Jump to content

Recommended Posts

Posted

*sigh* *head explode* *face palm* *bang head against wall*

 

We have just re-installed Impero after our trial (Excellent bit of software, highly recommended) but a certain member of leadership has caught on that they can now watch every member of staff's computer etc...

 

Personally I am massively uncomfortable with this so I need a few spanners, what is the legality of monitoring staff and the general policies towards it?

 

I know that legally an employer can do it but do we need to tell staff before hand? If so what do we have to tell them? I know for a fact that if I send out a blanket email to staff telling them that management are monitoring them it will cause an uprising and things will get messy and hopefully leadership would shelve the idea. So I am sincerely hoping there is a legal precedent or requirement for us to notify staff, is there?

 

As for me I run a *nix box so I am in the clear *whistles contently*

 

I would love to hear what other schools do and what policies and notices are given to staff with regards to the monitoring and if any major unions have any policies regarding it.

 

Thanks chaps and chappettes.

Posted
It needs to be in the AUP, if its not then its dodgy. Personally I think the whole surveillance thing is smarmy to start with.

 

An AUP, whats that? Oh the thing that governs acceptable use, yup wish we had one of those :)

 

I think It's time I drafted one up!

 

I agree that computer use should not be monitored, however student access is different.... IMHO you should monitor students to stop them accessing porn etc... which is a legal requirement I believe and to keep a better eye on the cat-and-mouse game of tracking down bugs in software that allow them to get things they should (eg installing Chrome to their local "AppData" folder) and at the end of the day it does vastly increase the time spent doing work as opposed to playing about if the students know they are being watched by their teacher they might at least pretend to work

 

Thanks for the link x-13, will check it out

Posted (edited)
IMHO you should monitor students to stop them accessing porn etc...

 

Nope.

 

That's what filtering is for.

 

Same with checking for disallowed files [Games etc.] You set up a script or something to search.

 

 

 

You only root around in files or watch desktops if it's the only option remaining.

 

 

it does vastly increase the time spent doing work as opposed to playing about if the students know they are being watched by their teacher they might at least pretend to work

 

That's a teacher problem, not an IT problem.

Edited by X-13
Posted
Without an AUP I think that you may be breaking the digital surveillance act or something like that. Surfice it to say that I'm quite sure that it is illegal and prosecutable if they have not signed an agreement allowing it. It used to be more lapse but I think they tightened it up with the DPA.
Posted

Nope.

 

That's what filtering is for.

 

Yes, BUT! Rather than sit and look through logs all day I can run up Impero and see from the thumbnails if a student is playing a game, check the full screen view, get the URL and block it. I don't look through student folders although if we get a sudden epidemic of students playing a game then we will sometimes do a "*.exe" search in their folders. I only pass on info about illegal/games/dangerous files. I think we are fair, it's up to teachers to keep the kids on track though, my job is to make sure the network stays as good as can be and if that means removing potentially dangerous or illegal files then that's part of what I am here for!

 

Without an AUP I think that you may be breaking the digital surveillance act or something like that. Surfice it to say that I'm quite sure that it is illegal and prosecutable if they have not signed an agreement allowing it. It used to be more lapse but I think they tightened it up with the DPA.

 

Interesting, thanks for the heads up there, I will have to read the digital surveillance act. in a physical sense when CCTV is used there HAS to be signs or some other way of notifying visitors, employees, students etc... that CCTV is in use otherwise again I think it's illegal so it makes sense that the same rules apply to digital surveillance too.

 

Will check it out, thanks!

Posted (edited)
Without an AUP I think that you may be breaking the digital surveillance act or something like that. Surfice it to say that I'm quite sure that it is illegal and prosecutable if they have not signed an agreement allowing it. It used to be more lapse but I think they tightened it up with the DPA.

 

IANAL, but I think it would come under the misuse of computers act.

 

 

Computer Misuse Act (1990)

Section 1:

 

unauthorised access to computer material, punishable by 6 months' imprisonment or a fine "not exceeding level 5 on the standard scale" (currently £5000);
Edited by X-13
Posted

In the US cases have been brought forward with regards to monitoring PC activity and reading emails (even old emails, say if you're suing your employer). The crux of the arguments are that the PCs and email accounts belong to the employer and you are not afforded ANY right to privacy on employer owned hardware or through their services.

