Jump to content

Recommended Posts

Posted

I'm a network manager for 8 schools in a MAT, and we have an in-house DPO. They have been in talks with the trustees and the net outcome of this is they have requested that all staff be given notice that the staff network shares will be erased on X date with no exceptions, so backup what they need to keep.

 

I believe the rationale is behind this is that we don't know if there is sensitive personal information about staff/students, lurking somewhere that it could be accessed by persons who really shouldn't be accessing it. The staff shares are many, many years old now, and I did indeed find a list of children in care that was in a folder relating to teaching resources that was accessible to all staff.

 

There are numerous problems that I foresee with this. Has anybody else been asked to do anything similar?! How have you tackled knowing exactly what you hold and where it is?

 

Any advice would be greatly appreciated!

Posted
Only when reorganising shares, not for any data protection reasons. Will find it suitably pointless though, as staff will just backup everything "they need" just in case. So the problem hasn't gone, it's just moved.
Posted

Thats more of a house keeping issue and permissions issue.

 

If staff can access all folders then they will be able to see what they shouldn't. You'll need to lock down the permissions so only staff that should access the sensitive information can.

 

If staff move files to where they shouldn't then they should be pulled up on it.

Posted

Where are they backing it up?

 

Only solution is to check every file one by one anyway.

 

Make old share read only. New share setup much harsher permissions, hierarchy, limited access, only ITS can write to root level etc.

 

Inset day, assign each staff member an area to check, and to move to the correct position in new hierarchy. Or if on list of things that must be kept, put in new archive share.

 

Make old share offline.

 

Wait 1 year. Delete old share files.

 

Or, move to GSuite, take no files with you, everything is now native google files.

Posted

There's several problems with this -

 

- Someone will forget to do this, or won't account for everything

 

- It won't resolve the problem, as users will just copy everything for ease

 

- There's a risk data will be copied to unencrypted USB devices

 

The better solution would be to upload everything to the likes of Google Drive, in an 'Archive' Team Drive and give access to data for so long and/or allow users to copy data into another 'Work in Progress' Team Drive.

 

In time restrict access to Archive, but it's still always there for select personnel.

 

- No loss of data/access to data is restricted

 

- All data accounted for

 

- Data's all encrypted

 

Going forward, organise data by Year or Term, so you don't have this problem again in future.

Posted

Not for data protection reasons, but we've done two similar exercises: the first time, we had a new head and she found lesson resources being used that were two curriculum changes out of date. Staff were warned that they would be removed and given the opportunity to copy essential stuff to a new area. Result = no one sorted anything, but a couple of people took complete copies. In your situation, your data protection position would end up worse than you started as you would have no idea who had copies of what and no control over permissions.

 

The second time, we were migrating file storage to O365. My instructions that time were to remove everything older than a year (i.e prior to our most recent Ofsted) and people could come to me if they *really* needed something. That was much more successful - we're a small school, but I've only been asked for three things in a year - and two of those were things that someone who'd left had failed to handover.

 

Once you get rid of a huge chunk of data, sorting through what's left is much more doable.

 

TL: DR of you give staff prior notice and allow them to take their own backups, it's a worse than useless activity.

Posted

There's only 2 kinds of classroom resources, vhs tapes from 1980 recorded off tv, and youtube videos that have just been taken down.

 

Doesn't include illegal streaming of netflix of course

Posted

We did something similar to this; we basically made staff copy over things they needed to a new network drive and just told them they could leave anything they didn't need behind. They were given dedicated time to do this; it wasn't expected they fit it in around their normal day. The network manager kept and eye out and called out the few who tried to just copy over everything. Once the deadline was reached, we made the original network drives unavailable but kept them around for a while. After some time, we went and fetched all the stuff that people had said they needed but forgotten. I left a few months ago so can't quite remember whether we'd for real deleted the drives, but certainly that was the plan.

 

Memory is a shaky thing, but I certainly don't remember any major problems or complaints with this process. It's absolutely not a complete fix, but as a starting point that lets you cut down the amount of data you have to index to identify all the personal information I think it's pretty reasonable

Posted

Not a comprehensive solution, but something that might help with decluttering...

 

We have FSRM set to expire items older than 5 (I think?) years. That task runs each August. Expired items are retained separately for the following year and staff can copy anything they need back to the main share during that time as they spot it.

 

As others have said, if people are told to just 'sort through it' they won't. More importantly, the people most likely to do nothing are the people you most need to be clearing up their stuff.

Posted

We’ve done this recently in a primary school. Exiting staff shares became a read only ‘archive’ staff were told to only move across what they needed.

 

I didn’t really expect it to work and staff would copy everything back. But to be fair to them, they’ve stuck with it and the whole AD and file structure is sooooo much better (we inherited the original setup).

 

But I agree. People are lazy. Most people who copy it all or nothing as it’s easier.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...