Jump to content

Recommended Posts

Posted (edited)

Our DPO's latest newsletter includes a recommendation not to use end-to-end encrypted messaging because we can't access it in the event of an SAR. They also suggest a school policy discouraging use of personal devices as people are sometimes more indiscreet/inappropriate on those media, so I suspect this is in response to a school getting an SAR for WhatsApp messages (it might even be from us, as we did have one recently!) but my understanding is as long as we don't instruct/encourage use of personal devices or WhatsApp, there's no reason not to allow staff to communicate with colleagues via those platforms.

 

What do you think?

Edited by 6Foot2
  • Thanks 2
Posted

Not an official school channel/policy to use it = personal communication, and won’t be covered by the SAR.

 

You need to be very careful with this though. If Whatsapp is normalised as a method of communication between staff, you’re on thin ice by not covering it.

 

Even just using pupil initials isn’t going to fully cover this. If a message about a pupil just said “Behaviour incident - see email” you’re better off.

  • Thanks 1
Posted

I don't think this has been tested legally yet, but I believe this comes down to "not actively encouraging it's use" as part of mitigation and could/should be in social media policies for staff as such.

You can't provide what you can't access.

Posted
I don't think this has been tested legally yet, but I believe this comes down to "not actively encouraging it's use" as part of mitigation and could/should be in social media policies for staff as such.

You can't provide what you can't access.

 

There's a difference between "not actively encouraging" and "actively discouraging" though. That said, if a department group exists, is there an implied expectation that staff join that group?

Posted
True - you can't stop them setting up such a group, it won't be punishable by any means if it happens. As for expectations - double edged sword, because you'd feel rather left out if you were the only one in your dept that didn't. (I sympathise with this - I only joined one of our groups last week after installing WA for the very first time!)
Posted

This is an interesting one.

 

I guess the best thing to do would be to instruct them not to use personal phones or wattsapp for any school communications. Put in it your staff IT policy too. At least then, you've covered yourselves if someone does something silly then it is their professionality on the line for not following the policies and instructions from the Head?

Posted
This is an interesting one.

 

I guess the best thing to do would be to instruct them not to use personal phones or wattsapp for any school communications. Put in it your staff IT policy too. At least then, you've covered yourselves if someone does something silly then it is their professionality on the line for not following the policies and instructions from the Head?

 

A couple of thorny aspects to that. We require 2FA (which most staff do from personal mobiles), we encourage staff to install apps for ClassCharts and TeamSOS on their phones, and many choose to install VOIP and email on their phones for convenience. So it would seem a bit odd to then say don't use WhatsApp. Also, I think the SLT have a WhatsApp group for convenience of rapid communication rather than email, and I don't want the Head to have to tell people "do as I say not as I do".

Posted
for convenience of rapid communication rather than email

You're right, that is thorny. As soon as a student is named - "Kylie-Mae is being horrendous today!", in a school-centric channel it gets difficult.

 

This should be covered with policy.

 

Ours:

 

Whilst respecting the privacy of authorised users, School maintains its legal right to monitor and audit the use of all communication systems by authorised users.All users should be aware that email and unified communications content can be monitored and recorded and is stored centrally.• Personal (defined as NOT School provided or approved) email accounts or unified communication systems must not be used by staff to conduct or support official school business.• Messages retained within your mailbox, including unified communication messages will be liable for disclosure under any relevant information request regime
Posted
You're right, that is thorny. As soon as a student is named - "Kylie-Mae is being horrendous today!", in a school-centric channel it gets difficult.

 

That sort of thing is more likely going out over the callout radios than in the SLT WA group, but anything in the WA group would be initials only.

 

Do you think it would be sufficient to say "don't use personal email" (because there's no reason to) and "if using non-school communication methods, please continue to follow the policies and CoC regarding safeguarding and privacy"?

Posted
As long as you're aware initials do not magically make something disappear from an SAR (and fairly moot in a WA group anyway) then that should be fine. Most of that is more common sense than anything else, and the only difference between saying that in a WA chat as opposed to having a Friday night pint with colleagues is it being in writing.
Posted
A couple of thorny aspects to that. We require 2FA (which most staff do from personal mobiles), we encourage staff to install apps for ClassCharts and TeamSOS on their phones, and many choose to install VOIP and email on their phones for convenience. So it would seem a bit odd to then say don't use WhatsApp. Also, I think the SLT have a WhatsApp group for convenience of rapid communication rather than email, and I don't want the Head to have to tell people "do as I say not as I do".

 

I mean it's only thorny for you as your encouraging using personal unmanaged devices for school use which to be honest in this day and age is not a good idea, especially for things like classcharts.

 

We've allowed staff to use authenticator as it doesnt actually store any pupil and staff data and provided ipads so that they don't need to use their own devices.

  • Thanks 1
Posted
I mean it's only thorny for you as your encouraging using personal unmanaged devices for school use which to be honest in this day and age is not a good idea, especially for things like classcharts.

 

We've allowed staff to use authenticator as it doesnt actually store any pupil and staff data and provided ipads so that they don't need to use their own devices.

 

ClassCharts doesn't store any data either, it's just a wrapper for the website; without a password to an active account, you can't view anything. Obviously someone could screen shot it, but the same applies to data on a school laptop too.

 

Authenticator on personal devices is the preferred method, key fobs have been provided for those staff who declined (while there is a case for saying site is open 6am-9pm but they choose to work at home so can buy their own fob, we didn't fancy taking that hard line for the sake of £20 here and there!)

