Jump to content

Recommended Posts

Posted

Got a q about staff members keeping confidential / CP related e-mails in their mailbox, we have some staff members who use their mailboxes as a filing cabinet rather than as a mailbox, one staff member has CP e-mails from 2019 - the staff member is a senior member of staff and deals with CP but should they have e-mails this old?

I was planning to migrate to O365 and purge all mail older than 1 year but they cried havoc and that plan is paused for now.

Just wondering of peoples thoughts? I am just an IT technician not a manager so officially I am a small fry but I can see this biting the school in the backside so I wanted peoples thoughts?

Posted

It's the DPO's problem. You are aware of it now, but clearly weren't previously aware of the sensitivity of the data contained in the system you manage, so you should brief them, without judgement. Observe that you a migrating to Office365 so if they wanted now might be an opportune moment to change how things are done (or some variation of that based on their response to your briefing).

 

To be honest the DPO should already know where the sensitive data is and how it is stored and handled, so to a significant extent the school (should) have (already) evaluated and managed the risk. Doesn't hurt to review these things from time to time though.

  • Thanks 1
Posted
Got a q about staff members keeping confidential / CP related e-mails in their mailbox, we have some staff members who use their mailboxes as a filing cabinet rather than as a mailbox, one staff member has CP e-mails from 2019 - the staff member is a senior member of staff and deals with CP but should they have e-mails this old?

I was planning to migrate to O365 and purge all mail older than 1 year but they cried havoc and that plan is paused for now.

Just wondering of peoples thoughts? I am just an IT technician not a manager so officially I am a small fry but I can see this biting the school in the backside so I wanted peoples thoughts?

 

The answer from me is why not? Their mailbox is private to them (subject to your AUP saying it’s searchable by senior management under specific circumstances. )

 

Is it any less secure than any other cloud storage? I doubt it.

 

As long as they’re using their school email for this and not their private one then I can’t see why it would be a risk.

 

Yes, people keep emails going back many years. A lot will probably never be needed, but transferring the content elsewhere is onerous and unnecessary.

 

A lot of CP stuff has to be retained for years. And your finance people have to keep their records for 7 years under HMRC rules.

 

Where it causes problems is the amount of storage needed by the email account and the time taken to do a search if you get a Subject Access Request.

Posted
AFAIK it's a statutory requirement for schools to keep a single central register for CP issues. Ofsted should be checking against this.
Posted
The answer from me is why not?

 

To push the counter argument: Because a breach of their email account / access to their laptop is much more likely than a breach of the dedicated CP system.

 

Of course mitigations exist (MFA, Screen Lock Times, Information Protection Policies etc) that can make an exchange mailbox safer, but they are not likely in place given the OP's surprise at finding this data was in systems they managed.

Posted
To push the counter argument: Because a breach of their email account / access to their laptop is much more likely than a breach of the dedicated CP system.

 

Of course mitigations exist (MFA, Screen Lock Times, Information Protection Policies etc) that can make an exchange mailbox safer, but they are not likely in place given the OP's surprise at finding this data was in systems they managed.

 

I think the overriding issue of having CP issues stored on disparate systems is that it itself is a risk to the child involved. If staff leave, new staff arrive it's just a terrible idea to have all the important records related to CP in different places. Chances are, when these records need to be accessed it will have to be done quickly and not always by the member of staff who has them in their mailbox.

  • Thanks 2
Posted

Given that you evidently have staff relying on (or at least expecting to have access to) CP information stored in mailboxes, that's an argument to hold off on purging mail at this point. You'll want all your ducks in a row before you pull that trigger!

 

1 year general retention seems quite hardline, imho. Best practice and data retention policy for student info, etc. is its own issue, but sometimes it is useful to be able to dig out old emails from well over a year ago. If you're resolved to 1 year, perhaps add a an extra month or so to allow for people to refer to stuff from ~around~ a year ago. That might be helpful at points within the academic year that might arrive later in the calendar year than in the year before.

