Jump to content

Recommended Posts

Posted
A quick word for me about safeguarding and liability got them moving sharpish. They are still allowed to do things like lesson plans on their personal accounts - but nothing concerning staff/pupil data is allowed on there. This is simply so they've still got their personally made resources when they leave - can't complain about that.

 

Not great for cover staff though, or their replacement when they leave. We ask staff to put all their lesson resources on the school network, either in MyDocs or shared folders.

  • Thanks 1
Posted
Your ICT policy should cover this, it's very bad practice and hard to defend if you have a breach.

 

Plus what happens when a parent asks for all the data regarding their child. Does the school know if those staff have 20+ year old personal data held in those areas? What happens when they leave?

 

Setting up a school G Suite isn't that hard, takes a little bit of time but worth it. The sync isn't that hard either to pull from AD. All free.

Posted
Plus what happens when a parent asks for all the data regarding their child. Does the school know if those staff have 20+ year old personal data held in those areas? What happens when they leave?

 

Setting up a school G Suite isn't that hard, takes a little bit of time but worth it. The sync isn't that hard either to pull from AD. All free.

 

I am more than happy to set up G Suite (with help) but staff will still use their own email. According to them it is more convenient. More than that it is SLT's way of thinking -' Oh! don't let the IT department know.' Not thinking of GDPR or security. I will give the option as part of my duty to alert SLT and provide better solution.

Many thanks for all the tips.

Posted
You need the backing of SLT and they should know better than to encourage the use of personal emails. Trouble is, they probably won’t until it’s too late by the sounds of it. Do you have a Safeguarding Governor who you could send your concerns to? I mean, you could get it to them anonymously I’m sure if you so needed to.
  • Thanks 1
Posted
I have a question - why is this being taken to "SLT"? Why not the DPO, the head or the chair of governors/trustees? They do realise that data breaches can now lead to rather large fines right?
  • Thanks 1
Posted
I have a question - why is this being taken to "SLT"? Why not the DPO, the head or the chair of governors/trustees? They do realise that data breaches can now lead to rather large fines right?

 

I agree. My first response was to talk to the DPO. With the weight of both DPO and you hopefully things will change fast.

Posted

What browser do most people in the school use?

We have chrome set up to only allow login from domain g-suite accounts. Just saying.

 

But really, there's only so much you can do without someone higher up on side. If SLT aren't going to do anything then (as others have said) go higher. And don't forget to mention the GDPR fines. Money normally makes people sit up and take note.

  • Thanks 1
Posted
This seems like a school that decided a DPO wasn't for them.

 

This was my thinking, too.

 

The head needs to get onboard with the fact that using private accounts is a real failing, even if there's a stated intention that it's only for things that don't include PII. Some sort of real-world analogy is needed. Something like staff meetings being conducted offsite at the local pub in amongst the locals, because it's nicer there. Or staff members' immediate family getting a free pass to wander on and off site without needing to sign in at reception, simply because members of staff trust their own family.

  • Thanks 1
Posted
This was my thinking, too.

 

The head needs to get onboard with the fact that using private accounts is a real failing, even if there's a stated intention that it's only for things that don't include PII. Some sort of real-world analogy is needed. Something like staff meetings being conducted offsite at the local pub in amongst the locals, because it's nicer there. Or staff members' immediate family getting a free pass to wander on and off site without needing to sign in at reception, simply because members of staff trust their own family.

 

Don't say that - at my last school the DH held senior staff meeting at the local pub - OK it was outside the catchment area but people have relatives - and ears!!

and yes - they did discuss pupil discipline issues at these meetings

 

I didn't attend - actually wasn't asked to - but it did seem dodgy at the time

  • Thanks 1
Posted
This seems like a school that decided a DPO wasn't for them.

 

Or one that decided to appoint a completely untrained member of staff to handle the DPO responsibility because the legal "experts" working for the local authority said that was ok!

Posted
Some sort of real-world analogy is needed. Something like staff meetings being conducted offsite at the local pub in amongst the locals, because it's nicer there. Or staff members' immediate family getting a free pass to wander on and off site without needing to sign in at reception, simply because members of staff trust their own family.

 

Bad analogies, as both those things routinely happen...

