Jump to content

Recommended Posts

Posted

OK got an odd one that I'd like to know if anyone else has come across.

 

We have a number of staff in school whose own children are students here. The staff work in various roles, from TA's to teachers to high level admin staff. A question has arisen on how much access to their own childs records should they get via our MIS?

 

Some of the various job roles require the person to see quite confidential data on students. A situation is currently ongoing where a member of staff, who is separated from the other parent of the child, is able to see conversations recorded between the school and the other parent. This information 'could' then be used to undermine a current custody battle.

 

I've spoken to the MIS support team (I'm deliberately being vague about names) to enquire if anything can be enabled to limit 'own child' access, and there isn't.

 

Has this cropped up anywhere else and if so, what have you done to address it?

Posted

Interesting point to raise, but a user should only ever access system for a legitimate need i.e. to record details on student record, if looking at a record they shouldn't than that would be a breach and would be on an audit log?

 

Only thing I can think of is there a private marker on certain records or can a record be marked as a sensitive record with only access to certain staff?

Posted
Interesting point to raise, but a user should only ever access system for a legitimate need i.e. to record details on student record, if looking at a record they shouldn't than that would be a breach and would be on an audit log?

 

Only thing I can think of is there a private marker on certain records or can a record be marked as a sensitive record with only access to certain staff?

If it's SIMS there aren't logs at the level of detail.
Posted

It’s not SIMS but in the same situation, there aren’t logs at that level of detail. Neither can we mark certain students as private, once permissions are assigned to a user (the required ones to do their job) they can view that level of info on any student.. including their own child.

 

My only thoughts are to cover this in a signed policy, but no real way to monitor only trust

Posted
We had this issue on progresso and I concluded there really wasn't a way to get the level of control required. The HT in the end had to resort to making reference to a paper document that was secured manually. I did make one suggestion, which was to store a document link to a Google document. That link could be controlled to provide access only to those that should have it. Presumably something similar could be set up for a traditional network location or onedrive or sharepoint etc. Out of interest, which MIS are you using?
Posted
We are using Bromcom. The idea of linking to a secure OneDrive area is intriguing, at least for some things. We already have CPOMS for some parts but general communications between school and parents tends to get logged in Bromcom.
Posted

I've not had the exact scenario you've encountered, but I have seen similar instances. Generally I think you should rely on their professionalism not to access information a parent wouldn't routinely have (this goes for looking up information on their child's peers too) and sometimes it will be the case a teacher teaches their own child/child's peers/friend's child.

 

In the specific situation you describe, I think a shared Google Doc which only those staff who need to know about the details of the custody case can access. Plus a note in SIMS of course to point people to the presence of this document in a non-standard place.

  • Thanks 1
Posted

Section 170 of the DPA 2018 Act also makes it a criminal office for someone to knowingly or recklessly obtain personal data without the consent of the data controller.

 

If a parent does this with the idea that it will give them an upper hand within a custody battle they may find it quickly back fires and they end up with a fine and an very unhappy judge.

 

Maybe incorporate this into any DP training so these particular staff are well aware of the consequences.

  • Thanks 1
Posted
I'd put in a request to [MIS provider]. All MIS products should be implementing row level ACLs anyway. The more DP issues arise, the more requests they'll get.
  • Thanks 1
Posted
I'd put in a request to [MIS provider]. All MIS products should be implementing row level ACLs anyway. The more DP issues arise, the more requests they'll get.

Should... Maybe. Are? No. I don't know of *any* MIS that offers this capability. Not everything has to be managed with technology. Organisational restrictions and policies also count.

Posted
Not everything has to be managed with technology. Organisational restrictions and policies also count.

 

Agreed. A staff member might teach their own child, at which point control can only be achieved by regulating working practices.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...