Jump to content

Recommended Posts

Posted

Hello

 

A senior member of staff has retired. They have just asked us to delete their e-mail correspondence. There is concern that there maybe critical information. What are the laws/rules about us accessing her e-mail?

Posted

They can ask but there is a requirement to retain certain information after a member of staff leaves for safeguarding reasons, so your school should follow its retention policy exactly as it does for every other member of staff that leaves.

 

The right to be forgotten doesn’t override the school’s other legal obligations.

 

Some data will be deleted sooner than others. Your DPO should know this.

Posted (edited)
Data retention should be defined by a retention policy and at the end of the day, all data belongs to the School/Trust so they can ask but there is no legal requirement to oblige. If in doubt, ask your DPO/HT/CEO for clarification. Edited by djm968
Posted
Hello

 

A senior member of staff has retired. They have just asked us to delete their e-mail correspondence. There is concern that there maybe critical information. What are the laws/rules about us accessing her e-mail?

 

Is this the account they had whilst working for your school or their personal email on record in your MIS?

Posted (edited)

"Nope, retention and audit rules mean we have to keep it for minimum X period plus or minus Y depending on the roles you held".

 

The mailbox contents are part of paid work done for the school, it's not theirs and they don't own it.

 

Is this a "staff member was daft enough to use work email for personal matters" scenario?

Edited by pete
Posted
Is this a "staff member was daft enough to use work email for personal matters" scenario?

 

I doubt it. In that instance, they'd simply have emptied their inbox when they left. This sounds more like wanting all the emails they sent other people to be removed.

Posted (edited)

This scenario is a good reason why an email system is inappropriate for storing safeguarding data.

In a previous school I worked at; all email was deleted at the beginning of each year and safeguarding info was kept on a separate system. It kept the school safe from costly subject access requests (SARs) whilst keeping legal data.

Your lucky she didn't ask for a SAR: or someone would have to go and find every email, in every inbox with personal information about her. You have a month to do that. At least she just asked for her email to be deleted!

 

Edit: Then again, if your holding info about who she's meeting down the pub, you don't have a legal reason to keep that either - and by the sounds of it the schools been ignoring GDPR for a number of years so you could just tell her to do one.

Edited by dmj
Posted
Your lucky she didn't ask for a SAR: or someone would have to go and find every email, in every inbox with holding personal information about her, with only 72hrs to do it. At least she just asked for her email to be deleted!

 

Pretty sure you have a month according to the ICO

 

How long does an organisation have to respond?

 

An organisation normally has to respond to your request within one month.

 

If you have made a number of requests or your request is complex, they may need extra time to consider your request and they can take up to an extra two months to respond.

Posted
Pretty sure you have a month according to the ICO

 

yeah your right, It's been a while since I did this stuff. It's 72hrs for a data breach.

Posted
In a previous school I worked at; all email was deleted at the beginning of each year

 

Interesting concept, although I suspect in reality that just means everyone archives to PST files (which of course you then can't search in the event of an SAR)

Posted
Interesting concept, although I suspect in reality that just means everyone archives to PST files (which of course you then can't search in the event of an SAR)

 

I think the point of the email deletion policy was that the organisation doesn't have a copy of the data, so it makes it very simple to comply with an SAR. If an individual retained a copy of the data it would be a breach of that policy. Being able to show (the ICO) that there are policies and procedures in place means the schools is 90% there. Most schools just ignore the rules and hope they don't get hacked.

Posted
Your data retention policy will specify the length of time to keep their mailbox contents. In our case, we put them into Exchange Litigation Hold as best practice, held for the appropriate time as specified. If they are SMT, then the length of time held is extended for safeguarding and continuity reasons.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...