psydii Posted May 22, 2018 Posted May 22, 2018 Any ideas what the current best practice is around putting personal information into staff pigeon holes/trays? Currently things go into sealed envelopes and then into the pigeon holes/trays. Is this generally considered secure enough?
hardtailstar Posted May 22, 2018 Posted May 22, 2018 I wouldn't say its secure at all. I always collect my boss's stuff from his pigeon hole and then give it to him back in the office. What is going to stop somebody just taking out someones letter and reading it?
djrscally Posted May 22, 2018 Posted May 22, 2018 I would say this is broadly secure enough.* Remember; you can't actually stop your employees maliciously stealing all the data that they want, and that's on them. All you have to be doing is taking appropriate steps to keep it secure, and I'd argue that as long as the room with the pigeon holes is controlled access to staff only (I.E. members of the public can't just wander in) then having confidential documents be in clearly marked opaque envelopes is enough to say you took appropriate steps to protect the data inside. *The caveat is that the exact answer depends on the nature and quantity of the personal data that's being delivered in this way, but I think for most things (certainly everything I've ever received through work) it would be ok.
FN-GM Posted May 22, 2018 Posted May 22, 2018 (edited) You're supposed to be protecting the data from external parties. Unless the Pigeon holes are in a public area such as the reception you should be fine. Edited May 22, 2018 by FN-GM
TheSysAdminLife Posted May 22, 2018 Posted May 22, 2018 GDPR could be regarded as a way to discourage organisations and individuals from allowing data to be where it shouldn't be. In this case I would count Students having access to pigeon holes a potential breach waiting to happen. Our pigeon holes are in a corridor that is used by many students regularly, no lock on the door at all. I think this needs to change. If the money is there for it, we'll push to get a card reader lock installed (which we use elsewhere) I think the OPs setup is okay, but they should think about the security of the room, too. Perfect world = Authorised access only on the pigeon holes themselves, all logged. Never going to happen, though. There's an element of trust placed on the staff, so securing the room should be adequate. djrscally is right.
enjay Posted May 23, 2018 Posted May 23, 2018 So long as the confidential letters are in sealed envelopes, I think this would be fine. My technician doesn't open my post anyway, and if your does, just tell them not to! Personally, I don't think people should open other people's named post anyway; if it said "the IT manager" or a former eomployee's name, but not if it is named to a current employee. I wouldn't open my technician's post and I don't expect him to open mine. Our pay slips have our home addresses on and get left in our pigeon holes. I'm not a big fan of this, having had a colleague at a previous school find out my address and turn up on the weekend for IT support!
FN-GM Posted May 23, 2018 Posted May 23, 2018 So long as the confidential letters are in sealed envelopes, I think this would be fine. My technician doesn't open my post anyway, and if your does, just tell them not to! Personally, I don't think people should open other people's named post anyway; if it said "the IT manager" or a former eomployee's name, but not if it is named to a current employee. I wouldn't open my technician's post and I don't expect him to open mine. I think it is illegal to open someone else post anyway. Our pay slips have our home addresses on and get left in our pigeon holes. I'm not a big fan of this, having had a colleague at a previous school find out my address and turn up on the weekend for IT support! You still have pay slips!! Not seen them in years. I have been emailed PDF files for donkeys years. From 2009 I think.
enjay Posted May 23, 2018 Posted May 23, 2018 I think it is illegal to open someone else post anyway. At home, yes. Not sure if that applies within a business or not. When I first started, I would open mailshots addressed to my predecessor, but now they get binned. If the company has had so little contact in the 5 years I've been here to think that's still the right name, I'm not interested in whatever is in the envelope! You still have pay slips!! Not seen them in years. I have been emailed PDF files for donkeys years. From 2009 I think. Our previous payroll company emailed them, but made such a mess of it I think the Finance Manager is scared of it now.
mthomas08 Posted May 23, 2018 Posted May 23, 2018 Move away from paper to email etc. I like you. You are a dreamer No seriously though if only! For the OP: good question. If steps are taken to be secure e.g. staff only area. You've already done one major step to be compliant. We have two sets of pigeon holes, an area for SLT with staff who deal with sensitive data and another area for departments in general. The sensitive pigeon holes are in the main office which is locked when empty. The main pigeon holes are in the staff room. Our auditor didn't pay much attention to it though if any.
enjay Posted May 23, 2018 Posted May 23, 2018 We have two sets of pigeon holes, an area for SLT with staff who deal with sensitive data and another area for departments in general. What about non-SLT who handle sensitive data? Arguably, our HR Manager handles more sensitive data than the Asst Head in charge of CPD.
