Jump to content

Recommended Posts

Posted (edited)

Hi

 

I have been asked to provide generic (Gov1@...) email addresses for our school governors, which I have said I'm not happy to do because of Safeguarding/Security issues. I've said I can create them individual emails, which isn't a problem. The clerk to governors has just emailed back saying that the chair and vice governor has approved it and they need them to comply with EFSA legislation (not sure what that is).

 

What does everyone else do? Do you allow generic emails? Does anyone know of official advice?

 

Thanks

Edited by TMBS
Posted
We don't allow anything generic. Generic = non-traceable and a safeguarding nightmare. It's your email system as a school, and the governors cannot instruct you to use it in a way that is not fit for purpose as they are not your managers. The head could though.
  • Thanks 1
Posted
Hi

 

I have been asked to provide generic (Gov1@...) email addresses for our school governors, which I have said I'm not happy to do because of Safeguarding/Security issues. I've said I can create them individual emails, which isn't a problem. The clerk to governors has just emails back saying that the chair and vice governor has approved it and they need them to comply with EFSA legislation (not sure what that is).

 

What does everyone else do? Do you allow generic emails? Does anyone know of official advice?

 

Thanks

 

We give our governors personalised individual email addresses. As for official advice, @elsiegee40 may be able to help.

 

By the way, I think you mean ESFA - Education and Skills Funding Agency; EFSA is the European Food Standards Agency. :p

  • Thanks 1
Posted

We have a generic one for the chair, "[email protected]" etc, but all the governor communications are sent to personal accounts. The school did set up named O365 accounts, but governors missed out on communications because they didn't by habit log in to that account. For mine, I set up e-mail forwarding but this was cancelled without communication at one point. I reset it up, but after several meetings where governors were out of the loop because of the attempt to switch to school controlled accounts, the CEO of the trust told the technician to reinstate communication to personal email accounts. Using generic ('Gov1@...) isn't really a safeguarding/security as you will know which person each account is for, but it's not a very sensible idea. The ESFA (not EFSA unless you are into European food safety :)) is the education skills and funding agency. They don't write laws, so this 'compliance' statement is the sort of thing often bandied about, but rarely backed up with a facts or links to the alleged legislation.

 

I suspect many of governors on here, like me, would argue that how you implement email communication securely to governors is an operational issue, and the chair and vice-chair should be advising what the strategic goal is and it's up to you and colleagues to decide how to achieve that.

 

There is still a requirement to adhere to the DPA, including all matters GDPR. In this instance, I'd suggest speaking to your DPO and ask for guidance - if you don't have a DPO to talk too, your chair and vice-chair have a more pressing issue.

Posted (edited)

No generic accounts here at all - every person gets one individually. If we want aliases on top of that so, "chair@" goes to a specific individual, that's fine. Or a distribution list address "governors@" which goes to all of them, that's fine too.

But a single shared address among multiple people? Not gonna happen.

 

Also, just to point out that governors are NOT executive staff. They do not get to make operational decisions like this, nor does the clerk to them. Operational decisions come from operational staff - CEO, COO, Headteacher, etc...

Edited by localzuk
  • Thanks 1
Posted
But a single shared address among multiple people? Not gonna happen.

I don't think the OP is saying one generic email for all the governors - but I could be wrong?

Posted
In which case, I wouldn't particularly have any issue with individual accounts being named "governor1@" "governor2@" etc... There's no safeguarding/data protection issues I can think of.
Posted
No generic accounts here at all - every person gets one individually.

Same at my school.

 

In which case, I wouldn't particularly have any issue with individual accounts being named "governor1@" "governor2@" etc... There's no safeguarding/data protection issues I can think of.

What about when a governor resigns (e.g. governor1@) and then their replacement is made to use the same number generic email address?

Posted
What about when a governor resigns (e.g. governor1@) and then their replacement is made to use the same number generic email address?

Why would you do that? The policy of delete and create new would still apply wouldn't it? I mean, we have people leave and new people with the same name join here sometimes, they end up with a different address.

Posted
Same at my school.

 

 

What about when a governor resigns (e.g. governor1@) and then their replacement is made to use the same number generic email address?

Yep. We did that years ago and the case made to me was that you just kept a table of who was allocated each email address on which dates. I argued that you were creating a solution to a problem that you'd created. It finally died when a previous head sent documents to the wrong governor and I was then asked "is there any easy way of identifying which email account belongs to which governor?"

 

We always struggled with governors failing to access accounts and therefore missing out on information (especially after we blocked forwarding to personal accounts). My recommendation is to use the governor's personal email accounts for communication, but NEVER use email to send confidential documents. Put everything on O365 or Google Drive and then you have much more control at the same time as increasing the chances of governors reading emails.

Posted
Ultimately, the best control is achieved by educating people. Whether O365, GMail, google Drive or personal accounts, in pretty much all cases they security is only as strong as the users password and possibly any 2FA employed. In every case, the confidential data will be on screen and can be printed, photographed, left open etc. Educate the governors and staff on best practice.
Posted

I'm chair of governors at my daughters school, they communicate with me via my personal email address, as does the LA when emailing me important/confidential documents.

