Article 38 – Electronic Mail
47110.1 Policy
-
The California Department of Corrections and Rehabilitation (CDCRCalifornia Department of Corrections and Rehabilitation or the department) manages an electronic-mail (e-mail) system to facilitate business communications and assist employees in performing their daily work activities. This policy outlines the approved use of CDCRCalifornia Department of Corrections and Rehabilitation e-mail and does not supersede State or federal laws or any other agency policies regarding confidentiality, information dissemination, or standards of conduct.
-
The State reserves the right to monitor and/or keep a record of all e-mail communications without prior notice.
-
Employees should have no expectation of privacy in the use of CDCRCalifornia Department of Corrections and Rehabilitation e-mail systems or in anything they store, send or receive on CDCRCalifornia Department of Corrections and Rehabilitation’s e-mail system.
-
The contents of e-mails properly obtained for discovery or management purposes may be disclosed without the permission of the user who created the message.
-
E-mail shall be retained as a business record and may be used as evidence in litigation, audits, or investigations.
-
E-mail may be subject to various types of access requests, including, but not limited to, records requests under California Public Records Act (Government Code (GCGovernment Code), sections 7920.000-7931.000), or the Information Practices Act of 1977, Civil Code (CIV), section 1798, et seq.
-
-
High Risk Confidential Information (HRCI) shall not be transmitted using e-mail without the application of department approved encryption. Any exclusions from or modification of this requirement must be approved in writing prior to implementation by the Information Owner and/or the Office of the Information Security Officer (OISO).
47110.2 Purpose
-
The purpose of this policy is to ensure all CDCRCalifornia Department of Corrections and Rehabilitation e-mail communications are being created, maintained, and retained consistent with the department policy, and State and federal laws. This policy details standards relating to the use of e-mail on the department’s network and is intended to:
-
Protect CDCRCalifornia Department of Corrections and Rehabilitation information.
-
Describe confidential and sensitive considerations when using CDCRCalifornia Department of Corrections and Rehabilitation’s e-mail system.
-
Outline the acceptable usage rules when utilizing CDCRCalifornia Department of Corrections and Rehabilitation’s e-mail system.
-
Maintain availability of CDCRCalifornia Department of Corrections and Rehabilitation’s e-mail system to sustain critical business operations.
-
-
Proper e-mail usage and security is a team effort involving the participation and support of all CDCRCalifornia Department of Corrections and Rehabilitation employees.
-
This document is not all-inclusive, and the OISO has the authority and discretion to address any unacceptable behavior or practice not specifically mentioned herein.
47110.3 Scope
-
This policy covers appropriate use and retention of CDCRCalifornia Department of Corrections and Rehabilitation provided e-mail and applies to all employees, vendors, volunteers, and agents operating on behalf of the department.
47110.4 Access to E‑mail
-
All access to e-mail shall be protected by password, and all policies pertaining to the use and protection of passwords shall apply. No generic or group access to an identity shall be used. Users shall only access a resource mailbox by using their own identity. Sharing a password for any reason is prohibited.
47110.5 Acceptable Use
-
The e-mail system is provided for official CDCRCalifornia Department of Corrections and Rehabilitation business. Using e-mail in an inappropriate manner may result in the loss of e-mail privileges, disciplinary action, or both. Examples of appropriate use of the department’s e-mail system include, but are not limited to, the following:
-
Scheduling, coordinating, documenting business meetings or assignments, and notifying employees of CDCRCalifornia Department of Corrections and Rehabilitation sanctioned events.
-
Notifying CDCRCalifornia Department of Corrections and Rehabilitation personnel of changes in work policies or work procedures after the appropriate approval process is completed.
-
Transmitting or sharing non-HRCI work related material, including documents, files, reference material, and links to websites.
-
Sending and receiving business related e-mail.
-
Scheduling personal appointments and lunch breaks on an electronic calendar.
-
The occasional use of email to create or send notes or messages of a predominantly personal nature, or for personal use. Such use, shall be kept to a minimum.
