Blog · Online safety and responsible use

The school's acceptable use policy for technology: how to write it and how to keep it working

Practically every school has rules on the use of technology. The problem is that they are not always gathered in one place. Some may appear in the school's internal regulations, others may have been communicated to families at the start of the year, and many decisions are applied simply because ‘it has always been done this way’. As long as no conflict arises, this scattering can go unnoticed. The difficulty comes when you have to respond to a specific situation. A school laptop comes back damaged, a family asks what information the school can see about their child's device or a teacher needs to know whether a particular app can be used in class. Without a common criterion, the answer depends too much on who receives the question. An acceptable use policy exists precisely so that those decisions are made before the problem arises.

The rules exist even if nobody has gathered them together

A school does not start from scratch. Decisions already exist about which devices are used, which websites are blocked, which apps can be installed, when a laptop can be used in class or what happens if a student breaks a rule. Many of them are even applied technically in the MDM, in the filtering system or in the network configuration.

The problem is that the written policy and the technology configuration may have evolved separately. There may be a restriction that was set up three school years ago to deal with a one-off situation, and nobody now remembers why it is still active. Or the opposite may happen: the regulations lay down a rule that was never actually applied technically.

That is why the first step should not be to download a template and start filling it in. It is better to take stock of what the school is actually doing today and then compare it with what it wants to do from now on.

The policy also does not need to become an endless document. A reasonably short, clear text known to teachers, students and families is usually far more useful than twenty pages that hardly anyone reads to the end.

What the school has to decide

A good policy should make it possible to answer fairly specific questions without improvising: who can use each type of device, in which phases of education, for which activities and at what times. It should also explain what happens with the devices the school lends to students, who is responsible if they are damaged or lost and what measures can be applied when the rules are broken. And there is one particularly important question that more and more families are asking: what the school can see and what it cannot.

It is not enough to say that ‘devices are monitored’. That phrase can mean many things. The school may block certain categories of browsing, keep certain logs or, if the technology allows it and there is adequate justification, use more advanced management features. These are different capabilities and should be explained differently.

Transparency avoids a lot of conflict. Families should know in advance what controls exist, what they are used for and which devices they apply to. In the same way, it is advisable to explain what the school does not do as well. If the system's capabilities are simply listed without defining their limits, it is easy to give the impression that much more is being watched than is really the case.

Filtering, logging and viewing are not the same thing

The distinction is worth explaining because technically these are very different actions. A filtering system can stop a device from accessing certain categories of content. In that case the policy decides what can and cannot be opened. Keeping logs that record what has been accessed is something else. And viewing or controlling a device's screen while someone is using it would be something else again.

All these possibilities should not be lumped together under the generic label ‘parental controls’ or ‘device monitoring’. If the school uses any of them, the policy must explain which tool is applied, for what purpose and in what circumstances.

In an educational setting this clarity is especially important because we are talking about minors. Information and data protection obligations mean that the people affected must be able to understand what processing takes place and why. The school's data protection officer is also the right person to review these aspects before the policy is approved and communicated.

A school device and a family device are not the same

This is one of the most important distinctions when writing the policy. You cannot simply talk about ‘devices’ as if they all belonged to the same environment.

When a laptop, a tablet or an interactive panel belongs to the school, the school can manage it as part of its infrastructure: installing apps, configuring the Wi-Fi, applying restrictions, setting updates or recovering the device when necessary. If that device leaves the building because it is assigned to a student or a teacher, it remains the school's property and is still subject to the terms of use that have been set.

The situation changes when the device belongs to the family or to the student. The school can set the conditions for accessing its network and services, but the ability to manage a personal device requires a specific framework and should not be taken for granted. The conditions must be fully explained and reviewed from a data protection point of view before any additional management is applied to a device that is not the school's property.

That is why the policy needs to separate the two scenarios clearly. Promising families a level of control that does not technically exist causes problems when the time comes to apply it. And applying the same policies designed for a school-owned computer to a family device can also cause unnecessary conflict.

The rules can also change by phase of education

A primary pupil (ages 6–12) does not need the same degree of autonomy as a Bachillerato student (ages 16–18). The same goes for the tools available, the times of use or the browsing restrictions.

The policy should allow the school to reflect its own educational approach and to evolve with age. There may be phases in which the use of devices is closely guided and others in which students are expected to take on more responsibility. Technology must be able to keep pace with that evolution.

This has a very specific consequence for the infrastructure: the MDM, the filtering and the network should allow different policies to be applied by phase, group or user type. If the tool only allows one identical policy for the whole school, it will probably end up forcing the school to choose between restricting some students too much or others too little.

At PenwinEdu we have seen for years that this is one of the areas where it shows most whether a solution has really been designed with education in mind. A school is not a homogeneous group of users, and technology should not treat it as if it were.

