Jump to content

Recommended Posts

Posted (edited)

I have had this message from one of our members who has spoken to the ICO about opening attachments like pdfs.

 

I've been on the live chat with the ICO. It looks like we would need to open the PDF file if an FoI is submitted in that way. If we refused on security grounds, we would need "compelling evidence" to justify this and PDF files are less dangerous than websites.

 

The person I chatted with says ICO opens email attachments.

 

Personally, I think that builds a grey area into our cyber security advice and makes us more susceptible to attacks where people make links look like PDF files or use double dot extensions (foi-request.pdf.exe), but I can see the point they're making.

 

He did say "if you take and document a reasonable position we are unlikely to have any serious issue with you even if we find you to be in error." so, even if they ruled against our refusal, the outcome would simply be telling us to respond, no punitive action for the delay.

Edited by elsiegee40
  • Thanks 3
Posted (edited)

I think the best advice to schools is that if they receive an FoI request and are suspicious about it to contact the ICO directly.

 

The school has a requirement to put security measures in place and the tribunal was clear that it was perfectly reasonable for schools to have a policy that says not to click on unknown links. This advice would be the same for anything unknown.

 

If schools let the ICO know then they can investigate it within context and give the correct advice at the time.

 

If this particular request is resubmitted it may even be considered vexatious.

Edited by elsiegee40
  • Thanks 1
Guest
This topic is now closed to further replies.



×
×
  • Create New...