enjay Posted March 4 Posted March 4 We've been contacted by a former student requesting some of their school work. We've deleted their accounts/folders in line with our retention policy (they left 3 years ago) but obviously the documents are still held in our Redstor backup, because nothing ever gets deleted from that. Where do we stand on a) keeping these files accessible in backup, and b) admitting we've got them?
TechMonkey Posted March 4 Posted March 4 Is this an official request (SAR) or just a "Hey, do you still have my work?" kind of request? Will it cost you, monetarily, to retrieve the work and will it be a ball ache? My first response would be do you have a policy about this, as you need to be seen to be consistent, not just doing it for the kids that are nice. I would say this isn't a DP issue as long as you have done your due diligence to check it is the right pupil. Ultimately though if you have it and it isn't going to be a pain to get, then is there a reason not to do it?
enjay Posted March 4 Author Posted March 4 They haven't used the words SAR but you don't need to in an SAR so it would be hard to draw the distinction. There's no mentary cost to getting it, just someone's time in recovering the data and verifying the identity of the requester. I'm slightly concerned about precedent-setting, but also this highlights for me that RedStor means (eventually) we'll be keeping stuff beyond the 7 year IRMS recommendation too. We haven't had it for 7 years, so we haven't reached that point yet but we will.
flipthebit Posted March 4 Posted March 4 I'm led to believe if it's done in writing requesting specific information for that specific person I think it qualifies as a SAR and should be responded to within a specific timeframe. Whether you can/will provide the information is another matter. As mentioned there should be a policy for this.
Fazza Posted March 4 Posted March 4 Your Data Retention should be decided in writing by you School/Academy and should be in a policy somewhere stating how long and why you keep certain data so as long as you abide by that policy you are OK. If you can easily recover the files from you backup then I'd do it and help a former student - you never know they might start working in a School and could one day be your boss, or worse, a Teacher who till get their own back (if you don't give them their work) and log jobs complaining all the time!! It's a small world! Seriously though, if you can easily locate/recover their work then for me the only issue is confirming they are who they say they are, maybe talk to their former form teacher to confirm etc.
flipthebit Posted March 4 Posted March 4 Things being in backups is tricky as you can't easily remove the stuff you should remove whilst keeping they stuff you have to keep. I don't think destruction is required if it's impractical, but retention is. One might override the other.
enjay Posted March 4 Author Posted March 4 We have a policy for how long we keep students' work (which is why we've deleted their folders!). My question is around how we actually have data beyond that retention period because of our immutable backup.
enjay Posted March 4 Author Posted March 4 6 minutes ago, Fazza said: for me the only issue is confirming they are who they say they are, maybe talk to their former form teacher to confirm etc. How would their former tutor be able to confirm identity? I know we had a student of that name (they're in our MIS), the question of identity is whether this email has come from that person or not. If I do respond with the data, I'll ask for some other identifying data or possibly even a scan of their ID.
Fazza Posted March 4 Posted March 4 2 hours ago, enjay said: We have a policy for how long we keep students' work (which is why we've deleted their folders!). My question is around how we actually have data beyond that retention period because of our immutable backup. If you are keeping data longer than stated in your policy then you (the school/academy) is therefore in breach of that policy. 2 hours ago, enjay said: How would their former tutor be able to confirm identity? I know we had a student of that name (they're in our MIS), the question of identity is whether this email has come from that person or not. If I do respond with the data, I'll ask for some other identifying data or possibly even a scan of their ID. That's between their tutor and the student, as long as you get it in writing from the Tutor that they say the student is who they say they are then you're good to go - the tutor could always ring them if they never emailed them on their personal email account etc. If in doubt you need to take advice from whoever is in charge of Data Protection as they are ultimately responsible for that sort of thing. It's not different I guess to anybody doing an SAR for example, how do you know they are who they say they are - whatever procedure is followed for that is most likely what you need to follow for a student - again your DPO (or whatever they maybe called these days) will tell you what 'evidence' you need to prove they are who they say they are. If they are still in your MIS system and have a photograph you could always say the files were too large to email so you have put them on a CD or USB stick and they will need to come in to collect it and then if they look like their photo, you're good to go!
itskdog Posted March 4 Posted March 4 3 hours ago, TechMonkey said: Is this an official request (SAR) or just a "Hey, do you still have my work?" kind of request? Our DPO, Judicium, have told us that any request for data should be treated as an SAR, there's no magic legalese that suddenly makes something an SAR. The ICO's own guidance also says the following: "An individual does not need to use a specific form of words, refer to legislation or direct the request to a specific contact."
enjay Posted March 4 Author Posted March 4 30 minutes ago, Fazza said: If you are keeping data longer than stated in your policy then you (the school/academy) is therefore in breach of that policy. And that's exactly my point - we can't delete this data, because it's held in an immutable backup. Do we re-write the policy to say we retain data indefinitely? Do we say where we can/can't delete it from? Do we amend our practices so we only recover data from the last X years, even though we actually have older data?
