themightymrp Posted June 28, 2019 Posted June 28, 2019 OK got an odd one that I'd like to know if anyone else has come across. We have a number of staff in school whose own children are students here. The staff work in various roles, from TA's to teachers to high level admin staff. A question has arisen on how much access to their own childs records should they get via our MIS? Some of the various job roles require the person to see quite confidential data on students. A situation is currently ongoing where a member of staff, who is separated from the other parent of the child, is able to see conversations recorded between the school and the other parent. This information 'could' then be used to undermine a current custody battle. I've spoken to the MIS support team (I'm deliberately being vague about names) to enquire if anything can be enabled to limit 'own child' access, and there isn't. Has this cropped up anywhere else and if so, what have you done to address it?
Brimstone Posted June 28, 2019 Posted June 28, 2019 Can't answer your question but that's a great quote in your signature..... 1
MatthewL Posted June 28, 2019 Posted June 28, 2019 Interesting point to raise, but a user should only ever access system for a legitimate need i.e. to record details on student record, if looking at a record they shouldn't than that would be a breach and would be on an audit log? Only thing I can think of is there a private marker on certain records or can a record be marked as a sensitive record with only access to certain staff?
jmak Posted June 28, 2019 Posted June 28, 2019 Interesting point to raise, but a user should only ever access system for a legitimate need i.e. to record details on student record, if looking at a record they shouldn't than that would be a breach and would be on an audit log? Only thing I can think of is there a private marker on certain records or can a record be marked as a sensitive record with only access to certain staff?If it's SIMS there aren't logs at the level of detail.
themightymrp Posted June 28, 2019 Author Posted June 28, 2019 It’s not SIMS but in the same situation, there aren’t logs at that level of detail. Neither can we mark certain students as private, once permissions are assigned to a user (the required ones to do their job) they can view that level of info on any student.. including their own child. My only thoughts are to cover this in a signed policy, but no real way to monitor only trust
Ditto Posted June 28, 2019 Posted June 28, 2019 We had this issue on progresso and I concluded there really wasn't a way to get the level of control required. The HT in the end had to resort to making reference to a paper document that was secured manually. I did make one suggestion, which was to store a document link to a Google document. That link could be controlled to provide access only to those that should have it. Presumably something similar could be set up for a traditional network location or onedrive or sharepoint etc. Out of interest, which MIS are you using?
themightymrp Posted June 29, 2019 Author Posted June 29, 2019 We are using Bromcom. The idea of linking to a secure OneDrive area is intriguing, at least for some things. We already have CPOMS for some parts but general communications between school and parents tends to get logged in Bromcom.
enjay Posted July 1, 2019 Posted July 1, 2019 I've not had the exact scenario you've encountered, but I have seen similar instances. Generally I think you should rely on their professionalism not to access information a parent wouldn't routinely have (this goes for looking up information on their child's peers too) and sometimes it will be the case a teacher teaches their own child/child's peers/friend's child. In the specific situation you describe, I think a shared Google Doc which only those staff who need to know about the details of the custody case can access. Plus a note in SIMS of course to point people to the presence of this document in a non-standard place. 1
rom1984 Posted July 1, 2019 Posted July 1, 2019 Section 170 of the DPA 2018 Act also makes it a criminal office for someone to knowingly or recklessly obtain personal data without the consent of the data controller. If a parent does this with the idea that it will give them an upper hand within a custody battle they may find it quickly back fires and they end up with a fine and an very unhappy judge. Maybe incorporate this into any DP training so these particular staff are well aware of the consequences. 1
Michael Posted July 1, 2019 Posted July 1, 2019 To put it simply, this isn't a technology or more specifically an MIS issue. It's a user management issue. 1
BOOT Posted July 1, 2019 Posted July 1, 2019 I'd put in a request to [MIS provider]. All MIS products should be implementing row level ACLs anyway. The more DP issues arise, the more requests they'll get. 1
themightymrp Posted July 3, 2019 Author Posted July 3, 2019 That's what Bill Gates said. And good old Bill is referenced at the end of the quote...
localzuk Posted July 3, 2019 Posted July 3, 2019 I'd put in a request to [MIS provider]. All MIS products should be implementing row level ACLs anyway. The more DP issues arise, the more requests they'll get. Should... Maybe. Are? No. I don't know of *any* MIS that offers this capability. Not everything has to be managed with technology. Organisational restrictions and policies also count.
enjay Posted July 3, 2019 Posted July 3, 2019 Not everything has to be managed with technology. Organisational restrictions and policies also count. Agreed. A staff member might teach their own child, at which point control can only be achieved by regulating working practices.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now