Jump to content

Recommended Posts

Posted

What is the exact legal position in the following situation;

 

member of teaching staff alows pupil to log in as them so that they can use the internet (the pupil is banned from playing games)

 

BTW the school as yet dosn't have a policy about this thats why i would like to know if/what the legal position is i.e. data protection etc..

 

From this i will be able to create a policy for the SLT to decide upon.

Posted

Aside from the legal position, this pupil (I assume he's been banned from playing games because he ignored instructions to stop) will have access to all that teacher's work and possibly sensitive material, with all the consequences that follow, such as being able to delete files and folders.

I'm not sure how the Data Protection Act (DPA) will work here, but my assumption is that the teacher will be responsible to some extent for giving him access to his area.

I know similar incidents happen here, despite staff being told not to do it.

Of 109 AUP's being handed out last September to all staff with laptops, 35 haven't been signed and returned yet.

Posted (edited)

Shouldn't be done. If you search hard enough on here you will find people deal with it in different ways depending on the authority they have. The pupil has not been given permission to access the network as a member of staff. Ok the actual member of staff has given the pupil permission, but if like most networks, this also provides information that is restricted to staff members only. A pupil logging on will be able to see everything that a teacher can see(potentially private information about pupils which should be available for all staff only) I'm sure you could make a case for breaking the computer misuse act (if you search for this on here you will find many similar questions) and both parties are probably at fault

 

Others will probably be able to give you a better answer than I can give, but personally I think that both parties should have their accounts temporarly banned(at least internet access) to make the point that this is a serious offence. Unfortunately I am not in a position to ban staff members(even though I really want to) this would be up to senior management to decide depending on the offence.

 

If you haven't got any policies in place there is probably not a lot you can do. But are you saying that no one signs an acceptable use policy when they join the school? If so you need to get one ASAP to cover for such actions. Or are you asking for a policy which specifically covers pupils using staff accounts?

Edited by pallen
Posted

You need an AUP and fast. I suspect that unless it is written down that users may not share their logon with anyone, you have no case against the staff member concerned.

 

Only yesterday I was training new staff members and pointing out that using somebody else's logon was a disciplinary offence. They looked shocked, but it's in the AUP.

 

Hopefully someone like Grumbledook will be along soon who knows a lot of the legal side.

Posted
You need an AUP and fast. I suspect that unless it is written down that users may not share their logon with anyone, you have no case against the staff member concerned.

 

Only yesterday I was training new staff members and pointing out that using somebody else's logon was a disciplinary offence. They looked shocked, but it's in the AUP.

 

Hopefully someone like Grumbledook will be along soon who knows a lot of the legal side.

 

Thats why i need a "legal" definitian so that i can create an AUP for Staff. The legal bit is the frightner so to speak.

Posted
In the absence of a policy the Head Teacher is legally responsible for the member of Staffs action. This includes a large fine when prosecuted for a DPA violation.
Posted
What is the exact legal position in the following situation;

 

member of teaching staff alows pupil to log in as them so that they can use the internet (the pupil is banned from playing games)

 

BTW the school as yet dosn't have a policy about this thats why i would like to know if/what the legal position is i.e. data protection etc..

 

From this i will be able to create a policy for the SLT to decide upon.

 

Some of our teachers do this as well and we can't stop them as they say it makes their job easier...

Guest theeldergeek
Posted

Of 109 AUP's being handed out last September to all staff with laptops, 35 haven't been signed and returned yet.

 

Lock their accounts until they do return them.

Posted
Some of our teachers do this as well and we can't stop them as they say it makes their job easier...

 

Thats where the problem lies. Kids have a legit ban but other staff need them to have access.

Posted

Remember under the Data Protection Act the school has to make sure all reasonable measures are put in place to prevent the missuse of data stored on its servers. Because this member of staff is letting students use their login, which creates the opportunity for data missuse and the school is now aware of it, I think you'd be well within your rights to restrict down their rights on the system to ensure the school is complying with the act.

 

That's just one angle you might like to take, but I'd get your SLT to authrise any such action as well as making them fully aware of the potential repercussions of things like this.

 

Mike.

Posted

If you are allowing people to access your network, they should abide by your rules. If you state that there should be no sharing of accounts then it should not happen. As elsiegee40 has said if you have it in your AUP everyone will know about it and breaking your rules means they should get whatever your SMT has deemed an appropriate punishment.

 

If it is in black and white, no one can argue. Get an AUP and fast, even if it means you have to put a provisional one on your intranet while SMT finalise it.

Posted
Also be aware that if you have no AUP, the LEA security policy usually clicks in as being the rule of law. So you might want to get a copy of that and see what it says.
Posted

The AUP should be part of the whole school policy, in the same way that your school's pay policy, behaviour policy, etc are. Get an AUP properly written out and accepted by the board of governors, and then get the school to inform all staff that it has become part of their contract (although if their contract already says they have to follow all school policies, which it probably does, then you just need to publish the new policy to the staff). That way there'll be no need to get anyone to sign anything (unless they disagree with it).

