Online Safety Policy
HSCS: 3.20, 3.21, 3.22, 3.23, 3.24, 3.25
This policy should be read in conjunction with the Data protection and confidentiality policy, Acceptable internet use policy and General Data Protection Regulation (GDPR) privacy notice.
Our nursery is aware of the growth of internet use and the advantages this can bring. However, it is also aware of the dangers and strives to support children, staff and families in using the internet safely.
We refer to ‘Safeguarding children and protecting children and protecting professionals in early years settings: online safety considerations’ to support this policy.
The use of technology has become a significant component of many safeguarding issues such as child sexual exploitation, radicalization, and sexual predation: technology often provides the platform that facilitates harm.
The breadth of issues included within online safety is considerable, but can be categorized into three areas of risk:
- Content: being exposed to illegal, inappropriate or harmful material; for example, pornography, fake news, racist or radical and extremist views
- Contact: being subjected to harmful online interaction with other users; for example commercial advertising as well as adults posing as children or young adults
- Conduct: personal online behaviour that increases the likelihood of, or causes, harm; for example making, sending and receiving explicit images, or online bullying.
Within the nursery, we aim to keep children, staff and parents safe online. Our safety measures include:
- Ensuring we have appropriate antivirus and anti-spyware software on all devices and update them regularly
- Ensuring content blockers and filters are on all our devices, e.g. computers, laptops, tablets and any mobile devices
- Ensuring all devices are password protected and have screen locks. Passwords should be kept safe and secure, changed regularly and not write them down
- Monitoring all internet usage across the setting
- Providing secure storage of all nursery devices at the end of each day
- Keeping passwords safe and secure, not sharing or writing these down. These will be changed at least every term to keep the devices secure
- Ensure management monitor all internet activities in the setting
- Locking away all nursery devices at the end of the day
- Reviewing all apps or games downloaded onto devices ensuring they are age and content appropriate
- Ensuring no social media or messaging apps are installed on nursery devices
- Management reviewing all apps or games downloaded to tablets to ensure all are age appropriate for children and safeguard the children and staff
- Using only nursery approved devices to record and/or photograph in the setting
- Ensuring that staff do not to use personal electronic devices with imaging and sharing capabilities, including mobile phones, smart watches and cameras
- Never emailing personal or financial information
- Reporting emails with inappropriate content to the internet watch foundation (IWF https://www.iwf.org.uk/)
- Teaching children how to stay safe online and report any concerns they have
- Ensuring children are supervised when using internet connected devices
- Ensuring children are supervised when using internet devices
- Using tracking software to monitor suitability of internet usage (for older children)
- Not permitting staff or visitors private access to the nursery Wi-Fi
- Integrating online safety into nursery daily practice by discussing computer usage ‘rules’ deciding together what is safe and what is not safe to do online
- Talking to children about ‘stranger danger’ and deciding who is a stranger and who is not; comparing people in real life situations to online ‘friends’
- When using online video chat, such as Zoom, Teams, Skype and FaceTime etc. (where applicable) discussing with the children what they would do if someone they did not know tried to contact them
- Staff model safe practice when using technology with children and ensuring all staff abide by an acceptable use policy such as instructing staff to use the nursery internet equipment for matters relating to the children and their education and care. No personal use will be tolerated (see Acceptable internet use policy)
- Monitoring children’s screen time to ensure they remain safe online and have access to material that promotes their development. We ensure that their screen time is within an acceptable level and is integrated within their programme of learning
- Making sure the physical safety of users is considered, including the posture of staff and children when using devices
- Being aware of the need to manage our digital reputation, including the appropriateness of information and content that we post online, both professionally and personally. This is continually monitored by the setting’s management
- Staff must not friend or communicate with parents on personal devices or social media accounts
- Ensuring all electronic communications between staff and parents are professional and take place via the official nursery communication channels, e.g. the setting’s email addresses and telephone numbers. This is to protect staff, children and parents
- Signposting parents to appropriate sources of support regarding online safety at home
Cyber security
Good cyber security means protecting the personal or sensitive information we hold on children and their families in line with the Data Protection Act. We are aware that cyber criminals will target any type of business including childcare and ensure all staff are aware of the value of the information we hold in terms of criminal activity e.g. scam emails. All staff are reminded to follow all the procedures above including backing up sensitive data, using strong passwords and protecting devices to ensure we are cyber secure.
To prevent any attempts of a data breach (which is when information held by a business is stolen or accessed without authorisation) that could cause temporary shutdown of our setting and reputational damage with the families we engage with, we inform staff not to open any suspicious messages such as official-sounding messages about 'resetting passwords', 'receiving compensation', 'scanning devices' or 'missed deliveries'.
Staff are asked to report these to the manager as soon as possible and these will be reported through the National Cyber Security Centre (NCSC) Suspicious email reporting service at report@phishing.gov.uk
Policy Adopted:
January 2025 - S.Sneddon
Policy Reviewed: January 2026 - S.Sneddon