localzuk Posted July 21, 2020 Posted July 21, 2020 So, the ECJ recently (July 16th) basically ruled that the Privacy Shield agreement is invalid. This is the agreement many services schools use to justify the transfer of data out of the EU to the USA. https://www.theregister.com/2020/07/20/privacy_shield_declared_invalid_consequences/ So, my question is this - how does this impact us? Should we all stop using services in the US? Do we have to get explicit consent from parents and children to use these services in light of this?
paulkerton Posted July 21, 2020 Posted July 21, 2020 Currently, I think it means very little until something else is put in it's place, especially with us now out of the EU, and Brexit looming, I'm sure a simple legislation change would sort it. I'm sure organisations like Apple, Microsoft and Google are no doubt looking into the data regions implications, and whether they will offer those solutions and services to the UK and EU users for free, rather than keeping things like that behind paid solutions.
localzuk Posted July 21, 2020 Author Posted July 21, 2020 The issue is that US law basically makes any data transfer illegal - CLOUD Act is not compliant with GDPR, so I don't see how anything can be done without coordinated legislative change? As it stands, it does seem rather like we're all breaking the law if we use services of US companies at the moment...
paulkerton Posted July 21, 2020 Posted July 21, 2020 I'm sure @jamesleonard might be able to clarify some of this from the Google for Education side of things.
Steve21 Posted July 21, 2020 Posted July 21, 2020 Out of curiosity what services are you currently using that store the data in the US? Surely based on the wording of the article (or at least how I read it), if you're using their EU data centres you're still covered? (Both o365/GSuite allowing you to pick those etc) Or is it more specific smaller websites you're referring to? Steve
localzuk Posted July 21, 2020 Author Posted July 21, 2020 Out of curiosity what services are you currently using that store the data in the US? Surely based on the wording of the article (or at least how I read it), if you're using their EU data centres you're still covered? (Both o365/GSuite allowing you to pick those etc) Or is it more specific smaller websites you're referring to? Steve You wouldn't be covered, I don't think, no. The issue is that US law via their CLOUD Act allows them to slurp data from non-US data centres, even if they're owned by a non-US subsidiary, with no recourse to appeal or privacy from the people whose data it is. Basically, as non-US citizens you have zero recourse against the US govt about any of it - which is against GDPR. Which is why SCCs with US entities also seem to be useless - sure, they are civil mechanisms that would be legal, but the US law behind it all means that as soon as the govt over there says something the SCC is useless. We have a few US based companies we use. Eg. WeVideo, Plickers, Join It, Class Dojo, to name a few. 2
Ditto Posted July 21, 2020 Posted July 21, 2020 You wouldn't be covered, I don't think, no. The issue is that US law via their CLOUD Act allows them to slurp data from non-US data centres, even if they're owned by a non-US subsidiary, with no recourse to appeal or privacy from the people whose data it is. Basically, as non-US citizens you have zero recourse against the US govt about any of it - which is against GDPR. Which is why SCCs with US entities also seem to be useless - sure, they are civil mechanisms that would be legal, but the US law behind it all means that as soon as the govt over there says something the SCC is useless. We have a few US based companies we use. Eg. WeVideo, Plickers, Join It, Class Dojo, to name a few. I agree, pretty much not covered. Also, I note 'theregister' article when it states in relation to UK GDPR that it "may quickly begin to diverge from standards established by the GDPR". Or another way, we could have our rights eroded at the expense of EU relations. All in all, it's a bit of a mess!
