PhilNeal Posted February 28, 2016 Posted February 28, 2016 I'd be very interested in members views on the use of Google in light of the Safe harbour changes i.e. sensitive personal data must not be held outside the EU. It seems to me that using Google Docs etc. could expose a school to contravening Safe Harbour rules?
flyinghaggis Posted February 28, 2016 Posted February 28, 2016 I'd be very interested in members views on the use of Google in light of the Safe harbour changes i.e. sensitive personal data must not be held outside the EU. It seems to me that using Google Docs etc. could expose a school to contravening Safe Harbour rules? AFAIK all Google's GAFE UK data is held on European servers so there shouldn't be any issues? I believe MS Office 365 also hold there data in Europe so at least the main two education players won't be affected by the safe harbour ruling.
PhilNeal Posted February 28, 2016 Author Posted February 28, 2016 I knew MS held data in the EU but thought Google weren't as clear. Have you got a link to their policy? Thanks Phil
FN-GM Posted February 28, 2016 Posted February 28, 2016 If the UK leaves to EU it will mix things up again! Oh the joys of working in IT.
localzuk Posted February 29, 2016 Posted February 29, 2016 (edited) Google's response to the question "Q 8.1 – In providing the service do you limit the transfer of personal data to countries within the EEA?", they state In accordance with ICO guidance (http://goo.gl/ppoe4H) regarding the transfer of personal data outside of the EEA, Google offers both 1) participation in the US-EU (and Switzerland) Safe Harbor framework and 2) model contract clauses as means of meeting the adequacy and security requirements of the European Commission’s Data Protection Directive, thus negating the need to limit the transfer of personal data outside the EEA. As such, Google does not limit the transfer of personal data outside the EEA. "Q 8.2 – If you transfer data outside the EEA do you explain to schools when (and under what circumstances) data will be transferred to these locations?" Yes, this is explained in the Google Apps for Education Agreement: As part of providing the Services, Google may transfer, store and process Customer Data in the United States or any other country in which Google or its Group Companies maintain facilities. "Q 8.3 – If you transfer data outside the EEA does your standard contract include the unmodified EU approved “model clauses” in respect of such transfers?" Google offers a data processing amendment and the full text of EU-approved model clauses to customers as amendments to the standard contract. In conformity with clause 10 of the model clauses, Google adds a clause - provided strictly for business-related issues - involving each party’s aggregate liability to the other. This provision does not modify or contradict the model clauses. Further, in conformity with guidance provided by the Article 29 Working Party Opinion 05/2012 on Cloud Computing, in its data processing amendment Google provides for independent third party audits of Google systems in lieu of direct customer audits. "Q 8.4 – If you transfer data outside the EEA, (and do not offer the unmodified EU approved "model clauses", can you confirm that the requirements of the DPA are met in respect of the need for adequate protection for the rights and freedoms of data subjects in connection with the cross-border transfer and processing of their personal data?" Google participates in the US-EU Safe Harbor Framework, as well as offering a data processing amendment and model contract clauses as an additional means of meeting the adequacy and security requirements of the European Commission's Data Protection Directive. All taken from here - http://goo.gl/ahoxcV I think you're mixing up your terms @PhilNeal. SafeHarbor has been determined to be unworthy of the paper it is written on. The issue is that potentially, those organisations that utilise it for transfer of data outside of the EU could be breaching the Data Protection Act (in the UK), and EU law. The ICO's advice, as far as I can tell, was to hold tight on judgment until the new agreement "Privacy Shield" was in place, as well as stating that with model clauses in place in contracts organisations would still potentially be covered anyway. My view is that those using Google's services right now shouldn't be immediately jumping ship, but keeping an eye on the ICO's advice and should be doing a proper analysis of how they're using it, and the implications. For those who don't yet use their services, I'd be holding off until their is clarity on the issue - again going by ICO advice. If the UK leaves to EU it will mix things up again! Oh the joys of working in IT. Yup. If the UK leaves, the government could legislate our data protection laws to be as strong or as weak as they wished. That said, we'd then also be in the same position as the USA when it came to EU companies transferring data to us. We'd need to adequately address EU data protection laws in order for that data to be transferred legally. In other words, more work for companies offering services to the EU. Edited February 29, 2016 by localzuk
maark Posted February 29, 2016 Posted February 29, 2016 Since the cabinet office and HMRC use Google I don't think schools should be too worried. UK government department swaps Microsoft for Google Have noticed that Microsoft seem to scaremonger about this as they seem to be trailing google in things like colloboration, classroom tools etc.
CyberNerd Posted February 29, 2016 Posted February 29, 2016 AFAIK all Google's GAFE UK data is held on European servers so there shouldn't be any issues? I believe MS Office 365 also hold there data in Europe so at least the main two education players won't be affected by the safe harbour ruling. The GCE (Google Compute Engine) Data IS held in EU if you request it, GAFE isn't necessarily held in EU but could be.
PhilNeal Posted February 29, 2016 Author Posted February 29, 2016 It was using Google Docs in particular that concerned me. If a school is storing sensitive data in documents that are held on Google servers then it could be outside the EU and that isn't as I understand it legal.
localzuk Posted February 29, 2016 Posted February 29, 2016 It was using Google Docs in particular that concerned me. If a school is storing sensitive data in documents that are held on Google servers then it could be outside the EU and that isn't as I understand it legal. There isn't a firm and fast "legal/illegal" definition as far as I've been told. Its all about risk and how protected the data is.
Geoff Posted February 29, 2016 Posted February 29, 2016 I'd like to point out there's somewhat of a question mark as to if the UK DPA complies with the GDPR anyway. If this follows through to it's logical conclusion you might find that having your data stored in Ireland at the behest of Amazon AWS (for example) is more compliant than having it in your own server room. 'Leave' or 'Stay' in the referendum? UK has to implement GDPR either way • The Register
matt40k Posted February 29, 2016 Posted February 29, 2016 It was using Google Docs in particular that concerned me. If a school is storing sensitive data in documents that are held on Google servers then it could be outside the EU and that isn't as I understand it legal. If its anything like survey monkey you can't store sensitive data on the service. Looking quickly at the QA's, they have a opt-in for health (data) - but it doesn't cover docs, only mail, calendar and drive (which I guess has client-side encryption?) and calendar and mail shouldn't contain sensitive data.
IrritableTech Posted February 29, 2016 Posted February 29, 2016 It was using Google Docs in particular that concerned me. If a school is storing sensitive data in documents that are held on Google servers then it could be outside the EU and that isn't as I understand it legal. DPA principle 8 says: Personal data shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data. Safe Harbor was meant to be a quick way of ensuring that adequate levels of protection were in place. Organisations governed under the DPA are still able to transfer data outside of the EEA as long as they are happy with the level of protection and declare it in their statement. Each service will need to be assessed more closely until any other agreement comes into practice. It's a risk assessment and review type thing.
Geoff Posted February 29, 2016 Posted February 29, 2016 Oh and don't forget 'Privacy Shield' might end up a load of old tosh as well. Privacy Shield doomed from get-go? NSA bulk surveillance waved through | Ars Technica UK
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now