Jump to content

Recommended Posts

Posted

Wouldn't have thought it was against the DPA as I assume they all have a good reason to be accessing the data unless they are using other accounts because they hold more access rights than their own accounts.

 

This sort of thing would should probably be dealt with via AUP's etc really

  • Thanks 1
Posted

It is also in breach of DPA too - principle 7.

Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.

Each account on SIMS is allocated to a user based on their need to access (process) data and to use the account of anyone else would be unauthorised. If they have been told by the SIRO / Head to use teh account of someone else then this could be counted as authorisation, but it puts into question the organisational measures, which can (and will) be challenged by the ICO in the event of a breach.

  • Thanks 1
Posted

It could be okay, if they have the same level of access, as they aren't gaining extra access, which as above is not allowed. The problem is ensuring they have the same access, as it's too easy for someone to be given extra access on request, or if their role changes slightly.

 

To just gain access to basic data, i would say it's okay, and if it's a time saving thing, it could be worth setting up a generic account with the basic access. We did this in the staff room of a previous school, set to auto-login to windows and via AD to SIMS. To save staff needing to log in themselves. This had physical security in place and would be locked or off at night.

 

In a classroom environment, my concern would be the auditing; anyone that can edit data, which even class teachers can do for basic data, there is little auditing of who did what. So if two people use the same account, then how do you ensure the data is safe, and if it gets botched, who is responsible? This would then be a breach.

 

Also, for attendance recording, the system needs to record who took the register and any subsequent changes. I think this is a legal requirement. I have suspected for some time that SIMS doesn't record accurately when a register is taken by someone else, but haven't been able to confirm. So this would be something to be aware of as well.

Posted
We got told by Capita that we could not use Generic accounts probably because of Data Protection and tracebility issues. I something dodgy is put on a students SIMS profile the tracebility has dissappered. I would highly advise against generic accounts or sharing of SIMS logins.
Posted
We got told by Capita that we could not use Generic accounts probably because of Data Protection and tracebility issues. I something dodgy is put on a students SIMS profile the tracebility has dissappered. I would highly advise against generic accounts or sharing of SIMS logins.

 

Logging who did what is limited in the extreme, except in the Dinner Money module.

Posted

I think its incredibly bad practice but, as has been mentioned already, it need not be "illegal" in itself. It contains the potential for bad stuff to happen though.

 

The question I would ask is why are they sharing? Is there a problem there with one person's access or with a workflow that would currently be too awkward otherwise that needs to be fixed.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...