Jump to content

Recommended Posts

Posted (edited)

One of the things that I have seen mentioned in a lot of articles about GDPR is that a data audit should be undertaken. I am going to propose this to senior management and am looking for what exactly a data audit involves. Would something like this cover the requirements for an audit?

 

 

  • What data we hold
  • Why we hold that data (Thanks @TechMonkey)
  • Where we get that data from
  • What consent was obtained that we could use that data
  • How consent was obtained
  • Who has access to the data
  • Who we share that data with (both internally and externally)
  • How long we hold the data for
  • How we dispose the data
     

Edited by DavePa
  • Thanks 1
Posted
I think I read somewhere that if you're sharing data with external companies, they should sign an agreement with you on how they handle the data.
Posted
I think I read somewhere that if you're sharing data with external companies, they should sign an agreement with you on how they handle the data.

 

Good one. Anyone using your data is a data processor so:

Data controllers may only appoint data processors which provide sufficient guarantees to implement appropriate technical and organisational measures to ensure processing meets the requirements of the GDPR.

Data processor activities must be governed by a binding contract with regard to the controller.

and

requirement to demonstrate compliance... These records must be provided to the supervisory authority on request.

(from https://www.taylorwessing.com/globaldatahub/article-obligations-on-data-processors-under-gdpr.html)

 

May have to make a log of what companies you give data to and which ones have given you assurances, contracts and allowed you to see their records.

 

That then begs the question, would an online Education service, for example Education City, be counted as a Data Processor because we upload names, DoBs and they have test scores. In my view, yes.

Posted
With regards the above I think it is vital that the company has a policy in place that states they comply with security obligations equivalent to Principle 7 of the Data Protection Act. We then include these companies on our Privacy Notice so it is transparent with parents.
Posted
As a side issue, can I ask about what responsibility we have, other than assurances from the company in question, to see and check what is happening to our data which is held in the SIMS cloud?
Posted

When it comes to managing and handling data then you should also be completing a risk assessment.

 

We are not talking going down ISO27001 here, but there are a few key areas you should consider.

 

Always remember CIA when it comes to DP and IS (Data Protection and Information Security).

Preservation of Confidentiality, Integrity and Availability.

 

What are the risks for the various data sets? Think about the triad above.

 

This should be part of your audit.

Posted
@browolf it certainly does. Under GDPR if you do not have a formal contract or SLA with your IT recycling partner, you will be liable in the event of data breach, and be subject to a fine.

 

Surely only if you contract data destruction to them? If you are ensuring you wipe or remove HDDs yourself then why would a recycling partner be processing any data for you? If you send devices with sensitive data on them to be recycled then you are breaching DPA anyway.

Posted

By having a contract with them, it covers what they will do with the equipment.

If you are owning all the risk of destroying all data then the contract will have to say that, so it covers them from any risk as well. Contracts are a two-way thing.

  • Thanks 1
Posted (edited)
Surely only if you contract data destruction to them? If you are ensuring you wipe or remove HDDs yourself then why would a recycling partner be processing any data for you?

 

While that might be true, many IT recycling companies (including ourselves) handle data destruction as a standard part of their recycling service. We would also always advise against handling data destruction yourself, as ITAD companies (again including ourselves) use specialist data wiping software which destroys beyond recovery, and holds the relevant accreditations to be able to handle data securely. And if for whatever reason we can't fully wipe the hard drive, or it's not reusable, we physically destroy it using our industrial shredder.

 

If you send devices with sensitive data on them to be recycled then you are breaching DPA anyway.

 

This isn't entirely correct - if you send devices holding sensitive data to a third party for data disposal/recycling without doing so under a formal contract or have not ensured they are qualified or competent to carry this out, you will be in breach of GDPR. It is not illegal under GDPR to contract out your data disposal requirements, nor is it in breach of the DPA.

Edited by Stone_Charli
  • Thanks 1
Posted

 

If you send devices with sensitive data on them to be recycled then you are breaching DPA anyway.

 

This isn't entirely correct - if you send devices holding sensitive data to a third party for data disposal/recycling without doing so under a formal contract or have not ensured they are qualified or competent to carry this out, you will be in breach of GDPR. It is not illegal under GDPR to contract out your data disposal requirements, nor is it in breach of the DPA.

