Jump to content

Recommended Posts

Posted
The purpose of staff training is to inform and educate the staff on the business processes and policies so that they can follow them in the execution of their work, you are correct that the AUP/Training is required to be kept up to date but depending on the policy it may never change, I assume most business' no smoking policies where written once in the 90/00's and have never been updated. Also to be honest the statutory defense is that the staff where provided training, not that they remembered it.

[/Quote]

So my question would be, do you hand out the no smoking policy every year? Yes, the statutory defence was they were provided training but that defense did not stand up as the training was considered stale, so pointless. I would class getting everyone to read an AUP and sign they read it is stale. But I am not an employment judge.

 

I was told in about 2010 to distribute IT policies every year by an SLT after they had consulted with a employment lawyer and they quoted the AUP related case I cant find a citation for. I am not a solicitor or have any formal training in law so I could be wrong however the reading I get from the ruling, is not that the training was at fault but it was delivered too long ago.

[/Quote]

Fair enough if you were told to do it, but that was in 2010, over 13 years ago. Things move on and without a case to back it up and not having heard of it ever my view is that I'm not going to blindly do something and I would question why anyone would without an ongoing instruction, and even then blindly doing somehting unquestionably seems pointless.

 

The training had been delivered several years ago

We accept that that training had covered harassment related to race. However, in all cases the training which had been delivered was several years before the events in question and was clearly stale. We do not accept that the respondent had taken all reasonable steps to avoid discrimination in the workplace for a reasonable step would have been to refresh that training.

 

The training made clear what to do but it wasn't done

The training had made plain to the employees what they should do if they heard unacceptable remarks and they all failed to follow that guidance. The training patently needed to be refreshed and it would have been a reasonable step to do so.

 

The company lost the case

The statutory defence advanced by the respondent is not made out.”

 

Not from the ruling but from the Nelsons Business Law link

In fact, Allay (UK) Ltd had provided Mr Pearson with refresher training after finding out about the comments that had been made, which the Employment Tribunal found supported their assertion that in the employer’s mind, that would have been an effective step to take.

[/Quote]

 

Interesting as one of the other links says the training had been done recently but the actual training was stale. But even if that was all correct, that case is about harrasement, equality, not policies and staff's responsibility of reading them. It is not only a different ball game, but a different pitch and shaped ball.

 

Also as a safest path approach I am not doing any harm by distributing AUPs regularly.

You could argue that it is doing harm by desensitising staff and leading to staff just ticking or signing regardless and not reading or understanding what has been sent out.

 

My view is, if a policy is changed or updated, staff should be informed. Staff should be reminded of their responsibilites and where to find policies.

But I am not a lawyer, if it makes you and the school feel like something is being done then that may be benefit enough.

Posted

I think "smoking training" is a red herring. It is simple - "thou shalt not smoke on company premises, or in company vans. Thou shalt comply with the law in place at the relevant time".

 

Whereas AUPs tend to be longish documents, covering things that the layman may have no clue as to what it means. (Maybe they should but..) MFA, AUP, and a whole host of other TLAs that obfuscate rather than enhance a document.

 

Of course, anyone HERE will have a nice, simple, plain English AUP, won't we?

Posted

I came to this one a little late and it has been an interesting discussion.

There are a lot of things that I could repeat based on some of the replies, but I hope people don't mind if I bring together a summary.

 

Thank you @pete, for reminding people that Safeguarding does not trump GDPR, nor does GDPR trump Safeguarding. Whenever you do something with personal data you need a purpose (reason, requirement, etc.) and also a lawful basis (Legal Obligation, Consent, Public Task, Legitimate Interest, Contractual Obligation, Vital interest), and for Special Category PD you need an additional basis too. Safeguarding is the purpose you are processing/handling data, including sharing it with other agencies who need it for them to do their bit on safeguarding. Yes, you need a lawful basis and Legal Obligation or Public Task is the usual option here (the choice between the two is for a debate at another point). It is as simple as that. You need to share something with LADO? Fine.

It says to be mindful of data protection principles. You need to give stuff to LADO ... don't just email super sensitive stuff without encrypting it ... don't leave it on the bus ... give it to the right person. There's nothing there about anything trumping anything else. Generally, it's just common sense.

