Jump to content

Recommended Posts

Posted
We've had a firm policy for a few years now: no access for anyone until their employment start date. No laptop loan, no email account, no 'lite' access of any sort.

 

All our resources are in Google Drive and Classroom. Without access to that over the summer, new staff would have a rough first week.

Posted (edited)

I disagree with the ICO here, nothing in the GDPR says "Thou shalt not give access to people who don't work for you yet" and indeed we regularly give information to people who don't work for us AT ALL and this is not considered a problem...provided that you take the appropriate organisational and technological measures necessary to protect the data that the GDPR actually does mandate.

 

Imma contact them too.

 

Edit:

 

Long story short:

 

ico_ciarah: Your school would need to consider any security risks linked with supplying new members of staff access to the data. If you think you can mitigate any risks through appropriate training (etc.), it is possible.

ico_ciarah: We cannot say yes, or no. It is ultimately your school's judgement.

 

So my view is; if you are supplying the equipment they're doing this on, have put them through the same GDPR training that your staff sit and they've agreed to be bound by your data protection policy as part of the contract they signed - this is not an automatic no at all.

Edited by djrscally
Posted
I disagree with the ICO here, nothing in the GDPR says "Thou shalt not give access to people who don't work for you yet" and indeed we regularly give information to people who don't work for us AT ALL and this is not considered a problem

 

Ha, good point!

Posted
All our resources are in Google Drive and Classroom. Without access to that over the summer, new staff would have a rough first week.

 

The school could quite easily remedy that by starting their contract earlier if they chose to.

 

I disagree with the ICO here, nothing in the GDPR says "Thou shalt not give access to people who don't work for you yet" and indeed we regularly give information to people who don't work for us AT ALL and this is not considered a problem...provided that you take the appropriate organisational and technological measures necessary to protect the data that the GDPR actually does mandate.

 

We are discussing giving people, who have no connection with the school, detailed and personal information about staff, students and parents. I'm pretty sure that is explicitly covered by the law NOW, let alone what the GDPR has added.

Posted
The school could quite easily remedy that by starting their contract earlier if they chose to.

 

 

 

We are discussing giving people, who have no connection with the school, detailed and personal information about staff, students and parents. I'm pretty sure that is explicitly covered by the law NOW, let alone what the GDPR has added.

 

See my edit; I don't think it's an explicit no at all.

Posted
sure, it depends on what data you give them.

 

Yeah I mean I wouldn't give them anything a teacher wouldn't ordinarily see obviously, but certainly contextual info about the classes they're gonna pick up like their targets and prior attainment and things.

Posted
Yeah I mean I wouldn't give them anything a teacher wouldn't ordinarily see obviously, but certainly contextual info about the classes they're gonna pick up like their targets and prior attainment and things.

 

Cool. Can you email me the contextual info about some of the classes too. I'd be interested in seeing it.

Posted
Cool. Can you email me the contextual info about some of the classes too. I'd be interested in seeing it.

 

Sure just get HR to let me know once you've got a job here and all your contract and compliance stuff is sorted.

Posted
Sure just get HR to let me know once you've got a job here and all your contract and compliance stuff is sorted.

 

That's the rub though, because the staff don't have jobs with you until their contract has started.

So if they decided to leak all the information on line the school would have no way of holding them to account.

You can (and must) risk assess this, but the school is liable for the data loss.

Posted (edited)
That's the rub though, because the staff don't have jobs with you until their contract has started.

So if they decided to leak all the information on line the school would have no way of holding them to account.

You can (and must) risk assess this, but the school is liable for the data loss.

 

But is that really any different from a current staff member? The bare fact that they don't currently work for you is meaningless - if they deliberately leaked the information on line then they'd be prosecuted just like any current member of staff who deliberately mishandled data would be. The risk you're mitigating is that this unknown person will accidentally mishandle data, and you mitigate that in exactly the same way you do for current staff members by having them read and agree to follow the policies, training them and giving them equipment that you know to be safe.

 

Edit; Like I say, we ​very frequently​ give people who don't work for us access to our data. That is not automatic grounds for exclusion

Edited by djrscally
Posted
But is that really any different from a current staff member? The bare fact that they don't currently work for you is meaningless - if they deliberately leaked the information on line then they'd be prosecuted just like any current member of staff who deliberately mishandled data would be. The risk you're mitigating is that this unknown person will accidentally mishandle data, and you mitigate that in exactly the same way you do for current staff members by having them read and agree to follow the policies, training them and giving them equipment that you know to be safe.

 

No I think it is quite different.

The staff are not employees before their contract starts - or after their contract ends.

If you hand me data and I put it online , you are liable and I am not. Want to test it out ?

  • Thanks 1
Posted
No I think it is quite different.

The staff are not employees before their contract starts - or after their contract ends.

If you hand me data and I put it online , you are liable and I am not. Want to test it out ?

