Nothing to see here, again...
The end of the school year approaches and I cannot but help ask my contacts about developments at that school. You know: the one where I had the breakdown which was the genesis of this blog.
Well, the pattern of substantial yearly turnover continues to hold true: six teachers this year… Six, i.e. nearly 50% of class-based teachers. Nice.
I’ll look forward to reading a newsletter where the head uses their double speak to explain the normalcy of that outcome: the usual nothing to see here approach, I’d wager. And I’m sure that the useless governing body and local council won’t bat an eyelid. Why change things now? Integrity is so passé…
Anyway, while I’m here: here’s one from the vaults that has been bugging me of late. I just cannot let it lie. And now I have a sterling excuse what with my recent diagnosis! If you can't milk an ADHD diagnosis, then what can you milk?
So here goes…
I made a Subject Access Request (SAR) once I left that school. I had been victimised in a toxic working environment. I knew there was written proof of it.
Under data protection laws like the UK GDPR, it is a criminal offense to delete, amend, or alter personal data to prevent its disclosure after receiving a SAR.
From: Data Protection Act 2018
It is an offence for a person listed in subsection (4) to alter, deface, block, erase, destroy or conceal information with the intention of preventing disclosure of all or part of the information that the person making the request would have been entitled to receive.
To ensure compliance, organisations must immediately freeze standard deletion and modification schedules for the requested data.
But it doesn't mean that they will.
And at the school, they very much didn't. As far as I can tell, the law was completely ignored. Indeed, in a staff briefing,quite a while after I had made my SAR, the narcissist in chief apparently told their staff that I had made the SAR, which would surely be a blatant breach of my privacy. Why on earth would the entire staff need to know? I don’t want to seem cynical but could it have been indeed to prevent disclosure of information? Surely not?
But then it would appear that the head also requested for staffto delete any mails that were not recent. This would include any emails to/from me and that I was mentioned in. Not dodgy at all…
Anyway, the advice to ensure that this sort of scenario doesn’t happen is to more or less know exactly what records you are looking for, to be specific and ask for them. If you already hold copies of documents that are not provided, you can point to these and question why they didn’t hand over those records when responding to the SAR.
And of course, I was not provided with quite a few documentsthat I already held. Which of course is illegal. This did nothing to allay my suspicion that other documents which would have confirmed my suspicions of victimisation existed.
Hence this e-mail from 20/09/21 that I sent to the school’s Data Protection Officer (DPO) at the time:
Dear DPO,
Re: Subject Access Request
Thank you for information you have sent me. As there are a number of e-mails between myself and (the head) that I can distinctly remember which have not been included in the documents you sent me - for example:
· correspondence ahead of the Year 6 residential trip of 2019 where (the head) claimed I was putting the trip in jeopardy due to negligence in providing necessary documentation;
· correspondence in the weeks before my breakdown where (the head) suggested my performance as subject leader was falling below standards;
· correspondence where (the head) said that no amendments could be made to her write-up of a union meeting.
There is little correspondence included in the data sent to me about my competence being put into question, my subsequent nervous breakdown of November 2019 and its repercussions (ex: emails to other staff and parents explaining my absence, my cover; my departure from the school; etc.).
These are significant gaps so I would therefore be grateful if you could investigate further. I would ask that you give me access to staff mails including my full name, first name or initials within the main body of the email.
If you need any more information, please let me know as soon as possible.
I look forward to receiving your response to my request for personal data within one calendar month.
Yours sincerely,
Alex Gwinnett
To which I got this rather wishy-washy response:
11th October 2021
Dear Mr Gwinnett
Re: Subject Access Request
Further to your email of 20th September 2021, we have spoken with (the company) who provide(s) the email system for the school. They have confirmed that they have provided everything that is on the system regarding your request. I spoke with the ICO’s office for advice as clearly you were expecting something that we cannot produce. They said;
I am sorry but what we have supplied is what (the company) say they were holding, we are not in a position to help you further in this matter.
