enjay Posted October 14, 2019 Posted October 14, 2019 A quick word for me about safeguarding and liability got them moving sharpish. They are still allowed to do things like lesson plans on their personal accounts - but nothing concerning staff/pupil data is allowed on there. This is simply so they've still got their personally made resources when they leave - can't complain about that. Not great for cover staff though, or their replacement when they leave. We ask staff to put all their lesson resources on the school network, either in MyDocs or shared folders. 1
mthomas08 Posted October 16, 2019 Posted October 16, 2019 Your ICT policy should cover this, it's very bad practice and hard to defend if you have a breach. Plus what happens when a parent asks for all the data regarding their child. Does the school know if those staff have 20+ year old personal data held in those areas? What happens when they leave? Setting up a school G Suite isn't that hard, takes a little bit of time but worth it. The sync isn't that hard either to pull from AD. All free.
saggu Posted October 16, 2019 Author Posted October 16, 2019 Plus what happens when a parent asks for all the data regarding their child. Does the school know if those staff have 20+ year old personal data held in those areas? What happens when they leave? Setting up a school G Suite isn't that hard, takes a little bit of time but worth it. The sync isn't that hard either to pull from AD. All free. I am more than happy to set up G Suite (with help) but staff will still use their own email. According to them it is more convenient. More than that it is SLT's way of thinking -' Oh! don't let the IT department know.' Not thinking of GDPR or security. I will give the option as part of my duty to alert SLT and provide better solution. Many thanks for all the tips.
Edu-IT Posted October 16, 2019 Posted October 16, 2019 You need the backing of SLT and they should know better than to encourage the use of personal emails. Trouble is, they probably won’t until it’s too late by the sounds of it. Do you have a Safeguarding Governor who you could send your concerns to? I mean, you could get it to them anonymously I’m sure if you so needed to. 1
localzuk Posted October 16, 2019 Posted October 16, 2019 I have a question - why is this being taken to "SLT"? Why not the DPO, the head or the chair of governors/trustees? They do realise that data breaches can now lead to rather large fines right? 1
elsiegee40 Posted October 16, 2019 Posted October 16, 2019 I have a question - why is this being taken to "SLT"? Why not the DPO, the head or the chair of governors/trustees? They do realise that data breaches can now lead to rather large fines right? I agree. My first response was to talk to the DPO. With the weight of both DPO and you hopefully things will change fast.
LukeRowberry Posted October 17, 2019 Posted October 17, 2019 This seems like a school that decided a DPO wasn't for them.
Rob_D Posted October 17, 2019 Posted October 17, 2019 What browser do most people in the school use? We have chrome set up to only allow login from domain g-suite accounts. Just saying. But really, there's only so much you can do without someone higher up on side. If SLT aren't going to do anything then (as others have said) go higher. And don't forget to mention the GDPR fines. Money normally makes people sit up and take note. 1
DGardiner Posted October 17, 2019 Posted October 17, 2019 id just be blocking all email services and using the filtering solution to restrict the login options of google to our domain https://support.google.com/a/answer/1668854?hl=en At the end of the day it will all comeback and bite them and they will point at you, dont put yourself in that position. 1
jthompson Posted October 17, 2019 Posted October 17, 2019 This seems like a school that decided a DPO wasn't for them. This was my thinking, too. The head needs to get onboard with the fact that using private accounts is a real failing, even if there's a stated intention that it's only for things that don't include PII. Some sort of real-world analogy is needed. Something like staff meetings being conducted offsite at the local pub in amongst the locals, because it's nicer there. Or staff members' immediate family getting a free pass to wander on and off site without needing to sign in at reception, simply because members of staff trust their own family. 1
mikeprice Posted October 17, 2019 Posted October 17, 2019 This was my thinking, too. The head needs to get onboard with the fact that using private accounts is a real failing, even if there's a stated intention that it's only for things that don't include PII. Some sort of real-world analogy is needed. Something like staff meetings being conducted offsite at the local pub in amongst the locals, because it's nicer there. Or staff members' immediate family getting a free pass to wander on and off site without needing to sign in at reception, simply because members of staff trust their own family. Don't say that - at my last school the DH held senior staff meeting at the local pub - OK it was outside the catchment area but people have relatives - and ears!! and yes - they did discuss pupil discipline issues at these meetings I didn't attend - actually wasn't asked to - but it did seem dodgy at the time 1
Bionic Posted October 17, 2019 Posted October 17, 2019 This seems like a school that decided a DPO wasn't for them. Or one that decided to appoint a completely untrained member of staff to handle the DPO responsibility because the legal "experts" working for the local authority said that was ok!
enjay Posted October 17, 2019 Posted October 17, 2019 Some sort of real-world analogy is needed. Something like staff meetings being conducted offsite at the local pub in amongst the locals, because it's nicer there. Or staff members' immediate family getting a free pass to wander on and off site without needing to sign in at reception, simply because members of staff trust their own family. Bad analogies, as both those things routinely happen...
