Email, Systems and Access Logs
Processing that happens whether or not anybody intends it, generating the largest holding about any employee and the one nobody has assessed.
OPERATIONAL DATA AUDIT
What the systems record without anybody deciding
- EmailContent and metadata, retained by defaultUsually the largest holding about any person
- Access logsWho opened what, whenGenerated automatically, retained indefinitely
- Building accessBadge eventsA record of arrival and departure times nobody chose to keep
- Device managementCompliance state, sometimes locationCheck what is actually enabled
- CalendarMeetings, attendees, titlesReveals more than people expect
- Call and messaging metadataWho, when, how longRarely in any record of processing
- RetentionWhatever the system defaults toThe decision nobody made
- AssessedWhether anybody has ever justified holding itUsually not
Most employment processing is deliberate: somebody decided to collect it. Operational data is different. It is generated by systems doing their job, retained by default, and almost never assessed.
The record described in “Email, Systems and Access Logs” should remain evidence of a workflow rather than a shortcut to judging a person. When an employer evaluates time tracking software with clear records for time tracking software, it should define what managers may see, how an employee can correct an inaccurate entry and which decisions require corroboration beyond activity data.
Why it matters
By volume it exceeds everything in the HR file.
For a separate benchmark relevant to “Email, Systems and Access Logs”, consult the WIRED security coverage. Use it to test purpose, data flow, retention, access and response procedures rather than substituting a generic checklist for the organisation’s actual records.
It is personal data: an access log is a record of what a named person did and when. A badge system is a record of when they arrived.
And it is disclosable. A subject access request covers it, and organisations that have never considered it discover during a request that they hold years of it.
The decision nobody made
Retention is whatever the system defaults to, which is frequently indefinite.
Nobody chose eighteen months of badge events or three years of access logs. The product shipped that way, the implementer accepted it, and it has been accumulating since.
Which means the organisation is holding detailed behavioural records of its staff on a basis nobody has articulated, for a period nobody selected.
The legitimate purposes
Security investigation, system troubleshooting, capacity planning, regulatory requirements in some sectors.
Each is real, each justifies some retention, and none justifies indefinite retention of everything. The purposes imply periods measured in months for most categories.
Where it becomes something else
Operational data used for a purpose it was not collected for.
Access logs consulted to check somebody's working hours. Badge data used in a disciplinary. Calendar analysis to assess how somebody spends their time.
Each is a new purpose requiring its own basis and its own notice, and each is done routinely without either — usually by somebody who assumed that data the organisation already holds can be used for anything.
The audit worth running
List what the systems record, what the retention is, and whether anybody has justified it.
Set periods deliberately. Most organisations find they can reduce retention substantially with no operational loss, which also reduces the burden of every future request.
Telling people
Operational data belongs in the privacy notice, and it is routinely absent.
An employee who discovers during a request that the organisation holds three years of their building access history, undisclosed, has a complaint with substance.
When operational data becomes something else
Access logs consulted to check working hours. Badge data used in a disciplinary. Each is a new purpose needing its own basis and notice, and each is done routinely by somebody who assumed existing data can be used for anything.
Reducing retention costs nothing
Most organisations find they can shorten operational retention substantially with no loss, which also reduces the burden of every future request. The periods were defaults rather than decisions.
Retention is whatever the system defaults to, frequently indefinite. Nobody chose eighteen months of badge events; the product shipped that way and it has accumulated since.
Operational data belongs in the notice
And is routinely absent. An employee discovering during a request that you hold three years of their building access history, undisclosed, has a complaint with substance.
Telling people about it
Operational data belongs in the privacy notice and is routinely absent. Its absence is what makes the discovery during a request feel like concealment rather than oversight.