GrumbleDook Posted July 22, 2020 Posted July 22, 2020 (edited) Right now? We do not have a clear picture about it means for the UK. We need our Supervisory Authority (ICO) to provide more guidance on this. There are so many things to consider on this, not the least about what arrangement will be in place in the future between UK and US, and between UK and EU. Right now, the most you can all do is be mindful of where data is processed by US firms in the US, where data is processed by US firms with bases/DataCentres in the U.K./EU but are subject to inter-territorial law from the US, and where EU/UK processors are using US sub-processors. That is going to be an unbelievably long list so you have to just be mindful and wait. Edited July 22, 2020 by GrumbleDook 2
localzuk Posted July 22, 2020 Author Posted July 22, 2020 That is going to be an unbelievably long list so you have to just be mindful and wait. The problem is that from a risk perspective? We're rather wide open right now. Even if the ICO doesn't go stomping around telling people to stop using US companies etc... What happens when a litigious parent realises their child's data is being sent to the US without implicit consent, and takes us to court over it? This ruling seems to sit firmly on their side. So even if the UK courts erred on the side of caution, the litigant could well take it to a higher court where this ruling would be brought up. Obviously this would go into a DPIA as a risk, but the severity of the risk is quite high, even if it is unlikely (though, certain schools have seen some parents willing to go all out in their legal battles before).
enjay Posted July 22, 2020 Posted July 22, 2020 Surely based on the wording of the article (or at least how I read it), if you're using their EU data centres you're still covered? (Both o365/GSuite allowing you to pick those etc) How do you do that? I wasn't aware you even could with Google. I'd definitely like to get our MS and Google into EU data centres. - - - Updated - - - We have a few US based companies we use. Eg. WeVideo, Plickers, Join It, Class Dojo, to name a few. Ah bother, I've just last week bought a WeVideo subscription!
Steve21 Posted July 22, 2020 Posted July 22, 2020 How do you do that? I wasn't aware you even could with Google. I'd definitely like to get our MS and Google into EU data centres. Err for GSuite pretty sure it was in the account settings/company profile then data region? Normally it'd be done when setup so you might have it done already, think Google it's only US or EU, with 365 you can pick an area like London etc Steve
enjay Posted July 22, 2020 Posted July 22, 2020 Err for GSuite pretty sure it was in the account settings/company profile then data region? Normally it'd be done when setup so you might have it done already, think Google it's only US or EU, with 365 you can pick an area like London etc Steve I found https://support.google.com/a/answer/7630496?hl=en but it says I have to upgrade to Enterprise for Education to use that feature. Our Office365 data is already in EU, I've just checked that.
enjay Posted July 22, 2020 Posted July 22, 2020 Okay, so what's the actual impact of this on us? The ECJ ruling means the CIA and others can access data in our Google Apps, Office365, WeVideo, etc. accounts. I don't see anything saying we need consent to continue storing the data there, just that the school's DPIA must take this increased risk of access into account. Am I missing something, or could we just say "it's okay by us if US Govt agencies could access the data"?
localzuk Posted July 22, 2020 Author Posted July 22, 2020 (edited) Okay, so what's the actual impact of this on us? The ECJ ruling means the CIA and others can access data in our Google Apps, Office365, WeVideo, etc. accounts. I don't see anything saying we need consent to continue storing the data there, just that the school's DPIA must take this increased risk of access into account. Am I missing something, or could we just say "it's okay by us if US Govt agencies could access the data"? The issue is that we don't have any legal power to make that decision - we can decide to use services for our legally required purposes, but we can't decide "we're fine shipping that data out of the country, to be slurped up by their intelligence services, without the individual's permission or any recourse". The law states we're not allowed to ship data out of the country without certain protections. The USA doesn't provide those protections. Therefore, we would have to have consent to be able to send that data out of country and bypass the law preventing us doing it using any other justification. The only people who have the right to decide that are the people whose data it is - the staff and children (and their parents for below age children). Edited July 22, 2020 by localzuk
enjay Posted July 22, 2020 Posted July 22, 2020 The law states we're not allowed to ship data out of the country without certain protections. Does it? I thought the law said we had to assess the impact of storing and processing data, risk to individuals of that data being lost or compromised, etc. Are we not able to assess the risk as acceptable, especially as there is no appropriate alternative, and allow the data to be shipped out to the US?