 

As far as I know, under UK law you don't have to sign a new employment contract for it to become legally binding - if you don't disagree with it in writing (within 3 months) it becomes your new contract.

Posted
Bit OTT but if you want hit them with the good old Computer Misuse Act. Unauthorised use of a network. Yes the student has been authorised by the member of staff but they don't have the authority to grant that access.
Posted
Just been doing a bit of reading on this :nerd: and apparently my previous posting is not quite correct: you should make the AUP part of the whole school policy but NOT make it part of the staff contract of employment. Apparently then you can amend it without the employees needing to agree to it (see http://www.infosec.co.uk/ExhibitorLibrary/9/Refresh_your_AUP_20.pdf for more info). You shouldn't need to get staff to sign it however since they've already agreed to abide by the whole school policy by taking the job in the first place.
Posted
Still need a simple "this is what the legal side is" so that i can use it as the worst case for SMT to look over :)
Posted
Remember under the Data Protection Act the school has to make sure all reasonable measures are put in place to prevent the missuse of data stored on its servers.

 

Key word here is reasonable - it's one of those weasel words which lawyers use to keep themselves in jobs :-)

 

I don't know why the teacher let the pupil use the computer - it may just be that they're stupid or don't care about the school. It may be that the pupil had a really good reason for using a computer and the teacher listened to it and acted on it. I also don't know *how* the computer was used - eg was the teacher watching or did they just wander off and leave the pupil to it?

 

There obviously are good reasons not to let pupils use a staff login (we have a "guest" login which students can use if they can't log on for some reason; it's fairly restricted but it does give access to Moodle, for example - this means there's far less reason for a teacher to let a student use the teacher's login)

 

Past experience tells me that if you just tell a teacher "you're a *&^!%"; you shouldn't do that" then it doesn't help. If you can calmly and rationally get them to explain what they're doing and you can point out why they shouldn't then things are better. This won't always be the case - there are plenty of teachers (and IT technicians, network managers, any other occupation you care to mention) with no common sense - but it's generally better to try and keep things civil :-)

Posted

Taken directly from our DP guidelines for staff

7 Personal data will be kept safe from unauthorised processing and accidental loss, damage or destruction. This is one of the most important principles. This covers everything from ensuring that you do not share information with those who have no right to it, eg those professing to be ‘family members’, through to allowing unauthorised people access to a computer where you have personal, confidential or sensitive information, eg a student logging on to a staff laptop that has the SEN register on it, or sharing your password with another person, therefore allowing them complete access to all the information that you have.
Posted (edited)

rather than the DPA is it not more thoughly covered in the Computer Misuse Act 1990, I know wikipedia isn't 100% but an quote from there reads as follows

 

Thus, using another person's username or identifier (ID) and password without proper authority to access data or a program, or to alter, delete, copy or move a program or data, or simply to output a program or data to a screen or printer, or to impersonate that other person using e-mail, online chat, web or other services, constitute the offence. Even if the initial access is authorized, subsequent exploration if there is a hierarchy of privileges in the system, may lead to entry to parts of the system for which the requisite privileges are lacking and the offence will be committed

 

the full text of the Computer Misuse Act 1990 is to be found Here para 17 (5) could be used to highlight the act of staff logging students on as themselves?

 

I have to say in the schools I have worked in the back up of the Computer Misuse Act, and presenting this to SMT and govenors had the desired effect of reducing the practice of logging on students with staff accounts (there are always going to be the odd one that like to break the rules!!)

 

Also through this I had it highlighted that it was my decision as the NM to call in police if an offence had been committed even if the head didn't agree. This never happened fortunatly, but good to have that understanding!

Edited by buzzard
Typo!
Posted
Remember under the Data Protection Act the school has to make sure all reasonable measures are put in place to prevent the missuse of data stored on its servers.

 

Part of our IT policy is that computers in class rooms and other curriculum areas should not have access to MIS or other admin files and resources. Passwords do become compromised, and staff do leave PCs logged-on when they leave class rooms (you can't legislate against stupidity!).

 

It is a current issue for us as we are combining our admin and curriculum networks. We have set up scripts and GPOs to ensure admin resources are only available in offices and team rooms.

 

(I am not condoning staff letting pupils use their accounts – Our AUP clearly states that pupils must not use other peoples computer accounts, I would suggest it is very unprofessional for staff to allow them to do so.)

Posted

We had exactly this situation 2 years ago. I locked the staff member account, I locked their internet to whitelist, I logged them off. When they came up they tried to justify it, I reduced them to tears and hit them with the AUP, listed the whys and why nots, and said if they'd like to push it further, I'll call the LEA in and they can justify it to them..

 

Oh boy, did that make the point...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...