Jump to content

Recommended Posts

Posted
Hi guys we have had a staff member file a SAR wanting copies of e-mails about them sent by a particular individual, problem is (well it's not really a problem IMO it is good practice) that person keeps a clean mailbox and deletes e-mails older than 3 months if they are no longer relevant. (and obviously we had no idea this SAR would be filed so the mails were deleted) Do I need to do a mailbox restore and run the SAR against that to get older e-mails or is that beyond the scope of the SAR??? it is an O365 mailbox so I'm not even sure if that is possible? (I have already ran the discovery search, there was no hold on the mailbox)
Posted (edited)

Have a read of this,

 

Information is ‘deleted’ when you try to permanently discard it and you have no intention of ever trying to access it again. The ICO’s view is that, if you delete personal data you hold in electronic form by removing it (as far as possible) from your computer systems, the fact that expensive technical expertise might enable you to recreate it does not mean you must go to such efforts to respond to a SAR.

 

The ICO will not seek to take enforcement action against an organisation that has failed to use extreme measures to recreate previously ‘deleted’ personal data held in electronic form.

 

source

https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/right-of-access/how-do-we-find-and-retrieve-the-relevant-information/

Edited by djm968
  • Thanks 4
Posted (edited)
Also don't you have to be careful about this? What's stopping me delete everything related to a SAR every time we receive one?

 

Any personal data that needs to be retained e.g HR/Finance, should be retained in compliance with your schools data retention policy. SARs are one of the reasons it is important that any data that does not need to be retained, should be routinely deleted.

Edited by djm968
Posted
Also don't you have to be careful about this? What's stopping me delete everything related to a SAR every time we receive one?

 

Because deleting it after receiving a SAR is illegal.

  • Thanks 3
Posted

eDiscovery in 365 returns recently deleted items, so deleting to get to avoid an already served SAR is not possible. The ICO would take a very dim view if it were discovered that attempts to delete data were made to avoid the SAR.

 

Such an action violates one of the principals of GDPR:

"...including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).”

 

..And you would be unlawfully impeding the subject's right of access to data the organisation held at the time the request was made.

Posted

Fascinating reaction here. Big differences between:

* How they manage their inbox and deleting files

* How your data retention policy is set

* Deleting content about a SAR after the SAR is requested

 

Basically no matter what a user does, the organisation should be able to retain the data for the length of your data retention policy seperately.

Posted

 

It does go on to say that if you have backups you should be able to provide data stored within them, so in this instance if there is a backup of the mailbox that can be accessed then emails should be provided from this.

Posted (edited)
It does go on to say that if you have backups you should be able to provide data stored within them, so in this instance if there is a backup of the mailbox that can be accessed then emails should be provided from this.

 

You are right and this is why you should not be keeping any data for any longer than you are required to keep it, as set out in your data retention policy. You wouldn't backup or archive deleted data... would you?

 

https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/principles/storage-limitation/#no_longer_need

Edited by djm968
Posted (edited)

The user wanted e-mails sent from one particular user (hosted on o365, we have a hybrid deployment atm) to an external organisation, mentioning them; only a few of our users are on O365 so I have no special backup policy in place for these mailboxes yet,

 

TBH reading the guidelines if O365's e-discovery returns recently deleted e-mails then that will have to do.

But on O365 the hold on items deleted from "Deleted Items" (end users can purge items from this backup but they are also kept under "Purges") - the date range is only 14 days however. Anything that has been deleted from Deleted Items for more than 14 days by default is removed even if it hasn't been purged.

 

The date range the applicant specified was this current School year (so Sept up until now). I guess to really fulfil the requirements I would have to put a retention hold of 6 months or a year on every single mailbox we have hosted ??? as we have no idea who would file a SAR for what reason. Is that what people here do, put a retention period of say 6 months ?? or change the default "purge" retention to 6 months ? (edit Interesting what Koldov posted, they want their "purge" retention time to be tiny)

 

The SMT user didn't delete any of the e-mails maliciously (like was stated here, even if they had done, the e-mails would still show up under Recoverable Items > Purges) it is just they only kept mails for a short amount of time. Kind of like when a student says they need an older copy of some work but the copy they want is dated 4 months ago or someone wants to see CCTV for an incident that was 3 months old...

 

the ICO says "the general rule is that you cannot hold personal data indefinitely ‘just in case’ it might be useful in future" and this external organisation board issue had been closed and dealt with, or so we thought prior to this SAR...

Edited by mikes
Posted (edited)

While this is not an ideal situation, it seems that it is normal practice in your organisation to treat email as transient communications, then as long as you are not deleting data you should be retaining, the deletion of emails about the subject shouldn't be a problem, since all emails get treated the same way. I would expect the worst that will happen is a sternly worded email from the ICO advising you to put in place and explicit data retention schedule.

 

You would need to work with your DPO to make sure you have all your ducks lined up in a row, but you can only provide that which you have on record.

 

It is a principal of GDPR that unless there is a legitimate reason to retain data you should not. So a blanket hold should not be necessary, and indeed is probably counter productive. That said, some communications definitely fall inside legislation requiring you to keep them for a period of time. However best practice would be for these communications to be stored in a system explicitly designed to hold records for those communication types.

 

 

Many organisations have a very short email retention policy - not so much that email is to be retained for a period, but that after a short time email is to be deleted. All communications that must be retained should be archived in the appropriate system. It sounds very much like your organisation is operating somewhat like this, but may be lacking the formalised policies that would help evidence this as your standard practice.

