Jump to content

Recommended Posts

Posted

Good morning all,

 

Does anybody have any advice about the most efficient way to meet an SAR in terms of finding all emails sent that might include the subject in the title or body of the email, please?

 

Thank you

Posted

**stares at 10,000 emails in Purview** and that's just SLT and the SEN team.

Very roughly, off the top of my head...

Typically if the scope is broad, we do SLT, SEN, Safeguarding Team, and the data subjects Heads of Year, Tutors and teachers. Using the student's name as the keyword. ediscovery seems to do quite an impressive job of pulling up emails where the subject is referred to as "J.B."  when the search term was actually "Joe Bloggs", and also sometimes managed to pull up teams chat between staff that is clearly related (you can tell by time and the context) but doesn't mention the name at all.  We then do a quick sanity check, and might poke around if there are clearly gaps, tuning our search terms until we are happy we're capturing everything in scope.

Once we have our results, we then create a set of tags, with two groups, one "Not for export", the other "For Further Review".

Under Not for Export we have "duplicate", "not about subject",  "data from MIS" and "privileged". 

Under "for further review" we have three tags "no redaction required", "requires redaction", "Check with DPO"
We use various pivots inside ediscovery to (fairly) quickly tag duplicates and data from sims, not about subject. Tagging any that are actually in scope of the SAR as either not redaction required or requires redaction depending on obvious signals.

Very rarely is anything tagged "privileged" and if it is there is already a solicitor sitting with the head and this is bounced over to them for review. Usually it is reclassified to either "no redaction" or "requires redaction" with notes from the solicitor. Similar with anything tagged check with DPO (typically used when there is a potential conflict with safeguarding or third parties).

Once we have everything tagged we export to individual files with names based on the guid of the object in ediscovery. This allows much more a much more precise review to be undertaken by the DPO / Solicitors, and for these reviews and conversation to happen over email - since we are talking about guids and not the data subjects data. Also when it makes its way to the data subject as our formal response, they also can reference the guid should theory want to follow up something specific. But I'm jumping ahead.

Once we have all the documents/emails exported, we convert to pdf and take a directory listing into Excel.

We then redact as appropriate. Though each pdf is run through redaction tools to remove metadata. Justification for all redaction are recorded in the excel sheet.

Once complete the folders are then checked,  there should be three files per file exported, the original, the pdf and the redacted pdf. We take another directory listing into excel and save as evidence.

The redacted pdfs are then moved to either a ready for disclosure folder, or ready for review (if it warrants a review by the DPO, or there are solicitors involved on our side).

The results are then handed over and the SAR closed off. We  keep the ediscovery case for a year.

 

  • Like 1
Posted

yes that's what happened here.  Had to search for a pupil but they have initials that not only also match a member of staffs initials but also a commonly used 2 letter word.   So really infeasible.

Going through 10000 e-mails one by one.

Does your school hire solicitors to help with this process?  I believe we are supposed to get help from our LEA's data team but they don't offer any help at all.

  • Like 1
Posted

^ Ah, the Ian Tyler/Olivia Kincaid problem.  Yeah, had a couple of those.

 

We use solicitors for advice for the more.....tricky.....SARs, especially those with additional context bubbling away in the background.  But it's not a routine thing (most are straightforward without a lot of interleaved personal data).

  • Like 1
Posted
59 minutes ago, mikes said:

yes that's what happened here.  Had to search for a pupil but they have initials that not only also match a member of staffs initials but also a commonly used 2 letter word.   So really infeasible.

Going through 10000 e-mails one by one.

Does your school hire solicitors to help with this process?  I believe we are supposed to get help from our LEA's data team but they don't offer any help at all.


I would be pushing back on the idea of searching for initials and ask them to clarify their request and provide more specifics.
Firstly, there are only 676 combinations of A-Z twice, and if 10,000 results are coming up and the vast majority of them are false positives, thats a "disproptionate search" and "manifestly excessive" on the grounds of the balance of the request against the burden of the cost.

  • Like 1
Posted

Yeah we brought this up with our LEA's data team but they just said too bad for you  you have to do it as it could relate to them !     And yes the SAR does have context behind it too but that's a level above me in the hierarchy. I believe we should charge for this SAR at least, but again I don't believe that will happen

  • Like 1
Posted
4 minutes ago, mikes said:

Yeah we brought this up with our LEA's data team but they just said too bad for you  you have to do it as it could relate to them !     And yes the SAR does have context behind it too but that's a level above me in the hierarchy. I believe we should charge for this SAR at least, but again I don't believe that will happen

 Calling @GrumbleDook 🤣

  • Like 1
Posted

Back in 2018, when GDPR came into effect, our SLT mandated that child records should be stored in a central location and that all emails were to be deleted after 365 days.

