Jump to content

Recommended Posts

Posted
Should be easy enough to sent a "you have new email" message to their personal account if they don't check gov account much?

 

Funnily enough, this is exactly what I was asked about back when we were initially provisioning governors' accounts. I couldn't figure out a way to do it (Gmail).

Posted (edited)

Named accounts for individual governors- generic aliases for specific roles... chair@ clerk@

 

It’s not rocket science to do this. Non techies probably don’t have the knowledge to understand why things are done this way.

 

There is no official advice on email for governors @TMBS. Use your common sense and a lot of patience to steer them into the correct solution for GDPR and Safeguarding, etc.

 

I’m on the run at the moment, but I am sure @GrumbleDook share his wisdom if he is about

Edited by elsiegee40
Posted
Funnily enough, this is exactly what I was asked about back when we were initially provisioning governors' accounts. I couldn't figure out a way to do it (Gmail).

 

https://stackoverflow.com/questions/10420435/trigger-google-apps-script-by-email hacky.

 

https://pseudo-server.com/blog/gmail-unread-email-display-esp8266-oled-mqtt/ maybe overkill

 

https://chrome.google.com/webstore/detail/notifier-for-gmail/dcjichoefijpinlfnjghokpkojhlhkgl?hl=en

Posted

I just need to add that Gov1@ is a ridiculous idea. Far too much risk of the wrong thing being sent to the wrong person.

 

When we governors are dealing with highly sensitive things like exclusion or staff discipline it’s vital that only the governors on the panel are contacted.

 

You probably know that anyway @TMBS, but it’s worth reiterating

Posted
I just need to add that Gov1@ is a ridiculous idea. Far too much risk of the wrong thing being sent to the wrong person.

 

When we governors are dealing with highly sensitive things like exclusion or staff discipline it’s vital that only the governors on the panel are contacted.

 

You probably know that anyway @TMBS, but it’s worth reiterating

 

Good point!

 

at my last school I suspect that such things MAY have just gone to their own private email addresses - for reasons of privacy and security

 

 

and yes - I did comment - many times

Posted

Use of their personal email accounts can work for Governors ... but there are risks.

This is why things like GovernorHub can work instead.

 

A low risk approach is to have named accounts, segregation from the general staff and students, a variation on the starters/leavers to ensure the relevant close down of accounts and even consider restricting where those can accounts can send/receive emails from.

 

Shared mailboxes for generic accounts for chair@ etc. can be useful, but you need to remember that these could be used by a whistleblower and so you do need to be careful on confidentiality as to who access things.

 

If there is specific guidance then review, translate and implement. If you can post a link to that guidance it would be appreciated by many.

Posted
Would it be acceptable for them to use personal accounts to send each other information which included sensitive stuff - like for example details of a bullying case brought by a member of staff against an SMT member??
Posted
Would it be acceptable for them to use personal accounts to send each other information which included sensitive stuff - like for example details of a bullying case brought by a member of staff against an SMT member??

 

Many governing boards operate with personal email accounts. However, they should never be used for sensitive data, especially now GDPR is in force.

 

When ours did, we always used paper for the sensitive stuff. It was never sent by email.

 

We now download papers for regular meetings from the cloud. It’s not sent by email, just notification to login to our account and download it.

 

For exclusion and staff panels, the sheer volume of paperwork attached has always meant that scanning and uploading it, then subsequently downloading it would take hours. Our clerk produces photocopied packs in proper files with file dividers that are collected from school.

  • Thanks 1
Posted

We issue our governors in schools @Governors.school.co.uk email acccounts

 

they cant email outbound, 2FA is enforced. and this is the only account any email is exchanged with... might be a bit draconian but keeps control in our hands

  • Thanks 1
Posted
Many governing boards operate with personal email accounts. However, they should never be used for sensitive data, especially now GDPR is in force.

When ours did, we always used paper for the sensitive stuff. It was never sent by email.

We now download papers for regular meetings from the cloud. It’s not sent by email, just notification to login to our account and download it.

For exclusion and staff panels, the sheer volume of paperwork attached has always meant that scanning and uploading it, then subsequently downloading it would take hours. Our clerk produces photocopied packs in proper files with file dividers that are collected from school.

