Dos_Box Posted October 28, 2015 Posted October 28, 2015 (edited) This has appeared on the Beeb: Schools given Dropbox guidance after Safe Harbour warning - BBC News The UK's data watchdog has told schools they do not need to abandon leading internet services despite fears about the legality of continuing to use them. The guidance follows an email sent to educators in a London borough by their IT chief, who advised them to stop using Dropbox and other cloud products. That warning followed a ruling by Europe's top court, which declared a system used to authorise personal data transfers to the US was invalid. Now, the advice is to hold fire. In short, don't panic. Until we tell you to. Edited October 28, 2015 by Dos_Box 1
pcstru Posted October 28, 2015 Posted October 28, 2015 Interesting. It seems to me the advice is very poor - about on a level with "don't worry, it's too complicated even for us so we aren't going to come after you". And then we have : "There's no new and immediate threat to individuals' personal data that's suddenly arisen that we need to act quickly to prevent," the Information Commissioner's Office (ICO) told the BBC. Err ... . It is not new but I don't see how it is not immediate (US agencies can compel companies based in the USA to disclose data they might hold (hold on behalf of your organisation) on individuals) and unless the ICO has abandoned the principles of the DPA, then that situation is simply not compatible with those principles. Still, it is about what we have come to expect from the ICO. Utterly useless.
CyberNerd Posted October 28, 2015 Posted October 28, 2015 Err ... . It is not new but I don't see how it is not immediate (US agencies can compel companies based in the USA to disclose data they might hold (hold on behalf of your organisation) on individuals) and unless the ICO has abandoned the principles of the DPA, then that situation is simply not compatible with those principles. Do you really care if the US authorities see any data though? If they don't get it themselves they will just ask GCHQ, who I am sure will oblige. It's scary from a big brother PoV, but no less so than the rootkits in our phones already /tinfoil.
pcstru Posted October 28, 2015 Posted October 28, 2015 Do you really care if the US authorities see any data though? If they don't get it themselves they will just ask GCHQ, who I am sure will oblige. It's scary from a big brother PoV, but no less so than the rootkits in our phones already /tinfoil. What I care about is that we, as a data controller, comply with the law of the land to the best of our ability. In terms of access to data by UK agencies; they can come to us directly and compel us to divulge data under UK law. So if GCHQ get hold of personal data relating to our staff or customers, we are complying with the law of the land. If US agencies get hold of it, we are not. I think there is an easy test of this : simply substitute North Korea for USA and see if everyone is still happy.
CyberNerd Posted October 28, 2015 Posted October 28, 2015 No I don't trust the US, or the North Koreans. I'm still not worried if the NSA knows about Timmy's Specific Learning Difficulty. The UK government (DfE) has said certain services are OK, and the ICO has said they will not prosecute us anyway. I don't 'like' governmental spying, but I don't think a school has to worry about it much either - esp when we are following government guidelines.
pcstru Posted October 28, 2015 Posted October 28, 2015 No I don't trust the US, or the North Koreans. I really struggle to follow this. If you do not trust a partner then why, when such trust is implicit in fair processing, are you using them as a 3rd party data processor? I'm still not worried if the NSA knows about Timmy's Specific Learning Difficulty. The UK government (DfE) has said certain services are OK, and the ICO has said they will not prosecute us anyway. The risk might come from the data subject making a claim in a case where they are damaged by foreign agencies getting hold of data. Our responsibility is first and foremost to the data subject under the law, rather than to (just) protecting the reputation of the organisation.
CyberNerd Posted October 28, 2015 Posted October 28, 2015 I really struggle to follow this. If you do not trust a partner then why, when such trust is implicit in fair processing, are you using them as a 3rd party data processor? The risk might come from the data subject making a claim in a case where they are damaged by foreign agencies getting hold of data. Our responsibility is first and foremost to the data subject under the law, rather than to (just) protecting the reputation of the organisation. If any government agency wants our data they will get it and there is absolutely nothing you'll be able to do about it. That is why I don't worry.
pcstru Posted October 28, 2015 Posted October 28, 2015 If any government agency wants our data they will get it and there is absolutely nothing you'll be able to do about it. That is why I don't worry. So if you can't stop someone from getting your data, you should not 'worry' about your responsibilities to data subjects? I think that is actually a pretty common attitude - bizzare and wrong IMO, but common. Talk Talk might just argue that zero day exploits mean that anyone who really wants access to their customers data will get it, so why should they worry?
CyberNerd Posted October 28, 2015 Posted October 28, 2015 So if you can't stop someone from getting your data, you should not 'worry' about your responsibilities to data subjects? Just follow the advice from the government and ICO and you'll be fine. I think that is actually a pretty common attitude - bizzare and wrong IMO, but common. Talk Talk might just argue that zero day exploits mean that anyone who really wants access to their customers data will get it, so why should they worry? One is comparing a multinational company that gives a contract and model clauses being forced to give information (or being infiltrated) by a government agency, the other is an SQL injection organised by children.
pcstru Posted October 28, 2015 Posted October 28, 2015 Just follow the advice from the government and ICO and you'll be fine. That seems rather bizarre advice in the circumstances. You do realise that this subject has arisen because a European court judgement has ruled that following government 'advice' offers inadequate protection for data subjects? One is comparing a multinational company that gives a contract and model clauses being forced to give information (or being infiltrated) by a government agency, the other is an SQL injection organised by children. Your rationale was that you can do nothing about it : "If any government agency wants our data they will get it and there is absolutely nothing you'll be able to do about it. That is why I don't worry." The fact is you can minimise the opportunities, the "attack surface". You cannot make it impossible, but you can act to make it equally difficult for all who would process data relating to your data subjects unlawfully. You can certainly avoid using companies that you know are unable to protect personal data processed by your organisation and as far as the law goes, you would seem obliged to do that. The ICO might issue advice (some of which is poor), they do not write or re-write the law.
GrumbleDook Posted October 28, 2015 Posted October 28, 2015 Translation - There are lots of legal and politic things that need to be worked through so whilst we do that don't stress. If you do have to change we will advise you. However, the advice from the IT folk at that LA in London is not as daft as it seems. Whilst it is not a case that you should panic, it is a case that you should twice about starting to use services that you have not used before if they were previously covered by Safe Harbor. It looks like the ICO has only said don't make changes ... nothing about there being no risk if you deciding whether to start using such services.
sparkeh Posted October 28, 2015 Posted October 28, 2015 I think @GrumbleDook has very sensible advice. We use GAFE with the model clauses, it isn't entirely clear how the modal clauses are affected. There's no point in running around like Corporal Jones while the official advice is to still tight and wait for the repercussions of the ruling to be worked out (and any revised Safe Harbour that might be hammered out). However we won't be signing up for anything new until we have further guidance.
GrumbleDook Posted October 28, 2015 Posted October 28, 2015 Model clauses are not affected. Already had that chat with ICO Helpline. It was in relation to O365 but works for others using them too. 1
sparkeh Posted October 29, 2015 Posted October 29, 2015 Details emerge of what the EU wants from a revised Safe Harbour agreement. Highlights are a move away from self regulation to Judicial oversight and annual review. Talks to be held next month. Wonder how the US will react to that? Safe Harbor 2.0: Judges to keep NSA spying in check – EU justice boss • The Register 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now