 

I don't see the need for a school branded one ?

Posted
If they are sending confidential data to a personal address, they could be falling foul of GDPR - they can't control the connection between your email provider and theirs, so the emails potentially could be intercepted. It also means that they can't delete that data if they need to, or audit it for subject access requests etc...
  • Thanks 1
Posted

At my last school we had a generic gov account - but with an agreement that one specific governor would be the only one with access

 

When that changed to a different person then this would be documented in the meeting minutes and the new person would change the password immediately

 

The reason for this was that they wanted all governor emails to be recorded in one single place rather than gov1 having stuff about x gov 2 about y the gov3 takes over x and gets some about that

 

etc etc

 

worked fine for a few months - then that gov left for 'reasons'

 

just before I left I checked and it hadn't been accesses for over a year - possibly because I changed the password when the gov left and I wasn't told who was taking over from him

 

 

shows how much agreements and procedures mean

Posted
I don't quite get the rationale behind using governor1, governor2, etc. Anyone sending an email to an individual governor, or receiving one, would presumably first need to know the identity of whichever governor is assigned to whichever account. What does the obfuscation achieve?
Posted
Using generic ('Gov1@...) isn't really a safeguarding/security as you will know which person each account is for, but it's not a very sensible idea.

That was my argument as I wouldn't know who each account was for. I wasn't being provided with names, just a request for 15 generic accounts which the chair would give out. My concern from safeguarding stance would be if any of the accounts were used to contact students, register with 'adult' websites, etc and with security generic accounts are more liable to be hacked and compromised.

 

As a governor can you see why there might be the need for a generic rather than named account.

 

Thanks for your input/advice :)

Posted
By the way, I think you mean ESFA - Education and Skills Funding Agency; EFSA is the European Food Standards Agency. :p

That makes more sense! The clerk has put EFSA and I couldn't understand what Food had to do with it :D

Posted
Hi

 

I have been asked to provide generic (Gov1@...) email addresses for our school governors, which I have said I'm not happy to do because of Safeguarding/Security issues. I've said I can create them individual emails, which isn't a problem. The clerk to governors has just emailed back saying that the chair and vice governor has approved it and they need them to comply with EFSA legislation (not sure what that is).

 

What does everyone else do? Do you allow generic emails? Does anyone know of official advice?

 

Thanks

 

I am going through the same process of setting up email accounts specifically for our Governors (as opposed to them using personal email accounts etc.) too.

 

Working on the basis of using a subdomain, (e.g. name@governor..com) within our existing Office 365 Tenant, combined with GAL (Global Access List) Segregation. (https://gallery.technet.microsoft.com/GAL-Segmentation-or-GAL-245d9440)

 

This has been successfully created, however I am still researching and looking for confirmation that (governors) will not be able to access any (other) Office 365 Resources (SharePoint, Calendars, anything else basically!) that have been created by Staff (who are in same Tenant, but different / parent domain) especially when some Governors are parents. - If anyone knows how to do / check this etc. any advice would be very much appreciated!

Posted
Why would you do that?

Some people might only create a set number of generic accounts and then end up reusing them to save time/effort? :confused:

 

The policy of delete and create new would still apply wouldn't it?

It should. :)

 

I agree with @jthompson. Using generic accounts seems pointless since all governors will need to know which governorX@ email address belongs to each governor.

 

You might as well create named email accounts to start with!

Posted
I'm chair of governors at my daughters school, they communicate with me via my personal email address, as does the LA when emailing me important/confidential documents.

I don't see the need for a school branded one ?

Ultimately it comes down to individual's interpretation of what steps go towards meeting the requirements of the DPA and in truth it is an exercise of risk management. Key areas often quoted are control and access to data during and after your time as a governor. Often quoted is if there is a SAR (subject Access Request), then that's easier to deal with if all communications are in the schools logs. Also quoted is data retention rules - again more easily dealt with if the info is in-house.

 

From experience, if a school controlled system is set up, you will have to train the governor on it's use. That didn't happen at my school and ultimately it was scrapped in favour of personal emails at the CEO's instruction. Even with that training, some individuals in our governing body, (ex-head of school and not so au-fait with computers and emails!), even if successfully trained would always print everything off and cart it around. Unfortunately, as far as I am aware, there is no one authoritative set of guidelines/best practices for schools, something that many of us hoped the DfE could help with. That might be improved in future, but as of now, this same conversation is going on across the whole country with many opinions expressed, but little hard evidence of any of the approaches achieving 'compliance' in the eyes of the law.

Posted

Need to consider why they have emails, and why they're not accessing them, and changes over time.

 

Why do they have emails? To be sent confidential stuff? Why are they being sent that stuff? Is everyone getting it? Or just specific people? Should future people have access to it by default?

 

Should be easy enough to sent a "you have new email" message to their personal account if they don't check gov account much?

 

Aliases. chairgov@ goes to current chair, etc.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...