Jump to content

Recommended Posts

Posted (edited)

Hi

 

 

One of our teachers has asked for a mapped drive for their account to access to all our students network shared folders so

as they can view and mark their work .

 

My inital thoughts where that i shouldnt do this becuase of Data protection , though I am being told as their files are not personal DP does not count !

 

 

Does anyone else do this ?

 

should this be allowed ?

 

if not why not ?

 

Thx

Edited by sjpage10
Posted
Yup, we do this - but rather than a mapped drive letter I've just put shortcuts to the relevant folders' UNC paths in the staff drive. Don't forget to modify the NTFS permissions on the student folders to give teachers READ ONLY access otherwise that's a whole other can of worms!*
Posted
Take it to the head, It's a data protection issue but they need to discuss their needs with someone who can balance needs with protection. think of some suggestions before you do, A communal area maybe?
  • Thanks 1
Posted

Part of our AUP states that staff can view any files stored on personal filestores - the pupils sign this at the beginning of each year and there's a copy online for parents.

 

Personally, I don't see it as any different to reading what a pupil's written in their excersise book.

  • Thanks 1
Posted

The level of access very much depends on the age of the children. In primary it's not unusual for teachers to have read-write access to pupils' folders.

 

In secondary, exam boards come on the scene and they take a very dim view of teachers having the ability to modify a student's course work. Read only!

 

Students, through the AUP, should be aware that their home drives are not completely private. As long as SLT have agreed this in writing, I would allow it. Do make sure that SLT have agreed first though. You should never be doing something like this without their agreement and without them having been informed of any risks associated. (e.g. write access and exam boards)

  • Thanks 1
Posted (edited)

Thx for the replys

 

i contacted our local data protection officer who said

Thank you for your email. My thoughts are that an individual teacher should not be given access. DP Principal 3 states that “Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed” so to give access to all pupils (including the ones that are not taught by the teacher) would not be appropriate.

 

 

 

Principal 6 states that “Personal data shall be processed in accordance with the rights of data subjects under this Act” and I think that to give access to an area that is password protected by the students would again be inappropriate.

 

 

 

I agree that individual access may be required in order to investigate a security risk etc, but access to all students for marking some is not.

 

 

 

I hope that this is helpful

 

 

now one of our deputies has spoken to him and agreed as long as there was no personal data in the folders it would not be an issue

 

though I am still not sure

 

however it seems this may be the norm !

Edited by sjpage10
Posted
our AUP also states that use of the school computers, network etc is only permitted for schoolwork... so there shouldn't be any personal data in there anyway...
Posted
This is one of the reasons schools have used VLE's in the past so students can submit work and it can be marked online without requiring changes to file access for staff. Another option (as suggested) is to use a shared area for pupils to submit work. Using either method also promotes users to name their files appropriately so the people marking them can identify it without having to open it first, something that is not always done when it is only used by pupils.
Posted
Thx for the replys

 

i contacted our local data protection officer who said

 

 

 

now one of our deputies has spoken to him and agreed as long as there was no personal data in the folders it would not be an issue

 

though I am still not sure

 

however it seems this may be the norm !

 

Problem with that is that you wouldn't know it was personal until it was too late. I would only access files if I had a reason to, either for a file restore, check for corruption or checking the content (illegal/inapropriate etc) etc but generally all of these would have come through a request NOT because I just wanted to access them.

 

I personally would always take the side of caution and put a solution in place which would allow the member of staff to do what they need to without providing access to all users data. A shared area would allow you to do this.

Posted

Read only access setup here - again part of the AUP for students that staff may have read access to their work.

We've also got it in the staff AUP that IT Staff and SMT may access their documents in the event of a disip issue.

 

We set it up with a 'Pupils Read Access' AD security group - when we add staff to it the NTFS permissions kick into place that allows them access and a security group filtered GPO gets applied that maps a network drive to show them the root of the students folders.

Posted
I would only access files if I had a reason to, either for a file restore, check for corruption or checking the content (illegal/inapropriate etc) etc but generally all of these would have come through a request NOT because I just wanted to access them.

 

Same here,

 

even though we may tell them 'do not store any personal information' you can bet they would

 

however it does seem that there are a lot who just give full read only access !

 

I think a general shared area (that they all ready have and use) with a wrk folder should suffice

Posted
To take a slightly different viewpoint, and play devil's advocate a little, depending upon the age of the pupils involved I would consider there to be a potentially bigger duty of care issue if staff can't access pupil filestores. Say they're storing bomb making info or something - the more people that have the potential to find it the better, surely?
Posted
My last school just mapped a drive for all staff, and it's written into the AUP here that staff can access student areas, although in practice it's not given here. What we do have is a separate mapped drive for all users called Submissions, with a variety of odd permissions on it - students can then save into this drive specifically (but not delete from it!) and teachers can then mark it at their leisure. No worries about accessing private areas then.
Posted (edited)
To take a slightly different viewpoint, and play devil's advocate a little, depending upon the age of the pupils involved I would consider there to be a potentially bigger duty of care issue if staff can't access pupil filestores. Say they're storing bomb making info or something - the more people that have the potential to find it the better, surely?

 

Well in that case I would have thought that staff would have had a reason to go looking rather than accidently discovering the fact. In real terms teachers are not going to have the time to search through all files just in case there is something in there which might prove to be a problem. Thats why in the past I have run scipts to search users area for specific file names/text which found files saved on the pupils area with lists of proxy websites etc. However, I realise some schools do allow staff access to read the files and also don't see this too different from access to pupils books. BUT whatever you do, ensure that it is documented and part of your AUP so if anything happens you have a paper trial which specifies how the network is used and why you have made any changes.

