johnpd Posted April 29, 2019 Posted April 29, 2019 What are the rules around putting in SAR requests against other members of staff mailboxes to find out what they are saying about you? Just had one- seems like a good way to see if I’m being put on staff naughty list if you ask me but in this case staff member feels they have been treated unfairly and want to use this method. Thanks John
synaesthesia Posted April 29, 2019 Posted April 29, 2019 Fully within their right to do so whether it's an employer or a 3rd party. The employer can withhold information generally only if it identifies someone else or if part of an ongoing criminal investigation, no different to any other SAR.
johnpd Posted April 30, 2019 Author Posted April 30, 2019 Fully within their right to do so whether it's an employer or a 3rd party. The employer can withhold information generally only if it identifies someone else or if part of an ongoing criminal investigation, no different to any other SAR. Ok thanks... as much as I agree with it, the workload is silly - searching and entire office 365 with SAR cases and extracting them into PST, sharepoint etc is not something I have time for.
synaesthesia Posted April 30, 2019 Posted April 30, 2019 Shouldn't be too difficult frankly as it's a click and wait task. The only difficulty is going through them to redact unnecessary information which shouldn't really be your job.
TechMonkey Posted April 30, 2019 Posted April 30, 2019 Interesting. But would the name of who sent the email be redacted? So they would know what has been said but no necessarily who said it? Also how does this work from a Management perspective? I mean as a line manager would all communication be passed that involved them, I mean what if a disciplinary was being pulled together or they were being taken through proceedings?
enjay Posted April 30, 2019 Posted April 30, 2019 Like any other SAR, get the requester to narrow down specifically what they're after and why, so you can target your search. Is there a particular mailbox or timeframe they're interested in? If it relates to a specific incident, could a keyword search also narrow it down? They don't want to be given every email every sent which mentions them, you don't want to find every email ever sent which mentions them, so work out what they do want, then give them that.
PotNoodleTech Posted April 30, 2019 Posted April 30, 2019 searching and entire office 365 with SAR cases and extracting them into PST, sharepoint etc is not something I have time for. How are you doing this current? Sounds a much faster method than my DPO currently uses. If I can save time that would be awesome!
mb2k01 Posted April 30, 2019 Posted April 30, 2019 Interesting. But would the name of who sent the email be redacted? So they would know what has been said but no necessarily who said it? Also how does this work from a Management perspective? I mean as a line manager would all communication be passed that involved them, I mean what if a disciplinary was being pulled together or they were being taken through proceedings? This is where staff often need to be educated on their use of email. It is easiest to remember that it needs to be used to communicate business purposes - and in a context that could/should be read by anyone else. If anything sensitive or confidential is being said then it should be marked as such, or ideally not communicated in that method at all. Once those standards are enforced it is a quick and easy process to extract SARs and redaction time should be minimal. Ok thanks... as much as I agree with it, the workload is silly - searching and entire office 365 with SAR cases and extracting them into PST, sharepoint etc is not something I have time for. Time is largely irrelevant if the organisation is doing what they should. If the above practice is taken then time should be minimised, but if not - the time needs to be invested as it is a legal right of the individual, and the DPO's role states they need to be given adequate time to undertake the role. (I guess at that point a conversation at senior level takes place -i.e. do we continue to allow the DPO to spend a huge amount of time on these things, or do we train staff to make sure that the DPO's time is managed more effectively.
mb2k01 Posted April 30, 2019 Posted April 30, 2019 How are you doing this current? Sounds a much faster method than my DPO currently uses. If I can save time that would be awesome! If you have Office 365 then utilising the Search and Compliance Centre and other tools available via protection.office.com 1
enjay Posted April 30, 2019 Posted April 30, 2019 If anything sensitive or confidential is being said then it should be marked as such, or ideally not communicated in that method at all. That may be the ideal, but I don't think it is an achievable one. To give my HT's example on this, we have a particularly vulnerable student here and within 6 months of them starting, a search of the HT's inbox returned several hundred emails about this child. It would not be feasible to have all of those conversations verbally and then document them afterwards.
mb2k01 Posted April 30, 2019 Posted April 30, 2019 That may be the ideal, but I don't think it is an achievable one. To give my HT's example on this, we have a particularly vulnerable student here and within 6 months of them starting, a search of the HT's inbox returned several hundred emails about this child. It would not be feasible to have all of those conversations verbally and then document them afterwards. The Head needs to consider if email is the place to have those discussions given the issues it might create - i.e. time to extract when SARs come in, risk of accidentally forwarding when mistyping someone, forwarding the wrong part of a thread etc. A better solution would be a dedicated product (CPOMS is one I would recommend) where safeguarding conversations can take place and be marked appropriately too. 2
TechMonkey Posted April 30, 2019 Posted April 30, 2019 A better solution would be a dedicated product (CPOMS is one I would recommend) where safeguarding conversations can take place and be marked appropriately too. But if the SAR asks for all records pertaining to the child would that system not still be covered?
mb2k01 Posted April 30, 2019 Posted April 30, 2019 But if the SAR asks for all records pertaining to the child would that system not still be covered? It would be covered, but the export / redaction process would be far easier as you would know the information contained would be categorised. Additionally, if a system like that was used (meaning the general chatter type info wouldn't be there) you'd be much better placed if you were minded to go back and ask the requester if they were happy to narrow down their query knowing you could export prudent info quickly.
Ditto Posted April 30, 2019 Posted April 30, 2019 The OP posted about staff, but for pupil data it's worth also reading ICO's comments here as there are circumstances where denying access to certain info is allowed.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now