Jump to content

Recommended Posts

Posted

Hi

 

I've read the sticky thread above

http://www.edugeek.net/forums/data-protection-information-handling/196381-gdpr-new-staff-accounts-access-data-before-official-start-date.html

 

I'm wondering if anyone has an NDA to give staff so they can access the network before September that they would be willing to share. HR and us are in agreement that access shouldn't be given before September. However the HT is really pushing for it.

 

Signing our AUP I don't think will cover it so wondered if people went down the NDA route

 

Thanks

Posted

So long as they have signed a contract of employment I don’t see why an AUP isn’t sufficient.

 

If you are very concerned you could even adapt the wording of your AUP to say “Staff, Governors, contractors and Visitors/Guests” instead of just Staff

 

I can’t think what an NDA would have in it that an AUP doesn’t have. For example it should already have content about data protection, confidentiality, appropriate use of email etc

  • Thanks 2
Posted

Agree with others that signing AUP is sufficient. Additionally, when I discussed this with HR expert and they pointed out, for teaching staff, they have a professional status and code of conduct to follow. Breaching that could seriously jeopardise their career, so it was felt other signatures/paper-work not necessary.

 

Some schools I worked with have a slightly stricter attitude with non-teaching staff, but it was rare for them to need any access before start of contract. I'd be interested to hear the HR's reasoning, as in this case I'd go with the head's decision. As @Zammo suggests, if your AUP doesn't provide the required assurance, then probably better to change that. NDA's aren't really appropriate in a school - I met them when working with IBM, but that was to protect intellectual property and I've seen then as part of a package when leaving employment (usually as part of a 'separation' agreement with disputed employment issues) and neither apply in this scenario.

  • Thanks 2
Posted (edited)
So long as they have signed a contract of employment I don’t see why an AUP isn’t sufficient.

 

HR manager at my previous school said contracts of employment aren't sufficient, as they have a start date of 1st September, so don't apply to access granted before that date.

 

All staff here sign a confidentiality agreement along with the contract, and are only granted access to data (whether that's IT access, hard copy or discussions about specific students) once they've signed it. I didn't really question it at the time or wonder why it wasn't in the main contract; I didn't object to the terms, so I signed it. I wonder if it is an LA legacy or because support staff don't necessarily have the same codes of conduct as teachers, or maybe LA felt it was necessary in schools where data is often shared prior to employment start date.

Edited by enjay
Posted

We allow staff access to email and their logons from August the 1st but restrict access to the MIS until 1st of September. They have to get their login details from us and we give them the AUP and a crash course induction.

 

We have the fight every year, the line managers want the staff set-up ASAP, the Data Protection bod screams blue murder and we compromise on the previous solution. It is messy and I can understand the issue but I'm never quite sure what loophole could be exploited, what the new member of staff is not covered by. If they were to leak data then surely they would be terminated and the usual processes followed? They can't just yell "Neh neh I'm not an employee yet" and we would have to shrug and suck up that they fooled us.

Posted
We allow staff access to email and their logons from August the 1st but restrict access to the MIS until 1st of September.

 

That's probably a reasonable framework and a good compromise between HR's wishes and T&L wishes, but do consider what's not in the MIS though - SEN profiles, EHCPs, details of meetings with ed psych or social care, etc. are typically on file servers not the MIS. We have Go4Schools, so for us even more of the data is not in SIMS (in fact, mainscale teachers only ever use SIMS to write Year 11 reports!).

Posted (edited)
We allow staff access to email and their logons from August the 1st but restrict access to the MIS until 1st of September. They have to get their login details from us and we give them the AUP and a crash course induction.

 

We have the fight every year, the line managers want the staff set-up ASAP, the Data Protection bod screams blue murder and we compromise on the previous solution. It is messy and I can understand the issue but I'm never quite sure what loophole could be exploited, what the new member of staff is not covered by. If they were to leak data then surely they would be terminated and the usual processes followed? They can't just yell "Neh neh I'm not an employee yet" and we would have to shrug and suck up that they fooled us.

 

If they were to leak data then surely they would be terminated and the usual processes followed?

 

You have "usual processes" for non-employees having access to students' PII and potentially leaking it? Cool. How do they differ from the "usual processes" for staff leaking PII? Is it not easier to have a "usual process" to not give people access in the first place. Something something ounce prevention something something pound of cure.

 

They can't just yell "Neh neh I'm not an employee yet" and we would have to shrug and suck up that they fooled us.

 

Well I mean, they could well say "Neh neh I'm not an employee yet" in the sense that your org will still be responsible for the leak (if not more so, you chose to give non-employees access!) and voiding their contract may well be small comfort compared to the bother the school is in...

