Skip to content
End This At Any Time You can end a remote session at any time

All notes / Obligations

Recording, Retention and Access Requests

What the programme accumulates, how long to keep it, and the request that should be rehearsed before it arrives.

Obligations · Procedure

General orientation, not legal advice; retention requirements differ by jurisdiction.

The boundary described in “Recording, Retention and Access Requests” should also be set before any workforce system is introduced. A team evaluating this workforce tool for attendance sheet template can keep the use proportionate by stating the purpose, selecting only necessary settings and giving employees a clear route to review or correct records.

A support operation generates a continuous record of who looked at whose screen. Deciding what to keep is part of running it rather than an afterthought.

For an independent reference related to “Recording, Retention and Access Requests”, consult the ICO employment-practices guidance; it provides a useful external check on security, privacy and operating assumptions before a process is adopted.

What accumulates

Connection logs: who, which machine, when, how long, against which ticket.

Session recordings, where enabled.

File transfer records.

Chat transcripts, where the tool includes messaging.

And ticket notes, which sit elsewhere and are frequently forgotten in this analysis.

A workable schedule

Connection logs: months, long enough to investigate something discovered later.

Recordings: weeks unless there is a specific reason, because they are the heaviest and most sensitive.

Transfer records: with the connection logs.

Anything attached to an incident or dispute: per that process, which overrides the schedule.

Written down, automated where possible.

Why recordings should be short

They contain whatever was on the screen, including personal and third-party material.

Their investigative value decays quickly.

And a long-retained library is both a target and an obligation, which nobody would approve if asked to approve it explicitly.

Access controls on recordings

Few people, logged, with a stated reason for each access.

Not browsable by the support team generally.

Reviewed occasionally, because access to recordings is itself an activity worth watching.

The access request

"Who connected to my machine, and do you have recordings?"

The answer should take minutes.

It usually takes a day of confusion because nobody has tried, which is an argument for rehearsing it once with a volunteer.

What people are surprised by

That recordings exist at all.

That connection logs show times they thought were private.

And that a support session touched their machine without their knowledge, where unattended access was used.

Each is reasonable surprise and each is reduced by telling people in advance.

Deletion in practice

Check it happens: backups, the vendor's systems, exported clips somebody saved for training.

A schedule covering only the primary store is incomplete.

And get the vendor's own retention in the contract, which the procurement note covers.

When the programme changes

Platform migration, outsourcing, a change of provider.

Old recordings and logs need a decision rather than a default.

Migrating everything because it is easier is how holdings outlive their purpose indefinitely.

What to check

Is there a written retention schedule, and is it enforced?

How long are recordings kept, and who can browse them?

Could you answer an access request this week?

And do you know what your vendor retains?