saggu Posted October 17, 2019 Author Posted October 17, 2019 You need the backing of SLT and they should know better than to encourage the use of personal emails. Trouble is, they probably won’t until it’s too late by the sounds of it. Do you have a Safeguarding Governor who you could send your concerns to? I mean, you could get it to them anonymously I’m sure if you so needed to. It is the SLT who are using it. There is a Safeguarding Governor but unlikely it will be anonymous.
elsiegee40 Posted October 17, 2019 Posted October 17, 2019 It is the SLT who are using it. There is a Safeguarding Governor but unlikely it will be anonymous. Go to your school website and use the whistleblowing procedure then. Follow that if nobody will take notice of the Safeguarding and Data Protection risks. 2
mthomas08 Posted December 9, 2019 Posted December 9, 2019 I am more than happy to set up G Suite (with help) but staff will still use their own email. According to them it is more convenient. More than that it is SLT's way of thinking -' Oh! don't let the IT department know.' Not thinking of GDPR or security. I will give the option as part of my duty to alert SLT and provide better solution. Many thanks for all the tips. Recently went on some updated GDPR training. He was quite clear that you shouldn't be doing it and the words" just incase" he clearly stated no don't do it. How does your DPO deal with SARs? Has the DPO reported to the Governors/HT over personal Gmail accounts? We had a SAR not long ago and the pile of work was ridiculous but had to be done. Emails had to be copied, paper copies made, our MIS data exported (including scanned/documents) and making sure every external site we used was included. All that information had to be double checked to make sure it didn't include personal details of anyone else. We even got told during the training that we should be redacting more information than what we do. Every person in this seminar failed the task.... including me and our DPO. We should be redacting MUCH more and only the directly related data should be allowed.
enjay Posted December 9, 2019 Posted December 9, 2019 Easy solution - get someone to do an SAR. SAR would only apply to data on school systems, wouldn't it? So, if someone is storing student data in a personal GMail account, it wouldn't be subject to an SAR. Or am I wrong?
elsiegee40 Posted December 9, 2019 Posted December 9, 2019 If staff are using personal email for their professional life then SAR would include that too as far as I am aware. It would be pretty obvious from email chains when it was happening.
jthompson Posted December 9, 2019 Posted December 9, 2019 If staff are using personal email for their professional life then SAR would include that too as far as I am aware. It would be pretty obvious from email chains when it was happening. Only if you can get hold of the email chains in the first place! Not straightforward if they were happening completely exclusive of school accounts.
elsiegee40 Posted December 9, 2019 Posted December 9, 2019 Only if you can get hold of the email chains in the first place! Not straightforward if they were happening completely exclusive of school accounts. Which is why Staff must use school systems for school business. If they start mixing the two it will become obvious that they are doing so and thus their personal account will get involved. Staff really need proper training on how to protect themselves and their career. It needs to include both data protection and Safeguarding risks. And it needs to scare the pants off them in some cases. I used to do it as part of the induction of every new member of staff at my last school on their first day of employment. It was effective.
saggu Posted December 9, 2019 Author Posted December 9, 2019 Recently went on some updated GDPR training. He was quite clear that you shouldn't be doing it and the words" just incase" he clearly stated no don't do it. How does your DPO deal with SARs? Has the DPO reported to the Governors/HT over personal Gmail accounts? We had a SAR not long ago and the pile of work was ridiculous but had to be done. Emails had to be copied, paper copies made, our MIS data exported (including scanned/documents) and making sure every external site we used was included. All that information had to be double checked to make sure it didn't include personal details of anyone else. We even got told during the training that we should be redacting more information than what we do. Every person in this seminar failed the task.... including me and our DPO. We should be redacting MUCH more and only the directly related data should be allowed. DPO left. Waiting for new DPO. BTW HT and DHT agreed to have corporate Gmail account. I have purchased the domain but waiting for the checks to be finished. I understand that being a school it is complicated to do the company checks.
saggu Posted December 9, 2019 Author Posted December 9, 2019 I have a question - why is this being taken to "SLT"? Why not the DPO, the head or the chair of governors/trustees? They do realise that data breaches can now lead to rather large fines right? SLT don't agree that school can be fined.
saggu Posted December 9, 2019 Author Posted December 9, 2019 Or one that decided to appoint a completely untrained member of staff to handle the DPO responsibility because the legal "experts" working for the local authority said that was ok! I can echo this!
mikeprice Posted December 9, 2019 Posted December 9, 2019 SLT don't agree that school can be fined. Hmmm - so who exactly do they think would be held responsible if, for example, all the special needs reports were accessed due to carelessness?? you??? anyone any examples of school being fined - a concrete example might be needed here 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now