific instruments. All these peri music teachers have to have a school email address to be able to email their students. This way we can monitor/audit it.

 

A few of the peris are annoyed that we do this and say other schools don't do it but I think it's something that is needed to be done so we have a trail of communication.

Posted

I'm sure this isn't correct way of doing it at all. We are told that it's recommended to use school email for all related emails to the school. Not to use personal ones to store work etc. We are even setting up the Governors to use school email.

 

If there is a breach or sensitive information sent around and that data is on a 'personal' email account.......... Sorry but I consider this a 'risk' and although not punishable... unless there is a breach because it's on personal email and not a work one.

Posted
If they won't listen, force the issue. Close the account because you are receiving unwanted emails. Open new one, cause inconvenience. . Much better demonstration of why this is a terrible idea than a CP breach.
Posted

And breathe and relax ...

 

1) by using a system not under the control of the school, the school would not be able to control what happens with personal data that goes to it. Whilst ICO will explain that it is the school’s decision ... this is on the understanding that a true risk assessment is taken and recorded ... and this would clearly by very high risk ... and hard to show compliance.

 

2) safeguarding wise ... stop!!!! Protect yourself from possible allegations. This is not where you want to be.

 

I think most people have covered off the issues you face but I would echo @elsiegee40 that this would raise significant safeguarding concerns should Ofsted ask ... raise to your DSL, and the relevant governor working with DSL.

  • Thanks 3
Posted

Why is the school objecting so much to this?

 

Office 365 is free for education use. I know of a lot of schools (mostly secondary however) who have official email accounts for pupils, staff and governors.

 

I do think there is an issue with Data Protection here, if not, it's a very grey area to be in it.

 

I personally think Ofsted would have a field day with this should it come to their attention during a visit. This is since the school doesn't have control of the data and it cannot be monitored. Both of which can lead to a whole host of issues. Let's say a teacher and pupil have been messaging inappropriately, it cannot be monitored easily. But if it is all kept "in-house" it could easily be reviewed. In addition to this, you have the issue with spam emails (you would have to implement individual rules on each account to block a domain etc).

Posted
Is this a thread bump from 1998, or is your school seriously that much out of touch? DP is one thing, bit safeguarding and PREVENT are quite another - this needs to be dealt with and soon.
  • Thanks 3
Posted

Just a snippet from the ICO guidance re FoI requests and work use of private email addresses

 

"In order to avoid the complications of requesting searches of private

email accounts, and other private media, records management

policies should make clear that information on authority-related

business should be recorded on the authority’s record keeping

systems in so far as reasonably practicable.

 

It is accepted, that in certain circumstances, it may be necessary to

use private email for public authority business. There should be a

policy which clearly states that in such cases an authority email

address must be copied in to ensure the completeness of the

authority’s records. In this way, records management policies will

make it easier for public authorities to determine whether

information is held and to locate and retrieve it in response to

requests. If the information is contained within the public

authority’s systems it can also be subject to consistently applied

retention and destruction policies. "

 

https://ico.org.uk/media/for-organisations/documents/1147/official_information_held_in_private_email_accounts.pdf

  • Thanks 1
Posted
I agree with all of the above. Most of it is advice for the school (for you to pass on). In terms of what you need to do, I would refuse point blank to use personal email for any school business. That's to protect you, not the school.
Posted

Just wondering how you make sure a teacher does not have school related data when they leave. Imagine what data someone like the deputy head or office staff could have in their emails.

 

All my schools also insist that the governors use school supplied accounts.

Posted
Just wondering how you make sure a teacher does not have school related data when they leave. Imagine what data someone like the deputy head or office staff could have in their emails.

.

There’s a thread on that topic in this forum somewhere.

 

And I agree OP has a real problem with people holding onto data after they leave.

Posted
I agree with what everyone else says here but at the same time imagine someone moaning their email is broken and just shrugging and saying "speak to google".
Posted
I agree with what everyone else says here but at the same time imagine someone moaning their email is broken and just shrugging and saying "speak to google".

 

Fortunately gmail doesn’t break very often. We used it at my last school without incident. Many schools do. Same goes for office 365

Posted
Just wondering how you make sure a teacher does not have school related data when they leave. Imagine what data someone like the deputy head or office staff could have in their emails.

 

Exactly the point I made yesterday to an ex-staff member who now works for an organisation providing 1:1 support to some of our students. They need the data now but they don't need it when the child finishes their exams in a few months. A school-controlled email address is the only way you ensure this.

Posted

Wow, @jenhet, I wonder how many other schools are in the same position?

 

Your job there sounds doubly difficult and I'm left wondering if they have allowed you to advance from Server NT and Windows XP yet as well!!

 

Seriously there are, as ever, many fabulous answers here that point us all in the right direction. Reading through them I'm left wondering about a chink I see in my own school's GDPR armour; that being Governor's email. When the fabulous Andy Ratcliffe set up our O365 in 2014 we added all Governors and the Clerk as addresses and duly let them know they had the addresses but to date, they have steadfastly refused to use them.

Posted (edited)
Reading through them I'm left wondering about a chink I see in my own school's GDPR armour; that being Governor's email.

 

Your school may be different, but when I raised that very question with the HT, she said the Governors don't need school email addresses because the only information they receive over email is public record. Anything sensitive is handled verbally in the meetings. The Chair of Governors has a school address, that's it.

Edited by enjay
  • Thanks 1
Posted
All our governors have a school email address with 2 Factor authentication setup (as well as all our staff).
  • Thanks 1
Posted

That makes a lot of sense. Out of curiosity, how did you manage to win that particular argument?

 

I've got a couple of staff who can't even manage complicated passwords! :rolleyes:

 

All our governors have a school email address with 2 Factor authentication setup (as well as all our staff).
Posted

Governors, as I have said before, shouldn’t be dealing with identifiable personal information. They work at a strategic level and should never be working with data for an individual,

Thus, while there may be a confidentiality problem, there is no DPA/GDPR risk.

 

The exception is those that serve on Behaviour (Exclusion) Panels and Staff Disciplinary Panels. In most schools these are, mercifully, few and far between and the vast quantity of paperwork is usually a photocopied file. It’s far too big to email.

 

The third case is those on a pay committee and, again, it’s relatively straightforward to sort this out without school emails for governors.

 

We have secure logins via the school website to get all governor ‘paperwork’. We do not have school emails. What’s emailed does not include sensitive data.

 

You cannot escape governors processing electronic data on home computers and your governor terms need to address how governors dispose of both electronic and paper data they receive from the school.

  • Thanks 1
Posted
That makes a lot of sense. Out of curiosity, how did you manage to win that particular argument?

 

I've got a couple of staff who can't even manage complicated passwords! :rolleyes:

 

We had a small data breach (not IT related I'll add!) so we can win most arguments when it comes to security and locking things down. Luckily, all our teaching staff have 1:1 iPads so we can use the Google Authenticator app as 2 factor. Requires a phone number to setup initially but after that they can use the authenticator app.

 

We're even thinking about doing students now as they have 1:1 iPads also. Not sure if this'll work though.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...