Jump to content

Recommended Posts

Posted

Just got this email from Dropbox:

 

Hi there,

 

If you're a user living outside of North America (U.S., Canada, Mexico), we're updating our Terms of Service to better serve you and the growing number of Dropbox users around the world. These changes include the fact that we'll be providing our services (including Dropbox, Dropbox for Business, Carousel, and Mailbox) to you via Dropbox Ireland starting on June 1, 2015. Please note that none of our services or features are changing as a result of this. You can read the updated terms at https://www.dropbox.com/terms.

 

Have questions about these changes? Visit our Help Center.

 

Thanks for using Dropbox!

The Dropbox Team

I presume this means it'll tick all the data protection boxes and EU Safe Harbour rules, which can only be a good thing right? :)

Posted
Doesn't make any difference to data protection really! The data is still going to be going outside the EU, so sufficient risk assessment needs to be undertaken before using the service etc...
Posted
Doesn't make any difference to data protection really! The data is still going to be going outside the EU, so sufficient risk assessment needs to be undertaken before using the service etc...

 

Is Dropbox Ireland outside the EU? :confused:

Posted
Is Dropbox Ireland outside the EU? :confused:

 

Not sure why the confusion. Dropbox Ireland is a company, just like Google Ireland is a company. Their servers are still all around the world, just like Google's are. The data still leaves the EU. Dropbox aren't moving all their servers to Ireland - that's why they say their services won't be changing.

 

Dropbox runs on top of AWS last I checked, and there's no system in place to keep EU data local to the EU.

  • Thanks 1
Posted
Not sure why the confusion. Dropbox Ireland is a company, just like Google Ireland is a company. Their servers are still all around the world, just like Google's are. The data still leaves the EU. Dropbox aren't moving all their servers to Ireland - that's why they say their services won't be changing.

 

Dropbox runs on top of AWS last I checked, and there's no system in place to keep EU data local to the EU.

 

What you're saying seems to be in contradiction to what Google and Microsoft told me at BETT in that all data meets the EU Safe Harbour policies which makes it safe for schools to use it. The LGfL also confirmed this is the case.

 

From what you're saying, technically, this would make Office 365 a problem for all schools too right?

Posted
What you're saying seems to be in contradiction to what Google and Microsoft told me at BETT in that all data meets the EU Safe Harbour policies which makes it safe for schools to use it. The LGfL also confirmed this is the case.

 

From what you're saying, technically, this would make Office 365 a problem for all schools too right?

 

Safe Harbour is a voluntary agreement saying they will comply with EU rules. Google, Dropbox and Microsoft are all signatories. However, how good is a voluntary agreement?

 

Office 365 for schools has all data remain in the EU.

Posted
i suspect its also to do with the american govenment not being able to request data if its stored outside their borders at least ms are fighting to keep it that way last i heard
Posted

The ICO say:

 

[h=3]The Safe Harbor scheme is recognised by the European Commission as providing adequate protection for the rights of individuals in connection with the transfer of their personal data to signatories of the scheme in the USA.[/h]

Posted
The ICO say:

 

The Safe Harbor scheme is recognised by the European Commission as providing adequate protection for the rights of individuals in connection with the transfer of their personal data to signatories of the scheme in the USA.

 

 

 

Each time data leaves the UK/EU, a business should have ensured that it is safe and complies with the rules. This means running risk assessments. Not every organisation will get the outcome from a risk assessment that approves of data leaving the EU - regardless of what the ICO says.

 

No organisation should just look at the ICO site and give carte blanche to all export of data to the USA under Safe Harbor.

 

If your organisation is happy with the protections offered by Safe Harbor, then that is your prerogative.

 

The EU kicked off an analysis of Data Protection/whether the Safe Harbor scheme was actually any use a year or so ago (can't find the articles now, weirdly!!). Until that investigation concludes, my view is one of erring on the side of caution.

Posted
Each time data leaves the UK/EU, a business should have ensured that it is safe and complies with the rules. This means running risk assessments. Not every organisation will get the outcome from a risk assessment that approves of data leaving the EU - regardless of what the ICO says.

 

No organisation should just look at the ICO site and give carte blanche to all export of data to the USA under Safe Harbor.

 

If your organisation is happy with the protections offered by Safe Harbor, then that is your prerogative.

 

The EU kicked off an analysis of Data Protection/whether the Safe Harbor scheme was actually any use a year or so ago (can't find the articles now, weirdly!!). Until that investigation concludes, my view is one of erring on the side of caution.

 

You won't get fined by the information commissions office if you 'are following their rules "carte blanche".

Do you also risk assess against your own servers, with third party penetration tests etc as part of your risk assessment? Not many do.

Posted
You won't get fined by the information commissions office if you 'are following their rules "carte blanche".

Do you also risk assess against your own servers, with third party penetration tests etc as part of your risk assessment? Not many do.

 

See, you misunderstand what the ICO do. They don't make "rules". They give advice and guidance. The law makes the rules.

 

Of course I risk assess my own servers! I risk assess how vulnerable the data is, I risk assess how important data is etc...

 

If you're not, then how can you be ensuring the safety and integrity of your data?

 

Third party penetration tests are a tool, not a risk assessment. Your risk assessment may include such testing, but it will depend on what data is where and the needs of keeping it safe!

Posted

Sounds like rubbish to me.

If an independent authority (ICO) says safeharbour provides adequate protection then I'll take their word for it over @localzuk.

 

or is there some other sort of agenda going on here with the reference to Office365 which is "ok" but dropbox which is (apparently) not on this forum....?

Posted

I am not saying the ICO are wrong. I am saying that Data Protection is far more than just following what the ICO say blindly. The law is clear that responsibility lies with us, as the people processing and holding data.

 

You should be performing risk assessments when looking at exporting data to foreign countries, ICO or Safe Harbor or not!

 

Every organisation will draw their line in a different place. We've drawn ours saying we're not happy with our data leaving the EU, ICO or not. It is the line that a number of councils have drawn.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...