 

 

Sorry, I'm being slightly frivolous but do think about whether or not your liabilities and processes for staff leaking data are fit for purpose for non-staff being given to access to data which they subsequently leak.

Edited by Roberto
  • Thanks 1
Posted

They get nowt here until their contract starts. Bluntly - they're not an employee here until that point, so shouldn't have access to anything much until then. I'm sure it can be covered with other agreements and I know that some staff want to hit the ground running, but I know our policy means we're much better covered.

 

If they were a PGCE student on second placement, then got a job here straight from that, I may reconsider.

Posted
I know that some staff want to hit the ground running, but I know our policy means we're much better covered.

 

Like any access to data, it's a cost-benefit analysis. What is the likelihood a new staff member is going to intentionally leak your data? What is the likelihood they will accidentally leak the data (this will vary person-to-person, in the main part depending on what data protection/GDPR training they've received)? What is the impact on T&L of them not having access? Are there other ways you can provide access to the bits they actually need, e.g. SoW and maybe some SEN profiles, without granting everything else? SoW can be emailed to personal addresses, for example.

  • Thanks 3
Posted
They get nowt here until their contract starts. Bluntly - they're not an employee here until that point, so shouldn't have access to anything much until then. I'm sure it can be covered with other agreements and I know that some staff want to hit the ground running, but I know our policy means we're much better covered.

 

If they were a PGCE student on second placement, then got a job here straight from that, I may reconsider.

 

But I would have thought the contract would just signpost to other policies such as a the AUP and CoC... in which case you can just present those earlier surely?

 

Im not sure what you mean by "our policy means we're much better covered"... in what way are you better covered once their commencement date has passed?

 

If DP is done correctly, then a premise of granting the least access necessary to perform a role should already be in place. That means that incoming staff should be given the access needed to prepare for their new job, staring from "visitor" permissions and building up. Having one size fits all approaches to access just leads to people bending and breaking the rules as they are not able to do their job.

 

Example: head of history wants access for their new teacher who is going to be teaching classes staring on 3rd September. Contract does not start until the 1st which is then 2 days of INSET. Realistically no teacher would want to go into their first day blind. IT say "no, sorry the policy is clear". What does the head of history do? Either ask SLT to intervene (best case) or start emailing documents, information etc across to the private email.

 

In this example a worse situation has been created by an inflexible policy

 

Instead. what could have happened is the new teacher be presented with a copy of AUP and CoC and asked to sign and agree. Access is given to the folders they need and nothing else beyond. When the contract starts any additional access is given if needed.

 

If you wanted to look at it another way, you could analyse the risk of granting access. Is the risk of breach/misuse greater with an incoming member of staff? is the likelihood greater? if so then what can be done to mitigate?

 

Finally remember your AUP should cover all sorts of people, not just staff who have signed contracts.

Posted

I think this thread has devolved into one of the big issues with GDPR rules. People treat it as a blocker to schools doing their jobs - which is not what they're there for.

 

Simply put, follow the proper processes for making your decisions about whether to give access. Do a DPIA. Ensure your new staff sign agreements tying them to the terms of their contract and your internal policies from the day they sign them, and I cannot see a reason why you couldn't give them access before they start.

 

We generally don't do that here, unless it is pushed for by someone high up (we have done it for one member of staff here this year, based on our CEO's say so). All in all, we should be covered.

 

In reality, what is the difference between an employee signing an employment contract stating they'll abide by policies, and a non-employee signing an agreement stating they'll abide by policies? An agreement signed by 2 parties is a legally binding contract regardless of whether it is an employment contract, or a data access agreement.

  • Thanks 2
Posted

I am always confused by this problem, as I understand it the AUP & etc. is a contract and unless you have got wording about start dates or employment status it is applicable from the moment is is signed therefore, the school has done it's due diligence in getting your already vetted (or they would not have been offered a job) prospective member of staff to sign the AUP, & etc. policies. Nothing magic happens on the day the employment starts to stop a user from being careless or malicious.

 

As I am not a legal expert I always just kick this upstairs and my current school follows my reasoning as above but I don't know how much of this is due to a stunning legal argument and how much is due to staff moaning about needing access. The correct answer would be to move the contract dates but that's not going to happen.

Posted
"our policy means we're much better covered"... in what way are you better covered once their commencement date has passed?

Only before the contract starts. Afterwards it's the same.

 

We do try to provide them with SoW etc, usually emailed to a personal address (as there's no students names or anything confidential in there). As I say, it's not that our policy is right, just that it's one way of doing it that covers our behinds a bit.