Posted
You need the backing of SLT and they should know better than to encourage the use of personal emails. Trouble is, they probably won’t until it’s too late by the sounds of it. Do you have a Safeguarding Governor who you could send your concerns to? I mean, you could get it to them anonymously I’m sure if you so needed to.

 

It is the SLT who are using it. There is a Safeguarding Governor but unlikely it will be anonymous.

Posted
It is the SLT who are using it. There is a Safeguarding Governor but unlikely it will be anonymous.

 

Go to your school website and use the whistleblowing procedure then. Follow that if nobody will take notice of the Safeguarding and Data Protection risks.

  • Thanks 2
  • 1 month later...
Posted
I am more than happy to set up G Suite (with help) but staff will still use their own email. According to them it is more convenient. More than that it is SLT's way of thinking -' Oh! don't let the IT department know.' Not thinking of GDPR or security. I will give the option as part of my duty to alert SLT and provide better solution.

Many thanks for all the tips.

 

Recently went on some updated GDPR training. He was quite clear that you shouldn't be doing it and the words" just incase" he clearly stated no don't do it.

 

How does your DPO deal with SARs? Has the DPO reported to the Governors/HT over personal Gmail accounts?

 

We had a SAR not long ago and the pile of work was ridiculous but had to be done. Emails had to be copied, paper copies made, our MIS data exported (including scanned/documents) and making sure every external site we used was included. All that information had to be double checked to make sure it didn't include personal details of anyone else. We even got told during the training that we should be redacting more information than what we do. Every person in this seminar failed the task.... including me and our DPO. We should be redacting MUCH more and only the directly related data should be allowed.

Posted
Easy solution - get someone to do an SAR.

 

SAR would only apply to data on school systems, wouldn't it? So, if someone is storing student data in a personal GMail account, it wouldn't be subject to an SAR. Or am I wrong?

Posted

If staff are using personal email for their professional life then SAR would include that too as far as I am aware.

 

It would be pretty obvious from email chains when it was happening.

Posted
If staff are using personal email for their professional life then SAR would include that too as far as I am aware.

 

It would be pretty obvious from email chains when it was happening.

 

Only if you can get hold of the email chains in the first place! Not straightforward if they were happening completely exclusive of school accounts.

Posted
Only if you can get hold of the email chains in the first place! Not straightforward if they were happening completely exclusive of school accounts.

 

Which is why Staff must use school systems for school business. If they start mixing the two it will become obvious that they are doing so and thus their personal account will get involved.

 

Staff really need proper training on how to protect themselves and their career. It needs to include both data protection and Safeguarding risks. And it needs to scare the pants off them in some cases. I used to do it as part of the induction of every new member of staff at my last school on their first day of employment. It was effective.

Posted
Recently went on some updated GDPR training. He was quite clear that you shouldn't be doing it and the words" just incase" he clearly stated no don't do it.

 

How does your DPO deal with SARs? Has the DPO reported to the Governors/HT over personal Gmail accounts?

 

We had a SAR not long ago and the pile of work was ridiculous but had to be done. Emails had to be copied, paper copies made, our MIS data exported (including scanned/documents) and making sure every external site we used was included. All that information had to be double checked to make sure it didn't include personal details of anyone else. We even got told during the training that we should be redacting more information than what we do. Every person in this seminar failed the task.... including me and our DPO. We should be redacting MUCH more and only the directly related data should be allowed.

 

DPO left. Waiting for new DPO.

BTW HT and DHT agreed to have corporate Gmail account. I have purchased the domain but waiting for the checks to be finished. I understand that being a school it is complicated to do the company checks.

Posted
I have a question - why is this being taken to "SLT"? Why not the DPO, the head or the chair of governors/trustees? They do realise that data breaches can now lead to rather large fines right?

 

SLT don't agree that school can be fined.

Posted
Or one that decided to appoint a completely untrained member of staff to handle the DPO responsibility because the legal "experts" working for the local authority said that was ok!

 

I can echo this!

Posted
SLT don't agree that school can be fined.

 

Hmmm - so who exactly do they think would be held responsible if, for example, all the special needs reports were accessed due to carelessness??

 

you???

 

anyone any examples of school being fined - a concrete example might be needed here

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...