Jump to content

Recommended Posts

Posted

Hi all,

 

Just after a bit of advice.

 

In previous years new staff have been given usernames and passwords for their accounts on a new staff induction day, normally in the July before they start in the September.

 

I’m a little cautious about providing access, not provided it at previous schools until the first day of their contract. Reason for being cautious is that I don’t believe they should have any access to anything school related until they officially start. With the GDPR I especially don’t think they should get access to anything that may contain personal data until they actually start working for us.

 

I do appreciate that this makes it difficult for new starters to do lesson plans, seating plans etc.

 

I’d appreciate any thoughts on this.

 

Thanks

 

Iain

Posted
You can let them on the system, but you could take them out of any necessary permissions groups beforehand, not put them in any SIMS or other MIS templates, and not add them to any mailing groups. They'll still be able to start working in their own home area though.
  • Thanks 1
Posted
You can let them on the system, but you could take them out of any necessary permissions groups beforehand, not put them in any SIMS or other MIS templates, and not add them to any mailing groups. They'll still be able to start working in their own home area though.

 

Thanks for that, that’s pretty much where I’m getting to. However, we use Salamander for user account creation. I think I’m going to have to talk to salamander about creating accounts prior to official start date that don’t get full access until contract start date (not in certain security groups or distribution groups for example).

 

Sadly though one thing they do on their new staff day is some training on school use of Sims/PARS so I am being asked to provide a level of access at least on this day, I could then disable the sims/pars accounts once that day has finished.

Posted (edited)

It’s a very difficult one. Teachers get their class lists and breakdown on vulnerable groups well before the new academic year starts and use this to do their lesson planning. Expecting them to make the correct (any) teaching decisions and do full planning without this information... or to do it all in the two days between their official date of employment and when the kids turn up is unreasonable and not in the best interest of pupil outcomes.

 

The decision on what teachers see is not yours to make I feel. It needs to go to the Head for risk assessment and an informed decision.

 

Do write down your GDPR concerns before asking the Head for a risk assessment and decision. However, let the Head make the decision.

 

I think this is a decision that you cannot make on your own.

Edited by elsiegee40
  • Thanks 4
Posted
It’s a very difficult one. Teachers get their class lists and breakdown on vulnerable groups well before the new academic year starts and use this to do their lesson planning. Expecting them to make the correct (any) teaching decisions and do full planning without this information... or to do it all in the two days between their official date of employment and when the kids turn up is unreasonable and not in the best interest of pupil outcomes.

 

.

 

This almost begs the question how do they get this information should they be bound by their contractual term and conditions before term starts?

  • Thanks 1
Posted (edited)
Sadly though one thing they do on their new staff day is some training on school use of Sims/PARS so I am being asked to provide a level of access at least on this day, I could then disable the sims/pars accounts once that day has finished.

 

One might suggest there should be test/training systems with dummy data in them for this kind of thing, which would nicely get around the issue. Besides, general staff training is arguably not a reasonable use of students' personal data.

Edited by Roberto
  • Thanks 1
Posted
This almost begs the question how do they get this information should they be bound by their contractual term and conditions before term starts?
Teacher contracts are weird in any case. When they change schools, they continue being paid by the school they're leaving up to the point they start at the new school.

 

Teachers must abide by Teacher's Standards, a binding DfE document, coontinuously throughout their career.

 

While it would be better if GDPR and confidentiality got a specific mention in this document, I guess it is covered by the personal and professional conduct section:

"Teachers must have an understanding of, and always act within, the statutory

frameworks which set out their professional duties and responsibilities"

  • Thanks 1
Posted

I don't think this is an automatic no. Nothing in the GDPR says you can't give data to people just because they don't directly work for you. Worst case, have HR tweak your contracts to specify that the duties of confidentiality apply to any personal data they see prior to their first day on site.

 

My biggest issue would be that they would presumably not yet have ICT equipment that's vetted by your team. I'd want them logging in through rdp or something rather than just getting sent the data and using their own computers to work on it.

  • Thanks 2
Posted
I assume nobody hands over logins and access without a signed contract of employment and AUP; one or both of these should cover Data Protection. These documents need to make it very plain that they are binding from the date of signature.
  • Thanks 2
Posted

Remember - GDPR and the DPA are not there to stop you or your school doing its job. Just because someone hasn't officially started their contract does not mean they can't have access to the things they need to prepare. The key is recognising that risk, assessing it, and putting in place controls and restrictions to make sure things are done properly.

 

You also need to make sure you privacy policy covers the use of the data in this way.

  • Thanks 2
Posted
Our staff are given access to Google Apps on their induction day, so they can access key information and start planning lessons. They have already signed their contracts and the AUP by this stage. They are given SIMS and everything else on the inset day. This is more about not overloading them on induction day / them forgetting it over a busy end of term and summer break.
  • Thanks 1
Posted

Presumably the new staff have already signed their contract to accept the job and have cleared DBS and reference checks . There should be a statement in the contract in regards to them having access to data before official start date and the requirements in accordance with the IT policy. Have them sign the IT policy and a statement added to that it also applies before official start date.