This pretty much solved the issue for us. You don't have find data that you don't hold. 

  • Like 3
  • 2 weeks later...
Posted

Hey all,

 

I'm doing an SAR at the moment, ran through the ediscovery but it exported the PSTs as individual files, beforehand it used to dump it all into one, does anyone know how to get it to carry on exporting to a single PST file? 

Posted
11 minutes ago, jam53ice said:

Hey all,

 

I'm doing an SAR at the moment, ran through the ediscovery but it exported the PSTs as individual files, beforehand it used to dump it all into one, does anyone know how to get it to carry on exporting to a single PST file? 

 

You can yes as this is how i do it, i don't have a SAR requests live currently but it something in the export setting you can change to put it into 1

Posted
3 minutes ago, DalekSec said:

 

You can yes as this is how i do it, i don't have a SAR requests live currently but it something in the export setting you can change to put it into 1

Yeah, I haven't done one in over a year and last time I did it, I remember there was an option to export as one file, but on this new version of purview, I can't seem to find it. 

 

I'm re running the query at the moment with a different source to see if that makes a difference. 

Posted

What's the point of using initials for students when it just causes more work later? Can we stop people doing that? And always using full names?

Posted

In the past i recall ediscovery struggling when there have been too many pivots and filters applied before export. In the early years it used to be so bad that I'd have a ticket open with MS Support for most of ediscovery SARs. 

In the current version for me (with A5) the export to PST option in the Export fly-out on the right hand side of the screen, under Export Format "Create .PSTs for messages where possible"

 

This isn't an option we use for SAR Cases as we do the redaction etc after export and need the filenames to be the ID (a guid) so we can provide a full audit trail. 

Posted (edited)
15 minutes ago, mavhc said:

What's the point of using initials for students when it just causes more work later? Can we stop people doing that? And always using full names?

Yes. Its part of the training I give here. Use sensitivity labels if you want to stop the email content potentially flashing up on someones screen. 

 

Inter-org sharing can be a pain, but this looks like it is properly solved real-soon-now: https://admin.cloud.microsoft/?ref=MessageCenter/:/messages/MC1147390

Edited by psydii
Posted

In terms of Microsoft's services, Have they now not limited the eDiscovery to a basic search? I believe to obtain the level of data a SAR requires you now need an extra 'chargeable' license from Microsoft for 'Purview/Priva' ?

Posted
1 hour ago, mavhc said:

What's the point of using initials for students when it just causes more work later? Can we stop people doing that? And always using full names?

 

I believe it's done so it's impossible/harder to find details/emails so when a SAR request comes in asking for emails etc. from/to John Smith you have to do exactly what has been requested in the SAR so unless they specifically mention to search for the initials (and even then if you have multiple people with those initials it's therefore impossible to give them the info they require) then you have to search for John Smith and if that brings back no emails etc. then that's what you say.  How legal this is is up to a lawyer, but this is my (basic) understanding of why some SLT are doing this.  Must have been a course they've all been on telling them this or maybe Union advice in a newsletter.

Posted
7 minutes ago, Fazza said:

 

I believe it's done so it's impossible/harder to find details/emails so when a SAR request comes in asking for emails etc. from/to John Smith you have to do exactly what has been requested in the SAR so unless they specifically mention to search for the initials (and even then if you have multiple people with those initials it's therefore impossible to give them the info they require) then you have to search for John Smith and if that brings back no emails etc. then that's what you say.  How legal this is is up to a lawyer, but this is my (basic) understanding of why some SLT are doing this.  Must have been a course they've all been on telling them this or maybe Union advice in a newsletter.

If they want to  circumvent the law, they should at least sha512 the name - using initials is still personal identifiable information.

echo "John Snow" | sha512sum
b9ba65703ac550171abc0914b2e065deedca1a0836f31fb0bce2fed9a3e6e3e3ce4c2df973e8eff95a188210c74f156ddc32e0145f04984768d2a747ad9f359c

 

  • Like 1
  • Haha 3
Posted

Lol. I'm looking at an SAR where a hash of the data subjects name would be in scope, both because they said "all data" but also because they explicitly called out unique numbers or references that may have been created as an anchor between systems including where obfuscation of their identity might have been the goal.

Deliberately obfuscating a persons identity for the purposes of avoiding a discovery process by/on behalf of  that person is going to get those doing it into trouble.

 

  • Like 2
Posted
2 minutes ago, psydii said:


Deliberately obfuscating a persons identity for the purposes of avoiding a discovery process by/on behalf of  that person is going to get those doing it into trouble.

 

Agree, the whole point of SAR is to comply with GDPR laws. ICO isn't going to look kindly if you are actively trying to evade the law. Using initials in particular seems egregious because the SLT are actively using it to identify the person!

  • Like 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...