Jump to content

FenderJay

Members
  • Posts

    4
  • Joined

  • Last visited

Reputation

0 Neutral

About FenderJay

Employer (optional)

  • Company Represented
    School SCR
  1. It's a complex area and I agree with what you're saying @localzuk. I contributed to this thread as my main concern is that I've seen 2 companies advertising to schools that they "must" now add all contractors to their SCR, and that social media checks are a statutory part of Safer Recruitment (they're not). To clarify a little further, with contractors, the key factor is what data you're capturing. Personal identifiable information is protected under a different legal framework and it can't be held for the same period that contracted employee data can be. As long as you're holding a business address (and not a personal address) and you're not retaining DOBs, you're ok to retain that information. It's correct that there is no legal definition of 28 days. However when it comes to personal identifiable information, this is considered best practice and has been established in a number of legal cases in the UK. It's ultimately about minimising your risk exposure as a Trust. My experience is swayed as I've spent a number of years working on policy in the Academies Programme. I've a seen a number of issues that have resulted in rebrokerings and legal action around compliance, data and staffing. In almost every instance, the Trust had acted in good faith but they didn't understand the legal frameworks they operated within and had fallen foul.
  2. Former MAT COO and DPO here. We had a major failure in our SCR management process that resulted in the Trust's schools being rebrokered. I'm very familiar with the SCR software market and the wider data protection issues having spent 2 years working with the DfE on related issues. There are 2 big issues to be mindful of that a number of SCR providers are offering: 1. Social media reference checking: This is a major risk area that exposes the Trust to legal action on the grounds of discrimination. There have been 2 big legal cases against MATs on the grounds of hiring discrimination and both times the Trust lost. The latest KCSIE highlights that "as part of the shortlisting process, schools should consider carrying out an online check," however it does not stipulate this to be social media and it provides no framework to follow. Under UK employment law, it's highly advisable that any school get consent from candidates prior to any check of social media. For one, it's critically that any checks are carried out on the correct accounts. Get the wrong account, or a spoofed account, and the school could be in big trouble. Once schools begin looking at any candidate's online activity, this falls under GDPR and is protected. A candidate can request a SAR and have full visibility on what the school checked and how they used that information. The school (and Trust) need a robust policy when it comes to vetting online activity as this isn't covered by default in the Safer Recruitment process. The Equality Act 2010 protects an individual's characteristics include (but are not limited to) age, disability, gender reassignment, race, religion or belief, sex, and sexual orientation. If a school rejects a candidate based on social media content that reveals or pertains to any of these characteristics, they could be at risk of a discrimination claim. I've seen some SCR providers offering in-depth social media 'reports' in which they've pulled a single post and labelled it "potential hate speech," or pulled up posts from when the candidate was under 18. There's no audit trail on how they found that post and whether that account has been verified to belong to the individual. If that information is used to discount a candidate from an interview process, 9 out of 10 times, that will break Equality Law. The penalties are huge, you're talking 6 figure payouts typically. Rolling that out across a Trust and devolving that process to business managers (who typically apply for vetting checks) is a massive risk. Until the DfE provider more guidance and protection for schools, it's too big of a risk to take. 2. Adding contractors to a SCR: There's no legal requirement to do this, and while it seems like common sense, it raises process and GDPR issues. A school is required to ensure contractors are vetted correctly when they're undertaking regulated activities or they're in the school unsupervised, however most contractors don't fall into this category. Once a contractor is added to a SCR, the school typically captures a lot of personal identifiable information. Under GDPR, once the contractor is finished, a school can only hold this type of information for 28 days unless they have a demonstratable reason why it must be held longer. "In case the contractor returns" is not a viable reason, however I've already seen a number of schools building their 'bank' of contractor information in their SCR thinking it's saving time if they ever return. This simply isn't allowed, this data must be deleted. Having a visitor management system directly populate a SCR isn't advisable as most schools have no awareness of data deletion requirements for non-employees.
×
×
  • Create New...