Last updated: 
3 months 2 weeks ago
Blog Manager
One of Jisc’s activities is to monitor and, where possible, influence regulatory developments that affect us and our customer universities, colleges and schools as operators of large computer networks. Since Janet and its customer networks are classified by Ofcom as private networks, postings here are likely to concentrate on the regulation of those networks. Postings here are, to the best of our knowledge, accurate on the date they are made, but may well become out of date or unreliable at unpredictable times thereafter. Before taking action that may have legal consequences, you should talk to your own lawyers. NEW: To help navigate the many posts on the General Data Protection Regulation, I've classified them as most relevant to developing a GDPR compliance process, GDPR's effect on specific topics, or how the GDPR is being developed. Or you can just use my free GDPR project plan.

Group administrators:

Information Commissioner on Backups and Deleted Files

Wednesday, October 17, 2012 - 10:17

The Information Commissioner has published new guidance on when information will be ‘held’ by a public authority for the purposes of the Freedom of Information Act (note that Scotland has its own law and guidance). Paragraphs 28-36 of the guidance deal with the tricky topic of deleted computer files and backups.

The guidance suggests that the focus should not be on whether it might be technically possible to recover a file, but on whether the authority’s behaviour indicated an intention to do so. Thus leaving a file in a computer’s recycle bin does indicate an indication to recover it, but emptying the recycle bin is a sign of no further intention (even if it might be technically possible to reconstruct the file from hidden information on the disk).

For off-line storage the guidance distinguishes between backups, where the information is only kept as a “safeguard against disaster”, and archives, where there whole purpose of storage is to allow future recovery. Identifying which storage is which, and treating it in accordance with that identification, is therefore important. The guidance highlights a recent Tribunal case where the absence of a “fixed policy on the deletion and reuse of the backup tapes” seemed to indicate that the tapes were actually being used as an archive.

Although it will be up to a future Tribunal case to determine whether this was actually the reason for the decision, documenting and following a clear deletion and reuse policy for backups may be important if you don’t want to have to search them to respond to Freedom of Information requests.