jisc rsc eastern technical managers forum june 2013 'byod tech managers forum

25
BYOD Where does institutional liability end ? 26 June 2013 RSC Eastern Technical managers Forum

Upload: jisc-rsc-eastern

Post on 29-Jun-2015

142 views

Category:

Technology


1 download

DESCRIPTION

Slides from presentation by Betty Willder, Jisc Legal on BYOD

TRANSCRIPT

Page 1: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

BYOD Where does institutional liability end ?

26 June 2013RSC Eastern Technical managers Forum

Page 2: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

Hello!

Betty Willder [email protected]

0141 548 4939

www.jisclegal.ac.uk

http://twitter.com/JISCLegal

Page 3: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

About Jisc Legal

• Role: to avoid legal issues becoming a barrier to the use of technology in tertiary education

• Information service: we cannot take decisions for you when you are faced with a risk

Page 4: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

“ … 47% of all UK adults now use their personal smartphone, laptop or tablet computer for work purposes. But less than 3 in 10 who do so are provided with guidance on how their devices should be used in this capacity, raising worrying concerns that people may not understand how to look after the personal information accessed and stored on these devices…” http://www.ico.gov.uk/news/latest_news/2013/survey-guidance-on-byod-personal-devices-07032013.aspx

Page 5: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

The Issues

Copyright (using other people’s stuff)

Data protection (respecting privacy)

e-Safety (protecting users)

e-Security (protecting the organisation)

Page 6: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

The Difference

Not linked to place (mobile!)

Personal, invasive and pervasive

Own device

Combines access and communication

Page 7: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

What’s the biggest issue about mobile?

1. Copyright2. Data protection3. e-Safety4. e-Security5. Haggis

1. 2. 3. 4. 5.

0% 0% 0%0%0%

Page 8: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

Copyright & Mobile Devices

be ‘appy’ with your appsT&Cs‘Personal use’Per device, per user,multi-use

Page 9: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

Do you have a mobile device with copyright infringing content with you?

1 2 3 4 5

0% 0% 0%0%0%

1. Can I call my lawyer?2. Maybe.3. I’m looking around to see

what option others are pressing.

4. Yes.5. Definitely not, guv. Honest.

Page 10: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

Data Protection & BYOD

Compliance and privacy

Purposes / purpose creep

Surveillance

Marketing - PECRs

Page 11: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

“ … 47% of all UK adults now use their personal smartphone, laptop or tablet computer for work purposes. But less than 3 in 10 who do so are provided with guidance on how their devices should be used in this capacity, raising worrying concerns that people may not understand how to look after the personal information accessed and stored on these devices…” http://www.ico.gov.uk/news/latest_news/2013/survey-guidance-on-byod-personal-devices-07032013.aspx

Page 12: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

e-Safety & Mobile Devices

Enables new, pervasive communicationAnonymity and accessDuty of careCriminal offences

Page 13: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

e-Security & Mobile Devices

BYODBYOVRDLYODDP, liability,breach of T&Cs

Page 14: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

The college/employer legal obligations

• Statutory obligations to comply with

various pieces of law

• Common law obligation of duty of care

Page 15: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

Statutory Obligations

• Difficult to meet them if systems are not technically up to date using latest standards etc

• Data protection probably most risky area• Help available on BYOD – ICO guidance

Page 16: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

So where does college liability end?1. It extends to all permitted

mobiles2. Only to staff mobiles not

students’3. Not our mobiles – not our

responsibility4. It depends5. In tears

1 2 3 4 5

0% 0% 0%0%0%

Page 17: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

The employee legal obligations

• The employee ‘is’ the college• Any personal liability?• College needs to rely on its

employment contracts, behavioural policies and disciplinary policies

• BYOD is about people, not devices

Page 18: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

The student’s legal obligations• The student ‘is not’ the college but…• …accesses college licensed materials,

college personal data, e safety, e-security• College needs to rely on its student

contract, behavioural policies and disciplinary policies

• Common law obligation of duty of care

Page 19: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

The JISC Legal BYOD Toolkit – what’s in it?

Page 20: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

BYOD Toolkit (1 May 2013)

Jisc Legal has published a BYOD toolkit in response to the rise in learners and employees using their personal computing devices (typically smart phones and tablets) in the work and learning environment.

The toolkit includes a variety of resources:

1. Your Staff, Mobile Devices, Law and Liability

To some extent bring your own device (BYOD) is already happening in your institution. Staff are already using their mobile devices to access their work emails, papers and documents from off campus. This paper focuses on the legal issues surrounding staff bringing their own devices.

2. Your Students, Mobile Devices, Law and Liability

Students will increasingly expect that all information and services currently available from a university or college desktop will be available to them via their mobile device. At the same time, institutions will want to ensure that systems and information are secure, and users adhere to policies on access to systems. This paper focuses on the legal issues surrounding student mobile use.

3. Risk, Liability and Mobile Devices

This paper provides a quick reference for managers as to the main legal risks which need to be assessed against your institution’s risk strategy before opening your institution’s ICT system to mobile access by staff and students using their own devices.

4. Bring Your Own Device Policy Template for Further Education

The BYOD Policy template is intended as a guide to help providers write an effective policy that states what their institution's approach is to the use of personally owned devices by staff and learners.

Page 21: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

New Guidance

Page 22: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

FAQ: Can we seize and forensically analyse a staff or student’s device in the case of suspected misuse?

1 2 3 4

0% 0%0%0%

1. Yes our policy says we can2. No- only the police can do this

under warrant3. Maybe if the circumstances

are serious enough 4. I’m looking around to see

what option others are pressing.

Page 23: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

Policies

• BYOD• DP AUP/student behaviour• Staff procedures – dp, copyright,

safeguarding, e-safety… • Disciplinary policies• Publicise and enforce!

Page 24: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

Enforcing your policies

• If want to rely on them, need to have them in place!

• Need to be fair – consultation?• Consistently enforced• Very challenging in BYOD• Use technology

Page 25: Jisc RSC Eastern Technical Managers forum June 2013 'BYOD Tech Managers forum

Any Questions ?

http://jiscleg.al/BYODToolkit