Download PDF
Netwrix > Case Studies > Automating Data Retention Workflows for GDPR Compliance: A Case Study on Hull College
Netwrix Logo

Automating Data Retention Workflows for GDPR Compliance: A Case Study on Hull College

Technology Category
  • Cybersecurity & Privacy - Intrusion Detection
Applicable Industries
  • Education
  • Retail
Use Cases
  • Object Detection
The Challenge
Hull College, a large educational institution with over 15,000 students enrolled each year, faced a significant challenge in managing and securing the millions of files containing students' personal information. The college needed to meet GDPR data retention requirements, which required full visibility into all these files and enforcement of appropriate retention periods. The IT team sought to automate the data discovery and classification processes to ensure accuracy and avoid disrupting other IT projects. Additionally, the college needed to promptly address data subject access requests (DSARs). Given the vast number of files, manual search for regulated information was impractical, necessitating automation. The IT team also aimed to monitor unusual activities and receive alerts for potentially harmful ones, such as privilege escalation, attempts to access financial or HR data, and suspicious file deletions.
About The Customer
Hull College is a prominent educational institution based in Kingston upon Hull, England. The college offers further education, higher education, and university degrees in a variety of fields, including computing, engineering, arts, and sports. Operated by Hull College Group, the college manages three centers in the city and enrolls 15,000 students across its campuses each year. The college's IT team is responsible for managing and securing the vast amount of student data, ensuring compliance with GDPR data retention requirements, and promptly addressing data subject access requests.
The Solution
John Bayes, IT Director at Hull College, selected Netwrix over other solutions due to its out-of-the-box functionality and ease of configuration and use. The solution was implemented to improve data governance. Netwrix Data Classification was used to scan the college's file servers, allowing for archiving of over half of the records that were no longer required and setting appropriate retention policies for the remaining files. All documents containing students' PII were classified, ensuring they are stored only in secure locations. Netwrix Data Classification also streamlined the response to DSARs, enabling the IT team to efficiently find and export all personal data associated with an individual who submits a DSAR. This process typically takes just 5 minutes. Additionally, Netwrix Auditor provided daily reports summarizing user activities across the IT environment and highlighting areas requiring prompt attention. Alerts on anomalous user behavior helped in detecting potential security incidents.
Operational Impact
  • The implementation of Netwrix has significantly improved the data governance at Hull College. The automation of data discovery and classification processes has not only ensured accuracy but also freed up the IT team to focus on other projects. The ability to promptly address DSARs without delaying other projects has enhanced the college's compliance with privacy obligations. The solution's alert system for unusual activities and potentially harmful actions has improved the college's security posture, enabling the IT team to spot malicious actors before they can inflict real damage. Overall, the solution has streamlined the college's data management processes, improved its GDPR compliance, and bolstered its data security.
Quantitative Benefit
  • Over a million files were discovered and classified
  • Over half of the records were archived as they were no longer required
  • It typically takes just 5 minutes to kick off a search and get back all the relevant records for a DSAR

Related Case Studies.

Contact us

Let's talk!

* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that IoT ONE may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from IoT ONE.
Submit

Thank you for your message!
We will contact you soon.