  • Thanks 1
Posted
As mentioned before, if they are doing anything prior to their contractual start date, they are being a volunteer, and so would sign anything that a volunteer would sign.
Posted

I don't want to come across as being awkward but...

 

The school is looking to implement something that has a legal element to it. Coming on the internet and taking advise from "random people" isn't a good idea. Shouldn't the school contact legal professionals. Especially if it comes to legal action down the line.

Posted
As mentioned before, if they are doing anything prior to their contractual start date, they are being a volunteer, and so would sign anything that a volunteer would sign.

 

While @FN-GM is correct and legal advice should be sought and followed for my own education why does a user need to sign two sets of AUPs? As long as it has has no mention of employment status or dates it is in legal terms a contract between the school and the signatory stating the expectations for use of the school's computer equipment. These should not change between a volunteer and a member of staff or in fact a student or guest and a member of staff.

Posted
While @FN-GM is correct and legal advice should be sought and followed for my own education why does a user need to sign two sets of AUPs? As long as it has has no mention of employment status or dates it is in legal terms a contract between the school and the signatory stating the expectations for use of the school's computer equipment. These should not change between a volunteer and a member of staff or in fact a student or guest and a member of staff.

 

He doesn't say something separate, just that a teacher working before their contract kicks in would be classified as a volunteer so get them to follow the same processes you would any other volunteer and treat them like any other volunteer, for example with their level of access. If you have a single AUP, which as you say is a benefit, that a volunteer would sign then get them to sign it. If it is a single AUP then they won't need to sign a new one once their contract kicks in as you will have one on file already.

  • Thanks 1
Posted
While @FN-GM is correct and legal advice should be sought and followed for my own education why does a user need to sign two sets of AUPs? As long as it has has no mention of employment status or dates it is in legal terms a contract between the school and the signatory stating the expectations for use of the school's computer equipment. These should not change between a volunteer and a member of staff or in fact a student or guest and a member of staff.

 

Depending on how the AUP is constructed, it may signpost the Staff code of conduct or other policies.

Posted
While @FN-GM is correct and legal advice should be sought and followed for my own education why does a user need to sign two sets of AUPs? As long as it has has no mention of employment status or dates it is in legal terms a contract between the school and the signatory stating the expectations for use of the school's computer equipment. These should not change between a volunteer and a member of staff or in fact a student or guest and a member of staff.

AUPs should absolutely change depending on the status of the individual. You can tell a member of staff not to do certain things, but you can't tell a volunteer or a child the same things. For example, you'd include references to data protection and safeguarding requirements in a staff AUP, but not a children's AUP. Not to mention, age matters - a document written for adults to sign should not be given to children to sign - they just won't understand it. You must spend some time writing a specific AUP for children in language they can understand.

 

We have a different AUP for general staff/governors/trustees, IT staff, volunteers, and children.

Posted
Not to mention, age matters - a document written for adults to sign should not be given to children to sign - they just won't understand it. You must spend some time writing a specific AUP for children in language they can understand.

 

Yes and no. Could an adult not sign one written in language a child can understand?

Posted
Yes and no. Could an adult not sign one written in language a child can understand?

And then you're back to the other point - things that aren't relevant to children. So you'd end up writing an AUP, in child friendly language, for adults only, as it'd contain things that don't apply to children... I think this may also be down to the age of the children some of you have in your schools. All of ours are below 13.

Posted
And then you're back to the other point - things that aren't relevant to children. So you'd end up writing an AUP, in child friendly language, for adults only, as it'd contain things that don't apply to children... I think this may also be down to the age of the children some of you have in your schools. All of ours are below 13.

 

Is there much in an AUP which isn't relevant to children though? Data protection and safeguarding come under different policies, so they AUP is more for things like "don't break the computers", "don't try and bypass the security", "don't access inappropriate materials or resources", "don't do any commercial work on them". I don't have an issue getting our Y11-13 students to sign those things, YMMV with the age of your students though, I'd forgotten you're at a middle school.

Posted
Is there much in an AUP which isn't relevant to children though? Data protection and safeguarding come under different policies, so they AUP is more for things like "don't break the computers", "don't try and bypass the security", "don't access inappropriate materials or resources", "don't do any commercial work on them". I don't have an issue getting our Y11-13 students to sign those things, YMMV with the age of your students though, I'd forgotten you're at a middle school.

Yes. For example, a clause stating staff must lock their machines when away from them - children *can't* do that in our schools. Rules about taking photos of children on phones. Very specific to adults, as children aren't allowed phones. Rules about reporting e-safety breaches, different processes for staff and children. There's a LOT of difference between our AUPs. The child AUP is a single side of A4. The staff one is 3 pages.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...