Jump to content

Recommended Posts

Posted (edited)

We've had a SAR from an ex-member of staff who is pursuing legal action against the school, and a specific member of staff here.

 

They have provided date ranges and have requested emails to and from $MemberOfStaff and themselves, within those date ranges.

They have also requested emails to and from a second member of staff and themselves within another date ranges.

 

Now technologically, not an issue. I've knocked up a script, dumped all the emails and attachments, and sent them on to our data guy. Easy.

But there's a little confusion around how or what should be redacted.

 

Obviously we should redact anything related to pupils, pupil contacts, other members of staff, etcetera, that we're in agreement on, but I'm under the impression that if the information is of no consequence, it is provided, regardless of its relevancy. So if the ex-member of staff and one of the named contacts are chatting about what chinese to order tonight, it's not relevant, but it's not of consequence, we give that to them, because they have asked for all emails.

 

SLT are thinking it's the other way around, simply telling them there were emails sent from X to Y at datestamps V/W/X/Y/Z and only providing the related information (email body, attachments, etc) if it is deemed relevant.

My response to this is that they have asked for all emails, therefore any email is relevant to the requested scope by simply existing within those date ranges.

 

Additionally, does any consent need to be obtained from the named members of staff? One could argue if these emails are his data, it's also their data too?

Do the named members of staff need to be told that this information has been requested, and is (if it is) being shared?

Edited by Garacesh
Posted

Hi,

 

1. Yes, they asked for all emails within that range, so all emails is what you provide. Relevancy, is not relevant ;)

2. No consent required for emails with other data in as anything identifiable would be redacted.

  • Thanks 2
Posted
A great question and I'm really not sure. I'd be interested in the advice ICO give if you call them. Do you have an outsourced DPO you can run this by, or an internal one - and what level of experience they have?
Posted (edited)
2. No consent required for emails with other data in as anything identifiable would be redacted.

So just to be clear, to throw a few scenarios, 'cause I don't just wanna assume and get it wrong.

 

$Ex-Member-of-Staff sends an email to $NamedPerson1 with marks schemes.

This falls squarely within the scope of the request. In this scenario, we include the email contents and any email attachments.

 

$NamedPerson2 is off ill and is communicating via email with $Ex-Member-of-Staff. $EMoS asks for $NP2's address to run workbooks to be marked out to their home. $NP2 obliges.

In this scenario, we include the email exchange, but redact the given address as personal data.

 

$Ex-Member-of-Staff discusses via email changing a rota, offering to swap times with a third person who has not been named in this SAR

In this scenario, we include the email exchange but redact the third person's identity as personal data.

Edited by Garacesh
superfluous word removal
Posted (edited)

If they are persuing legal action, I would very much recommend that you run the whole thing past your legal team as well as the DPO. The DPO will ensure you disclose what you are required to and make sure you do not disclose what you must not. There is a wide area between those two positions where the legal team may have a view. Ultimately this is between your DPO and your legal team, and it should be made clear who has ultimate authority in signing off the release of the SAR.

 

I would say that emails between individuals are only within scope of an SAR if they //edit// contain information //edit// *about* the subject.

Edited by psydii
tweaking my phrasing based on feedback below
Posted

Indeed, this is something your DPO should be handling anyway. As long as everything is correctly redacted there should be nothing to worry about - the DPO should be documenting what has been redacted and why, and as long as they can show the ICO those reasons, everyone is happy as far as the law is concerned.

To re-iterate though, if they request all email communication between 2 parties, then it does mean all and context is not relevant - after all, you nor the data person might be in a position to know what the context is - an email inviting someone to lunch might seem innocuous but it could in fact be vital to whatever complaint is happening.

Posted

The DPO is handling it, just to be clear, we're just a little iffy in what needs to be included. I'm not the one doing the redactions etc, I just dumped all the emails into text files, but I know we have a fair few folks on here more knowledgeable than I about this, so figured it was worth the ask.

 

Good shout about legal @psydii.. I assume the council has legal services we can discuss it with..

Posted

Whilst it's a great idea to involve the legal team, they have no say in the output of an SAR. They may be able to advise from their experience, but the SAR is a legal request between the requestee and the school, even if it's being made on behalf of the requestee by their legal representation. If that legal team is not part of the school, you'd then need to get consent to involve them.

The ICO will be the best bet for advice, however they will sit on the fence as much as they possibly can, making sure the onus stays directly with the school to make final decisions but they will try and guide you in the right direction because they understand that they can't offer a one-size-fits-all answer to many queries.

Posted (edited)
I would say that emails between individuals are only within scope of an SAR if they //edit// contain information //edit// *about* the subject.

Having discussed with the DSL in person, this is his angle too, and I understand his position better now.

 

$EMoS has requested all emails, between himself and $NP1 and/or $NP2, between A and B dates.