If you have wish to contact the ICO’s office their website is www.ico.org.uk
Yours sincerely,
(DPO)
My response:
12/10
Dear (DPO),
Thank you for your letter of 11/10/21 in response to my email of 20/09/21.
You quote: The ICO’s view is that, if you delete personal data you hold in electronic form by removing it (as far as possible) from your computer systems, the fact that expensive technical expertise might enable you to recreate it does not mean you must go to such efforts to respond to a SAR.
Could you confirm that this means that after I initially made a SAR this summer, staff were asked to permanently delete their e-mails? Before I get in touch with the ICO, I would like my facts to be in order.
Yours sincerely,
Alex Gwinnett
There was no response from the DPO; it would appear that they obviously no longer wanted to be involved. Instead, the school office sent me this:
19/10
Dear Alex,
To confirm, staff were not instructed to delete any emails relating to your SAR. The entire staff team were asked to provide all emails covering your SAR and, if they did not want to complete this task themselves, then (the company) would be instructed to locate all emails still on the system and include them. You have been given everything that was on the system on the dates that you put in all of your SARs.
Kind regards
School office
My reply:
Dear (school office),
Please inform (the DPO) that I know that staff were instructed to delete all of their unessential mails over a year old shortly after I made my initial SAR. This was weeks before I actually received any data from him. As stated in my correspondence with him, there are some very specific emails that have not been included in the data I received. This appears to be irregular to me: accordingly, I will have to pursue this through other channels.
Best regards,
Alex
I tried to pursue this with the ICO but ultimately was stonewalled. I never really fully realised that the head’s instructions to delete any emails related to me could potentially be construed as a criminal offence. Until now. I have since been in touch with an ex-employee from the school office who had sent me the above email. They remembered the staff meeting and had this to say:
I wasn’t told to delete stuff because you put in a SAR but I do remember in a morning briefing that she told staff that we had to comply with GDPR and not keep things longer than needed and this included emails. (…)
She told all staff (…) to delete emails once they were no longer needed but I didn’t realise that this was anything to do with you. To be honest I didn’t think anything of it at the time. Only later it started to make more sense.
This is the second time that someone who worked in the office has opened up after their unhappy experience at the school to confirm that dishonesty was afoot there. Lest we forget, another person working there was leant on to cover up the truth about the head redacting minutes from a meeting with the union. Once they left, they were liberated from the toxicity and able to confirm this. On top of that, it is important to reiterate that at least four members of the school office left after breakdowns induced by the head’s toxic culture.
While the person I quote above was able to confirm that the head had made up some nonsense story about GDPR hence the email quoted above, they were not at said staff briefing. They were just reporting on what they had been told.
However, ex-colleagues were in the staff briefing and informed me that the head had specifically mentioned my SAR… Well, well, well…
It’s astonishing that even after all these years, things like this keep coming out of the woodwork. And yet, nothing seems to come of it. At least, this piece doesn’t come from the furious, frustrated and f-ed up me of a few years ago. I am over that. But it doesn’t mean that I should just ignore the past, or thepresent for that matter. I can still be a thorny onlooker and care for my friends who still feel the negative impact of toxicity. Solidarity.
Addendum
Since writing the above, I have done a little more digging and come across a forgotten email leaked to me by other ex-employees. It was from the head - allegedly in response to advice from their DPO. For obvious reasons, I will simply summarise it here. It was sent to the school's employees shortly after I made my SARs, and most importantly, before these requests were granted.
The DPO had allegedly warned that emails over a year old should not be kept as they may have to be justified in court! They warned that the ICO was clamping down on schools. They even stated that schools would have to declare any non-deleted emails in the event of a SAR. They added that any emails pertaining to staff could just be printed and put into HR files. You couldn't make this stuff up.
The head went on to advise how to bulk delete emails and volunteered the school's IT consultant's help in clearing the decks.
Alarm bells anyone?

Comments
Post a Comment