 

BTW - I have worked in places which used a shared area & VLE to submit work for marking which worked well. We also had permissions for staff to access pupils area for those times where pupils worked in groups and then the one who stored the work was off for the next session. This allowed staff to copy over files for pupils to continue working, but not all staff were interested in doing this as it was not in their JD.

Edited by penfold
Posted

All schools that I have worked in give staff have read only access. I find different departments seem to like working in different ways, most ICT teaching staff prefer to have direct access to student homes for marking.

 

As overs have said here, I can't see the problem of giving staff read access to students data. Clear it with Line manager or SMT if it is a new facility that staff want.

 

Instead of giving every staff member read ony is create a group and give that group read access, add the staff that need access to that group. This will give you better future control.

Posted

My take on it is this: a student's work area is not intended to be for personal use, it is for school use. Those files are not their personal files. They are work produced for the school*.

 

And this is where you AUP comes into play. We have had to have numerous conversations with staff who use the network as their own personal storage/backup area by putting personal (often illegal) content onto the WORK network. It is not designed for this purpose and as such any personal files which are lost are NOT ITs responsibility and we will not spend time trying to recover files which are not work related. (OK we may, but that is not the official stance). So long as you have documented who has access to what you shouldn't have a problem.

  • Thanks 1
Posted (edited)
1.If anyone is in any doubt, students work is 'personal data' under the DPA as it meets the definition found here of "Data 'obviously about' a particular individual". However, it would not usually be considered sensitive personal data, which is subject to stricter safeguards.

 

My thoughts are that an individual teacher should not be given access. DP Principal 3 states that “Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed” so to give access to all pupils (including the ones that are not taught by the teacher) would not be appropriate.

 

 

 

Principal 6 states that “Personal data shall be processed in accordance with the rights of data subjects under this Act” and I think that to give access to an area that is password protected by the students would again be inappropriate.

 

 

So if it is personal data then DP says to give access to all pupils (including the ones that are not taught by the teacher) would not be appropriate.

 

!

 

can you state in your AUP that it is not Personal if students work is 'personal data' under the DPA as it meets the definition ?

Edited by sjpage10
Posted (edited)

That's one person's opinion that giving access to all staff would not be appropriate. It's not a fact. It might be correct, but without actual legal guidance I would take it with a pinch of salt. As I mentioned, most MIS systems give access to confidential data to teachers that don't teach a child. Do you also regard that not appropriate, and should we therefore automatically assume those systems are not DPA compliant?

 

I suppose what I should really have said is that student work areas are not private areas. Data can be "personal" under the DPA without being private.

Edited by AngryTechnician
Posted

We recently gave our teaching staff access to the pupils' MyDocs folders, and they are very happy with this for the following reasons:

* makes homework submission easier (shared areas are too prone misuse/abuse as pupils delete/rename/overwrite other pupils' work)

* allows the teacher to monitor progress on an ongoing task

* allow teachers to access collaborative work stored in one pupil's area so the others can carry on if the "owner" is off sick

* is used when pupils forget to print work off

* is used by a teacher to show pupils' work to the rest of the class

* can be useful in pastoral issues

 

We don't impose restrictions surrounding which pupils' work they can see, but trust their professional conduct (as with MIS data, etc, as already mentioned, or emails sent to the All Staff group). The access is only available to teaching staff, not admin or support staff.

 

As others have said, the areas are not to be considered as personal, private areas - they are areas which the pupils have in order to do their school work. The same goes for staff MyDocs folders too; they all know that I can see them and SLT may ask for access to them. If you don't want something seen, don't put it on the school's network; that is what pen drives and your personal, private, home computer are for.

  • Thanks 1
Posted

As all employees of a school have a duty of care over each and every child in the school there is a reasonable presumption that some or most information about that child may need to be accessed by any member of staff. Areas where this is not the case is usually related to health or specific relationship information and access to this should only be given to the relevant members of staff. Within MIS there are granular contrails over this data or to modules which enable access to this data and so most MIS will meet the 8 principles. (paraphrased from notes at Information Handling and Data Security working group meetings, Becta 2008)

 

To summarise a few other bits (most mentioned above)

 

1 - The school should clearly set out in its AUP what it expects of users (staff and students) with regards to use of the school systems to hold personal files.

2 - Access to areas which might contain personal files should be restricted yet that should not interfere with the school's duty of care.

3 - Can of worms ... lets go fishing!

 

Ok, in reality I think most people are forgetting what is personal data and what is 'personal' files. Someone writing down a story that is nowt to do with their school work is a personal file, but is not likely to hold personal data ... this is a question about IPR surely, not about data protection. Also remember that even 'work' files can hold personal data ... take a geography lesson where children complete questionnaires about extra-curricular activities ... this could be a spreadsheet listing what each child in a class does after school, what route they walk home, etc ... yet this is in the work area?

 

Again, a reality check says that this sort of information is readily accessible by the staff in the school and so would be fine to access ... and the main concern should be about whether information is written down about bullying, disclosures, etc. This falls under Duty of Care and if there is a concern then it gets fed through the CPO at the school, they request access to information and deal with it. If staff have ready access to the home areas of children dn come across such information then the school needs to have a clearly set out policy of how it is reported and dealt with. Not a DP issue, but an important one nonetheless.

 

Also remember that the school already has granted explicit access to one or more members of staff to be able to access every file and folder ... and that trust should be explicit in your job description and contract. To also give that to other staff is a leap, but not a big one. This really is a case of not whether you can do it, but more of how you manage it and the processes to cover things and make sure nothing falls through any gaps. In risk management terms ... avoid the risk by giving no-one access ... or share the risk with staff members but you have to educate them and bind them to some rules! Remember that some staff might not *want* that responsibility!

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...