 

This probably wouldn't fall under digital survelance as it is the employers hardware / services.

 

That is US findings but I think we would fall in line.

Posted
In the US cases have been brought forward with regards to monitoring PC activity and reading emails (even old emails, say if you're suing your employer). The crux of the arguments are that the PCs and email accounts belong to the employer and you are not afforded ANY right to privacy on employer owned hardware or through their services.

 

This probably wouldn't fall under digital survelance as it is the employers hardware / services.

 

I see your point but going back to CCTV, a shopping center can't legally put CCTV up and watch you without first telling you clearly. That gives you the decision that if you go inside you give consent to be watched, if you don't give consent then you can go elsewhere. I would expect that the same applies to computer monitoring. While the hardware and software does indeed belong to the employer they are still watching YOUR actions.

 

A few sources online basically repeat what SYNACK said, that there should be an AUP in place that includes the fact that employee activity will be monitored. Then staff have the choice to give consent and keep the job or go elsewhere.

 

On the subject of AUPs does anyone fancy sending me a copy of theirs in a PM? Or even a censored/draft version so I can get an idea of what a secondary school AUP should involve? (I wont use it as-is, I will only use it as a resource to see what should be on our AUP)

Posted
IANAL, but I think it would come under the misuse of computers act.

 

 

Computer Misuse Act (1990)

Section 1:

 

I too believe this relates to what the media likes to call "hacking", in that the unauthorised access is equivalent to breaking and entering. As the school technically owns the devices it wouldn't be unauthorised. Although I have often wondered about licensed content, for example, if a member of staff was watching a licensed video clip which stated it could only be viewed on one device by one user, surely if I remote view their machine and watch then that would break the license and thus be illegal?... Probably not the case but it does make me wonder.

Posted
I see your point but going back to CCTV, a shopping center can't legally put CCTV up and watch you without first telling you clearly. That gives you the decision that if you go inside you give consent to be watched, if you don't give consent then you can go elsewhere. I would expect that the same applies to computer monitoring. While the hardware and software does indeed belong to the employer they are still watching YOUR actions.

 

Logic like that winds me up.

 

Everywhere has that, "by entering you consent". No, I [derp]ing don't. And as EVERYWHERE has it, I have no choice in the matter.

 

Lots of companies with phone support are doing this as well. "We're going to record you. If you don't like it, go away."

 

Eh, no. I paid for support [or it's under warranty] you can't get out of it like that. It's breach of contract. [i'm still not a lawyer.]

 

 

Who? Leadership? Give me a break...

 

I'd be careful what you say. You've already said they're monitoring people.

Posted (edited)
Logic like that winds me up.

 

Everywhere has that, "by entering you consent". No, I [derp]ing don't. And as EVERYWHERE has it, I have no choice in the matter.

 

Lots of companies with phone support are doing this as well. "We're going to record you. If you don't like it, go away."

 

Eh, no. I paid for support [or it's under warranty] you can't get out of it like that. It's breach of contract. [i'm still not a lawyer.]

 

 

 

I'd be careful what you say. You've already said they're monitoring people.

 

This is true, but there's no AUP in place to stop me saying it, and it's non-identifiable etc... I will consider an edit though ;)

 

The old "by doing x you consent to y" is a bit grey, but in some places it's the only real option but in a situation with paid support etc... I guess unless it's stated in the contract at the time of purchase it's a bit dodgy

Edited by shadowx
Posted

Data protection and monitoring at work

An introduction to monitoring staff

 

And a cautionary tale: Monitoring of employee breached human rights, says European court

 

And from ICO: Guidance and Information for Employers about the Data Protection Act - ICO Look at the employment practises code.

 

In short, your employer is setting themselves (and you, if you're facilitating their activities) up for an interesting time ahead. At best, you'll have higher staff turnover. At worst, you'll be taken to court either by staff or ICO.

 

You're not monitoring for defined reasons

You haven't assessed the impact of said monitoring

You haven't informed or discussed it with staff

Your SLT have no clue as to the legality of what they're doing, nor do they appear to have asked the "what effect on morale will this have?" question

You don't even have an AUP (so even if you find Jeff doing unnatural things to toasters, you've no recourse).