  • Thanks 1
Posted
A couple of thorny aspects to that. We require 2FA (which most staff do from personal mobiles), we encourage staff to install apps for ClassCharts and TeamSOS on their phones, and many choose to install VOIP and email on their phones for convenience. So it would seem a bit odd to then say don't use WhatsApp. Also, I think the SLT have a WhatsApp group for convenience of rapid communication rather than email, and I don't want the Head to have to tell people "do as I say not as I do".

 

SLT really should not be using a WhatsApp group for any thing, this was all recently covered by the Sue Gray report it encourages an unprofessional approach to both the content and retention of the messages. It also opens up staff to having their personal devices and accounts seized in an investigation. I would also put good money on the fact that the SLTs family are also reading these messages.

 

I know it is most likely that any advice will be ignored but this should all be on a school controlled service such as Office 365 and ideally on a school device.

  • Thanks 3
Posted
I would also put good money on the fact that the SLTs family are also reading these messages.

 

I'm confident that's not the case with our SLT, but I take the point.

 

I know it is most likely that any advice will be ignored but this should all be on a school controlled service such as Office 365 and ideally on a school device.

 

I would agree with that for school-sanctioned communication or "official" school business, but surely we can't direct staff not to have any contact with colleagues via personal devices. Let's say I give a colleague a lift to work, should we have to get our laptops out to send an Office365 email saying we're running late? I also don't see how we can regulate colleagues who are also friends venting about a situation, just as we can't stop them venting to their non-school family or friends.

 

Personally, I think the "use school devices only" ship has sailed now, but we can impose device management plans on people who choose to install school accounts on personal devices, and provide some guidance on what (not) to say to a friend on WhatsApp.

 

Ultimately if these are personal devices being used for communication which the school has not required via that platform, wouldn't they fall outside an SAR anyway?

Posted
I'm confident that's not the case with our SLT, but I take the point.

 

I assume that 75% of users share their phone with their family and this is so natural to them that if you ask if anyone else has access to their phone most of them would say no, because in their heads there is no link between their child playing a game or their partner making a call and someone else having access.

 

I would agree with that for school-sanctioned communication or "official" school business, but surely we can't direct staff not to have any contact with colleagues via personal devices. Let's say I give a colleague a lift to work, should we have to get our laptops out to send an Office365 email saying we're running late? I also don't see how we can regulate colleagues who are also friends venting about a situation, just as we can't stop them venting to their non-school family or friends.

The individual members of staff should be provided with a framework of acceptable communication methods for differing content and then they should use their profession judgment to ensure they are hold up the standards required. If this requires policing or enforcing this should fall on the SLT and governing body or trust not the IT team.

 

Your two examples cover a range of possibilities, a personal message about a lift if fine for any communication method however, a personal venting about a situation could range from harmless to career endingly actionable.

 

Personally, I think the "use school devices only" ship has sailed now, but we can impose device management plans on people who choose to install school accounts on personal devices, and provide some guidance on what (not) to say to a friend on WhatsApp.

 

Ultimately if these are personal devices being used for communication which the school has not required via that platform, wouldn't they fall outside an SAR anyway?

 

I agree that the use of separate devices is a lost cause, the White House had to let Barack Obama use his Blackberry and this has rolled down ever since, however if the staff are using these with the knowledge of the leadership and are discussing work they are covered by a SAR.

  • Thanks 1
Posted

Using only school-managed services for school business seems like a clear enough distinction to me. You shouldn't have to namecheck any particular app or service in doing that.

 

When you can provide staff with Google Chat, nobody has any business whatsoever using WhatsApp for staff to staff work comms.

 

The fact that officials in government seem to be habitually doing govt business in ephemeral WhatsApp chats has always amazed me. There must be IT people constantly tearing their hair out about that.

  • Thanks 4
Posted
When you can provide staff with Google Chat, nobody has any business whatsoever using WhatsApp for staff to staff work comms.

 

That's a valid point. With Google Chat and Teams both available, staff are only using WhatsApp for familiarity.

  • Thanks 1
Posted
Using only school-managed services for school business seems like a clear enough distinction to me. You shouldn't have to namecheck any particular app or service in doing that.

 

When you can provide staff with Google Chat, nobody has any business whatsoever using WhatsApp for staff to staff work comms.

 

The fact that officials in government seem to be habitually doing govt business in ephemeral WhatsApp chats has always amazed me. There must be IT people constantly tearing their hair out about that.

 

Didn't this get brought up with the covid enquiry and our lovely government back then?

Posted

A few things to note.

 

Your staff should only use systems with due diligence completed and subsequently allowed.

It should be clear what the relationship between you and the system provider is (Data Controller-Data Processor, Data Controller-Data Controller, Joint Controllers?).

Any use of personal data on personal devices would come under BYOD policies ... check them and get them updated.

 

Unless the school is using WhatsApp for Business then they truly have little ownership on what is going on. This is what Teams/Google Chat and others are there for.

I have repeatedly said that WhatsApp is usable for personal use, and even possible to have limited use at work for non-essential and non-sensitive things. The core though is performing a risk assessment. If there is still a high risk and someone is willing to accept it (and have the subsequent discussion with the ICO about a Public Body doing High Risk processing) then that is the organisation's decision and folk have to live with it.

 

I don't envy your DPO's work.

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...