gopher_1999 Posted January 4, 2022 Posted January 4, 2022 Hello A senior member of staff has retired. They have just asked us to delete their e-mail correspondence. There is concern that there maybe critical information. What are the laws/rules about us accessing her e-mail?
elsiegee40 Posted January 4, 2022 Posted January 4, 2022 They can ask but there is a requirement to retain certain information after a member of staff leaves for safeguarding reasons, so your school should follow its retention policy exactly as it does for every other member of staff that leaves. The right to be forgotten doesn’t override the school’s other legal obligations. Some data will be deleted sooner than others. Your DPO should know this.
djm968 Posted January 4, 2022 Posted January 4, 2022 (edited) Data retention should be defined by a retention policy and at the end of the day, all data belongs to the School/Trust so they can ask but there is no legal requirement to oblige. If in doubt, ask your DPO/HT/CEO for clarification. Edited January 4, 2022 by djm968
hardtailstar Posted January 4, 2022 Posted January 4, 2022 Hello A senior member of staff has retired. They have just asked us to delete their e-mail correspondence. There is concern that there maybe critical information. What are the laws/rules about us accessing her e-mail? Is this the account they had whilst working for your school or their personal email on record in your MIS?
pete Posted January 4, 2022 Posted January 4, 2022 (edited) "Nope, retention and audit rules mean we have to keep it for minimum X period plus or minus Y depending on the roles you held". The mailbox contents are part of paid work done for the school, it's not theirs and they don't own it. Is this a "staff member was daft enough to use work email for personal matters" scenario? Edited January 4, 2022 by pete
enjay Posted January 5, 2022 Posted January 5, 2022 Is this a "staff member was daft enough to use work email for personal matters" scenario? I doubt it. In that instance, they'd simply have emptied their inbox when they left. This sounds more like wanting all the emails they sent other people to be removed.
dmj Posted January 5, 2022 Posted January 5, 2022 (edited) This scenario is a good reason why an email system is inappropriate for storing safeguarding data. In a previous school I worked at; all email was deleted at the beginning of each year and safeguarding info was kept on a separate system. It kept the school safe from costly subject access requests (SARs) whilst keeping legal data. Your lucky she didn't ask for a SAR: or someone would have to go and find every email, in every inbox with personal information about her. You have a month to do that. At least she just asked for her email to be deleted! Edit: Then again, if your holding info about who she's meeting down the pub, you don't have a legal reason to keep that either - and by the sounds of it the schools been ignoring GDPR for a number of years so you could just tell her to do one. Edited January 5, 2022 by dmj
Zoom7000 Posted January 5, 2022 Posted January 5, 2022 Your lucky she didn't ask for a SAR: or someone would have to go and find every email, in every inbox with holding personal information about her, with only 72hrs to do it. At least she just asked for her email to be deleted! Pretty sure you have a month according to the ICO How long does an organisation have to respond? An organisation normally has to respond to your request within one month. If you have made a number of requests or your request is complex, they may need extra time to consider your request and they can take up to an extra two months to respond.
dmj Posted January 5, 2022 Posted January 5, 2022 Pretty sure you have a month according to the ICO yeah your right, It's been a while since I did this stuff. It's 72hrs for a data breach.
enjay Posted January 5, 2022 Posted January 5, 2022 In a previous school I worked at; all email was deleted at the beginning of each year Interesting concept, although I suspect in reality that just means everyone archives to PST files (which of course you then can't search in the event of an SAR)
jthompson Posted January 5, 2022 Posted January 5, 2022 Even if you were to delete that person's mailbox for them, it does nothing to remove recipients' copies of their messages.
dmj Posted January 5, 2022 Posted January 5, 2022 Interesting concept, although I suspect in reality that just means everyone archives to PST files (which of course you then can't search in the event of an SAR) I think the point of the email deletion policy was that the organisation doesn't have a copy of the data, so it makes it very simple to comply with an SAR. If an individual retained a copy of the data it would be a breach of that policy. Being able to show (the ICO) that there are policies and procedures in place means the schools is 90% there. Most schools just ignore the rules and hope they don't get hacked.
MartinT Posted January 5, 2022 Posted January 5, 2022 Your data retention policy will specify the length of time to keep their mailbox contents. In our case, we put them into Exchange Litigation Hold as best practice, held for the appropriate time as specified. If they are SMT, then the length of time held is extended for safeguarding and continuity reasons.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now