Jump to content

Recommended Posts

Posted

I have just been asked to install some software at a primary school so the teachers can upload assessment info along with photos for all the students. I know that Google and Microsoft etc have had to sign up or meet certain European requirements needed to hold data for schools. looking on the website for this software all the data is held on a server in Canada and is aimed at Canadian / American schools. the only blurb I can find about data requirements is that they are FOIPPA compliant.

 

Anyone know if being FOIPPA compliant meets the European / UK data requirements?

Posted

As far as I remember (and I will check again) there is still no equivalent to the US Safe Harbor Agreement between EU and Canada.

The equivalent of the ICO in Canada and our ICO have worked together on a number of projects and there is clear connection between relevant laws, but that doesn't mean companies would follow it.

 

You would have to do your own assessment of the company and the relevant local laws (which you should still do for Safe Harbor, to be honest).

 

The other people to have a conversation on this is the ICO Helpline

https://ico.org.uk/global/contact-us/

They are an extremely helpful bunch and will point you in the right direction.

 

Sorry I can't give a more specific response at the moment. If I find anything else I will update the thread.

Posted

After trawling the ICO website I have found the following info,

 

[h=2]Which countries have an adequate level of protection?[/h]The European Commission has decided that certain countries have an adequate level of protection for personal data. Currently, the following countries are considered as having adequate protection.

[TABLE=class: dp, width: 631]

[TR]

[TD=align: left]Andorra

Argentina

Canada

Faroe Islands

[/TD]

[TD=align: left]Guernsey

Isle of Man

Israel

Jersey

[/TD]

[TD=align: left]New Zealand

Switzerland

Uruguay

[/TD]

[/TR]

[/TABLE]

 

Although the United States of America (US) is not included in the European Commission list, the Commission considers that personal data sent to the US under the voluntary “Safe Harbor” scheme is adequately protected. When a US company signs up to the Safe Harbor arrangement, it agrees to:

 

But the ICO also say that the company must meet other requirements such as, the service is only available overseas and a similar service is not available in the EU.

 

https://ico.org.uk/for-organisations/guide-to-data-protection/principle-8-international/#adequate

 

https://ico.org.uk/for-organisations/guide-to-data-protection/principle-8-international/

 

I will continue looking

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...