Fazza Posted March 4 Posted March 4 (edited) 3 minutes ago, enjay said: And that's exactly my point - we can't delete this data, because it's held in an immutable backup. Do we re-write the policy to say we retain data indefinitely? Do we say where we can/can't delete it from? Do we amend our practices so we only recover data from the last X years, even though we actually have older data? Only your School/Academies Data Protection person can answer those questions. The law says something about keeping it for a reasonable time, no mention of indefinitely. There must be a retention setting/policy on your immutable backup, if not one needs setting up and you should contact your backup companies tech support for assistance on this matter. Edited March 4 by Fazza 1
enjay Posted March 4 Author Posted March 4 2 minutes ago, Fazza said: Only your School/Academies Data Protection person can answer those questions. I am my school's data protection lead (but not DPO, obviously). I thought this forum was to get advice from others about their practices, which is why I posted as we're not the only school who uses Redstor and other such backups, and probably not the only school who is accidentally not following our data retention policy because of these backups.
Fazza Posted March 4 Posted March 4 Just now, enjay said: I am my school's data protection lead (but not DPO, obviously). I thought this forum was to get advice from others about their practices, which is why I posted as we're not the only school who uses Redstor and other such backups, and probably not the only school who is accidentally not following our data retention policy because of these backups. You need to contact Redstor for advice on what your options are. Even immutable backups can be 'opened' so data can be deleted but it's a complex procedure (as by definition this is not supposed to be possible) it can involve MFA and all sorts of encryption keys. Redstor support is very good so just explain the issue to them and they'll tell you what to do to prevent this from happening in the future.
enjay Posted March 4 Author Posted March 4 Just now, Fazza said: You need to contact Redstor for advice on what your options are. From a quick search, it looks like I can specify a data retention schedule within Redstor, but our data retention policy isn't that simple - for example, currently some documents are retained for 7 years, while others are only kept for 12 months. Some safeguarding files have to be kept for decades (and that's the law, not our internal policy). I've contacted our DPO for their input, too.
TechMonkey Posted March 4 Posted March 4 Interestingly there seems to be conflicting advice about backups and SAR. My understanding was that backups were not covered by SAR but ICO says they are. Other advice seems to be that as long as the data is not used for active processing and only for restoring then it is OK. I think the confusion is from ICO using the term backup systems to cover not only backups but also hot sites and other replicated systems. 36 minutes ago, itskdog said: Our DPO, Judicium, have told us that any request for data should be treated as an SAR, there's no magic legalese that suddenly makes something an SAR. The ICO's own guidance also says the following: "An individual does not need to use a specific form of words, refer to legislation or direct the request to a specific contact." It wasn't my intention to say there has to be a magic shibboleth to be allowed to get data, but there is a difference between a request for data and someone off hand asking if you still have it and a difference in how they can be approached. And yes, I am totally aware that the response will be that there should be no difference they should all be approached exactly the same and I know this will start an "Akshully" debate which I am not trying to start. What I am saying is that in reality there is a difference.
Fazza Posted March 4 Posted March 4 10 minutes ago, enjay said: From a quick search, it looks like I can specify a data retention schedule within Redstor, but our data retention policy isn't that simple - for example, currently some documents are retained for 7 years, while others are only kept for 12 months. Some safeguarding files have to be kept for decades (and that's the law, not our internal policy). I've contacted our DPO for their input, too. Then you'd need to make sure people saving files that are only kept for 12 months are stored in a different location to all the other files. With regards to the safeguarding files, they should really be on a different system separate to your file servers - a lot of places use CPOMS for that I believe. Mistakes happen all the time and quite a lot of the times we don't realise that we've made a mistake until things like this happen - over the years we've identified all sorts of issues with data retention, even our Director who is our data protection guy has identified things that we are keeping for far too long, the thing is to identify the issues, notify your DPO for advice and then come up with a plan to 'fix' it going forward. Redstor support is very good and should help you sort the settings out going forward and may have an answer for how you can delete data from the immutable backup you have, you may have to set it to expire and then wait for it to expire before you can do it. As long as you DPO is aware and documents your plan of action then you'll be fine. With Teachers coming and going all the time we have god knows how many files that we shouldn't be keeping on our file servers - we have found that Microsoft File Server Resource Manager (FSRM) can be used to delete files of a certain age or even archive/move them somewhere else so maybe going forward you could use this to search for keywords and then move the files to a folder that is only kept for 12 months etc. so for example if the files you can only keep for 12 months are to do with Pensions you could update your data protection policy to say that everyone must have the word Pension in the filename so FSRM can deal with it. Not played with FSRM yet but I have just done a restore of one of our file servers that has all sorts of data it shouldnt have on it and will be testing to see how it can handle/delete/archive files over 7 years old etc. I believe it can even email out to the original creator to say it has been moved/archived so it sounds promising..