 

The main issue will be giving staff access to system that they have not had any training with as the setup or system may be totally different to their current school. I would provide them with user guides or best to offer twilight training session and then give access to systems.

  • Thanks 1
Posted
It’s a very difficult one. Teachers get their class lists and breakdown on vulnerable groups well before the new academic year starts and use this to do their lesson planning. Expecting them to make the correct (any) teaching decisions and do full planning without this information... or to do it all in the two days between their official date of employment and when the kids turn up is unreasonable and not in the best interest of pupil outcomes.

 

The decision on what teachers see is not yours to make I feel. It needs to go to the Head for risk assessment and an informed decision.

 

Do write down your GDPR concerns before asking the Head for a risk assessment and decision. However, let the Head make the decision.

 

I think this is a decision that you cannot make on your own.

 

I think you're right and it's another one of those things that our school has never really carefully considered and this is a good opportunity to revisit this and make the process secure for the school. I agree, as well, that not being able to do planning and preparation prior to September is unreasonable, extremely restrictive and is ultimately to the detriment of teaching and learning.

 

I'm going to discuss this further with our SLT, however, what has now been decided is that new staff will be doing GDPR training on the new staff induction day which will allow us to drill into the new staff the importance of Data Protection even though I'm sure they will have had some training at previous schools.

Posted
Access here is given once the AUP is signed and not before. The AUP covers what is and isn't OK and has recently been updated to reflect any changes (there weren't many) caused by GDPR. Once that has been signed the staff are legally bound to behave themselves whether they are in contract or not.
  • Thanks 2
Posted
I suspect it's more straightforward to sort for teachers than other staff as they're bound by the professional standards whichever school they're employed by. Unless you have a system which pulls data from SIMS (eg Target Tracker) there's probably significant value in giving them access to SIMS pupil data over the holiday. Most teachers (especially if they're new and keen to make a good impression) will do some preparation over the holidays, so it's not just the inset days. As long as I had a signed AUP and equipment loan form I don't think there's much reason not to give equipment out either. The difficulty with that for us would be getting the old kit back from other staff in time as we don't have any spare.
Posted
I suspect it's more straightforward to sort for teachers than other staff as they're bound by the professional standards whichever school they're employed by. Unless you have a system which pulls data from SIMS (eg Target Tracker) there's probably significant value in giving them access to SIMS pupil data over the holiday. Most teachers (especially if they're new and keen to make a good impression) will do some preparation over the holidays, so it's not just the inset days.

 

Good point. On the induction day, we give new teachers their SIMS login details but don't do any training on it. Those staff who know how to use it are free to log in over the summer if they wish; everyone (familiar with SIMS or otherwise) gets training on the September inset days.

 

As for the teacher versus support staff thing, it isn't really relevant because we very rarely get new support staff coming in before their first contracted day anyway, so we do their induction then. Support staff join in small numbers (and often not on 4th September anyway) we can induct them individually.

Posted

We give new staff access to the system from the induction day. Obviously at this point the recruitment process is almost complete, jobs formally accepted etc.

 

If we waited for their contracts to come through from the LA, they wouldn't have access until they'd been in the job a couple of months!

 

However, they don't get access until we have a signed AUP on file, and their DBS has come back and been accepted. All the policies and agreements we expect them to read are accessed via the system, so without a login they can't even do that.

  • Thanks 1
  • 1 month later...
Posted (edited)

Just to follow up on this, I've just spoken with the ICO Small Business helpline about this same situation.

 

Their answer was that no staff should have any access to school data or systems until the start date on their contract under GDPR and Data Protection legislation. He did say that there may be some other, specific to schools legislation which would override and allow it, but that's not his area, so couldn't advise on it. But failing that, from a strictly ICO/GDPR point of view, they say no access allowed before start date, even with a contract and AUP signed in advance.

 

Interesting!

 

Edit - in case anyone else wants the contact details, they can be found here: https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2017/10/new-data-protection-advice-service-aimed-at-small-organisations-preparing-for-the-general-data-protection-regulation/

0303 123 1113, Option 4

Edited by Valyyn
  • Thanks 3
Posted
Our policy is that they can have their account as soon as the DBS clearance comes through. Many new staff want to get onto e-mail and Firefly during the summer break and that's ok with us generally.
Posted
Yeah, that's basically what we've always done in the past. From what the ICO are saying though, doing that now places us in breach of the GDPR :/
Posted

Our (fully trained) DPO advised the senior team that staff must NOT have accounts and access to key data when they are not in a contract of employment.

The headteacher overrode this and the decision was minuted - we now give accounts to all.

In this case the HT ignored the professional advice offered to him; and I guess that as long as nobody whistlebows he will be safe in his job......

Posted
I've flagged this to our HT to include in our next discussion with our DPO. I suspect it will be about as popular as a fart in a lift if they confirm this...
Posted

We've had a firm policy for a few years now: no access for anyone until their employment start date. No laptop loan, no email account, no 'lite' access of any sort.

 

It's nice just to be able to give a clear "no" and have SLT back it up. It also avoids having awkward negotiations about having access to this or that. However, there's a niggling thought in the back of my head that departments might just be emailing stuff out to private email addresses ahead of time as a result.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...