Purpose
This policy sets out the conditions under which FUNDA staff may use personal mobile devices to access childcare registers. It ensures compliance with safeguarding, data protection, and UK GDPR, and provides clarity for staff, parents, and regulators.
Scope
This policy applies to all FUNDA staff who are responsible for signing children in and out of Wraparound Care, Holiday Camps, or other childcare services where registers are required.
Policy Statement
FUNDA’s childcare registers are cloud-based and accessed securely through an approved application or web portal.
Registers contain sensitive child and parent information (personal data). Protecting this data is a legal and safeguarding responsibility.
Staff may access registers using personal devices only as a backup or in an emergency situation, when no FUNDA device is available.
The primary expectation is that staff use FUNDA-provided or designated devices for register management.
Rules for Using Personal Devices
Backup/Emergency Use Only
Personal devices must not be used as the default method for register access.
They may only be used if FUNDA devices are unavailable, not working, or in an emergency to ensure children are safely signed in/out.
Cloud Access Only
Registers may only be accessed via FUNDA’s official cloud-based system.
No register information may be downloaded, exported, or stored locally on the device.
Automatic Log-Out
The register system automatically logs users out after inactivity.
Staff must also log out at the end of each session.
Device Security
Personal devices must be secured with a PIN code, password, or biometric lock.
Devices must not be shared with friends, family, or children.
Data Handling
Screenshots, photos, or copies of register data are strictly prohibited.
Staff must not save login details in an insecure way (e.g., notes app, visible paper).
System Monitoring & Audit Logs
FUNDA’s register system includes admin logs that record staff access and usage.
These logs allow management to review activity and identify any potential data protection breaches, including attempted screenshots or unauthorised access.
Any breach identified through logs will be treated as a serious disciplinary matter and may also be reported to the Information Commissioner’s Office (ICO).
Safeguarding
If a device used to access registers is lost or stolen, this must be reported immediately to a line manager and may need to be logged as a data breach.
Staff must never allow children or parents to view or use the system on their personal device.
Responsibilities
Staff: Ensure compliance with this policy at all times and only use personal devices when necessary as a backup.
Managers: Monitor practice and provide reminders/training where required.
Data Protection Officer (DPO): Conduct risk assessments, review admin logs as required, and review this policy annually.
Parent Assurance
Parents can be assured that:
All registers are stored securely in the cloud.
No data is stored on staff personal devices.
Strict security measures are in place to protect both child and parent information.
Personal devices are only used in exceptional circumstances, not as standard practice.
FUNDA uses system audit logs to monitor staff access and detect any data breaches swiftly.
Review
This policy will be reviewed annually or sooner if required by changes in legislation, Ofsted guidance, or FUNDA operational needs.
