Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

What are the rules around putting in SAR requests against other members of staff mailboxes to find out what they are saying about you?

 

Just had one- seems like a good way to see if I’m being put on staff naughty list if you ask me but in this case staff member feels they have been treated unfairly and want to use this method.

 

Thanks

John

Posted
Fully within their right to do so whether it's an employer or a 3rd party. The employer can withhold information generally only if it identifies someone else or if part of an ongoing criminal investigation, no different to any other SAR.
Posted
Fully within their right to do so whether it's an employer or a 3rd party. The employer can withhold information generally only if it identifies someone else or if part of an ongoing criminal investigation, no different to any other SAR.

 

Ok thanks... as much as I agree with it, the workload is silly - searching and entire office 365 with SAR cases and extracting them into PST, sharepoint etc is not something I have time for.

Posted

Interesting. But would the name of who sent the email be redacted? So they would know what has been said but no necessarily who said it?

 

Also how does this work from a Management perspective? I mean as a line manager would all communication be passed that involved them, I mean what if a disciplinary was being pulled together or they were being taken through proceedings?

Posted
Like any other SAR, get the requester to narrow down specifically what they're after and why, so you can target your search. Is there a particular mailbox or timeframe they're interested in? If it relates to a specific incident, could a keyword search also narrow it down? They don't want to be given every email every sent which mentions them, you don't want to find every email ever sent which mentions them, so work out what they do want, then give them that.
Posted
searching and entire office 365 with SAR cases and extracting them into PST, sharepoint etc is not something I have time for.

 

How are you doing this current? Sounds a much faster method than my DPO currently uses. If I can save time that would be awesome!

Posted
Interesting. But would the name of who sent the email be redacted? So they would know what has been said but no necessarily who said it?

 

Also how does this work from a Management perspective? I mean as a line manager would all communication be passed that involved them, I mean what if a disciplinary was being pulled together or they were being taken through proceedings?

 

This is where staff often need to be educated on their use of email. It is easiest to remember that it needs to be used to communicate business purposes - and in a context that could/should be read by anyone else.

If anything sensitive or confidential is being said then it should be marked as such, or ideally not communicated in that method at all.

Once those standards are enforced it is a quick and easy process to extract SARs and redaction time should be minimal.

 

Ok thanks... as much as I agree with it, the workload is silly - searching and entire office 365 with SAR cases and extracting them into PST, sharepoint etc is not something I have time for.

 

Time is largely irrelevant if the organisation is doing what they should. If the above practice is taken then time should be minimised, but if not - the time needs to be invested as it is a legal right of the individual, and the DPO's role states they need to be given adequate time to undertake the role. (I guess at that point a conversation at senior level takes place -i.e. do we continue to allow the DPO to spend a huge amount of time on these things, or do we train staff to make sure that the DPO's time is managed more effectively.

Posted
How are you doing this current? Sounds a much faster method than my DPO currently uses. If I can save time that would be awesome!

 

If you have Office 365 then utilising the Search and Compliance Centre and other tools available via protection.office.com

  • Thanks 1
Posted

If anything sensitive or confidential is being said then it should be marked as such, or ideally not communicated in that method at all.

 

That may be the ideal, but I don't think it is an achievable one. To give my HT's example on this, we have a particularly vulnerable student here and within 6 months of them starting, a search of the HT's inbox returned several hundred emails about this child. It would not be feasible to have all of those conversations verbally and then document them afterwards.

Posted
That may be the ideal, but I don't think it is an achievable one. To give my HT's example on this, we have a particularly vulnerable student here and within 6 months of them starting, a search of the HT's inbox returned several hundred emails about this child. It would not be feasible to have all of those conversations verbally and then document them afterwards.

 

The Head needs to consider if email is the place to have those discussions given the issues it might create - i.e. time to extract when SARs come in, risk of accidentally forwarding when mistyping someone, forwarding the wrong part of a thread etc.

A better solution would be a dedicated product (CPOMS is one I would recommend) where safeguarding conversations can take place and be marked appropriately too.

  • Thanks 2
Posted

A better solution would be a dedicated product (CPOMS is one I would recommend) where safeguarding conversations can take place and be marked appropriately too.

 

But if the SAR asks for all records pertaining to the child would that system not still be covered?

Posted
But if the SAR asks for all records pertaining to the child would that system not still be covered?

 

It would be covered, but the export / redaction process would be far easier as you would know the information contained would be categorised.

Additionally, if a system like that was used (meaning the general chatter type info wouldn't be there) you'd be much better placed if you were minded to go back and ask the requester if they were happy to narrow down their query knowing you could export prudent info quickly.

Posted
The OP posted about staff, but for pupil data it's worth also reading ICO's comments here as there are circumstances where denying access to certain info is allowed.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...