Jump to content

Recommended Posts

Posted (edited)

This has appeared on the Beeb: Schools given Dropbox guidance after Safe Harbour warning - BBC News

 

The UK's data watchdog has told schools they do not need to abandon leading internet services despite fears about the legality of continuing to use them.

The guidance follows an email sent to educators in a London borough by their IT chief, who advised them to stop using Dropbox and other cloud products.

That warning followed a ruling by Europe's top court, which declared a system used to authorise personal data transfers to the US was invalid.

Now, the advice is to hold fire.

 

In short, don't panic.

Until we tell you to.

Edited by Dos_Box
  • Thanks 1
Posted

Interesting. It seems to me the advice is very poor - about on a level with "don't worry, it's too complicated even for us so we aren't going to come after you".

 

And then we have : "There's no new and immediate threat to individuals' personal data that's suddenly arisen that we need to act quickly to prevent," the Information Commissioner's Office (ICO) told the BBC.

 

Err ... . It is not new but I don't see how it is not immediate (US agencies can compel companies based in the USA to disclose data they might hold (hold on behalf of your organisation) on individuals) and unless the ICO has abandoned the principles of the DPA, then that situation is simply not compatible with those principles.

 

Still, it is about what we have come to expect from the ICO. Utterly useless.

Posted

Err ... . It is not new but I don't see how it is not immediate (US agencies can compel companies based in the USA to disclose data they might hold (hold on behalf of your organisation) on individuals) and unless the ICO has abandoned the principles of the DPA, then that situation is simply not compatible with those principles.

 

 

 

Do you really care if the US authorities see any data though? If they don't get it themselves they will just ask GCHQ, who I am sure will oblige.

It's scary from a big brother PoV, but no less so than the rootkits in our phones already /tinfoil.

Posted
Do you really care if the US authorities see any data though? If they don't get it themselves they will just ask GCHQ, who I am sure will oblige.

It's scary from a big brother PoV, but no less so than the rootkits in our phones already /tinfoil.

 

What I care about is that we, as a data controller, comply with the law of the land to the best of our ability. In terms of access to data by UK agencies; they can come to us directly and compel us to divulge data under UK law. So if GCHQ get hold of personal data relating to our staff or customers, we are complying with the law of the land. If US agencies get hold of it, we are not.

 

I think there is an easy test of this : simply substitute North Korea for USA and see if everyone is still happy.

Posted

No I don't trust the US, or the North Koreans. I'm still not worried if the NSA knows about Timmy's Specific Learning Difficulty. The UK government (DfE) has said certain services are OK, and the ICO has said they will not prosecute us anyway.

 

I don't 'like' governmental spying, but I don't think a school has to worry about it much either - esp when we are following government guidelines.

Posted
No I don't trust the US, or the North Koreans.

I really struggle to follow this. If you do not trust a partner then why, when such trust is implicit in fair processing, are you using them as a 3rd party data processor?

I'm still not worried if the NSA knows about Timmy's Specific Learning Difficulty. The UK government (DfE) has said certain services are OK, and the ICO has said they will not prosecute us anyway.

The risk might come from the data subject making a claim in a case where they are damaged by foreign agencies getting hold of data. Our responsibility is first and foremost to the data subject under the law, rather than to (just) protecting the reputation of the organisation.

Posted
I really struggle to follow this. If you do not trust a partner then why, when such trust is implicit in fair processing, are you using them as a 3rd party data processor?

 

The risk might come from the data subject making a claim in a case where they are damaged by foreign agencies getting hold of data. Our responsibility is first and foremost to the data subject under the law, rather than to (just) protecting the reputation of the organisation.

 

 

If any government agency wants our data they will get it and there is absolutely nothing you'll be able to do about it. That is why I don't worry.

Posted
If any government agency wants our data they will get it and there is absolutely nothing you'll be able to do about it. That is why I don't worry.

So if you can't stop someone from getting your data, you should not 'worry' about your responsibilities to data subjects?

 

I think that is actually a pretty common attitude - bizzare and wrong IMO, but common. Talk Talk might just argue that zero day exploits mean that anyone who really wants access to their customers data will get it, so why should they worry?

Posted
So if you can't stop someone from getting your data, you should not 'worry' about your responsibilities to data subjects?

Just follow the advice from the government and ICO and you'll be fine.

 

I think that is actually a pretty common attitude - bizzare and wrong IMO, but common. Talk Talk might just argue that zero day exploits mean that anyone who really wants access to their customers data will get it, so why should they worry?

 

One is comparing a multinational company that gives a contract and model clauses being forced to give information (or being infiltrated) by a government agency, the other is an SQL injection organised by children.

Posted
Just follow the advice from the government and ICO and you'll be fine.

That seems rather bizarre advice in the circumstances. You do realise that this subject has arisen because a European court judgement has ruled that following government 'advice' offers inadequate protection for data subjects?

 

One is comparing a multinational company that gives a contract and model clauses being forced to give information (or being infiltrated) by a government agency, the other is an SQL injection organised by children.

Your rationale was that you can do nothing about it : "If any government agency wants our data they will get it and there is absolutely nothing you'll be able to do about it. That is why I don't worry."

 

The fact is you can minimise the opportunities, the "attack surface". You cannot make it impossible, but you can act to make it equally difficult for all who would process data relating to your data subjects unlawfully. You can certainly avoid using companies that you know are unable to protect personal data processed by your organisation and as far as the law goes, you would seem obliged to do that. The ICO might issue advice (some of which is poor), they do not write or re-write the law.

Posted

Translation - There are lots of legal and politic things that need to be worked through so whilst we do that don't stress. If you do have to change we will advise you.

 

However, the advice from the IT folk at that LA in London is not as daft as it seems. Whilst it is not a case that you should panic, it is a case that you should twice about starting to use services that you have not used before if they were previously covered by Safe Harbor. It looks like the ICO has only said don't make changes ... nothing about there being no risk if you deciding whether to start using such services.

Posted

I think @GrumbleDook has very sensible advice.

 

We use GAFE with the model clauses, it isn't entirely clear how the modal clauses are affected. There's no point in running around like Corporal Jones while the official advice is to still tight and wait for the repercussions of the ruling to be worked out (and any revised Safe Harbour that might be hammered out).

 

However we won't be signing up for anything new until we have further guidance.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...