I have seen paper used for sensitive data, both operationally in school and as a governor on the basis of it helping to be GDPR compliant. It can address the control of data flow up to a point and is arguably less 'hackable' than electronic storage, but it lacks encryption. My other concern is ensuring retention polices are adhered to. Retaining the data securely for the required time period, but also the subsequent deletion once retention periods are up - which may be years - and the challenging areas. The recipients of such documents will often have completed their stint in the role long before the retention period is up, so storing and presumably shredding are things to be considered. All-in-all, it's not an easy situation to manage, whether it's paper based or electronic.

 

A big positive of GDPR is that all of this is now something that gets discussed and considered much more than it used to. Overall, things have improved in this respect which is good, but ultimately it comes down to having people treat the data appropriately and that's why I feel training is so important.

  • Thanks 1
Posted
I have seen paper used for sensitive data, both operationally in school and as a governor on the basis of it helping to be GDPR compliant. It can address the control of data flow up to a point and is arguably less 'hackable' than electronic storage, but it lacks encryption. My other concern is ensuring retention polices are adhered to. Retaining the data securely for the required time period, but also the subsequent deletion once retention periods are up - which may be years - and the challenging areas. The recipients of such documents will often have completed their stint in the role long before the retention period is up, so storing and presumably shredding are things to be considered. All-in-all, it's not an easy situation to manage, whether it's paper based or electronic.

 

A big positive of GDPR is that all of this is now something that gets discussed and considered much more than it used to. Overall, things have improved in this respect which is good, but ultimately it comes down to having people treat the data appropriately and that's why I feel training is so important.

 

Again, I can only go from 12 years personal experience of being a governor and a MAT trustee.

 

Where sensitive paperwork is handed over, it gets given back to the clerk at the end of the relevant meeting. I have never seen anyone want to hang on to it.

 

Where the same paperwork has been required again, for appeal at an independent panel, it has been retrieved from the Clerk’s secure storage and used before going straight back to the Clerk for destruction after the appropriate interval has passed.

  • Thanks 1
Posted
Immediate handback and secure storage addresses most of the risks and generally clerk's have had GDPR training. Unfortunately, our governing body dropped having a qualified clerk to offer the role given to one of the admin staff. It was a cost saving exercise and part of a number of changes post joining a parent MAT.
  • Thanks 1
  • 2 weeks later...
Posted (edited)
We issue our governors in schools @Governors.school.co.uk email acccounts

 

they cant email outbound, 2FA is enforced. and this is the only account any email is exchanged with... might be a bit draconian but keeps control in our hands

 

This is my intention too, and I have created Office 365 Email Accounts (e.g. Outlook) for our Governors, using the governor.schoolname.com convention, then implementing the following...

 

 

I am going through the same process of setting up email accounts specifically for our Governors (as opposed to them using personal email accounts etc.) too.

 

Working on the basis of using a sub-domain, (e.g. name@governor..com) within our existing Office 365 Tenant, combined with GAL (Global Access List) Segregation. (https://gallery.technet.microsoft.com/GAL-Segmentation-or-GAL-245d9440)

 

This has been successfully created, however I am still researching and looking for confirmation that (governors) will not be able to access any (other) Office 365 Resources (SharePoint, Calendars, anything else basically!) that have been created by Staff (who are in same Tenant, but different / parent domain) especially when some Governors are parents. - If anyone knows how to do / check this etc. any advice would be very much appreciated!

 

However, even though I have successfully setup GAL Segmentation when for example you go into calendar, and select "Import Calendar" and "From directory" you are able to list / view all accounts (e.g. schoolname.com) outside the scope of the governor GAL Segmentation.

 

After contacting MS Support they state that 'all' accounts within a single Microsoft Office 365 Tenancy, regardless of sub/domains used are part of the same 'company'. Therefore, I assume(?) that other Office 365 resources created (e.g. Streams whereby the default is accessible by "Everyone in your company") may also be accessible by the Governor accounts? I assume that this is, or would be no different from schools that use Office 365 for staff (schoolname.com) and students (e.g. students.schoolname.com)? Just wondered how you ensure content is not inadvertently accessible (by students)? I assume by specify specific groups / people?

 

Any advice would be greatly appreciated.

Edited by MYK-IT

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...