Skip to main content
How can we help you today?

Acceptable ICT use and online safety policy

Aims and scope

This document applies to all relevant laws and regulations in regard to acceptable information and communications technology (ICT) use and online safety including the Department for Education (DfE) statutory guidance on Keeping Children Safe in Education, Working Together to Safeguard Children, the Online Safety Act 2023, and the General Data Protection Regulation 2018 (GDPR) which sets out the framework for managing acceptable ICT use in the workplace and for those individuals who work remotely and who use ICT equipment and network systems outside the workplace.

Waverley Training Services (WTS) as a department of Waverley Borough Council (WBC) recognises that online safety is an essential part of safeguarding and acknowledges its duty to ensure all Learners and its employees are protected from potential harm when using mobile and smart technology.

Purpose

The purpose of this policy is to provide support, clarification, and guidance by outlining what is Acceptable ICT Use of all Waverley Information and Communication Technology (ICT) equipment and systems, mobile phones, and smart technology. It is also to safeguard and promote the welfare of all employees and Learners of WTS when using such equipment and systems.

This policy applies to all accessible Waverley Information and Communication Technology (ICT) equipment and systems, mobile phones, and personal devices such as tablets and wearable technology including smart watches/fitness trackers, smart rings and smart glasses which facilitate communication or have the capability to record sound or images.

The policy applies to all employees including the senior management team, tutors, Learners, external contractors, visitors, and other individuals who work for, or who provide services on behalf of the setting such as Awarding Organisations and End Point Assessment Organisations.

It applies to all users whether they are working from the centre’s main offices or at designated sites including off-site Learner visits and those working from home. This policy also applies to all users who remotely access the Council's network and systems.

You will be required to agree to comply with this Acceptable ICT Use Policy and to Council monitoring. In addition to this, monitoring via Addcom, which includes the monitoring of emails, internet use, and word-processed documents which are created, stored, or otherwise made on ICT equipment and systems.

The purpose of this policy is to:

  • Advise and protect all employees and other users.
  • Manage and secure WTS ICT Equipment, devices and systems.
  • Protect WTS ICT Equipment, devices and systems from misuse.

Regulations and other policies

It is a requirement that you understand and follow this policy, and you need to be aware of the risks involved in the appropriate use of Council ICT equipment, devices and systems. In certain instances, failure to follow this policy could lead to formal disciplinary proceedings which could be subject to investigation, up to including dismissal. It could also lead to criminal or civil action if illegal material is involved or if legislation is contravened.

This includes:

  • The General Data and Protection Regulation 2018 (GDPR2018).
  • The Humans Right Act 1998.

Users must not misuse ICT facilities by taking any action which is contrary to this policy and the Code of Conduct or which could bring the Council or WTS into disrepute, cause offence, or interfere with Waverley work or jeopardise the security of data, networks, equipment or software.

The Council's ICT equipment and systems are intended to provide business applications to support the provision of our service and to promote efficient communication within the office, other organisations and with our stakeholders. This policy gives advice on the appropriate use of the Council's ICT equipment and devices, and based business systems including but not limited to Personal Computers (PCs), laptops, mobile phones and smart technology, ICT operating and telecommunications systems (including emails and the internet).

The ‘staying safe’ outcome includes aims that children, young people and vulnerable adults are:

  • Safe from maltreatment.
  • Safe from accidental injury or death.
  • Safe from bullying and discrimination.
  • Safe from crime and anti-social behaviour in and out of education or training.
  • Secure, stable and cared for.

These aims equally apply to the digital world that children, young people and vulnerable adults will encounter whenever they use IT in its various forms. For example, there is a need to protect Learners from harm such as:

  • The use of the internet for grooming children, young people and vulnerable adults with the ultimate aim of sexual exploitation.
  • The use of IT as a platform for bullies, who may torment their victims via websites, online forums, text or email messages.
  • Exposure to inappropriate content when online, which can lead to their involvement in County Lines and/or anti-social behaviour.

It is the responsibility and duty of all employees to ensure every child, young person and vulnerable adult in their care is safe, and the same principles apply to the ‘Virtual’ digital world as would apply to if they were attending the premises in person.

All Safeguarding concerns must be reported to the Designated Safeguarding Lead (DSL) or the Deputy Designated Safeguarding Lead (DDSL) in their absence. In the event that neither the DSL nor the DDSL is available, any concerns should be reported to the Centre Manager.

Centre Manager: Adele O’Sullivan

Designated Safeguarding Lead: Krystel Rajewski

Deputy Designated Safeguarding Lead: Charmaine Winter

The Online Safety Act 2023

The Online Safety Act 2023 is a new set of laws that protect children and adults online. It places a range of duties and responsibilities on social media companies and search services making them more responsible for their users’ safety when on their platforms. The Act will give internet providers new duties to implement systems and processes to reduce risks when their services are used for illegal activity, and to take down illegal content when it does appear.