However, a lot of that is mailing list emails that are "has anybody got..", "I found this...", "So and so has just absconded from my lesson", etcetera.

These emails do fall within the scope of the request, however, they are not data about the subject.

 

The ICO's What is personal data? page states the following:

  • If it is possible to identify an individual directly from the information you are processing, then that information may be personal data.
  • If you cannot directly identify an individual from that information, then you need to consider whether the individual is still identifiable. You should take into account the information you are processing together with all the means reasonably likely to be used by either you or any other person to identify that individual.

 

Now let's take an example email to $EMoS by $NP2, fittingly redacted as appropriate.

Does anyone have a year 7 class that $PupilForename could watch? For one of her tasks she needs to watch one child twice in English and then have an informal chat with them about their learning in English. Could anyone suggest a child for this so I can contact parents and check this is ok?

 

Well this information neither identifies nor is about the individual making the subject access request.

The only bit of relevance to that individual it pertains is that it ended up in their inbox, so whilst it meets the criteria laid out in the request (an email to $EMoS by $NP2 within the specified date range), it is still not data about the subject.

 

So going off the snippet from the ICO's page above, this information cannot be used to directly identify the individual, nor can it be used to infer the identity of the individual. Additionally, it has zero capability to be used by anybody to identify the individual.

Edited by Garacesh
  • Thanks 1
Posted (edited)

So going off the snippet from the ICO's page above, this information cannot be used to directly identify the individual, nor can it be used to infer the identity of the individual. Additionally, it has zero capability to be used by anybody to identify the individual.

 

...however it may be pertinent to the subject's legal complaint, which is where the legal team need to cast their eye over it and get to call the shots, because in a bun-fight, there are other mechanisms by which a complainant can get access to the emails.

 

 

 

BTW I'm pretty sure in your example the $pupilForeName is actually $StudentTeacherForename, which may make this email highly relevant if (say) the complaint is about how the school handled supporting them as the Student Teacher lead...

Edited by psydii
Posted

Well this information neither identifies nor is about the individual making the subject access request.

The only bit of relevance to that individual it pertains is that it ended up in their inbox, so whilst it meets the criteria laid out in the request (an email to $EMoS by $NP2 within the specified date range), it is still not data about the subject.

 

Hang on, are you confusing what you redact with what you disclose? You need to redact the name, but because the email was sent between EMoS and NP2 in date-range, you need to disclose it under the SAR.

Posted
Having discussed with the DSL in person, this is his angle too, and I understand his position better now.

 

$EMoS has requested all emails, between himself and $NP1 and/or $NP2, between A and B dates.

However, a lot of that is mailing list emails that are "has anybody got..", "I found this...", "So and so has just absconded from my lesson", etcetera.

These emails do fall within the scope of the request, however, they are not data about the subject.

 

The ICO's What is personal data? page states the following:

 

 

Now let's take an example email to $EMoS by $NP2, fittingly redacted as appropriate.

 

 

Well this information neither identifies nor is about the individual making the subject access request.

The only bit of relevance to that individual it pertains is that it ended up in their inbox, so whilst it meets the criteria laid out in the request (an email to $EMoS by $NP2 within the specified date range), it is still not data about the subject.

 

So going off the snippet from the ICO's page above, this information cannot be used to directly identify the individual, nor can it be used to infer the identity of the individual. Additionally, it has zero capability to be used by anybody to identify the individual.

 

The example you give would have the personal data of ...

$EMoS was emailed on given date/time by $NP2. Did it contain any instructions or items that $EMoS could respond to? Even in the negative? If an outside person could see a copy of this email, would they be able to infer any further information about the $EMoS ... such as they were employed by the school?

You are looking for reasons to reduce the response by making a presumption about what the individual wants. You can go back and clarify the request, pointing out that there are a raft of 'general' school level comms that where issued or are they looking specifically at emails relating to $EMoS and the noted individuals directly?

  • Thanks 1
Posted
You are looking for reasons to reduce the response by making a presumption about what the individual wants.

I'm not looking to reduce anything, it's not me that's got to sort through it all, I don't care how long it takes :lol:

Just looking to get some clarification because our DPO isn't 100% sure.

 

The example you give would have the personal data of ...

$EMoS was emailed on given date/time by $NP2. Did it contain any instructions or items that $EMoS could respond to? Even in the negative? If an outside person could see a copy of this email, would they be able to infer any further information about the $EMoS ... such as they were employed by the school?

Valid point, the email may be of no consequence, but a third party with no prior knowledge would be able to infer there was an employee named J Bloggs.

So essentially my initial suspicion was right and we include him everything, except any personal data about anybody not listed in the request? So we redact any other names/etc that aren't $EMoS, $NP1 or $NP2 and ship off the rest?