 

AUP - Yes, getting people to read through *and understand* periodically is a good thing. Yes, there have been cases where the lack of renewed engagement has gone with the employer and some with the employee. Context is king in all of these. In short, whilst there is an expectation of staff to keep up to date, they need to have the opportunity and the access. Access is not just whether they have permissions but whether it is accessible. A legalese doc does not help anyone. KCSIE needs the update each year because a) it changes and b) the DfE wants to make sure that there is a consistent(ish) level of understanding. They have gone for the lowest common denominator on that, which is fine. Getting the AUP agreed upon each year is also understandable. Even if KCSiE has not created a change, it is good to remind people of expectations. Is the AUP a contract? For your children and parents, generally no. It may be that there is a home-school contract which is in place that does have some standing and it refers to the AUP as part of a set of 'rules'. For staff, if it is written as such, it is part of the school policies and procedures, and tied in with their contract of employment. This is not always the case, so before anyone says x, y, or z, it is worth checking.

 

Personal devices. Now this is a very difficult area. This is so reliant on having serious risk assessments run that it is scary to still see Heath-Robinson style approaches. Whilst the use of certificates on devices to ensure that MITM interception can take place on school owned and managed devices would readily fall under the lawful basis of Legal Obligation/Public Task, there will be concerns about whether this is intrusive. It is not that there is a balance between individual rights and the school's needs. The school's needs have to ensure they are using the least intrusive way. That does not mean that they don't do it if it is intrusive. It still remains as objectionably intrusive and has a high risk still, then the school needs to take the DPIA to the ICO. I have yet to hear of any school doing this, or schools being taken to task about their DPIAs specifically on this matter when the ICO did their review of MATs. School-owned devices that stay on-premise are generally seen as acceptable, but you have to be transparent about this. That cannot be stressed enough. By introducing this to 1-1 scheme devices, which are still owned/managed by the school, then additional factors have to be considered for use outside of school hours, off-premise and by family members. Generally, this is managed by selective use of the tools off-site/outside of school hours. I've written guidance about Privacy by Design which covers this for schools. Again, context is important here and it may be that the DPIA considers, in addition, at risk children being supported differently even though it could be more intrusive. But when it comes to personal devices ... it would not be practical for a school to rely on Legal Obligations or Public Tasks as the Lawful Basis as there is no requirement for children to use personal devices for their education. The school cannot use Legitimate Interest (not available for Public Authorities for their core purposes), Vital Interest is about saving people's lives ... so that leaves Contract and Consent. I mentioned contract earlier and the difficulties, so that leaves consent.

 

At this point you start to wonder whether the tool being used is the problem rather than the purpose. If a tool was there to support learning, rather than be seen purely for filtering/monitoring, then you have a different position. And this is why a number of tools have keystroke logging in place rather than the interception. It is not that one is better than the other, they generally can be used alongside each other, but it is sometimes about what it the least intrusive.

 

And this is where we talk about balance. We would like parents to agree to use tools, but also want them to know that schools are managing things effectively, respectfully, transparently and appropriately. Being clear that whoever you work with is under clear instructions via the Data Processing Agreement only to do what the school has agreed. That means any sub-processors used by that vendor are also restricted to those instructions (or more secure). Ensuring people know that you don't share with any 3rd parties (other Data Controllers who can use that data for whatever they want) but *the school* may in turn share that data with other agencies (LADO, NHS, etc.). The school making thoughtful decisions about where they want the tools to be running and when.

 

If a parent is raising this, it is usually a sign the school needs to do more work on their stakeholder communication, or needs to rethink their DPIA and look at what less intrusive options there could by with personal devices. It may be that this is a parent who works in the privacy arena but does not know how it works across education (we all know that there are some marked special cases in education), so could be a good evangelist for you after some initial dialogue.

 

I think I've summed up everything others have put, and put it into a general order.

  • Thanks 4
Posted (edited)

As a parent I filter my child’s internet daily I break his privacy but I have a duty of care. So I am confused as to why this comes up as an issue.

 

Why we got such daft laws we adults looking after kids of and we are trying to keep them safe. It going to be great in few years we protect a child’s privacy but they got abuse online that go down well.

Edited by nicholab
Posted

I would recommend the school get legal advice before responding as I would assume responding inaccurately would leave you open to potential legal action in the future.

 

Maybe your LA legal team could help?

