speakercon Posted July 29, 2025 Posted July 29, 2025 I've been having a go with the trial of purview... got about 10,000 items come back in the search. How do you go about reviewing all this data for relevance and removing anything out of scope?
pete Posted July 30, 2025 Posted July 30, 2025 It's partly learning how your school(s) communicate internally and also making sure your search terms and locations are sane. There'll be loads of things that mention the person that aren't about the person (or aren't the only copy of that information). For example: Our schools send out weekly automated "list of students whose attendance/behaviour/whatever is a bit troubling" reports to HOYs so they know where to apply course correction. Those are ignored because the same data is in the MIS export for the SAR. That same information is included in the meeting minutes between the HOY and that year's form tutors. And the meeting minutes of the HOY and their SLT link. And (if it gets to that stage) likely SLT meeting minutes.
DalekSec Posted July 30, 2025 Posted July 30, 2025 It's also important to note, are you the DPO? if so its not your job to filter out everything only to provide the result of the searches that have been requested. Then whoever is in charge of data protection to sort it out, as you may not be wanted to look at the content
speakercon Posted August 5, 2025 Author Posted August 5, 2025 (edited) Thanks, no it's not me who has to look through the data (luckily!). Edited August 5, 2025 by speakercon
PotNoodleTech Posted August 6, 2025 Posted August 6, 2025 On 30/07/2025 at 10:55, DalekSec said: It's also important to note, are you the DPO? if so its not your job to filter out everything only to provide the result of the searches that have been requested. Then whoever is in charge of data protection to sort it out, as you may not be wanted to look at the content Eh? So it's not the Data Protection Officers job to filter out the requests but it's whoever is in charge of data protection (should be the DPO??) job? Doesnt make much sense. DPO is ultimatly responsible for it all. 1
speakercon Posted August 6, 2025 Author Posted August 6, 2025 I think DalekSec means it's not an IT job to filter the data, and it is the DPO who should do this, that's how I read it? 2
MartinT Posted August 23, 2025 Posted August 23, 2025 It used to be my job to filter the requests in Microsoft Purview, and then output to PDF(s) for redaction in Adobe Acrobat. After that, the Compliance Officer who was in charge of data protection, would sit and perform the redactions. I preferred my job to hers!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now