You also have to say when the rules apply

A technology policy does not have to be the same twenty-four hours a day. A school-owned device that a student takes home may be subject to certain restrictions during school hours and to different ones in the afternoon and evening. The school itself must decide where that boundary lies and what use it wants to allow outside the classroom. The technology simply has to be capable of turning that decision into a specific configuration.

There may also be differences between a lesson, break time, a school trip or a special activity. The clearer that distinction, the less the teacher will depend on interpreting the rule in each situation.

An important idea comes up here again: technology should not decide educational policy. First the school determines what it considers appropriate; then the infrastructure is configured to try to apply it as simply as possible.

Families, students and teachers need tailored versions

The policy affects different groups and does not necessarily have to be communicated in exactly the same way to all of them. Families need to know the terms of use for devices, especially when a device leaves the school, and to have clear information on the management and monitoring measures in place. Students should receive an explanation suited to their age, with rules they can understand and relate to real situations.

Teachers are also part of the system. If the rules are applied differently in each classroom, the policy quickly loses its usefulness. In addition, the devices the school gives its staff are also subject to employment law.

Article 87 of the LOPDGDD (Spain's data protection act) recognises employees' right to privacy when using digital devices provided by their employer and requires criteria to be set for their use. The conditions that apply to a laptop given to a teacher therefore also need their own review and should not simply be copied from the student policy.

In institutions offering higher vocational programmes, as well as in universities and business schools, there is another scenario too: adult students. In those cases both the relationship with families and many of the reasons that justify certain measures in compulsory education change. A policy covering different educational levels has to reflect those differences.

What happens when someone breaks the policy

It is best to avoid dealing with each breach on an improvised basis. It is one thing for the school's leadership to adopt an educational or disciplinary measure, and another for a restriction to be applied technically to a device. The IT team should not become the one that decides what consequence a student faces. Its role is to apply the decisions the school has made, following the relevant procedure.

For example, if it is decided to restrict a student's access to a particular service temporarily, it should be clear who can request that measure, for how long and who authorises its removal. If these instructions reach the IT lead informally and there is no record, months later a restriction that nobody remembers asking for may still be active.

Technology makes it very easy to apply restrictions. That is precisely why there needs to be an equally clear procedure for removing them.

A technology policy has to be reviewed every school year

The document should not be written once and filed away indefinitely. A school's technology changes too quickly. Every year new apps appear, devices are replaced, the phases working with assigned devices may change and some management tools are modified. Educational needs change too, and the previous year's experience shows which rules worked well and which raised questions.

A review before the start of the school year is usually enough to keep the document up to date. The most effective approach is to review the policy and the technical configuration at the same time. For each important decision you can check whether there is an MDM, filtering or network policy that applies it and, conversely, whether each technical restriction that is still active reflects a decision the school still stands by.

Not every rule needs a technological solution. Some are upheld perfectly well through teachers' work and through education in responsible use. What matters is that the school knows which ones depend on technology and which do not.

The role of the technology provider

The acceptable use policy should not be written by the IT provider. It is the school's own decision because it reflects its educational approach, its way of working and the rules it wants to set with students, families and staff.

The provider's role begins afterwards: it must check that the tools available allow those decisions to be applied reasonably. If the school wants different policies for each phase, the infrastructure must support them. If it needs certain schedules, it must be possible to configure them. And if the system generates activity logs, the school needs to know exactly what it records, for how long and who has access to that information.

The provider also has to be able to say when a request cannot be met as it stands. Quietly adapting the rule to the product's limitations is doing things the wrong way round.

At PenwinEdu we work in precisely that order: first we understand what the school has decided and then we translate it, where possible and appropriate, into network, filtering and device management policies. Our experience in schools also allows us to anticipate situations that may not come up in the first meeting but will arise during the year.

A useful policy is one that matches what actually happens

The value of this document does not lie in having a perfectly worded technology policy for an inspection or to send to families. It lies in the fact that, when a question comes up in February, the answer a family receives is the one the school decided on in September, and that the device configuration reflects that decision.

The policy should make clear who can use each technology, for what, when, what the school monitors, what it does not monitor and what happens when someone breaks the rules. The infrastructure then has to support those decisions without adding unnecessary complexity to the work of teachers and the IT lead.

Sources

  1. Agencia Española de Protección de Datos, «Criterios para el tratamiento de datos personales en centros educativos» (2023) (in Spanish)
  2. Ley Orgánica 3/2018, de 5 de diciembre, de Protección de Datos Personales y garantía de los derechos digitales (LOPDGDD), artículos 34 y 87 (in Spanish)

At PenwinEdu we know that balance well because we manage schools' technology every day. We do not see filtering, MDM or the network as separate tools, but as elements that have to serve the school's educational approach and its own decisions. When policy and technology move forward together, there is less improvisation, families understand better how devices are used and the school can maintain consistent criteria throughout the year.