-
47110.6 Unacceptable Use
-
Examples of unacceptable use of the department’s e-mail system include, but are not limited to, the following:
-
Using the system to discuss, distribute, or share HRCI without CDCRCalifornia Department of Corrections and Rehabilitation approved encryption controls.
-
Reviewing, receiving, or intercepting the electronic communications of another employee without express, advance authorization by the employee or their management.
-
Logging on with a user’s credentials, other than your own.
-
Copying or routing notes, messages, documents, or memoranda to individuals who are not involved in the relevant work project or who otherwise have no business-related interest in the subject matter of the note, message, document, or file.
-
Except as otherwise provided in this policy, reading the e-mail of another user without their knowledge and consent.
-
Sending messages related to or about bets, pools, or other forms of gambling.
-
Using e-mail for any unlawful or illegal endeavor.
-
Soliciting or advertising for non-CDCRCalifornia Department of Corrections and Rehabilitation activities, including fundraising or items of a political nature.
-
Allowing access to or sending messages on behalf of incarcerated persons or supervised persons.
-
Distributing jokes, poems, chain-letters, or other non-business related material.
-
E-mail containing religious, humorous, political messages, hoaxes, or threats are forbidden and shall not be distributed. Receipt of such e-mail should be reported to management.
-
E-mail shall be free of offensive or unlawful material, including slanderous, discriminatory, sexual, pornographic, or profane content. This prohibition applies to e-mail attachments and to the content of websites referenced or linked from e-mail. Displaying, printing, disseminating, or possession of such material may result in disciplinary action.
-
Distributing copyright-protected material such as photographs, graphics, music, documents, etc., without the expressed consent of the copyright.
-
-
Regardless of the origin, forwarding inappropriate e-mails is forbidden. Restrictions on the use of e-mail wallpaper and stationary will be left to the discretion of each Hiring Authority.
47110.7 Confidential and Sensitive Information
-
Certain types of information maintained by CDCRCalifornia Department of Corrections and Rehabilitation are confidential and protected by State and federal law. The use of e-mail to send confidential information should be limited to an as-needed basis. Never send a user identity, password, or encrypted data and the decryption key in the same e-mail.
-
The following is a list of the types of information defined as HRCI that shall not be included in e-mail or attached to an e-mail, unless the e-mail and/or attachments are encrypted:
-
Personally identifiable information such as a person’s name in conjunction with the person’s social security number, credit or debit card information, individual financial account, driver’s license number, State IDInstitutions Division (see DAI) number, or passport number, or a name in conjunction with biometric information.
-
Personal health information such as any information about health status, provisions of health care, or payment for health care information as protected under the Health Insurance Portability and Accountability Act of 1996 (HIPAA).
-
Criminal Offender Record Information as defined in California Penal Code (PCPenal Code), sections 13100-13104.
-
Information that if disclosed would reveal vulnerabilities to, or otherwise increase the potential for an attack on, an information technology system of a public agency as specified in GCGovernment Code, section 6254.19. Examples include but are not limited to firewall and router configuration information, server names and IP addresses, and other system configuration details.
-
Any documentation of information which contains information or data within any Gang Database as defined in the Department Operations Manual (DOMDepartment Operations Manual), Chapter 5, Article 22, Gang Management, sections 52070.22-52070.24.
-
Records of investigations, intelligence information, or security procedures as specified in GCGovernment Code, section 6254(f); this includes but is not limited to information identifying confidential informants and security procedures contained in Restricted DOMDepartment Operations Manual.
-
Personnel, medical, or similar files, the disclosure of which would constitute an unwarranted invasion of personal privacy protected under GCGovernment Code, section 6254(c) or the Peace Officers Bill of Rights under GCGovernment Code, section 3300 et seq.
-
Encrypted e-mail must be used when HRCI information is sent to non-CDCRCalifornia Department of Corrections and Rehabilitation e-mail addresses.
-
-
Prior to sending any e-mail, verify the accuracy of the recipient’s e-mail address to prevent unintentionally sending it to an unauthorized individual. Once an e-mail is sent outside the department, it cannot be recalled and/or undone.
