mikes Posted March 28, 2022 Posted March 28, 2022 Hi guys we have had a staff member file a SAR wanting copies of e-mails about them sent by a particular individual, problem is (well it's not really a problem IMO it is good practice) that person keeps a clean mailbox and deletes e-mails older than 3 months if they are no longer relevant. (and obviously we had no idea this SAR would be filed so the mails were deleted) Do I need to do a mailbox restore and run the SAR against that to get older e-mails or is that beyond the scope of the SAR??? it is an O365 mailbox so I'm not even sure if that is possible? (I have already ran the discovery search, there was no hold on the mailbox)
synaesthesia Posted March 28, 2022 Posted March 28, 2022 If it's deleted, it's deleted - no questions asked, it's beyond the scope of the SAR. 2
djm968 Posted March 28, 2022 Posted March 28, 2022 (edited) Have a read of this, Information is ‘deleted’ when you try to permanently discard it and you have no intention of ever trying to access it again. The ICO’s view is that, if you delete personal data you hold in electronic form by removing it (as far as possible) from your computer systems, the fact that expensive technical expertise might enable you to recreate it does not mean you must go to such efforts to respond to a SAR. The ICO will not seek to take enforcement action against an organisation that has failed to use extreme measures to recreate previously ‘deleted’ personal data held in electronic form. source https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/right-of-access/how-do-we-find-and-retrieve-the-relevant-information/ Edited March 28, 2022 by djm968 4
elsiegee40 Posted March 28, 2022 Posted March 28, 2022 These email will have been sent TO someone else though. So may still be found in your email system in someone else’s inbox
bobsmith Posted March 28, 2022 Posted March 28, 2022 Also don't you have to be careful about this? What's stopping me delete everything related to a SAR every time we receive one?
djm968 Posted March 28, 2022 Posted March 28, 2022 (edited) Also don't you have to be careful about this? What's stopping me delete everything related to a SAR every time we receive one? Any personal data that needs to be retained e.g HR/Finance, should be retained in compliance with your schools data retention policy. SARs are one of the reasons it is important that any data that does not need to be retained, should be routinely deleted. Edited March 28, 2022 by djm968
GrumbleDook Posted March 28, 2022 Posted March 28, 2022 Also don't you have to be careful about this? What's stopping me delete everything related to a SAR every time we receive one? Because deleting it after receiving a SAR is illegal. 3
psydii Posted March 28, 2022 Posted March 28, 2022 eDiscovery in 365 returns recently deleted items, so deleting to get to avoid an already served SAR is not possible. The ICO would take a very dim view if it were discovered that attempts to delete data were made to avoid the SAR. Such an action violates one of the principals of GDPR: "...including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).” ..And you would be unlawfully impeding the subject's right of access to data the organisation held at the time the request was made.
paulkerton Posted March 28, 2022 Posted March 28, 2022 Fascinating reaction here. Big differences between: * How they manage their inbox and deleting files * How your data retention policy is set * Deleting content about a SAR after the SAR is requested Basically no matter what a user does, the organisation should be able to retain the data for the length of your data retention policy seperately.
steveg Posted March 28, 2022 Posted March 28, 2022 Have a read of this, source https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/right-of-access/how-do-we-find-and-retrieve-the-relevant-information/ It does go on to say that if you have backups you should be able to provide data stored within them, so in this instance if there is a backup of the mailbox that can be accessed then emails should be provided from this.
djm968 Posted March 28, 2022 Posted March 28, 2022 (edited) It does go on to say that if you have backups you should be able to provide data stored within them, so in this instance if there is a backup of the mailbox that can be accessed then emails should be provided from this. You are right and this is why you should not be keeping any data for any longer than you are required to keep it, as set out in your data retention policy. You wouldn't backup or archive deleted data... would you? https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/principles/storage-limitation/#no_longer_need Edited March 28, 2022 by djm968
Koldov Posted March 28, 2022 Posted March 28, 2022 I was quite interested in this as a cross-thread to: http://www.edugeek.net/forums/cloud-services/227010-m365-email-auto-deletion-policies.html about auto-deletion/retention policies.