Posted
There is no harm in asking for the clarification. If $EMoS doesn't want to wade through the humdrum school community stuff and just see what they need, then that makes everyone happy. Keep gathering the information whilst you ask the question (you could pause the time but that is not likely to help here) so there is no issue.
Posted (edited)

As always a little late to the party and throwing in my slightly different view on things...

 

$EMoS has requested all emails, between himself and $NP1 and/or $NP2, between A and B dates.

However, a lot of that is mailing list emails that are "has anybody got..", "I found this...", "So and so has just absconded from my lesson", etcetera.

These emails do fall within the scope of the request, however, they are not data about the subject.

 

I would not include full copies of any emails which are mailing list or general business as usual for running the school, such as pupil lists sent to a group of staff, in which the requester is not the subject of the email. These can simply be summarised in your response along the lines of:

In accordance with data protection laws personal information of other individuals has not been shared with you. Where possible personal information of others has been redacted, for example sections of emails have been blacked out to hide names of staff, pupils or parents.

In addition to the emails we have shared with you we also hold a number of emails which include your email address, staff initials or name where we have determined that the subject threads fall under the category of general business related to running of xxxxx Academy and day to day arrangements including:

"has anybody got.."

"I found this..."

"So and so has just absconded from my lesson"

 

ICO advice of this page How do we find and retrieve the relevant information? gives an example with the words "You do not have to provide the employee with a copy of each email"

 

I am 99% sure I was given this advice by the ICO helpdesk on two separate occasions.

 

But as others have pointed out the legal claim aspect could skew things - get legal advice! If you need a recommendation -> Dai Durbridge at https://www.brownejacobson.com/

Edited by garbage46
Posted
I would not include full copies of any emails which are mailing list or general business as usual for running the school, such as pupil lists sent to a group of staff, in which the requester is not the subject of the email.

 

I guess that depends what $EMoS is after. I've seen (and sent!) some group emails which are very much targeted at a specific person, and unfortunately seen group emails which are definitely bullying of a particular person. Also, $EMoS might be claiming they hadn't been supported, in which case an All Staff email saying training wasn't available would be highly relevant.

 

$EMoS could make the school's life easier by saying specifically what they're looking for, but they might not want to tip their hand in that way.

Posted (edited)
$EMoS could make the school's life easier by saying specifically what they're looking for, but they might not want to tip their hand in that way.

I don't know - nor want to know - the particulars of the legal action, but I suspect that this is very much the case.

Either that, or they don't really know what they want, so they just want everything, in the hopes that they'll find something vindicating.

 

I'm fairly certain our DPO has gone to the council for advice. As far as my role in all of this, I passed on everybody's comments at the back end of last week and have washed my hands of it all. I was asked to dump all the emails, so I did. Ticket closed.

Edited by Garacesh
Posted (edited)

Our requester specifically requested their name in many ways, e.g. Mickey Old Mouse, Mickey Mouse, M Mouse, MM, MOM, Mr Mouse, Mick... Problem was the MOM 3 letter "staff code" they use quite common, was also a common Welsh word, and there were a bunch of e-mails in Welsh I couldn't understand. I dumped them all and deleted the ones that obviously had nothing to do with the staff member (there was another staff member with the same name acronym e.g. Marvin Older Martian), going through them one by one, which took hours. Anything at all that mentioned her name, or the Welsh ones where I wasn't so sure, I left in, the HM and DPO had to go through each e-mail of which there were thousands, and sort it out.

Still it's a good incentive now to set our e-mail retention to just 1 year, maybe even 6 months, this summer.

 

But it seems anyone with a bone to pick can file these SAR's just to waste school time. This person requested a SAR then requested another one with slightly different parameters, I don't know why the staff member left but this thing seemed to be designed to waste our time because I never saw anything worth mentioning in there. If you left on unhappy terms right when you know the DPO and management will be super busy with exams you could file these 30 day SAR's knowing how much work it will cause them?

Edited by mikes
Posted
If you receive requests that are repeated or truly designed to waste time, and you are confident you could stand behind that stance to the ICO, they can be refused as being vexatious. Worth reviewing vexatious on ICO site. I, with the head, did use this once with an over demanding grandparent/carer and the requests dried up.
Posted
Problem was the MOM 3 letter "staff code" they use quite common, was also a common Welsh word, and there were a bunch of e-mails in Welsh I couldn't understand.

 

Presumably the Welsh word isn't written in ALL CAPS though, so could you scan for case when redacting? This must be a common problem though, as several first names (including yours!) are also common words.

 

But it seems anyone with a bone to pick can file these SAR's just to waste school time. This person requested a SAR then requested another one with slightly different parameters, I don't know why the staff member left but this thing seemed to be designed to waste our time because I never saw anything worth mentioning in there. If you left on unhappy terms right when you know the DPO and management will be super busy with exams you could file these 30 day SAR's knowing how much work it will cause them?

 

I guess it depends how much you want a reference from your former employer...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...