Case study: Staff checks stay within law

Case study: Staff checks stay within law

In the past there have been several cases where companies have been subject to, or forced to take, legal action due to the inappropriate content of emails or Web sites.

To prevent such problems, many firms carry out some monitoring of email and Internet use. One such company is legal practice Morgan Cole. As a law firm, it is aware of the importance of complying with the Data Protection Act (DPA) when carrying out staff monitoring, and is keen to strike an acceptable balance between employee privacy and company protection.

However, Morgan Cole’s system did not offer enough functionality. ‘We didn’t find it flexible enough to do what we wanted to,” says solicitor Mark Smith. “It didn’t match our acceptable usage policy.” Morgan Cole wanted proven technology with a good reputation to help it uphold its usage policy, and manage disclaimers on staff emails.

Access control

It chose tools from Clearswift’s MimeSweeper family of monitoring products. MailSweeper was installed to analyse incoming and outgoing email messages at the Internet gateway, and WebSweeper was set up to monitor and control Web-site access.

MailSweeper is also helping to enhance disclaimers in staff emails. ‘We’ve been looking at the wording of the disclaimer, and the introduction of a split-level one,’ says Smith. A solution is under development to create tailored disclaimers, which add a short summary of the disclaimer at the top of an email – where it is legally required – and add the full details at the end.

Smith says this type of system will make disclaimers more effective. ‘If you put a confidentiality clause on every email, somebody could argue against its validity because a simple lunch invite would have such a clause,’ advises Smith. ‘We want to put extra confidentiality disclaimers on some emails according to keywords. So, as an example, if the solution detects an email relating to a merger codenamed Bobcat, it would put a stricter disclaimer on this text.’

As well as implementing the Clearswift solutions, Morgan Cole has updated its acceptable usage policy. ‘A new policy has been signed by all employees,’ says Smith. It clearly tells staff what is expected of them.

Legal compliance

It is essential to ensure that use of monitoring solutions complies with the DPA. Paul Rutherford, chief marketing officer at Clearswift, says that if firms are employing tools to analyse and control Internet and email use, they need to ensure that staff are made aware of the processes and guidelines.

The first step is to define a policy that spells out for staff the type of content that is and is not acceptable. ‘Firms must also educate employees on these rules and why they have been introduced,’ adds Rutherford.

To ensure that staff are aware of the monitoring procedures, firms could include a section on the policy in employment contracts and induction courses, or ask staff to tick a box to acknowledge monitoring each time they log on to the network, says Rutherford. Firms might also hold briefings about email and Web use, and send reminders about good practices via email.

Summary

Business need: Law firm Morgan Cole wanted a more flexible content monitoring system to help it comply with data protection legislation.

Technical considerations: The system needed to support its policy on email and Internet use.

Solution: Morgan Cole bought new content monitoring tools and set them up after informing staff how the tools would be used.

Share

Subscribe to get your daily business insights

Resources & Whitepapers

The importance of UX in accounts payable: Often overlooked, always essential
AP

The importance of UX in accounts payable: Often overlooked, always essentia...

1m Kloo

The importance of UX in accounts payable: Often ov...

Embracing user-friendly AP systems can turn the tide, streamlining workflows, enhancing compliance, and opening doors to early payment discounts. Read...

View article
The power of customisation in accounting systems
Accounting Software

The power of customisation in accounting systems

2m Kloo

The power of customisation in accounting systems

Organisations can enhance their financial operations' efficiency, accuracy, and responsiveness by adopting platforms that offer them self-service cust...

View article
Turn Accounts Payable into a value-engine
Accounting Firms

Turn Accounts Payable into a value-engine

3y

Turn Accounts Payable into a value-engine

In a world of instant results and automated workloads, the potential for AP to drive insights and transform results is enormous. But, if you’re still ...

View resource
8 Key metrics to measure to optimise accounts payable efficiency
AP

8 Key metrics to measure to optimise accounts payable efficiency

2m Kloo

8 Key metrics to measure to optimise accounts paya...

Discover how AP dashboards can transform your business by enhancing efficiency and accuracy in tracking key metrics, as revealed by the latest insight...

View article