Jump to content

Recommended Posts

Posted

This is more about employment law than GDPR.

 

To be able to handle and process data on behalf of the Data Controller a relationship needs to be established.

For volunteers this will be based around things like the AUP and signing agreement to other policies, and for staff it is the employment contract.

The contracts have start dates but *may* have other things in there to say the relation starts from the point of signature on an unpaid / volunteer, reasonable basis. It has to say this as the school cannot ask for lots of work to be done whilst employed by someone else.

There is also risk about using devices from the old school to do work for the new school.

Generally I would suggest schools do a DPIA on leaver / starter processes and update processes / documentation / contracts as a result (get it written that it will be done in September to allow you a chance to review what did or didn’t work well?)

 

I’ve added it as an idea for the next iteration of the DfE toolkit, but that will be too late for this year.

  • Thanks 3
  • 1 month later...
Posted

This is stepping on employment law now so I had a chat with the ACAS helpline.

Unless a contract states what happens before the start date, then the start date is when the obligations and responsibilities apply as that is ... wait for it ... the start of the contract! This means that access cannot be given unless the member of staff has clearly shown that they have agreed to the school / organisation policies. That could be that the contract is updated to give them the status of 'volunteer' until they start as a paid employee, and it also means that you *have* to show that you have given any required training, etc. when giving access (this is part of GDPR demonstration of compliance). The same applies with safeguarding, H&S and so on. Just because someone is a volunteer it doesn't mean they have access to everything in the same way you don't let someone up the talloscope to change the lighting rig until they have had training.

 

Thanks GrumbleDook, that is so helpful and clear. One of mine and DPOs main concerns was giving someone access to school data before legally binding HR paperwork such as DBS had been completed.

 

It seems to be too late to implement the above "volunteer" contracts nor implement the training before we start back now.

Posted
This means that access cannot be given unless the member of staff has clearly shown that they have agreed to the school / organisation policies.

 

Would signing the AUP be sufficient?

Posted
Would signing the AUP be sufficient?

 

If your school feels that it is (risk assessment, etc.) and can justify that ... then personally I think that it would be doable ... is that what you would do with a volunteer?

Posted
If your school feels that it is (risk assessment, etc.) and can justify that ... then personally I think that it would be doable ... is that what you would do with a volunteer?

 

Yes. Anyone with a login to network/Google/SIMS signs the AUP, regardless of role or salary. Staff, unpaid interns, external agents e.g. school nurse, counselling services. The only people with access who haven't signed the AUP are companies who access in order to provide a service, e.g. Salamander, but they've all agreed to a separate code of conduct.

Posted
Yes. Anyone with a login to network/Google/SIMS signs the AUP, regardless of role or salary. Staff, unpaid interns, external agents e.g. school nurse, counselling services. The only people with access who haven't signed the AUP are companies who access in order to provide a service, e.g. Salamander, but they've all agreed to a separate code of conduct.

 

In which case, I think you have answered your own question :-)

  • 9 months later...
Posted
:bump:

 

Is there much else to say on this? Someone uses your systems then they have to considered a paid employee, a volunteer or a visitor. They should only have access to systems that are agreed for their particular role and should sign to say that they abide by any policies / procedures. It needs to be guided by contracts where possible, 'volunteer agreements' and by agreement of policies / procedures.

Posted
Is there much else to say on this? Someone uses your systems then they have to considered a paid employee, a volunteer or a visitor. They should only have access to systems that are agreed for their particular role and should sign to say that they abide by any policies / procedures. It needs to be guided by contracts where possible, 'volunteer agreements' and by agreement of policies / procedures.

 

I bumped it because people were looking for it. It is now stickied as I suspect this concern will be raised annually

  • Thanks 1
Posted
We make sure all our users sign the correct policies, and sign a confidentiality agreement. We're just about to have 2 members of the local authority needing access to Google Drive to help a student with his work.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...