enjay Posted March 4 Author Posted March 4 3 minutes ago, Fazza said: Then you'd need to make sure people saving files that are only kept for 12 months are stored in a different location to all the other files. I am not sure if the Redstor retention is that clever, i.e. to keep Location A for 12 months but Location B for 7 years - I'd need to delve deeper to be sure, though. 4 minutes ago, Fazza said: With Teachers coming and going all the time we have god knows how many files that we shouldn't be keeping on our file servers - we have found that Microsoft File Server Resource Manager (FSRM) can be used to delete files of a certain age File age isn't all that relevant, and I think if you deleted all files over X years, you'd find you've deleted all sorts of files which staff routinely use.
Fazza Posted March 4 Posted March 4 1 minute ago, enjay said: I am not sure if the Redstor retention is that clever, i.e. to keep Location A for 12 months but Location B for 7 years - I'd need to delve deeper to be sure, though. File age isn't all that relevant, and I think if you deleted all files over X years, you'd find you've deleted all sorts of files which staff routinely use. If you're not allowed to keep old student photos for longer than 7 years for example, it doesn't matter if the teachers still use them, they have to be deleted if that's what is in your policy. With regards to FSRM, deletion is only one option, you can even compress them to take up less space on your server or move them to another location and then only if someone says "oi! where have my files gone" you can always move them back as I believe (not tried it yet so can't be 100%) when they are moved to another drive/volume you can keep the same file structure making it easy to move them back. You can also use modified date rather than creation date as a parameter too - plenty of options to choose from but I'm currently messing about with Office365 SSO and FSRM is next on my list so not up to speed on it fully yet! If you backup at file level rather than vhdx/hyper-v level then there must be a way of having to backups performed with different settings, again Redstor support should be able to advise on a good solution going forward as you can't be the only place where different types of files have different retention periods. Let us know what they say as there are probably more schools/academies in the same boat as you but don't realise it yet!
enjay Posted March 4 Author Posted March 4 7 minutes ago, Fazza said: If you're not allowed to keep old student photos for longer than 7 years for example, it doesn't matter if the teachers still use them, they have to be deleted if that's what is in your policy. I wasn't meaning student photos, I was more thinking of lesson resources. Docs/PowerPoints probably aren't that old because they'll get tweaked over the years, but staff could easily have PDF or JPG resources from years ago - exam past papers, for example - which they still use (and teachers are known hoarders, so definitely will have files that old!).
Fazza Posted March 4 Posted March 4 6 minutes ago, enjay said: I wasn't meaning student photos, I was more thinking of lesson resources. Docs/PowerPoints probably aren't that old because they'll get tweaked over the years, but staff could easily have PDF or JPG resources from years ago - exam past papers, for example - which they still use (and teachers are known hoarders, so definitely will have files that old!). We're the same and have been discussing this exact thing, I believe with FSRM you can specify a last accessed date rather than creation and you could argue if a resource that was purchased 10 years ago and was last accessed 8 years ago it can be deleted! Our DPO (also our IT Director) has a very firm line with this sort of thing as he would rather just err on the side of caution (data protection wise) and just do a hard delete of most (but not all) files!! It all depends on how your DPO wants it handled. Going forward (in years to come due to licensing costs) we are going to move our file servers in to 'the cloud' as with Microsoft you can automate labels on files so anything to do with Pensions etc. that needs to be kept until after someone has retired for example can be automatically labelled with a label called 'Pensions' which can then be included or excluded from being deleted etc. - the standard license doesn't allow labelling so I think you need A5 licenses which come at a cost so that's why this will take a few years before it's sorted. It's a bit of a nightmare but we will get there (I hope)..
enjay Posted March 4 Author Posted March 4 Cloud-based file servers often charge based on usage too, so getting rid of all the unused files has a financial benefit too. One challenge we'll all face with something like this is getting people to use the labels (rather than complain when they're unlabelled files are purged), and use them correctly rather than label everything as 'Pensions' so it doesn't get deleted "just in case I need it...."
robintech Posted March 4 Posted March 4 not specific to OP but I was under the impression if you have the data and there wasn't an exemption then you have to provide it "Remember that you must also respond to subject access requests for any personal data you hold. This may be more difficult if you are holding old data for longer than you need." Principle (e): Storage limitation | ICO
Boredguy Posted March 5 Posted March 5 We don't use RedStore, but out backup solution from Barracuda is configured for all our Trust to only retain backups for a maximum of 1 year to ensure we're not holding it for too long and this is mentioned in the Trusts policy. It automatically purges the data at the time on the system. That doesn't mean that resources we hold are deleted when over 1 year old, purely that a backup made on the 5th March 2025 will automatically be removed when 6th March 2026 comes around. Thankfully we don't use Tape storage so it's a simple drop down option.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now