paulkerton Posted July 22, 2020 Posted July 22, 2020 I don't think it has the implications you think it does yet, especially with Brexit coming along, the UK has to put something in place for itself anyway for between the EU and the UK and the UK and the US. The ICO will advise as it moves forward. https://ico.org.uk/make-a-complaint/eu-us-privacy-shield/
localzuk Posted July 22, 2020 Author Posted July 22, 2020 Does it? I thought the law said we had to assess the impact of storing and processing data, risk to individuals of that data being lost or compromised, etc. Are we not able to assess the risk as acceptable, especially as there is no appropriate alternative, and allow the data to be shipped out to the US? There are specific restrictions on shipping data out of the EU - https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/international-transfers/ 1
localzuk Posted July 22, 2020 Author Posted July 22, 2020 I don't think it has the implications you think it does yet, especially with Brexit coming along, the UK has to put something in place for itself anyway for between the EU and the UK and the UK and the US. The ICO will advise as it moves forward. https://ico.org.uk/make-a-complaint/eu-us-privacy-shield/ And yeah, that page says not to start new uses of Privacy Shield. 1
GrumbleDook Posted July 23, 2020 Posted July 23, 2020 We also need to recognise that there is a problem with consistency of how Supervisory Authorities (ICO, CNIL, etc.) are responding to this from the very strict in some areas of Germany through to ‘keep calm and carry on’ from ICO. In our case, it is made difficult due to trade discussions between UK-EU and UK-US. It is also worth saying that many of your suppliers will also be doing a lot more digging and seeing where to make changes (or if they even should)... so asking suppliers right now about any position they have taken will probably get back a response of “we are seeking further clarifications” ... and so waiting for guidance from ICO and comment from DfE is the most schools can do right now. If there are parental complaints, then a note to show you are atLeast looking at it and have internally acknowledged the ICO advice, and then noted it in your risk register, is the best you can probably do right now.
dmj Posted July 23, 2020 Posted July 23, 2020 ] ... and so waiting for guidance from ICO and comment from DfE is the most schools can do right now. ie it's a free for all until we are told otherwise.
enjay Posted July 23, 2020 Posted July 23, 2020 And yeah, that page says not to start new uses of Privacy Shield. I checked. We bought WeVideo on 13th July :-)
Ditto Posted July 23, 2020 Posted July 23, 2020 What advice would be appropriate for how to manage this topic as a school governor? For now, I've highlighted this to the topic to our chair and suggested it is taken forward to the MAT trust body. I've recommended they ask the DPO (outsourced) for guidance. For now, I've suggested we need reassurance that the school is aware and will not use Privacy Shield going forward and then to monitor ICO advice. Perhaps we should review our policies and check our Data Mapping documentation is up to date and notes the location of the companies we exchange data with. Anything more suggested?
Ditto Posted August 28, 2020 Posted August 28, 2020 Brief update. I received an email from Coursera (U.S. company) which says, to deal with the invalidation of Privacy Shield that they have "... add the relevant Standard Contractual Clauses (SCCs) as a transfer mechanism for personal data being transferred out of the European Economic Area, Switzerland, and the United Kingdom to the United States.". This is their updated notice. Whether this approach is an appropriate way to remain GDPR complaint I'm not sure, but has anyone heard from providers on this topic where their data is held in the US?
paulkerton Posted September 1, 2020 Posted September 1, 2020 Google have added their own Standard Contractual Clauses to G Suite also. 1
Ditto Posted September 1, 2020 Posted September 1, 2020 Google have added their own Standard Contractual Clauses to G Suite also. I thought they might, but hadn't checked. I wonder if this will become the de-facto way US companies overcome this challenge. What's interesting, from a school/consumer perspective, it appears we have to wait for the Data Processor to make the move. As the Data Controller, perhaps we should ask any companies that haven't implemented a solution to go down the same route. This is of course assuming it's a legitimate means to achieve compliance...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now