Jump to content

Recommended Posts

Posted
I have a staff member that made a subject access request asking for all emails that mention his name including operational emails etc - using office 365 i was able to export those emails totaling about 30k emails - how are is everyone else dealing with such requests ? the main challenge is censoring all information within the emails that identifies other staff members this is proving to be an extremely difficult task given the number of emails!
Posted

Not a school but still public sector to an extent. So assuming the SAR is fully legitimate, unless you have software that can do it (and you trust it) then someone has to manually redact all the documentation themselves.

 

It's one of those things, think yourself lucky we have someone here whose full time job seems to be going through SARs, well at least 2 or 3 days a week. He frequently has to go through 1000s of emails.

 

Sometimes, and I'm not saying the member of staff will agree but you could tell them how many emails there are, and that it will take a long time to redact them, and ask if they want to be more specific to allow them to get the results quicker. We have had people provide more exact dates, or ask when there name is mentioned when corresponding to certain departments etc. You know things like, your name but not when sent to "All Staff" or "All Teachers" they might be happy with and it will remove a lot of the generic emails.

 

However, it fully depends on the other persons motives.

Posted
wouldn't that be an invalid request? because some e-mails may have their name in them, but its not their e-mails. Just export the member of staffs own e-mails and give them those?
Posted
wouldn't that be an invalid request? because some e-mails may have their name in them, but its not their e-mails. Just export the member of staffs own e-mails and give them those?

 

No, SAR is any email about the individual (if that's what they ask), not the individuals own emails.

Posted
I thought subject access requests was only for data that pertains to the subject, even if some one else's e-mail has their name in it, its not their data. But even if you did have to give over all the e-mails containing their name you would have to basically redact everything except their name, to protect the senders privacy and data, so the requester wouldn't have any context or information, just that some one has sent an e-mail containing their name. Or am I missing something?
Posted

Their right is to data about them. Their name on it's own is not data, but their name tied to anything else is data. Most of the emails which contain their name will have some data about them in some way, and they will therefore be entitled to them. Whilst you can redact other individuals names, it is best to provide as much context to the email as possible, although the advice we receive is it is better to over-redact something and then release more if it is queried, than to release something you shouldn't have.

 

It is most likely going to be a manual process. In the first instance, I would go back to the subject and clarify their request, are there specific emails that they are hoping to see, maybe only ones sent by certain members of staff?

 

We have also looked at changing our policies here, so emails are automatically deleted are a certain period of time for the vast majority of staff, the fewer emails there are, the quicker the job is!

 

Steve

Posted
Can you narrow the scope of the request? Are they interested in emails in a particular time period, from/to specific individuals, relating to a particular topic, etc?
Posted

Asking the requester to narrow the scope makes a lot of sense and is a reasonable question to ask. Here is an ICO video that I came across a few days ago. It's a couple of a few years old now but I suspect very relevant. It includes advise on working with the requester to scope the request, but they don;t have to explain why they are asking for the data. At just under an hour, it's not exactly brief, but I found it very helpful - especially correcting a common misconception around the ability for companies to hide behind 'it'll take too much time'. This video alone has made my view on retention periods shift.

 

The following is also a good to start from for further guidance:

https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-of-access/

Posted
especially correcting a common misconception around the ability for companies to hide behind 'it'll take too much time'.

 

That's probably because we do have that defence against FOIA requests, but not SARs.

Posted
Does this still apply when you use a persons initials? And is it their full name only? For example, if you have two Ben's and a Ben makes a SAR do you then have to go through and filter out the emails that are about the Ben making the SAR and not any other Ben?
Posted
Does this still apply when you use a persons initials? And is it their full name only? For example, if you have two Ben's and a Ben makes a SAR do you then have to go through and filter out the emails that are about the Ben making the SAR and not any other Ben?

 

If you can identify the data subject then it still applies. If there is only 1 Ben in your department and you write emails about Ben, then he is easily identifiable and therefore you would have to. If it isn't possible to work out who it is then you wouldn't, but I cant imagine anyone would write emails about someone that the other person couldn't work out who they were talking about!

 

Steve

Posted
but I cant imagine anyone would write emails about someone that the other person couldn't work out who they were talking about!

 

True, but there are plenty of times I send an email where the recipient knows who I'm talking about but no-one else reading it would. "Further to our earlier conversation about that Year 9 student" or whatever. There is also a repeat visitor to the IT office who my technician and I refer to as "frequent flyer number 1". None of those emails would be included in an SAR.

  • Thanks 1
Posted
I think the way you need to look at this, is you have a duty to try to provide as full and accurate as possible information, based on what requester asked for. You shouldn't breach the rights of any third parties in doing so, but you should avoid 'hiding' any information. The risk of not taking this approach is, if the requester raises a complaint with the ICO, you'll need to demonstrate you tried to fully provide the information asked for. This is discussed in some detail in the Webinar I linked in my earlier reply.
Posted

Any email that they’ve sent, was sent to them or they were CCed in need no redaction.

 

Any email links to safeguarding (including H&S and relevant competency concerns) may need to be reviewed and considered whether they should be shared.

 

Any that provide personal data of others who they don’t have a right to access need to be redacted ...

 

If you think this is linked to a complaint, an existing grievance or possible competency issues then discuss with HR and Legal for advice.

 

If you think that sharing any emails puts the rights and freedoms of others at risk then seek legal support.

 

Ultimately, whatever decision is made, justify it.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...