  • Thanks 1
Posted
As a parent I filter my child’s internet daily I break his privacy but I have a duty of care. So I am confused as to why this comes up as an issue.

 

Why we got such daft laws we adults looking after kids of and we are trying to keep them safe. It going to be great in few years we protect a child’s privacy but they got abuse online that go down well.

 

The laws aren't that daft. A chunk of what we think of as data protection and safeguarding both come under human rights. As children grow, so does their need for independence and protection of their own rights ... there is no exact age but you would not be as invasive for a 12 year old as you would a 5 year old. As they get older, you may be more specific in the things you are looking at as a parent but there are far more places that you give them their independence.

 

Prof. Sonia Livingstone's book on Parenting in a Digital Age is a really good place to start on this, and whilst I don't always agree with how she and the other researchers look at how it crosses into education, they do raise valid concerns.

 

Within schools we *have* to have accountability. If nothing else, the IICSA has shown that. That means schools have to be able to justify when they are using invasive means of protecting children, and they have to be able to justify the where and when.

As I have said, the question raised to the OP may have not been worded as effectively as it could have been around EdTech, but it is a valid one and one that should already be transparent to the parent.

  • Thanks 3
Posted
The laws aren't that daft. A chunk of what we think of as data protection and safeguarding both come under human rights. As children grow, so does their need for independence and protection of their own rights ... there is no exact age but you would not be as invasive for a 12 year old as you would a 5 year old. As they get older, you may be more specific in the things you are looking at as a parent but there are far more places that you give them their independence.

 

Prof. Sonia Livingstone's book on Parenting in a Digital Age is a really good place to start on this, and whilst I don't always agree with how she and the other researchers look at how it crosses into education, they do raise valid concerns.

 

Within schools we *have* to have accountability. If nothing else, the IICSA has shown that. That means schools have to be able to justify when they are using invasive means of protecting children, and they have to be able to justify the where and when.

As I have said, the question raised to the OP may have not been worded as effectively as it could have been around EdTech, but it is a valid one and one that should already be transparent to the parent.

 

Currently using still using Qustodio on my child device and this is the same as when younger. Every app has to be approved and Qustodio tells me a new app has been used. I may consider using nextDNS.

  • Thanks 1
Posted
As a parent I filter my child’s internet daily I break his privacy but I have a duty of care. So I am confused as to why this comes up as an issue.

 

You're also the legal owner of the device he's using and don't need anyone's consent to filter it however you choose.

 

Schools do need that consent if we're monitoring devices we don't own and it's a very unwise school who isn't explicit about the monitoring on any school-owned devices that enter homes.

 

We need to make sure that what we're doing is proportionate.

 

Why? So when $daft_school in your local area does something stupid with surveilance tools, your response is "How we monitor students is in the info pack to parents and there's also a copy on the website", rather than scrambling to find unexpected landmines planted by colleagues, such as this recent one:

 

One associate principal I spoke to for this story says his district would receive “Questionable Content” email alerts from Gaggle about pornographic photos and profanities from students’ text messages. But the students weren’t texting on their school-issued Chromebooks. When administrators investigated, they learned that while teens were home, they would charge their phones by connecting them to their laptops via USB cables. The teens would then proceed to have what they believed to be private conversations via text, in some cases exchanging nude photos with significant others—all of which the Gaggle software running on the Chromebook could detect. Now the school advises students not to plug their personal devices into their school-issued laptops.

 

https://www.techdirt.com/2023/10/16/aclu-calls-out-school-surveillance-programs-in-latest-report/

Posted
That seems unlikely, if not impossible (Gaggle). Pinch of salt with that example!

 

My thoughts exactly ... it would have to be a very bizarre set of circumstances for that even to be possible and it definitely sounds like the way things were caught (what apps were used, etc.) has not been explained correctly.

Posted
Currently using still using Qustodio on my child device and this is the same as when younger. Every app has to be approved and Qustodio tells me a new app has been used. I may consider using nextDNS.

 

Qustodio is not too bad as it goes, but you as a parent are making the decisions about risk and which apps are ok, not Qustodio or the school. If you child's device was to be used at school would you be happy for them to run their own tools on that device? When would you want them run and where? What apps/sites/activities would you expect to be restricted/allowed but monitored? What happens if you disagree with certain things (e.g. school automatically blocks anything nude, but that then hits many museums due to paintings and statues)?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...