 

If I just handed you data with no precautionary measures and you put it online because you didn't know it was wrong, sure. But if I'm being responsible (by training you, reading you the riot act and giving you secure IT equipment) and you're simply being malicious then that's not how it works; go look at the ICO's "Actions we've taken" pages. Where an employee maliciously handles data it's the employee that gets prosecuted and fined for it. There's plenty of examples of people either stealing data when they leave, or looking up details that they had no right to access (which is generally health workers nosying on the records of their neighbours or something) and so on and so forth.

I really don't see why the simple fact of employment or not is given such weight; particularly since we give out data to non-employees now.

Posted
You can (and must) risk assess this, but the school is liable for the data loss.

 

And there are the key words - risk assess. I thought most of GDPR was about risk assessment anyway, rather than hard and fast rules. The risk of a new staff member doing something malicious or negligent with the data is no greater - indeed is likely actually less * - than the risk of a "full" staff member doing something malicious or negligent. So, if we can justify why we took the risk and prove we considered it rather than doing it blindly, won't the ICO be okay with that?

 

* I say it is less likely to happen with incoming staff and than existing ones because they would want to make a good first impression and can't yet be disgruntled. If you think about many of the data leaks you read about, they are unhappy employees wanting to show up/damage their employer, or they're departing employees taking data to the new job at the competition.

Posted

So if they decided to leak all the information on line the school would have no way of holding them to account.

You can (and must) risk assess this, but the school is liable for the data loss.

 

With teachers, as they are professionals that are part of a professional body, you would have the recourse to go to the General Teaching Council (GTC) who could strike them off their list, which would cause them issues getting a teaching job in the UK.

Posted (edited)

Even after the risk assessment, you still need to have a contract. You have to have a contract with each individual company that supply services to you so it would stand to reason that you would need the same with individuals.

 

I really don't see why the simple fact of employment or not is given such weight; particularly since we give out data to non-employees now.

I concede that it doesn't need to be a contract of employment But you still do need a contract of some kind. I think my confusion is because usually the contact of employment would cover the data protection.

Edited by mjk
Posted
Even after the risk assessment, you still need to have a contract. You have to have a contract with each individual company that supply services to you so it would stand to reason that you would need the same with individuals.

 

 

I concede that it doesn't need to be a contract of employment But you still do need a contract of some kind. I think my confusion is because usually the contact of employment would cover the data protection.

 

I think it can be part of the contract of employment, if it's written such that signing it involves them agreeing to be immediately bound by your Data Protection Policy with respect to personal data for which the employer is the controller.

Posted
I think it can be part of the contract of employment, if it's written such that signing it involves them agreeing to be immediately bound by your Data Protection Policy with respect to personal data for which the employer is the controller.

 

We don't give logins out until staff have signed a) contract of employment, b) our AUP. The latter presumably constitutes a contract, which they would be breaching if they did something malicious with the data before their employment start date.

Posted

You have to remember that teachers have a peculiar contract that ensures continuous service. The actual date of employment is more a convenience to decide who pays them and is almost as inflexible as the 3 dates by which they must resign in order to take up a new post at the start of the following term.

 

I think your AUP needs to be nailed down to say that a teacher is agreeing to abide by it from the date it is signed and that it forms a contract between the teacher and the school.

 

At the point of signature, the issue of giving them access to next academic year’s class profiles is then a lower risk and this enables them to do their planning for the next academic year.

Posted
We have a new teacher starting and he is coming back into education from business. So, he wanted paying for transfer day. They have set him up a contract as a supply teacher until his full contract starts in September. Hopefully that heads off some of the GDPR issues...
Posted
We have a new teacher starting and he is coming back into education from business. So, he wanted paying for transfer day. They have set him up a contract as a supply teacher until his full contract starts in September. Hopefully that heads off some of the GDPR issues...

 

We've done that for staff joining from industry or employment breaks, too.

Posted (edited)

We're allowing pre starters to have an account, providing they sign to say they accept to abide by the IT AUP & our Data protection policy. This forms a "contract" under the GDPR.

 

We did say no full stop at first, then I looked at setting up seperate temp accounts but this proved impossible, as they wanted schemes of work which are heavily embedded in our shared areas and trying to clone or detach the data would be a nightmare. Ultimately we decided that they needed proper access but we needed to protect ourselves legally, as a few still have their employment contracts still outstanding.

Edited by DrCheese
Posted

We have a new assistant head starting, who will be data manager. We have the task of setting up assessments and reporting from scratch on a new system, to be in place by September.

 

Has anyone got confirmation from ICO that a signed agreement, not linked to employment status, is sufficient to protect the school from damages?

 

Personally I don't think we're covered. Most likely nothing will go wrong but the exposure to risk is a concern.

Posted
We have a new assistant head starting, who will be data manager. We have the task of setting up assessments and reporting from scratch on a new system, to be in place by September.

 

Has anyone got confirmation from ICO that a signed agreement, not linked to employment status, is sufficient to protect the school from damages?

 

Personally I don't think we're covered. Most likely nothing will go wrong but the exposure to risk is a concern.

 

The ICO are unlikely to give you a straight yes/no answer on this or indeed anything else. The standard response is that it is for you to assess your own risks and act accordingly

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...