PotNoodleTech Posted May 23, 2018 Posted May 23, 2018 It depends where the pigeon holes are! If they are in the staff room with fingerprint and retina scan controlled access to the room, then that is pretty secure. If they're in reception and visitors walk past them on the way to the sign in desk - then that is utterly insecure. It's an interesting one.
Oaktech Posted May 23, 2018 Posted May 23, 2018 Payslips are sealed, general correspondence is sealed, pigeon holes are not in a public area and not an area that kids can readily access (mag lock door). That being said, I believe very sensitive correspondance such as redundancy notices, termination of contract etc are handed over personally.
enjay Posted May 23, 2018 Posted May 23, 2018 PThat being said, I believe very sensitive correspondance such as redundancy notices, termination of contract etc are handed over personally. It's the not-immediately-obviously-sensitive stuff you need to consider too. What happens when someone is absent through illness, requests cover or in the case of termtime-only staff time-off during term? If any of these processes involve slips of paper in pigeon holes - even just a blank "why were you off sick?" form - then you should possibly reconsider.
Oaktech Posted May 23, 2018 Posted May 23, 2018 It's the not-immediately-obviously-sensitive stuff you need to consider too. What happens when someone is absent through illness, requests cover or in the case of termtime-only staff time-off during term? If any of these processes involve slips of paper in pigeon holes - even just a blank "why were you off sick?" form - then you should possibly reconsider. Good point - although here those forms are in a central location, Sickness, Leave of Absence, expenses, eyetest claim, that sort of thing are in a stack of drawers in the staff room. Illness should follow a process: You come back after an illness, a reminder email to fill the form in will have already been sent to you with a form attached, you can either fill in and email back - it's a word document - or you can print and hand over, or you take one out of the forms trays, fill it in and hand it directly to HR. If the process in the staff handbook is followed they shouldn't go near a pigeon hole. Having said all of that, I'm going to mention to the HOS that he should be putting LOA requests in envelopes not just dumping them back in trays. If HR do the form it's folded in an envelope, if the HOS does them then he's a bit lax.
enjay Posted May 23, 2018 Posted May 23, 2018 Illness should follow a process: You come back after an illness, a reminder email to fill the form in will have already been sent to you with a form attached, you can either fill in and email back - it's a word document - or you can print and hand over, or you take one out of the forms trays, fill it in and hand it directly to HR. If the process in the staff handbook is followed they shouldn't go near a pigeon hole. Here, the blank absence form is printed and put in the staff member's pigeon hole, so no details but still a visible flag someone has had time off. Staff can either return the completed ones via the HR Manager's pigeon hole (which is their choice) or in person.
andrew150690 Posted May 23, 2018 Posted May 23, 2018 Hi, You could use Office 365 Email encryption to send electronic copies of the documents going into the pigeon holes. We currently have a transport rule setup that automatically encrypts any emails that include the subject header 'Confidential' This then requires the end user to login to access the documents keeping everything secure and GDPR Compliant.
psydii Posted May 24, 2018 Author Posted May 24, 2018 Hi, You could use Office 365 Email encryption to send electronic copies of the documents going into the pigeon holes. We currently have a transport rule setup that automatically encrypts any emails that include the subject header 'Confidential' This then requires the end user to login to access the documents keeping everything secure and GDPR Compliant. Have you got a link to how you set that up?
Pink_Panda Posted May 24, 2018 Posted May 24, 2018 definitely not secure. In my last post pay slips over the summer got put into pigeon holes, mine got opened by someone else, who put a yellow sticky note on it saying: OOPS, sorry I opened it by mistake. Don't know who it was though. Not happy about that one. Also, at last place of work, the forms for the work force census got put into everyone's pigeon holes, at the end of a working day, with literally any personal information available, eg name and contact details of next of kin, car reg, home address etc. Was absolutely fuming about this one and had a right moan about it. Answer I got was: We've always done it like this!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now