jmak Posted June 1, 2020 Posted June 1, 2020 Question for either HE Edugeek or GDPR folk I think: An acquaintance has received an email sent to all [email protected] addresses expressing a political view. It wasn't a view they were unhappy with, but seems to have caused upset to people who don't agree with the view, those who don't think official email should be used to contact students unsolicited, those who have received replies from people with different views and those who think that the institution is supporting "the other side" by removing previously delivered emails from inboxes. Bearing in mind that use of the official email account is essential to receive official emails from the institution, is there a potential breach of GDPR, given that the recipients details are being used for a purpose that they didn't give consent for? Or is it usually dealt with as a breach of an AUP for users bulk distributing unsolicited emails? Or should the students be allowed to share their political views using the official email accounts?
mavhc Posted June 1, 2020 Posted June 1, 2020 don't need to know people's email addresses to mass email, they're not official email accounts anyway, they're school email accounts, if a student emails someone that's not an official policy of the school. Also who's upset by receiving an email they don't agree with? Seems like no one except actual official accounts should be able to bulk email anyway, fix the email server settings.
jmak Posted June 1, 2020 Author Posted June 1, 2020 My first reaction was "what, they let you do send to all on the global address list?" 1
mavhc Posted June 1, 2020 Posted June 1, 2020 My university emailed probably 10000 people years after they'd left, and then allowed replies to also go to those 10000 people because of an incorrectly configured mailing list, cue 1000 people asking to be unsubscribed
steve Posted June 1, 2020 Posted June 1, 2020 Question for either HE Edugeek or GDPR folk I think: An acquaintance has received an email sent to all [email protected] addresses expressing a political view. It wasn't a view they were unhappy with, but seems to have caused upset to people who don't agree with the view, those who don't think official email should be used to contact students unsolicited, those who have received replies from people with different views and those who think that the institution is supporting "the other side" by removing previously delivered emails from inboxes. Bearing in mind that use of the official email account is essential to receive official emails from the institution, is there a potential breach of GDPR, given that the recipients details are being used for a purpose that they didn't give consent for? Or is it usually dealt with as a breach of an AUP for users bulk distributing unsolicited emails? Or should the students be allowed to share their political views using the official email accounts? Our policy states: “The use of University email accounts for the sending and receiving of personal emails should be avoided.” I'd interpret a personal political view to be personal matter and if emailed to all users it would not acceptable under our policy. I wouldn't see any issue in a bulk removal from users mailboxes of this specific email if it caused concern or upset. You're not policing the content, but applying the policy. I'd expect the person sending the message to get a "reminder" of the acceptable use of University IT systems. We have strict controls around bulk messaging, so in theory this would never happen to us ........ 1
HPlum78 Posted June 2, 2020 Posted June 2, 2020 Most HE institutions will run a list service for staff and students if signed up to then depending on the settings for that list members may well be able to send to all the members of that list. The list owners are and would be responsible for the list and what rules/ policies would apply to it. I am guessing about what would be the case here as I don't think that allowing a student to mass mail would be allowed in general. 1
GrumbleDook Posted June 2, 2020 Posted June 2, 2020 If a user decided to send, for personal reasons, an email to all other users and it was not related to college business, to the 'school' they are in at the university (e.g. Political sciences) or part of an agreed group (political societies) then it is personal and is more likely to be an abuse of access then anything else. 1
mavhc Posted June 2, 2020 Posted June 2, 2020 Just phrase your political view in terms of how it affects the university, then it's not personal email.
jmak Posted June 2, 2020 Author Posted June 2, 2020 Just phrase your political view in terms of how it affects the university, then it's not personal email.Not me expressing the political view - and I don't even get to see the email as it has been removed.If a user decided to send, for personal reasons, an email to all other users and it was not related to college business, to the 'school' they are in at the university (e.g. Political sciences) or part of an agreed group (political societies) then it is personal and is more likely to be an abuse of access then anything else.Thanks. I had wondered whether the operator of the system had a responsibility, but I guess it's somewhat analogous to the case where Morrisons were deemed not to be liable for the data breach caused by a deliberate act of one of their employees who had broken company procedures. On this forum we often talk about how technology isn't a substitute for procedures, but in this case I think that the failure to implement a block on "send to all" has left the college in an awkward position where they have lots of unhappy students that could easily have been prevented. They are being accused both of racism for removing the original post and obstruction of free speech for removing the replies.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now