Jump to content

Recommended Posts

Posted

So, the ECJ recently (July 16th) basically ruled that the Privacy Shield agreement is invalid. This is the agreement many services schools use to justify the transfer of data out of the EU to the USA. https://www.theregister.com/2020/07/20/privacy_shield_declared_invalid_consequences/

 

So, my question is this - how does this impact us?

 

Should we all stop using services in the US? Do we have to get explicit consent from parents and children to use these services in light of this?

Posted
Currently, I think it means very little until something else is put in it's place, especially with us now out of the EU, and Brexit looming, I'm sure a simple legislation change would sort it. I'm sure organisations like Apple, Microsoft and Google are no doubt looking into the data regions implications, and whether they will offer those solutions and services to the UK and EU users for free, rather than keeping things like that behind paid solutions.
Posted
The issue is that US law basically makes any data transfer illegal - CLOUD Act is not compliant with GDPR, so I don't see how anything can be done without coordinated legislative change? As it stands, it does seem rather like we're all breaking the law if we use services of US companies at the moment...
Posted

Out of curiosity what services are you currently using that store the data in the US?

 

Surely based on the wording of the article (or at least how I read it), if you're using their EU data centres you're still covered? (Both o365/GSuite allowing you to pick those etc)

 

Or is it more specific smaller websites you're referring to?

 

Steve

Posted
Out of curiosity what services are you currently using that store the data in the US?

 

Surely based on the wording of the article (or at least how I read it), if you're using their EU data centres you're still covered? (Both o365/GSuite allowing you to pick those etc)

 

Or is it more specific smaller websites you're referring to?

 

Steve

 

You wouldn't be covered, I don't think, no. The issue is that US law via their CLOUD Act allows them to slurp data from non-US data centres, even if they're owned by a non-US subsidiary, with no recourse to appeal or privacy from the people whose data it is. Basically, as non-US citizens you have zero recourse against the US govt about any of it - which is against GDPR. Which is why SCCs with US entities also seem to be useless - sure, they are civil mechanisms that would be legal, but the US law behind it all means that as soon as the govt over there says something the SCC is useless.

 

We have a few US based companies we use. Eg. WeVideo, Plickers, Join It, Class Dojo, to name a few.

  • Thanks 2
Posted
You wouldn't be covered, I don't think, no. The issue is that US law via their CLOUD Act allows them to slurp data from non-US data centres, even if they're owned by a non-US subsidiary, with no recourse to appeal or privacy from the people whose data it is. Basically, as non-US citizens you have zero recourse against the US govt about any of it - which is against GDPR. Which is why SCCs with US entities also seem to be useless - sure, they are civil mechanisms that would be legal, but the US law behind it all means that as soon as the govt over there says something the SCC is useless.

 

We have a few US based companies we use. Eg. WeVideo, Plickers, Join It, Class Dojo, to name a few.

 

I agree, pretty much not covered. Also, I note 'theregister' article when it states in relation to UK GDPR that it "may quickly begin to diverge from standards established by the GDPR". Or another way, we could have our rights eroded at the expense of EU relations. All in all, it's a bit of a mess!

Posted (edited)

Right now? We do not have a clear picture about it means for the UK. We need our Supervisory Authority (ICO) to provide more guidance on this.

 

There are so many things to consider on this, not the least about what arrangement will be in place in the future between UK and US, and between UK and EU.

 

Right now, the most you can all do is be mindful of where data is processed by US firms in the US, where data is processed by US firms with bases/DataCentres in the U.K./EU but are subject to inter-territorial law from the US, and where EU/UK processors are using US sub-processors.

 

That is going to be an unbelievably long list so you have to just be mindful and wait.

Edited by GrumbleDook
  • Thanks 2
Posted
That is going to be an unbelievably long list so you have to just be mindful and wait.

The problem is that from a risk perspective? We're rather wide open right now. Even if the ICO doesn't go stomping around telling people to stop using US companies etc... What happens when a litigious parent realises their child's data is being sent to the US without implicit consent, and takes us to court over it? This ruling seems to sit firmly on their side. So even if the UK courts erred on the side of caution, the litigant could well take it to a higher court where this ruling would be brought up.

 

Obviously this would go into a DPIA as a risk, but the severity of the risk is quite high, even if it is unlikely (though, certain schools have seen some parents willing to go all out in their legal battles before).

Posted
Surely based on the wording of the article (or at least how I read it), if you're using their EU data centres you're still covered? (Both o365/GSuite allowing you to pick those etc)

 

How do you do that? I wasn't aware you even could with Google. I'd definitely like to get our MS and Google into EU data centres.

 

- - - Updated - - -

 

We have a few US based companies we use. Eg. WeVideo, Plickers, Join It, Class Dojo, to name a few.

 

Ah bother, I've just last week bought a WeVideo subscription!