Posted

 

1 year general retention seems quite hardline, imho. Best practice and data retention policy for student info, etc. is its own issue, but sometimes it is useful to be able to dig out old emails from well over a year ago. If you're resolved to 1 year, perhaps add a an extra month or so to allow for people to refer to stuff from ~around~ a year ago. That might be helpful at points within the academic year that might arrive later in the calendar year than in the year before.

 

We did a year at a place I worked and it worked well, took some work initially to get staff onboard as to why we were doing it.

It saved the admin/HR/SLT immense amounts of the work involved in searching subject access requests (SAR's) and is generally a good way to be compliant with holding out of date info (by deleting it!)

Posted

Best practice and data retention policy for student info, etc. is its own issue, but sometimes it is useful to be able to dig out old emails from well over a year ago.

 

So staff should be putting them in the MIS or the CP system, not in email. Email is not a storage system. As others have said, passing the information on if the member of staff leaves is bad enough but what happens if something happens to that member of staff suddenly. Almost certainly IT will have to try and piece their creative filing system together and make it available to someone else. Whereas if it was in the correct place then someone else can be given the appropriate permissions and they can be on top of whatever they need.

  • Thanks 1
Posted (edited)
To push the counter argument: Because a breach of their email account / access to their laptop is much more likely than a breach of the dedicated CP system.

 

Of course mitigations exist (MFA, Screen Lock Times, Information Protection Policies etc) that can make an exchange mailbox safer, but they are not likely in place given the OP's surprise at finding this data was in systems they managed.

 

Just a question do you know what's in all of your staff's mailboxes / documents etc? same with any shared folders? I am curious what other technicians do ! And yes my concern is phishing, data safety, as well as having it available in a centralized place! I've even heard of 2FA attacks now where they can fool a user to accept fake prompts now.

I believe the user does deal with the e-mails and files the information in SIMS, it's just they then leave the e-mail in their inbox with this info in it. I don't want to wipe the e-mails and wipe any information we should have kept but the user doesn't want to go through 3+ years of e-mails either.

 

Edit - and interesting that 1 year is a bit hardline, I've seen people on here say 6 months and one even said 3 months! (for generic mail folders e.g. inbox, any specially created folders the mail gets kept longer). 12 months I assumed was what most people had set ?

Edited by mikes
Posted

I know a few places that do 3 months now. I think it is to prevent what you are discovering, the hoarding of data and then inevitable impossibility of going through it.

I have heard the 15 months +/- a couple suggested above a lot in schools, for exactly the reason given. But proper documentation trumps hoarding.

  • Thanks 1
Posted

I often need to refer to old emails, in fact literally earlier today I wanted an email from April 2021. Yes, you can flag emails so they don't get purged, but I wouldn't have known at the time I would need that email again later so wouldn't have flagged it. Also, I suspect many people (me included?!) would just flag every email for longer retention! If you do implement a purge, what measures would you put in place to ensure people weren't just exporting emails, saving them as PDF, or even printing them?

 

A 3 month purge is pretty brutal. I wonder if this is organisations post-GDPR protecting themselves from SARs - if you don't have it, you can't disclose it.

Posted

As others have said, provided:

 

  • the information exists elsewhere (say in MyConcern so the deputy DSL and the rest of the safeguarding team can access if necessary)
  • the mailbox is protected with MFA
  • you've turned on alerting for odd logins and you review those logs
  • staff have undergone cybersecurity training recently (RPA customers, this should be ticked)

 

I wouldn't be too concerned. Police, local government child protection teams and others will continue to send confidential data to DSLs via email. The important part is the rest of the safeguarding team are in the loop.

 

With regard to very short retention periods, especially for someone wearing a DSL hat, that's a great way to cause a data breach by deleting information you're supposed to retain. It is non-trivial to present (usually several months long) email threads about a particular child in a coherent way uploaded to MyConcern that isn't a) painful for others to review b) likely to be useful in court.

Posted

On the retention period part of the question; lifted from our policy doc.

 

Safeguarding/Child Protection

Files on individual pupil referred (paper and electronic in iSAMS and CPOMS, with historical records from SIMs copied across)

Kept until a pupil leaves. Paper documents then scanned and only an electronic record retained in CPOMS/iSAMSso DoB +25 years

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...