 

Sorry, I should have been clearer. I wasn't saying it was illegal to use disposal companies, we use them often. I was pointing out that even currently if you send devices out to be recycled, not for data destruction, and you leave sensitive data on them you would be in breach of the DPA. How many stories have we seen of an old HDD on eBAY containing a treasure trove of data?

 

An interesting extension of that is how many people wipe their copier HDDs before sending them back after a lease?

 

Of course I would expect you to advise everyone to contract out data destruction ;)

Posted
An interesting extension of that is how many people wipe their copier HDDs before sending them back after a lease?

 

The lease agreement could specify that data destruction will take place. There is a particular copier company that refused to agree to this in a lease, until it got pointed out that they would no longer be able to supplier any Council, Govt department, etc ... they changed their minds very quickly.

Posted
Sorry, I should have been clearer. I wasn't saying it was illegal to use disposal companies, we use them often. I was pointing out that even currently if you send devices out to be recycled, not for data destruction, and you leave sensitive data on them you would be in breach of the DPA.

 

Well yes in this situation that would indeed be true. The seventh principle states "appropriate technical and organisational measures shall be taken against accidental loss or destruction of, or damage to, personal data", and the ICO guidance states that "Devices should not leave your organisation before you have established who is responsible for deleting the personal data contained on them". Guide I'm quoting from can be found here: https://ico.org.uk/media/for-organisations/documents/1570/it_asset_disposal_for_organisations.pdf

Of course I would expect you to advise everyone to contract out data destruction ;)

Our data destruction service is free - the main reason we do this is to protect the organisations that work with us (and ourselves, for that matter). We have the accreditations, the facilities and the resource to ensure data security and complete destruction. This is the case with many of our peers too.

Posted (edited)

Under the new GDPR regulations that are being enshrined into UK law in May 2018 all organisations whether private or public sector have to adhere to the following:-

 

1) All organisations have to have a contract/agreement with their Asset Disposal Company

2) All IT Assets need to be tracked and when disposing of redundant equipment a full audit report, serialised data erasure certificates should be provided to you so that you can update your CMDB system

3) All organisations have to have an Asset Disposal Policy

4) All organisations have to designate their asset disposal company as their data processor

5) All physical data such as hard drives should be wiped or shredded using CESG Approved Methods. Media Tape should be shredded using CESG Approved Methods

6) Organisation should ensure that their asset disposal partner are accredited and undergo regular audits either by standards such as ADISA (Asset Disposal and Information Security Alliance) and/or audited by the organisations themselves to ensure that the processes that they follow meet all current/impending legislation.

Edited by elsiegee40
Advertising removed
Posted (edited)
Under the new GDPR regulations that are being enshrined into UK law in May 2018 all organisations whether private or public sector have to adhere to the following:-

 

1) All organisations have to have a contract/agreement with their Asset Disposal Company

2) All IT Assets need to be tracked and when disposing of redundant equipment a full audit report, serialised data erasure certificates should be provided to you so that you can update your CMDB system

3) All organisations have to have an Asset Disposal Policy

4) All organisations have to designate their asset disposal company as their data processor

5) All physical data such as hard drives should be wiped or shredded using CESG Approved Methods. Media Tape should be shredded using CESG Approved Methods

6) Organisation should ensure that their asset disposal partner are accredited and undergo regular audits either by standards such as ADISA (Asset Disposal and Information Security Alliance) and/or audited by the organisations themselves to ensure that the processes that they follow meet all current/impending legislation.

 

 

Thanks @Tobylevens. Can you point me in the direction of where in the GDPR it states we need these precise things so I can pass this on to the Governors? Many thanks

Edited by elsiegee40
Advertising by TobyLevens removed from quote
Posted (edited)
...We would also always advise against handling data destruction yourself, as ITAD companies (again including ourselves) use specialist data wiping software which destroys beyond recovery, and holds the relative accreditations to be able to handle data securely. And if for whatever reason we can't fully wipe the hard drive, or it's not reusable, we physically destroy it using our industrial shredder.

