Zoom7000 Posted May 11, 2015 Posted May 11, 2015 Just got this email from Dropbox: Hi there, If you're a user living outside of North America (U.S., Canada, Mexico), we're updating our Terms of Service to better serve you and the growing number of Dropbox users around the world. These changes include the fact that we'll be providing our services (including Dropbox, Dropbox for Business, Carousel, and Mailbox) to you via Dropbox Ireland starting on June 1, 2015. Please note that none of our services or features are changing as a result of this. You can read the updated terms at https://www.dropbox.com/terms. Have questions about these changes? Visit our Help Center. Thanks for using Dropbox! The Dropbox Team I presume this means it'll tick all the data protection boxes and EU Safe Harbour rules, which can only be a good thing right?
localzuk Posted May 11, 2015 Posted May 11, 2015 Doesn't make any difference to data protection really! The data is still going to be going outside the EU, so sufficient risk assessment needs to be undertaken before using the service etc...
elsiegee40 Posted May 11, 2015 Posted May 11, 2015 Doesn't make any difference to data protection really! The data is still going to be going outside the EU, so sufficient risk assessment needs to be undertaken before using the service etc... Is Dropbox Ireland outside the EU?
Vasriel Posted May 11, 2015 Posted May 11, 2015 Looks like they are going to be moving all their income through Ireland so they can pay less Corporation tax.
localzuk Posted May 11, 2015 Posted May 11, 2015 Is Dropbox Ireland outside the EU? Not sure why the confusion. Dropbox Ireland is a company, just like Google Ireland is a company. Their servers are still all around the world, just like Google's are. The data still leaves the EU. Dropbox aren't moving all their servers to Ireland - that's why they say their services won't be changing. Dropbox runs on top of AWS last I checked, and there's no system in place to keep EU data local to the EU. 1
elsiegee40 Posted May 11, 2015 Posted May 11, 2015 Thanks. That's what I needed to know. A bit tricky on their part to make it sound like they are complying.
Arthur Posted May 11, 2015 Posted May 11, 2015 A bit tricky on their part to make it sound like they are complying. Twitter are doing something similar next week and moving all non-US accounts to Ireland. http://thenextweb.com/twitter/2015/04/18/twitter-updates-privacy-policy-for-non-us-accounts-and-moves-jurisdiction-to-ireland/
Zoom7000 Posted May 11, 2015 Author Posted May 11, 2015 Not sure why the confusion. Dropbox Ireland is a company, just like Google Ireland is a company. Their servers are still all around the world, just like Google's are. The data still leaves the EU. Dropbox aren't moving all their servers to Ireland - that's why they say their services won't be changing. Dropbox runs on top of AWS last I checked, and there's no system in place to keep EU data local to the EU. What you're saying seems to be in contradiction to what Google and Microsoft told me at BETT in that all data meets the EU Safe Harbour policies which makes it safe for schools to use it. The LGfL also confirmed this is the case. From what you're saying, technically, this would make Office 365 a problem for all schools too right?
localzuk Posted May 11, 2015 Posted May 11, 2015 What you're saying seems to be in contradiction to what Google and Microsoft told me at BETT in that all data meets the EU Safe Harbour policies which makes it safe for schools to use it. The LGfL also confirmed this is the case. From what you're saying, technically, this would make Office 365 a problem for all schools too right? Safe Harbour is a voluntary agreement saying they will comply with EU rules. Google, Dropbox and Microsoft are all signatories. However, how good is a voluntary agreement? Office 365 for schools has all data remain in the EU.
Arthur Posted May 11, 2015 Posted May 11, 2015 technically, this would make Office 365 a problem for all schools too right? No, since Microsoft have multiple datacenters in the EU where the data is stored. http://vgy.me/JGaDRQ.png
sted Posted May 11, 2015 Posted May 11, 2015 i suspect its also to do with the american govenment not being able to request data if its stored outside their borders at least ms are fighting to keep it that way last i heard
mjk Posted May 11, 2015 Posted May 11, 2015 The ICO say: [h=3]The Safe Harbor scheme is recognised by the European Commission as providing adequate protection for the rights of individuals in connection with the transfer of their personal data to signatories of the scheme in the USA.[/h]
localzuk Posted May 11, 2015 Posted May 11, 2015 The ICO say: The Safe Harbor scheme is recognised by the European Commission as providing adequate protection for the rights of individuals in connection with the transfer of their personal data to signatories of the scheme in the USA. Each time data leaves the UK/EU, a business should have ensured that it is safe and complies with the rules. This means running risk assessments. Not every organisation will get the outcome from a risk assessment that approves of data leaving the EU - regardless of what the ICO says. No organisation should just look at the ICO site and give carte blanche to all export of data to the USA under Safe Harbor. If your organisation is happy with the protections offered by Safe Harbor, then that is your prerogative. The EU kicked off an analysis of Data Protection/whether the Safe Harbor scheme was actually any use a year or so ago (can't find the articles now, weirdly!!). Until that investigation concludes, my view is one of erring on the side of caution.
mjk Posted May 11, 2015 Posted May 11, 2015 Each time data leaves the UK/EU, a business should have ensured that it is safe and complies with the rules. This means running risk assessments. Not every organisation will get the outcome from a risk assessment that approves of data leaving the EU - regardless of what the ICO says. No organisation should just look at the ICO site and give carte blanche to all export of data to the USA under Safe Harbor. If your organisation is happy with the protections offered by Safe Harbor, then that is your prerogative. The EU kicked off an analysis of Data Protection/whether the Safe Harbor scheme was actually any use a year or so ago (can't find the articles now, weirdly!!). Until that investigation concludes, my view is one of erring on the side of caution. You won't get fined by the information commissions office if you 'are following their rules "carte blanche". Do you also risk assess against your own servers, with third party penetration tests etc as part of your risk assessment? Not many do.
localzuk Posted May 11, 2015 Posted May 11, 2015 You won't get fined by the information commissions office if you 'are following their rules "carte blanche". Do you also risk assess against your own servers, with third party penetration tests etc as part of your risk assessment? Not many do. See, you misunderstand what the ICO do. They don't make "rules". They give advice and guidance. The law makes the rules. Of course I risk assess my own servers! I risk assess how vulnerable the data is, I risk assess how important data is etc... If you're not, then how can you be ensuring the safety and integrity of your data? Third party penetration tests are a tool, not a risk assessment. Your risk assessment may include such testing, but it will depend on what data is where and the needs of keeping it safe!
mjk Posted May 11, 2015 Posted May 11, 2015 Sounds like rubbish to me. If an independent authority (ICO) says safeharbour provides adequate protection then I'll take their word for it over @localzuk. or is there some other sort of agenda going on here with the reference to Office365 which is "ok" but dropbox which is (apparently) not on this forum....?
localzuk Posted May 11, 2015 Posted May 11, 2015 I am not saying the ICO are wrong. I am saying that Data Protection is far more than just following what the ICO say blindly. The law is clear that responsibility lies with us, as the people processing and holding data. You should be performing risk assessments when looking at exporting data to foreign countries, ICO or Safe Harbor or not! Every organisation will draw their line in a different place. We've drawn ours saying we're not happy with our data leaving the EU, ICO or not. It is the line that a number of councils have drawn.
localzuk Posted May 13, 2015 Posted May 13, 2015 This article is interesting, and ties into this discussion nicely - Angry Austrian could turn Europe against the US - thanks to data • The Register We could see the end of the SafeHarbor agreement if the ECJ decides this guy is right.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now