Edited by psydii
Posted
The user wanted e-mails sent from one particular user (hosted on o365, we have a hybrid deployment atm) to an external organisation, mentioning them; only a few of our users are on O365 so I have no special backup policy in place for these mailboxes yet.

 

TBH reading the guidelines if O365's e-discovery returns recently deleted e-mails then that will have to do.

But on O365 the hold on items deleted from "Deleted Items" (end users can purge items from this backup but they are also kept under "Purges") - the date range is only 14 days however. Anything that has been deleted from Deleted Items for more than 14 days by default is removed even if it hasn't been purged.

 

 

If the emails/data needed to be kept for compliance with the Schools data retention policy, then a process should be in place to ensure it cannot be deleted/destroyed until the retention date has expired. This could be as basic as printing an email and filing it in an HR folder for example.

Posted

Hoping this is not going off topic - it's an extension of the dicussion because I'm genuinely concerned employers/managers could sidestep complaints by regularly purging incriminating emails before anyone asks for them.

 

My hypothetical scenario is possibly a side issue where something trumps the principal of GDPR - say a member of staff has filed a grievance and the evidence of wrong doing is in an email - would the courts be happy that you've deleted the offending emails (before hearing about a case or a SAR)?

 

So not so much about data - and more a record of commununications with the individual?

 

Or in this case is it down to the individual to obtain copies at the time an offense occurs - because the organisation may not be required to produce their copies (because they've been purged) down the line?

Posted (edited)
Hoping this is not going off topic - it's an extension of the dicussion because I'm genuinely concerned employers/managers could sidestep complaints by regularly purging incriminating emails before anyone asks for them.

 

My hypothetical scenario is possibly a side issue where something trumps the principal of GDPR - say a member of staff has filed a grievance and the evidence of wrong doing is in an email - would the courts be happy that you've deleted the offending emails (before hearing about a case or a SAR)?

 

So not so much about data - and more a record of commununications with the individual?

 

Or in this case is it down to the individual to obtain copies at the time an offense occurs - because the organisation may not be required to produce their copies (because they've been purged) down the line?

 

And this is where your retention schedule is key. If the data needs to be kept, for whatever prupose you have, then it has to be kept. If the data is being purged by people in contradiction to the retention schedule, then that is a complaint in itself and can come back to bit the organisation and the managers deleting things. Remember that emails are a 2-way thing and you will often find copies of them, even in hard copy, because person X thinks that if they delete it, then it is gone ... not realising that person Y also has a copy.

 

And no ... nothing 'trumps' data protection, you will usually find that data protection actually supports what is needed.

Edited by elsiegee40
Posted
And no ... nothing 'trumps' data protection, you will usually find that data protection actually supports what is needed.

Whilst I'd like to agree with that statement, I'm not sure its entirely true when you look at the safeguarding clauses in the DPA 2018! :D

Posted
The date range the applicant specified was this current School year (so Sept up until now). I guess to really fulfil the requirements I would have to put a retention hold of 6 months or a year on every single mailbox we have hosted ??? as we have no idea who would file a SAR for what reason. Is that what people here do, put a retention period of say 6 months ?? or change the default "purge" retention to 6 months ?

 

Keep it for as long as you can justify keeping it, but certainly don't keep it just in case someone files an SAR. Two reasons for that: 1 - the ICO say "in case it is needed in the future" isn't sufficient grounds to retain, and 2 - if you keep it, you have to disclose it. Don't get me wrong - I'm not saying delete and burn everything so there's no evidence, just that some SARs use very broad terms and ask for "every email naming me", so if you've kept 4-year-old emails about which kids will be missing last period for a football match, you will have to discover those emails, redact the names of the rest of the team and hand them over.

 

That said, it makes sense to me for a retention policy to cover all of the current academic year.

Posted
2 - if you keep it, you have to disclose it. Don't get me wrong - I'm not saying delete and burn everything so there's no evidence, just that some SARs use very broad terms and ask for "every email naming me", so if you've kept 4-year-old emails about which kids will be missing last period for a football match, you will have to discover those emails, redact the names of the rest of the team and hand them over.

 

Yes, when I went on one of the groupcall GDPR training courses they banged this into me - If you don't have it, you can't provide it. You can't lose it either (in a data breach) so if you don't need to keep something, don't keep it. Don't keep it just in case you get an SAR, that's not a reason to keep it (& is a reason to get rid of it) - Just make sure it says that in your data policy, else someone will say you're not following your own policy

Posted
Whilst I'd like to agree with that statement, I'm not sure its entirely true when you look at the safeguarding clauses in the DPA 2018! :D

 

Re-read them. The clauses give cause and exception, and explain where it fits within other legislation ... that actually have equal or higher principles of protection. And even where exemptions apply, the ring-fencing also provides additional protections and does not completely eliminate all Rights. No matter what, it has to be logged and justified.

Posted
Yes, when I went on one of the groupcall GDPR training courses they banged this into me - If you don't have it, you can't provide it. You can't lose it either (in a data breach) so if you don't need to keep something, don't keep it. Don't keep it just in case you get an SAR, that's not a reason to keep it (& is a reason to get rid of it) - Just make sure it says that in your data policy, else someone will say you're not following your own policy

 

Not so much in the policy, more a case of your retention schedule. Another plug for the templates from IRMS.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...