Jump to content

Recommended Posts

Posted

Morning All

 

I have read over multiple threads in regards to SARs but I haven't answered my own question as of yet. We have had a request and I have pulled back all emails that contain the person's first name/surname/email/initials . I have redacted and sent on all the information I have. Their lawyers have come back and have suggested we are missing some emails. I have been 100% open with the emails I have I have grabbed but obviously, without going through every email in everybody's inbox I can't be 100% sure I have everything.

 

We have gone back to the lawyers and asked for more specifics and have searched for those also but have had nothing extra from the search.

 

What should be our reply here? I'm a bit confused about what I should be expected to do at this point. For all I know the email they are after could have been deleted before the request?

 

Thanks for any advice

Posted
Morning All

 

I have read over multiple threads in regards to SARs but I haven't answered my own question as of yet. We have had a request and I have pulled back all emails that contain the person's first name/surname/email/initials . I have redacted and sent on all the information I have. Their lawyers have come back and have suggested we are missing some emails. I have been 100% open with the emails I have I have grabbed but obviously, without going through every email in everybody's inbox I can't be 100% sure I have everything.

 

We have gone back to the lawyers and asked for more specifics and have searched for those also but have had nothing extra from the search.

 

What should be our reply here? I'm a bit confused about what I should be expected to do at this point. For all I know the email they are after could have been deleted before the request?

 

Thanks for any advice

 

You can only give them what you have - if they suspect something is missing the burden of proof is on them, but of course you do need to cover your back and make sure you've done all you can. Let them know the search terms you've provided and why it would be unreasonable to go further (i.e. just on a first name if it's something like Dave)

  • Thanks 1
Posted
Depending on your email provider you should be able to search deleted items and If you haven't done so already, I would request that they provide a specific date range and names of people then focus the search using this criteria and if possible include deleted items.
  • Thanks 1
Posted

Just current.

 

Would we be expected to trawl back through archives? For example, I have physical archived backups on tapes at the bursars house in a safe. Am I expected to go back through these?

 

Thanks

Posted

It's also worth pointing the solictors to your retention policies. Person A may still have an email but person B may have deleted a related email and it's fallen outside retention.

 

(our policies are set as "must exist for at least X time" for audit purposes, YPMV)

Posted
Just current.

Would we be expected to trawl back through archives? For example, I have physical archived backups on tapes at the bursars house in a safe. Am I expected to go back through these?

Thanks

I think the days of doing this are gone - from a DP and also a FOI perspective. The content of those archives would be subject to an FOI - do they contain PII?

Posted
Just current.

 

Would we be expected to trawl back through archives? For example, I have physical archived backups on tapes at the bursars house in a safe. Am I expected to go back through these?

 

Thanks

 

If you have the data and its within your records and data retention policy then yes (if its not why have they not been destroyed). What you asked is like saying I looked in my inbox and cannot find it but i may have them all in subfolders under my inbox / its not in the top drawer of the filing cabinet but its in the 2nd one etc... If its a valid record you need to search it be it paper, tape, CD, DVD, USB Stick etc...

  • Thanks 1
Posted
I think the days of doing this are gone - from a DP and also a FOI perspective. The content of those archives would be subject to an FOI - do they contain PII?

 

Do you mean the days of making archives are gone? If so what do you do with your finance and SEN infro that has to stick around? Also what is PII please?

 

Thanks

Posted
If you have the data and its within your records and data retention policy then yes (if its not why have they not been destroyed). What you asked is like saying I looked in my inbox and cannot find it but i may have them all in subfolders under my inbox / its not in the top drawer of the filing cabinet but its in the 2nd one etc... If its a valid record you need to search it be it paper, tape, CD, DVD, USB Stick etc...

 

Fair point. Does anyone keep archives anymore? If so how do they manage this? Maybe I need to readdress how we do things.

Posted
Fair point. Does anyone keep archives anymore? If so how do they manage this? Maybe I need to readdress how we do things.

 

Whilst I am in business not Edu, we use O365 for mail and it goes to the Online Archive after 2 years in the main mailbox, that archive (along with primary mailbox) is then kept based on records retention schedule as determined by our Legal Department based on GDPR / DPA etc... as we work globally that adds some extra challenges based on local laws in some places as well as auditability frameworks EG SOX in the US.

 

We are looking into training key teams on the Retention tags given our Records Retention schedule has different lengths for different matters EG Job Applicants data held for X months post interview etc these apply across Outlook / Exchange, SharePoint, Teams etc so we can be even better at it as we accept we are not perfect. This stuff applies in Education as well such as I remember SEN children's data used to have to be held till they were older than a non SEN child, looked after children were even longer than that etc...

 

O365 also helps us in relation to deleted emails as all mail is within that environment delete it its records still exist in the back end so we can produce if required / ensure that if someone was being inappropriate / hiding illicit goings on (yes it has happen) they can be pulled back from the system to be used in Court (either for our benefit or not as the case maybe).

 

Until you have to do the searching / do a test of a search to simulate such request and people have to think and look you don't realise how much work goes into these things. We talked though a test case as a group here and was quite alarming how much we would need to do to be confident we have searched everything. You have to go into peoples files, if they are on C Drives / local disks you cannot find them easily so you need those users laptops / desktops and search them, pulled the email to a local PST and no journaled copy then that needs it to be found etc its a serious amount of work. Mobile phones did someone text someone / whatsapp someone about it etc... its a serious minefield.