 

Your plan of action should be to tell them to Stop Right Now, and read the employment practises code's section on monitoring staff. And clip them round the ear from me too.

 

We monitor staff email, Internet and general network activity but we:

 

a) informed them in writing what we're doing and why

b) discussed and modified policies at staff meetings

c) don't have a human monitoring them (automated triggers and "can we prove if X happened?" requests, plus "grab 48hrs of traffic, quickly flick through" snapshots)

d) keep tight control on where that data is stored, processed and who it's released to.

Posted

Let's set out some key principles here ...

 

Staff are employed to do a variety of things within their contract of employment and the school has a right to ensure that they are meeting this contract. This can be done via a variety of means including visiting the classroom, observing lessons, auditing lesson plans, book scrutinies, looking at logs to see if staff are accessing non-work related websites when they are meant to be working, etc

 

And yes, this does include looking at staff laptops ... but there are some massive, and I do mean deal-breaker, caveats on this.

 

1 - The staff may also be using the devices outside of designated work periods to look at personal and private things. This can range from personal banking, booking holidays, pictures of their children, etc ... Unless your school has a clearly agreed policy (which is backed up by the contract of employment) to say the devices can *only* ever be used for employment-related activities then you cannot guarantee that you are looking at a device to check on work and so you risking seeing things you are not entitled to see.

 

2 - Even if you do get agreement that this can go ahead and staff are happy to take the risk that you might see something personal then the school is risking allegations of harassment and bullying. To some extent you can help this with policies ... and there is already precedent for this. CCTV can be used in the classroom but if you go back to how CCTV should be used in schools anyway, each time someone accesses it to view something it should be logged with a reason why, authorised by a relevant person, etc. This is a lot of paperwork, but designed to prevent abuse of CCTV systems and the same principles can be applied to other tools / services.

 

3 - A key feature is about automatic monitoring. This is why tools such as Securus / Policy Central which email a designated contact about key words, etc are a good option. It is not about someone watching it permanently but more about observing breaches in agreed practice / policies. This is the same principle of email logging / monitoring at work.

 

All of this forgets that these tools are there to support classroom management and learning, not to be a police-like tool. It does, however, allow for a lot of beneficial things to take place, including remote support (not just tech support but peer mentoring between staff), group training, evidence of activities to support performance management ...

 

So, AUP and backup from the contracts of employment are a must. Good policies about who can access and watch things, supported by logs (paper or otherwise) and working to teh same principles as something like CCTV. IF the key thing SLT are looking at is inappropriate use then a more automated service might be more in line with being acceptable.

Posted

Our LEA, when we were an LEA school, sent round an edict to all schools that there must be a clickthrough box before login to all PCs, stating that under RIPA, all communications are monitored by both them, and the SWGfL (being the upstream provider), and by accessing the machine, you agree to this. This was altered to include the school itself, as we also do monitoring.

 

The only monitoring that goes on here though is at the proxy for internet, and ABTutor for students. I've also used VNC to remotely connect to laptops etc... but don't think I've ever connected to a teacher computer without notifying them first.

 

The issue I think is *how* monitoring occurs - if it is fully automated logging, then no individual is being targeted Combining that with policies about how that data would then be used (eg. if accusations of porn viewing came up, etc...) should cover any possible allegation of harassment or bullying.

 

The issue of home or work use is, to me, irrelevant so long as all of the above is in place - the location is never mentioned in our policies, just that our equipment is covered by our policies.

 

However, we also get staff to sign a form saying they won't use issued laptops for personal use, so are covered both ways there.

  • Thanks 1
Posted
The issue of home or work use is, to me, irrelevant so long as all of the above is in place - the location is never mentioned in our policies, just that our equipment is covered by our policies.

 

There is a difference between work / home as a location for doing employment-related activities and personal / work use. If an unsuspecting member of staff is using it for internet banking (which is obviously within a secure webpage and presuming no interception is taking place) then the person viewing could be looking at personal data that they have no right to view. This is also an issue for those working in multiple schools who might be accessing services in other schools from that device ... so the person viewing could see information about a student not in their school. It is worth saying these are not hypothetical concerns and have caused issues in schools previously.

