Jump to content

Recommended Posts

Posted

Ideally your organisation needs a Data Retention policy and then you can work to those requirement. It's not an IT decision, it needs SLT and DPO input and some schools would also run it past the governors but that's not in my opinion essential.

I'd suggest having a look at the recent thread at https://www.edugeek.net/forums/data-protection-information-handling/241173-mis-data-retention.html

 

mods, maybe a thread merger is order?

  • Thanks 1
Posted

^ Whatever your retention policy says.

 

If you're writing that section of the retention policy, ours is:

 

Home folder: Archived for 13 months then deleted.

Student Email: Mailboxes are active until 31st August after the leaving date (or October if a student's daft enough to use a school email address for clearing and remembers to ask in time). Mailboxes are recoverable for 180 days after that.

Student OneDrive: As above.

 

Timeframes based on historical student behaviour and they usually gives the students sufficient time to remember their only copy of X was saved at school.

 

Examplar work (with identifying info removed) may be requested and stored for longer.

  • Thanks 2
Posted

This is purely IT stance, ie Home, Onedrive & Email

 

We have a contracted service that covers more Data Protection and their advice is "If data has no purpose or there’s no legitimate reason to keep it, it can be destroyed."

 

From that standpoint its arguable once they are no longer a Student we should remove

 

Albeit I accept what Pete says above in respect of some kind of retention period if they come back or to give reasnoble time to request after they have left

Posted

^ All of the IT areas that might contain personal data should have retention defined within your R&D schedule. Your retention decision-making is a whole-school consideration and having it written down where everyone expects it to be prevents surprises.

 

Include retention for things like:

 

  • Student homedirs
  • Staff homedirs (ideally include a requirement that their line manager checks/countersigns deletion)
  • SLT Email - deleted items (you may want a longer audit trail for bigger decisions by SLT and Governors etc. If you're using legal hold options, make sure it's documented)
  • Staff & Student Email - Deleted Items (We automatically empty it after X days, it's in the policy agreed by the trust board, yes, that's why your "important stuff" is gone)
  • Staff and Student email - junk email (see above)
  • Staff and Student Mailboxes
  • Internet Access Logs - without incident (general "Bob searched for penguins")
  • Internet Access Logs - with incident ("Sarah was flagged searching for inappropriate content and a member of the pastoral team was alerted" - retention tends to be longer, may be added to MyConcern)
  • Safeguarding / Misconduct logs (Smoothwall Monitor, Netsupport, etc) - as above. If these are exported as part of an evidence trail and included in a student record / MyConcern, document that too.
  • Network logs (event logs, webserver access logs, network performance data). Usernames, public IPs correlated with usernames, etc (webservers, 365 and Google Workspace logins)
  • MIS Data on Students (plus EIC, SEN extended retention considerations)
  • MIS Data on Staff (and also whether you need to keep "Bob worked here from X to Y in role Z" basic info perpetually to help deal with Teachers Pensions idiocy - we do.)
  • MIS Data on Parents / Next of Kin
  • Backup retention (once deleted, how long does it take for data to fully rotate out of the backups?)
  • Print logs (if you anonymize logs after X days, include that too)
  • CCTV Recordings
  • Telephone Recordings

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...