 

A common one we get requests to be forgotten off mailing lists... some teams have extracted data from the mailing list tool to local sheets for further analysis, we then have to ask teams to search for that data if its not stored in O365 where we can do a discovery for it, some even have printed it "for backup" and you have to chase them to confirm in writing to our Legal team they have shredded / blanked out that record (and they usually get a reminder of stop printing that stuff out unless essential!).

Posted
PII - Personally Identifiable Information. There are certain rules on retention periods, the commonly quoted one is CP files being DoB + 25 years. https://www.securestorageservices.co.uk/article/19/white-paper-retention-guidelines-for-schools

 

Once beyond those periods, you shouldn't be retaining the data - archives or not.

 

Thanks. So I could potentially have 25 years' worth of tapes that I need to go through to be 100% sure? How does everyone else manage this?

Posted
Whilst I am in business not Edu, we use O365 for mail and it goes to the Online Archive after 2 years in the main mailbox, that archive (along with primary mailbox) is then kept based on records retention schedule as determined by our Legal Department based on GDPR / DPA etc... as we work globally that adds some extra challenges based on local laws in some places as well as auditability frameworks EG SOX in the US.

 

We are looking into training key teams on the Retention tags given our Records Retention schedule has different lengths for different matters EG Job Applicants data held for X months post interview etc these apply across Outlook / Exchange, SharePoint, Teams etc so we can be even better at it as we accept we are not perfect. This stuff applies in Education as well such as I remember SEN children's data used to have to be held till they were older than a non SEN child, looked after children were even longer than that etc...

 

O365 also helps us in relation to deleted emails as all mail is within that environment delete it its records still exist in the back end so we can produce if required / ensure that if someone was being inappropriate / hiding illicit goings on (yes it has happen) they can be pulled back from the system to be used in Court (either for our benefit or not as the case maybe).

 

Until you have to do the searching / do a test of a search to simulate such request and people have to think and look you don't realise how much work goes into these things. We talked though a test case as a group here and was quite alarming how much we would need to do to be confident we have searched everything. You have to go into peoples files, if they are on C Drives / local disks you cannot find them easily so you need those users laptops / desktops and search them, pulled the email to a local PST and no journaled copy then that needs it to be found etc its a serious amount of work. Mobile phones did someone text someone / whatsapp someone about it etc... its a serious minefield.

 

A common one we get requests to be forgotten off mailing lists... some teams have extracted data from the mailing list tool to local sheets for further analysis, we then have to ask teams to search for that data if its not stored in O365 where we can do a discovery for it, some even have printed it "for backup" and you have to chase them to confirm in writing to our Legal team they have shredded / blanked out that record (and they usually get a reminder of stop printing that stuff out unless essential!).

 

Thanks very much. Lots of food for thought! Think we need to go through our retention policies.

Posted
Thanks. So I could potentially have 25 years' worth of tapes that I need to go through to be 100% sure? How does everyone else manage this?

Not necessarily. Depends on how long you've been archiving them for. The normal retention is basically 9 years for year 11 student leavers and 7 for sixth form leavers. Less sensitive data does not need to be retained for as long.

  • Thanks 1
Posted
Thanks. So I could potentially have 25 years' worth of tapes that I need to go through to be 100% sure? How does everyone else manage this?

 

You need to go through your records retention schedule for sure, you will have data older than scheduled to keep unless you have legitimate reason to keep beyond that I would expect if you seriously have 25 years of archive tapes.

 

Also you said the Bursar had these tapes at there house... assume they are all encrypted tape? Stored security in a location only they can get in safe bolted down so cannot be stolen if they are broken into etc? It would be much more safe and secure to get a fireproof safe on-site rated for time and the use and then ensure your fire plan covers its location etc...

  • Thanks 1
Posted
You need to go through your records retention schedule for sure, you will have data older than scheduled to keep unless you have legitimate reason to keep beyond that I would expect if you seriously have 25 years of archive tapes.

 

Also you said the Bursar had these tapes at there house... assume they are all encrypted tape? Stored security in a location only they can get in safe bolted down so cannot be stolen if they are broken into etc? It would be much more safe and secure to get a fireproof safe on-site rated for time and the use and then ensure your fire plan covers its location etc...

 

They are encrypted and in a safe just at the bursars house.

Posted

Hope you manage to get it all sorted soon! As well as looking at your retention policies there's an opportunity to train staff in what's appropriate to write in emails, even when initials and codes are used to identify people, which you are already looking at.

 

The IRMS toolkit is helpful for retention: https://irms.org.uk/page/SchoolsToolkit and some organisations offer support with SARs.

 

Good luck!

 

Claire

  • Thanks 2
Posted
PII - Personally Identifiable Information. There are certain rules on retention periods, the commonly quoted one is CP files being DoB + 25 years. https://www.securestorageservices.co.uk/article/19/white-paper-retention-guidelines-for-schools

 

Once beyond those periods, you shouldn't be retaining the data - archives or not.

 

PII does not exist with GDPR, it is Personal Data... which covers a fair chunk more!

  • Thanks 1
Posted
As others have already said, the IRMS toolkit is your best place to look, and if you review the DfE Data Protection toolkit you will see an explanation around weeding some data out over time which matches the IRMS information.
  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...