Posted (edited)
There is a difference between work / home as a location for doing employment-related activities and personal / work use. If an unsuspecting member of staff is using it for internet banking (which is obviously within a secure webpage and presuming no interception is taking place) then the person viewing could be looking at personal data that they have no right to view. This is also an issue for those working in multiple schools who might be accessing services in other schools from that device ... so the person viewing could see information about a student not in their school. It is worth saying these are not hypothetical concerns and have caused issues in schools previously.

 

I still don't see it. Our policy covers use of the school equipment (ignoring the signing a sheet saying work use only), that equipment is still ours if it is in school or out of school, and therefore the AUP covers its use wherever it is in use - if other places have their own policies regarding devices in use in multiple schools then the person working there would also need to deal with that (we have a few of these in our school - but they are part of our federation, and all schools in the federation have the same AUP). However, if the laptop is issued by us and the person has a second job somewhere, then using that computer for that other job would itself be against our AUP (much like taking it outside the UK would be too).

 

So, with our policy, there is no difference between home and work locations. If the policy covered use of IT in the school (and not 'equipment owned by the school') I'd agree with you though.

Edited by localzuk
Posted
Data protection and monitoring at work

An introduction to monitoring staff

 

And a cautionary tale: Monitoring of employee breached human rights, says European court

 

And from ICO: Guidance and Information for Employers about the Data Protection Act - ICO Look at the employment practises code.

 

In short, your employer is setting themselves (and you, if you're facilitating their activities) up for an interesting time ahead. At best, you'll have higher staff turnover. At worst, you'll be taken to court either by staff or ICO.

 

You're not monitoring for defined reasons

You haven't assessed the impact of said monitoring

You haven't informed or discussed it with staff

Your SLT have no clue as to the legality of what they're doing, nor do they appear to have asked the "what effect on morale will this have?" question

You don't even have an AUP (so even if you find Jeff doing unnatural things to toasters, you've no recourse).

 

Your plan of action should be to tell them to Stop Right Now, and read the employment practises code's section on monitoring staff. And clip them round the ear from me too.

 

We monitor staff email, Internet and general network activity but we:

 

a) informed them in writing what we're doing and why

b) discussed and modified policies at staff meetings

c) don't have a human monitoring them (automated triggers and "can we prove if X happened?" requests, plus "grab 48hrs of traffic, quickly flick through" snapshots)

d) keep tight control on where that data is stored, processed and who it's released to.

 

Excellent links, thanks for those!

 

We already have filtering and internet/email logging in place which purely logs the pages accessed by all users and the external email routing system we use keeps a log of messages sent/received but not their content. I am now wondering... would this level of logging need to be announced to staff?...It's not actually kept to purposely log staff it's just a side effect of the way the systems work really.

 

CCTV can be used in the classroom but if you go back to how CCTV should be used in schools anyway, each time someone accesses it to view something it should be logged with a reason why, authorised by a relevant person

 

This also rings alarm bells... At the moment the CCTV is hosted in our office, when a member of staff asks to look back at recordings we just click the buttons and what not and let them see it.... Students are never permitted to watch it unless they are supervised by an appropriate member of staff but any member of staff can, and do, come in here and watch the recordings...

Posted
Excellent links, thanks for those!

 

We already have filtering and internet/email logging in place which purely logs the pages accessed by all users and the external email routing system we use keeps a log of messages sent/received but not their content. I am now wondering... would this level of logging need to be announced to staff?...It's not actually kept to purposely log staff it's just a side effect of the way the systems work really.

 

Yes, it does need to be announced, particularly the Internet logging.

 

Completely disregarding the legal side of things, it's good user relations for the IT Dept. Part of being a sysadmin (and all the access & responsibility that entails) is not just being honest, but being seen to be honest and above-board.

 

"Hey, we do this, we do it in this way and we do it for X, Y and Z reasons" is waaaaaaaaaaaaaay better than "Shadowx secretly looks at what we're doing on the Internet" gossip in the staff room.

 

That's a major reason for an AUP - it sets out rights and expectations for all parties.

  • Thanks 1
Posted

Interesting... I will write an AUP pretty soon and I will put that kinda thing in there, 99% of staff are aware of it but like you said, it needs to be above board and officially set out in an AUP.

 

Luckily we get on with most of our staff here which helps!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...