Ofcom is now the independent regulator of online safety, and it has a broad range of powers to assess and enforce providers compliance within the framework. The Act has codes of practice and related criminal offences which will support in tackling the following but is not limited to:

  • Age-appropriate experiences for children online.
  • Providing adults with more control over the content they see.
  • The Act will tackle suicide and self-harm content.
  • It will tackle harmful algorithms.
  • The Act will protect women and girls.

Artificial Intelligence (AI)

WTS are excited about the opportunities for innovation and efficiency which AI (Artificial Intelligence) presents, and we intend to incorporate these in a safe and legally compliant manner which allows our employees and other stakeholders to obtain maximum benefit from these tools.

We need to ensure that organisational private, personal, stakeholder and other sensitive data is not intentionally or inadvertently transmitted to such platforms or related third parties in violation of compliance controls to which the organisation and employees of Waverley Borough Council must adhere to.

Employees must obtain explicit, documented authorisation from the Data and Administration Manager before using AI platforms for work-related tasks or for tasks of any kind carried out on a WTS device, whilst connected to such systems and/or networks.

This applies in instances whereby the employee in question does not believe that they have access to sensitive data or does not believe that AI use presents a risk.

The employee must be required to complete appropriate training on data classification standards and/or the appropriate use of generative AI platforms before authorisation is given.

Authorisation may be withdrawn at any time by the Data and Administration Manager.

Approved AI software to be used on WTS equipment and systems includes:

  • Microsoft Copilot.
  • TeacherMatic.

Waverley Training Services owned Digital Technology

The hardware, software and network resources purchased by WTS and WBC provided by either, are to be used for creating, researching and processing WTS related materials. All employees are responsible for exercising good judgement regarding the personal use of such resources. Storing personal files such as music, digital pictures or videos on those systems is not permitted.

WTS recognises that use of the internet connected devices is part of everyday life for most people. Devices of any kind that are brought onto site are the responsibility of the user. All members of the WTS community are advised to:

  • Take steps to protect their mobile phones or personal devices from loss, theft or damage; we accept no responsibility for the loss, theft or damage of such items whilst on the premises.
  • Devices should be secured with the use of passwords/PIN numbers to prevent unauthorised access, calls or actions on their devices.
  • The sending of abusive or inappropriate messages or content via any device is forbidden by all members of the WTS community, any breaches will be dealt with in line with the behaviour, WBC Code of Conduct and Safeguarding and child protection policies.
  • All members of the WTS community are advised to ensure that their mobile phones or personal devices do not contain content which may be offensive, derogatory or illegal, which would otherwise contravene our Behaviour or Safeguarding & Child protection policies.
  • All employees must ensure that when using personal devices to access WTS services, that the device has appropriate anti-virus software installed and running the latest security updates. Additionally, personal devices should be secured with a password or passcode to prevent unauthorised access.

Visitor use

Learners and visitors including contractors are expected to ensure that:

  • Mobile phones and personal devices must not be used to take photos or videos of any employee or Learner unless explicit consent has been given.
  • Mobile phones and personal devices must not be used to record conversations with employees or Learners, unless explicit consent has been given.
  • Learners and visitors who are on site for regular or extended periods of time are expected to use technology in accordance with this policy and other associated policies, including the Safeguarding and Child protection policy.
  • Learners or visitors who require access to WTS devices such as for online exams and any such arrangement must comply with this policy for the duration of their assessment.

WTS part of our funding agreement with the Department for Education (DfE), annually complete and maintain our Cyber essentials assurance certificate to protect our systems and the information we hold from the risk of cyber security threats. It supports in preventing:

  • Safeguarding issues due to sensitive data being compromised.
  • Impact on Learner outcomes.
  • Significant data breach.
  • Significant and lasting disruption, including the risk of repeated cyber incidents and attacks in the future.
  • Financial loss.
  • Reputational damage.

Anti-Virus software is installed on computers which are supplied to employees. This software is maintained daily and will stop the majority of PC virus problems, but it is still necessary for employees to remain vigilant when receiving new documents from outside the Council and unknown sources.

Downloading content from the internet or opening emails are the most common examples of how devices can be affected by a virus, any suspicious looking emails should be reported immediately, either to your line manager or via the Phish Hook function in email 365.

Complex password guidance

The definition of a complex password and the requirements are:

  • Passwords must be strong and unique for each individual account.
  • Must not contain three consecutive characters from your names or your username. Avoid using predictable words such as names of family members, pets, or places. For example: max1980.
  • A minimum of eight characters containing characters from at least three of the following groups:
  • Uppercase letters: A, B, C, D
  • Lowercase letters: a, b, c, d
  • Numerals: 0, 1, 2, 3, 4
  • Symbols: !@%$&

Creating a strong password

Secure passwords should be easier to remember and difficult to guess. Incorporating numbers and symbols can enhance password strength. Alternatively, a passphrase can be used instead, these are typically more memorable and are just as secure.