mikes Posted March 28, 2022 Author Posted March 28, 2022 (edited) The user wanted e-mails sent from one particular user (hosted on o365, we have a hybrid deployment atm) to an external organisation, mentioning them; only a few of our users are on O365 so I have no special backup policy in place for these mailboxes yet, TBH reading the guidelines if O365's e-discovery returns recently deleted e-mails then that will have to do. But on O365 the hold on items deleted from "Deleted Items" (end users can purge items from this backup but they are also kept under "Purges") - the date range is only 14 days however. Anything that has been deleted from Deleted Items for more than 14 days by default is removed even if it hasn't been purged. The date range the applicant specified was this current School year (so Sept up until now). I guess to really fulfil the requirements I would have to put a retention hold of 6 months or a year on every single mailbox we have hosted ??? as we have no idea who would file a SAR for what reason. Is that what people here do, put a retention period of say 6 months ?? or change the default "purge" retention to 6 months ? (edit Interesting what Koldov posted, they want their "purge" retention time to be tiny) The SMT user didn't delete any of the e-mails maliciously (like was stated here, even if they had done, the e-mails would still show up under Recoverable Items > Purges) it is just they only kept mails for a short amount of time. Kind of like when a student says they need an older copy of some work but the copy they want is dated 4 months ago or someone wants to see CCTV for an incident that was 3 months old... the ICO says "the general rule is that you cannot hold personal data indefinitely ‘just in case’ it might be useful in future" and this external organisation board issue had been closed and dealt with, or so we thought prior to this SAR... Edited March 28, 2022 by mikes
psydii Posted March 28, 2022 Posted March 28, 2022 (edited) While this is not an ideal situation, it seems that it is normal practice in your organisation to treat email as transient communications, then as long as you are not deleting data you should be retaining, the deletion of emails about the subject shouldn't be a problem, since all emails get treated the same way. I would expect the worst that will happen is a sternly worded email from the ICO advising you to put in place and explicit data retention schedule. You would need to work with your DPO to make sure you have all your ducks lined up in a row, but you can only provide that which you have on record. It is a principal of GDPR that unless there is a legitimate reason to retain data you should not. So a blanket hold should not be necessary, and indeed is probably counter productive. That said, some communications definitely fall inside legislation requiring you to keep them for a period of time. However best practice would be for these communications to be stored in a system explicitly designed to hold records for those communication types. Many organisations have a very short email retention policy - not so much that email is to be retained for a period, but that after a short time email is to be deleted. All communications that must be retained should be archived in the appropriate system. It sounds very much like your organisation is operating somewhat like this, but may be lacking the formalised policies that would help evidence this as your standard practice. Edited March 28, 2022 by psydii
djm968 Posted March 28, 2022 Posted March 28, 2022 The user wanted e-mails sent from one particular user (hosted on o365, we have a hybrid deployment atm) to an external organisation, mentioning them; only a few of our users are on O365 so I have no special backup policy in place for these mailboxes yet. TBH reading the guidelines if O365's e-discovery returns recently deleted e-mails then that will have to do. But on O365 the hold on items deleted from "Deleted Items" (end users can purge items from this backup but they are also kept under "Purges") - the date range is only 14 days however. Anything that has been deleted from Deleted Items for more than 14 days by default is removed even if it hasn't been purged. If the emails/data needed to be kept for compliance with the Schools data retention policy, then a process should be in place to ensure it cannot be deleted/destroyed until the retention date has expired. This could be as basic as printing an email and filing it in an HR folder for example.
GrumbleDook Posted March 28, 2022 Posted March 28, 2022 Also remember that the email is *not* the data. If the data has been put into the relevant system (e.g. MIS, assessment record, etc.) then the data is stil there.
bobsmith Posted March 28, 2022 Posted March 28, 2022 Hoping this is not going off topic - it's an extension of the dicussion because I'm genuinely concerned employers/managers could sidestep complaints by regularly purging incriminating emails before anyone asks for them. My hypothetical scenario is possibly a side issue where something trumps the principal of GDPR - say a member of staff has filed a grievance and the evidence of wrong doing is in an email - would the courts be happy that you've deleted the offending emails (before hearing about a case or a SAR)? So not so much about data - and more a record of commununications with the individual? Or in this case is it down to the individual to obtain copies at the time an offense occurs - because the organisation may not be required to produce their copies (because they've been purged) down the line?