I accept that we will, under GDPR, need to be able to produce a certificate to state that data has been destroyed - but for the last 2 or 3 years we have:

 

- Reformatted 2.5" hard drives, encrypted them using Bitlocker and put them into caddies for people that need portable storage

- Physically destroyed server / 3.5" hard drives - quite literally opened them up, scored the platters with a screwdriver, thrown all but 1 of the screws inside and then used the last screw to re-attach the cover

 

Before that both 2.5" and 3.5" drives were destroyed so in effect we will be paying for a service that we have never felt we needed - we remove the HDD and process as above, we remove the memory and then keep the carcass for spares (WiFi, Keyboard, screen, touchpad, etc. until such time as it is just an empty shell at which point it goes to WEEE waste.

Edited by DavePa
Posted

Not to be picky but and not aimed specifically at you ... more a case of a chance to make some general comments ... ;-)

 

Under the new GDPR regulations that are being enshrined into UK law in May 2018 all organisations whether private or public sector have to adhere to the following:-

 

1) All organisations have to have a contract/agreement with their Asset Disposal Company

This is correct for the disposal of items containing data and for WEEE. If you are disposing of items that do not contain data then it is only WEEE compliance that is required.

2) All IT Assets need to be tracked and when disposing of redundant equipment a full audit report, serialised data erasure certificates should be provided to you so that you can update your CMDB system

Most schools do not operate a CMDB. They may operate an Asset Register and that is the closest you will get.

3) All organisations have to have an Asset Disposal Policy

This does not have to be a discrete policy but both your Data Protection / Information Security polices and your WEEE/Waste policies should contain references to the disposal of assets from your asset register. Please also note that you will see references to assets to also mean 'information assets', when you are conducting any data protection / information security audits ... there is a difference. A physical asset may contain information assets that require disposal. Make sure anyone you work with knows and can explain the difference ;-)

4) All organisations have to designate their asset disposal company as their data processor

Slight rewording to give context perhaps ...

All Data owners and Data Processors should ensure that they list any company disposing of assets containing data (e.g. computer hard drives) as *a* data processor (or sub-data processor, depending on contractual arrangements). Permission of the data owner may be needed for a Data Processor to sub-contract work to another Data Processor (i.e. if they are not already named and permitted then you have to go and get permission)

5) All physical data such as hard drives should be wiped or shredded using CESG Approved Methods. Media Tape should be shredded using CESG Approved Methods

Please note the word *should*.

6) Organisation should ensure that their asset disposal partner are accredited and undergo regular audits either by standards such as ADISA (Asset Disposal and Information Security Alliance) and/or audited by the organisations themselves to ensure that the processes that they follow meet all current/impending legislation.
Add DipCOG on there.

 

If you are going to use a company to do this (and for many it is a good way of managing risk) then it would be good to work with other schools (via MAT and/or LA) to get sufficient bulk to make it worthwhile.

 

One of my slides next week will be a sad hammer and a sadder drill. Those days are gone :-(

  • Thanks 1
Posted
I accept that we will, under GDPR, need to be able to produce a certificate to state that data has been destroyed - but for the last 2 or 3 years we have:

 

- Reformatted 2.5" hard drives, encrypted them using Bitlocker and put them into caddies for people that need portable storage

You have wiped the drives, made them inaccessible to general recovery and they remain an asset within the organisation. As long as you have something in your policies about not trying to access deleted data / only IT Support can run recovery software, then the only risk is the loss of the device and it being recovered by someone else. Possibly look at doing more than a reformat?

- Physically destroyed server / 3.5" hard drives - quite literally opened them up, scored the platters with a screwdriver, thrown all but 1 of the screws inside and then used the last screw to re-attach the cover

If you can find examples of drives being recovered after doing this (i.e. there are) then it isn't good enough.

Before that both 2.5" and 3.5" drives were destroyed so in effect we will be paying for a service that we have never felt we needed - we remove the HDD and process as above, we remove the memory and then keep the carcass for spares (WiFi, Keyboard, screen, touchpad, etc. until such time as it is just an empty shell at which point it goes to WEEE waste.

To some extent, it is dependent on the level of personal information held on the device ... even desktop devices will have copies of files, roaming profiles, etc ... so you need to make an assessment on that.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...