  • Passphrase example: mouse-add-talon.
  • Add a memorable date or string of numbers.
  • Start with a capital letter or Punctuation symbol.

Passwords can be stored within a password manager. Both Google Chrome and Microsoft Edge have these built in as standard. This is the recommended, safest most secure way to store passwords.

Internet use

The internet contains a vast array of information. However, not all information on the internet is accurate, complete or reliable and employees should always critically evaluate its validity before using it.

Employees must not download any copyrighted graphics, software or any other programme from the internet at any time unless authorised to do so either as part of their duties and/or with the approval of your Line Manager.

Internet access is provided to assist you in your job role. You should only use the internet for legitimate purposes which relate to WBC and WTS business and for minimal personal use. Internet use must comply with.

  • Full compliance with WBC and WTS rules, policies and procedures including, but not limited to, this policy, WBC Equal Opportunities Policy, WBC Dignity and Respect policy and the WBC Disciplinary and Grievance Procedure.
  • Usage must not include sites such as online betting and gambling.
  • Usage does not commit the Council to contractual obligations.

Filtering and monitoring

The Council and Addcom regularly logs the use of ICT equipment and systems. The Council may need to monitor, intercept and record the use of ICT systems, including your PC, to ensure its use is not placing Council systems and/or services including your PC, at risk or is otherwise inappropriate.

To ensure it complies with its own legal obligations the Council and Addcom may monitor and record:

  • Times, periods of patterns of internet use, websites accessed, connection lengths.
  • Frequency, times and patterns of use of email use, email addresses to which you have sent emails and the size of attachments.
  • Telephone calls primarily for the protection of employees.

At WTS there is user-based internet filtering, allowing an appropriate level of browsing permission for different age groups, following the guidance from the DfE's Keeping Children Safe in Education.

The following are examples of blocked categories: Discrimination, Explicit Violence, Extremists groups, Gambling, Dating, Weapons, and Pornography.

Websites and services are reviewed individually from permitted categories such as social media, entertainment, streaming media and instant messaging.

All users of WTS ICT equipment must adhere to internet controls and make no attempt to bypass such restrictions. In the event of accidental breach please seek immediate guidance and support from your line manager or the Data and Administration manager.

Email misuse

Misuse of the email system or the internet system by the intended or negligent viewing, downloading or transmission, distribution or receipt of material or images listed below (without limitation), whether or not in working hours, will constitute as gross misconduct and the Council will take disciplinary action which may result in the offender’s dismissal, including summary dismissal in sufficiently serious cases.

The material must not be:

  • Defamatory, untrue or malicious.
  • Offensive, pornographic or obscene. This includes not only indecent or obscene material which it is an offence to possess or publish, but also materials which anyone in the office may reasonably view as distasteful or likely to cause offence to others.
  • In breach of copyright.
  • In breach of confidentiality of Council Information.
  • Harassment or discrimination centralising on the protected characteristics as part of the Equality Act 2010.
  • For personal business activities.
  • Illegal activities.
  • Bullying.
  • In breach of security regarding ICT equipment and systems.

Social media encompasses social networking sites such as but not limited to, Facebook, Instagram, WhatsApp, Snapchat, and ‘X’ (formerly Twitter) as well as more general types of social media such as but not limited to blogs, podcasts and digital images and videos.

Lines between public, private and professional can become blurred in the online world. All employees of WTS are personally responsible for the content they publish online. Users should be reminded that what they post will be published for a long time in regard to their digital footprint, and future employers can access your earliest posts from social media.

Employees should be aware of publishing of any material in their private life that defames WTS or WBC or has the potential to negatively impact the Council and its reputation or its business, which may result in disciplinary action which could lead up to including dismissal.

You are encouraged to report in confidence unlawful or inappropriate use of the email system or the internet to the Human Resources Manager or to any other person named in the Whistle Blowing Policy.

General statistical and system logging information relating to the management and operation of ICT systems

The reason for monitoring, intercepting and recording is to:

  • Check the use of ICT equipment and systems is legitimate and complies with Council rules.
  • Investigate misconduct and to comply with any of the Council's legal obligations in accordance with legislative requirements such as the regulation of Investigatory Powers Act 2000. The telecommunications (Lawful business practice) (interception of Communications) Regulations 2000, the computer misuse Act 1990, GDPR 2018 and Humans Rights Act 1998.

All employees have responsibilities under the Data Protection Act 2018 and the UK General Data Protection Regulation. This includes the confidentiality of all information held by WTS and Council systems. If you become aware that information you have access to, in the course of your employment may have become compromised or accessed inappropriately, you must inform the Data Protection Officer and your line manager as soon as possible.

Full details of how WTS process and handle data can be found in the Data Protection (GDPR) and Privacy Policy.

If you believe your account has been compromised, it is crucial to take immediate action to minimise potential impacts. Prompt reporting is essential to prevent further unauthorised access to your account and WTS systems. Our IT contractor Addcom must be notified of potential breaches.