GrumbleDook Posted March 28, 2022 Posted March 28, 2022 (edited) Hoping this is not going off topic - it's an extension of the dicussion because I'm genuinely concerned employers/managers could sidestep complaints by regularly purging incriminating emails before anyone asks for them. My hypothetical scenario is possibly a side issue where something trumps the principal of GDPR - say a member of staff has filed a grievance and the evidence of wrong doing is in an email - would the courts be happy that you've deleted the offending emails (before hearing about a case or a SAR)? So not so much about data - and more a record of commununications with the individual? Or in this case is it down to the individual to obtain copies at the time an offense occurs - because the organisation may not be required to produce their copies (because they've been purged) down the line? And this is where your retention schedule is key. If the data needs to be kept, for whatever prupose you have, then it has to be kept. If the data is being purged by people in contradiction to the retention schedule, then that is a complaint in itself and can come back to bit the organisation and the managers deleting things. Remember that emails are a 2-way thing and you will often find copies of them, even in hard copy, because person X thinks that if they delete it, then it is gone ... not realising that person Y also has a copy. And no ... nothing 'trumps' data protection, you will usually find that data protection actually supports what is needed. Edited March 28, 2022 by elsiegee40
paulkerton Posted March 29, 2022 Posted March 29, 2022 And no ... nothing 'trumps' data protection, you will usually find that data protection actually supports what is needed. Whilst I'd like to agree with that statement, I'm not sure its entirely true when you look at the safeguarding clauses in the DPA 2018!
enjay Posted March 29, 2022 Posted March 29, 2022 The date range the applicant specified was this current School year (so Sept up until now). I guess to really fulfil the requirements I would have to put a retention hold of 6 months or a year on every single mailbox we have hosted ??? as we have no idea who would file a SAR for what reason. Is that what people here do, put a retention period of say 6 months ?? or change the default "purge" retention to 6 months ? Keep it for as long as you can justify keeping it, but certainly don't keep it just in case someone files an SAR. Two reasons for that: 1 - the ICO say "in case it is needed in the future" isn't sufficient grounds to retain, and 2 - if you keep it, you have to disclose it. Don't get me wrong - I'm not saying delete and burn everything so there's no evidence, just that some SARs use very broad terms and ask for "every email naming me", so if you've kept 4-year-old emails about which kids will be missing last period for a football match, you will have to discover those emails, redact the names of the rest of the team and hand them over. That said, it makes sense to me for a retention policy to cover all of the current academic year.
DrCheese Posted March 29, 2022 Posted March 29, 2022 2 - if you keep it, you have to disclose it. Don't get me wrong - I'm not saying delete and burn everything so there's no evidence, just that some SARs use very broad terms and ask for "every email naming me", so if you've kept 4-year-old emails about which kids will be missing last period for a football match, you will have to discover those emails, redact the names of the rest of the team and hand them over. Yes, when I went on one of the groupcall GDPR training courses they banged this into me - If you don't have it, you can't provide it. You can't lose it either (in a data breach) so if you don't need to keep something, don't keep it. Don't keep it just in case you get an SAR, that's not a reason to keep it (& is a reason to get rid of it) - Just make sure it says that in your data policy, else someone will say you're not following your own policy
GrumbleDook Posted March 29, 2022 Posted March 29, 2022 Whilst I'd like to agree with that statement, I'm not sure its entirely true when you look at the safeguarding clauses in the DPA 2018! Re-read them. The clauses give cause and exception, and explain where it fits within other legislation ... that actually have equal or higher principles of protection. And even where exemptions apply, the ring-fencing also provides additional protections and does not completely eliminate all Rights. No matter what, it has to be logged and justified.
GrumbleDook Posted March 29, 2022 Posted March 29, 2022 Yes, when I went on one of the groupcall GDPR training courses they banged this into me - If you don't have it, you can't provide it. You can't lose it either (in a data breach) so if you don't need to keep something, don't keep it. Don't keep it just in case you get an SAR, that's not a reason to keep it (& is a reason to get rid of it) - Just make sure it says that in your data policy, else someone will say you're not following your own policy Not so much in the policy, more a case of your retention schedule. Another plug for the templates from IRMS.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now