CyberNerd Posted October 16, 2015 Posted October 16, 2015 If the choice of hitting the DEL key was mine I would probably hit it. Though I have this nagging feeling they might stop my pay if i do! Go for the model contract clause then, it is a reasonable thing to do. To be honest the risk is entirely theoretical . I've come to the conclusion that US government already own my data, even if it was on a server I do control. It would be interesting to see ICO prosecute a school because of this! 1
PotNoodleTech Posted October 16, 2015 Posted October 16, 2015 What kind of data are you putting on google anyway? You shouldn't be putting extremely sensitive (ethnicity, SEN, FSM, etc) data on google as you don't usually need that kind of data stored in the cloud for teaching and learning uses?
CyberNerd Posted October 16, 2015 Posted October 16, 2015 What kind of data are you putting on google anyway? You shouldn't be putting extremely sensitive (ethnicity, SEN, FSM, etc) data on google as you don't usually need that kind of data stored in the cloud for teaching and learning uses? Google is used as an Office system and it's used for admin too. Even our admissions are processed through it.
CAM Posted October 16, 2015 Posted October 16, 2015 Many MIS systems are also going cloud-based (Capita being one of the few providers who currently don't offer such a solution, notable as the largest MIS provider!). Handy for a MAT or other multi-site institution although I do wonder what benefit a cloud MIS will offer for single-site schools. And then there are VLEs, communications systems, etc where data is exported from the MIS to an external system. I guess each of these need to have their safe harbour status checked?
pcstru Posted October 16, 2015 Posted October 16, 2015 What kind of data are you putting on google anyway? You shouldn't be putting extremely sensitive (ethnicity, SEN, FSM, etc) data on google as you don't usually need that kind of data stored in the cloud for teaching and learning uses? The trouble is, once you deploy this stuff, how people actually use it tends to drift either from ignorance or because they know better (I've flagged DP issues with members of SLT, but I still find them using Google docs/drive for sometimes sensitive personal data).
Marshall_IT Posted October 16, 2015 Posted October 16, 2015 Capita do offer a cloud hosted version of SIMS.net and SLG.
CyberNerd Posted October 16, 2015 Posted October 16, 2015 Capita Hosted? Is that cloud? I think we can safely say it would meet the definition!
CAM Posted October 16, 2015 Posted October 16, 2015 Hmmm I thought they were moving into the cloud with SIMS 8, unless that's a dedicated cloud client coming later. My SIMS install is locally hosted.
crispybits Posted October 16, 2015 Posted October 16, 2015 Can anyone advise if this ruling has any impact on the telemetry collection being ramped up with every new update in Windows? Obviously scrapping Windows would be a massive step, but if they are keylogging in the wrong places and sending the wrong data back to Microsoft in the US doesn't this also make Windows 10 de facto illegal in the EU?
Garacesh Posted October 20, 2015 Posted October 20, 2015 Irish court hears Facebook data privacy challenge - BBC News The case that started it all is back in court.
foofighterjim Posted October 22, 2015 Posted October 22, 2015 More news from the US: Apple, Google and Twitter among 22 tech companies opposing Cisa bill | Technology | The Guardian Looks like they are trying to go even further down the rabbit hole!
Garacesh Posted April 13, 2016 Posted April 13, 2016 EU watchdogs demand revisions to Safe Harbour replacement - BBC News Safe Harbour replacement 'Privacy Shield' has been rejected by EU watchdogs. I have no idea if that's an official rejection on behalf of the EU or not, but at least the concerns are still being addressed.
enjay Posted April 14, 2016 Posted April 14, 2016 So, it would appear I agreed to the Data Processing Amendment back in October but not the Model Contract Clauses. Deleting our GAFE account isn't an option and we do hold sensitive data in Drive - should I also accept the MCCs in that case?
sparkeh Posted May 31, 2016 Posted May 31, 2016 So, Privacy Shield has been roundly critcised by the EDPS: Data watchdog rejects EU-US Privacy Shield pact - BBC News Still not in a good position then.
ZeroHour Posted June 1, 2016 Posted June 1, 2016 So, Privacy Shield has been roundly critcised by the EDPS: Data watchdog rejects EU-US Privacy Shield pact - BBC News Still not in a good position then. Yeah not sure what will happen next tbh. The protections fhey want the US wont want to give.
Marshall_IT Posted June 24, 2016 Posted June 24, 2016 Just with the results of the referendum I was wondering what affect it is going to have with future discussions and rulings on this and plans that were in place! Also what affect will us leaving the EU have on us storing information in Microsoft's and google's cloud services hosted in the EU which were previously safe!
elsiegee40 Posted June 24, 2016 Posted June 24, 2016 Just with the results of the referendum I was wondering what affect it is going to have with future discussions and rulings on this and plans that were in place! Also what affect will us leaving the EU have on us storing information in Microsoft's and google's cloud services hosted in the EU which were previously safe! We are in at the moment. Nobody will know what will be affected or how until we actually leave. Decisions on this remain until an awful lot of legalities have been gone through Speculation is futile 1
enjay Posted June 24, 2016 Posted June 24, 2016 As @elsiegee40 says, speculation at this stage is pointless. It is certainly something which needs to be addressed by whoever has the job of negotiating us out the EU, but it is probably years away from hitting our desks. Also, until we actually leave the EU (rather than just have a referendum result)(which isn't constitutionally binding anyway) we are a member of the EU and therefore the model clauses remain valid.
GrumbleDook Posted June 24, 2016 Posted June 24, 2016 There is no issue at this time. The Law that applies here is the Data Protection Act, which lays down about moving data outside of the EEA. Unless that law changes then there are no stipulations about having to have data within the UK. The ICO has issued a general response about the referendum result which is available here: https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2016/06/referendum-result-response/ Mark it as a risk, perhaps ... but not a big one 2
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now