Posted
How do you do that? I wasn't aware you even could with Google. I'd definitely like to get our MS and Google into EU data centres.

 

 

Err for GSuite pretty sure it was in the account settings/company profile then data region? Normally it'd be done when setup so you might have it done already, think Google it's only US or EU, with 365 you can pick an area like London etc

 

Steve

Posted
Err for GSuite pretty sure it was in the account settings/company profile then data region? Normally it'd be done when setup so you might have it done already, think Google it's only US or EU, with 365 you can pick an area like London etc

 

Steve

 

I found https://support.google.com/a/answer/7630496?hl=en but it says I have to upgrade to Enterprise for Education to use that feature.

 

Our Office365 data is already in EU, I've just checked that.

Posted
Okay, so what's the actual impact of this on us? The ECJ ruling means the CIA and others can access data in our Google Apps, Office365, WeVideo, etc. accounts. I don't see anything saying we need consent to continue storing the data there, just that the school's DPIA must take this increased risk of access into account. Am I missing something, or could we just say "it's okay by us if US Govt agencies could access the data"?
Posted (edited)
Okay, so what's the actual impact of this on us? The ECJ ruling means the CIA and others can access data in our Google Apps, Office365, WeVideo, etc. accounts. I don't see anything saying we need consent to continue storing the data there, just that the school's DPIA must take this increased risk of access into account. Am I missing something, or could we just say "it's okay by us if US Govt agencies could access the data"?

The issue is that we don't have any legal power to make that decision - we can decide to use services for our legally required purposes, but we can't decide "we're fine shipping that data out of the country, to be slurped up by their intelligence services, without the individual's permission or any recourse". The law states we're not allowed to ship data out of the country without certain protections. The USA doesn't provide those protections. Therefore, we would have to have consent to be able to send that data out of country and bypass the law preventing us doing it using any other justification.

 

The only people who have the right to decide that are the people whose data it is - the staff and children (and their parents for below age children).

Edited by localzuk
Posted
The law states we're not allowed to ship data out of the country without certain protections.

 

Does it? I thought the law said we had to assess the impact of storing and processing data, risk to individuals of that data being lost or compromised, etc. Are we not able to assess the risk as acceptable, especially as there is no appropriate alternative, and allow the data to be shipped out to the US?

Posted
Does it? I thought the law said we had to assess the impact of storing and processing data, risk to individuals of that data being lost or compromised, etc. Are we not able to assess the risk as acceptable, especially as there is no appropriate alternative, and allow the data to be shipped out to the US?

There are specific restrictions on shipping data out of the EU - https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/international-transfers/

  • Thanks 1
Posted

We also need to recognise that there is a problem with consistency of how Supervisory Authorities (ICO, CNIL, etc.) are responding to this from the very strict in some areas of Germany through to ‘keep calm and carry on’ from ICO.

 

In our case, it is made difficult due to trade discussions between UK-EU and UK-US.

 

It is also worth saying that many of your suppliers will also be doing a lot more digging and seeing where to make changes (or if they even should)... so asking suppliers right now about any position they have taken will probably get back a response of “we are seeking further clarifications” ... and so waiting for guidance from ICO and comment from DfE is the most schools can do right now.

 

If there are parental complaints, then a note to show you are atLeast looking at it and have internally acknowledged the ICO advice, and then noted it in your risk register, is the best you can probably do right now.

Posted
]

... and so waiting for guidance from ICO and comment from DfE is the most schools can do right now.

 

ie it's a free for all until we are told otherwise.

Posted
What advice would be appropriate for how to manage this topic as a school governor? For now, I've highlighted this to the topic to our chair and suggested it is taken forward to the MAT trust body. I've recommended they ask the DPO (outsourced) for guidance. For now, I've suggested we need reassurance that the school is aware and will not use Privacy Shield going forward and then to monitor ICO advice. Perhaps we should review our policies and check our Data Mapping documentation is up to date and notes the location of the companies we exchange data with. Anything more suggested?
  • 1 month later...
Posted

Brief update. I received an email from Coursera (U.S. company) which says, to deal with the invalidation of Privacy Shield that they have "... add the relevant Standard Contractual Clauses (SCCs) as a transfer mechanism for personal data being transferred out of the European Economic Area, Switzerland, and the United Kingdom to the United States.".

 

This is their updated notice. Whether this approach is an appropriate way to remain GDPR complaint I'm not sure, but has anyone heard from providers on this topic where their data is held in the US?

Posted
Google have added their own Standard Contractual Clauses to G Suite also.

I thought they might, but hadn't checked. I wonder if this will become the de-facto way US companies overcome this challenge. What's interesting, from a school/consumer perspective, it appears we have to wait for the Data Processor to make the move. As the Data Controller, perhaps we should ask any companies that haven't implemented a solution to go down the same route. This is of course assuming it's a legitimate means to achieve compliance...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...