47110.8 Unsolicited E‑Mail
-
Do not open attachments or internet links accompanying unsolicited e-mail. An unsolicited e-mail, such as unwanted advertisements, promotional content, or false messages that may appear to be sent on the behalf of the department may contain malicious content such as malware or phishing campaigns. Unsolicited e-mail should always be left unopened, deleted, and immediately reported to the department Office of the Information Security Officer (OISO) by clicking the mail functionality to “Report Junk” or “Report Phishing,” which notifies the ITInformation Technology security teams.
-
Three ways to identify phishing attempts:
If an email is received from an unknown or unexpected sender, do not engage with the sender or click any links in the email if the following indicators are present in the email; it is likely a phishing attempt:-
Demand: Sender requests personal information (email, password, credit card, or other sensitive information).
-
Urgency: Sender sets a fast-approaching deadline.
-
Consequence: Sender indicates something will happen if they do or do not receive the information they’re requesting.
-
47110.9 Use of Department‑Wide Distribution Lists
-
Use of department-wide distribution lists should be limited to departmental, State, ornational emergencies, and information from executive levels or program areas that affectall employees. Distribution of information not required by all employees shall be limited tothe affected work groups or physical locations.
47110.10 E‑Mail Administration
-
Enterprise Information Services (EISEnterprise Information Services (formerly Information Services Division)) shall perform all administration functionsrequired to maintain the department’s e-mail system. EISEnterprise Information Services (formerly Information Services Division) shall also maintain the e-mailhygiene system responsible for identifying e-mail that could compromise InformationTechnology (ITInformation Technology) assets.
47110.11 Local E‑Mail Usage Guidelines
-
Local operating procedures and guidelines may apply to e-mail content and handling providing they are more restrictive than this e-mail policy.
47110.12 E‑Mail Retention
-
E-mail shall be retained in accordance with the Records Management Act, GCGovernment Code, section14740, et seq. E-mail messages are official records and are subject to State, federal and CDCRCalifornia Department of Corrections and Rehabilitation rules and policies for retention and deletion. The e-mail Retention Policy defines how long information sent or received by e-mail should be retained. These policy guidelines cover only information that is either stored or shared via e-mail, including e-mail attachments. This policy establishes retention parameters to effectively capture, manage, and retain e-mail messages. All sent and received e-mail from the department’s e-mail system shall be retained for a minimum period of three years. Other legal requirements may require e-mail to be retained for a longer period.
-
All e-mail is subject to this policy.
-
This policy applies to all individuals using the CDCRCalifornia Department of Corrections and Rehabilitation e-mail system.
-
-
A litigation hold directive overrides any retention policy until the litigation hold has been cleared. When litigation is pending or future litigation is reasonably probable, CDCRCalifornia Department of Corrections and Rehabilitation shall preserve all relevant e-mail.
47110.13 Enforcement
-
Failure to comply with this policy and associated policies, standards, guidelines, and procedures may result in disciplinary action up to and including dismissal from State service for employees or termination of contracts for contractors, partners, consultants, and other entities. Legal action also may be taken for violations of applicable regulations and laws.
47110.14 Security Variance Process
-
If compliance is not feasible, or if deviation from this policy is necessary to support a business function, the respective manager shall formally request a security variance as defined by the OISO.
47110.15 Revisions
-
The Chief Information Officer (CIO) or designee shall be responsible for ensuring the contents of this Article are kept current and accurate.
References
-
(1) DOMDepartment Operations Manual, Chapter 3, Article 22, §§ 52070.22-52070.24.
-
(2) GCGovernment Code, §§ 3300 et seq., 6254.19, 6254(c), 6254(f), 7920.000-7931.000, 14740 et seq.
-
(3) Civil Code, Information Practices Act § 1798 et seq.
-
(4) California State Administrative Manual, § 5305.5.
-
(5) PCPenal Code, §§ 13100-13104.
Revision History
-
(1) Revised: July 1, 2013.
-
(2) Revised: June 9, 2026.