Jump to content

Recommended Posts

Posted

Has anyone started contacting or dealing with their processors about GDPR yet? I am starting to compile a template of what we need to ask and document. So far on my list I have:

  • Confirmation the data is stored in the UK
  • That they do not sub-contract processing
  • Who their Data Controller is and contact details
  • Evidence of compliance and security measures
  • A copy of their privacy policy

 

Am I missing anything?

 

Should the school be drawing up a contract that the processor will sign or is it something the company should create?

 

Finally where are people drawing the line over what types of suppliers they are contacting? For example someone has signed up for a service that needs first name, surname and UPN. Should I be grilling them even though they don't really hold any personal data? I know UPN seems to be contentious but I generally substitute a unique ID generated by the school so that isn't an issue.

 

Any thoughts?

  • Thanks 1
Posted
Has anyone started contacting or dealing with their processors about GDPR yet? I am starting to compile a template of what we need to ask and document. So far on my list I have:

  • Confirmation the data is stored in the UK
  • That they do not sub-contract processing
  • Who their Data Controller is and contact details
  • Evidence of compliance and security measures
  • A copy of their privacy policy

 

Am I missing anything?

 

Should the school be drawing up a contract that the processor will sign or is it something the company should create?

 

Finally where are people drawing the line over what types of suppliers they are contacting? For example someone has signed up for a service that needs first name, surname and UPN. Should I be grilling them even though they don't really hold any personal data? I know UPN seems to be contentious but I generally substitute a unique ID generated by the school so that isn't an issue.

 

Any thoughts?

 

Data being stored in the UK is not a GDPR thing ... Data being stored in the EEA is still likely to be fine as the local countries have relevant and equivalent laws around data protection ... it's called GDPR!

 

Also, with the EU Model Clauses being used more (Microsoft and Google being 2 large examples), then it comes down to risk management rather than a legal requirement as to where data is processed.

 

As for compliance and security measures ... you are not going to get a lot of detail on a number of areas here. Companies are protective of security information ... a large chunk of the response will be generic.

 

The company will draw this up in their contract and T&Cs. Schools that want to draw something up and get companies to sign will need to pass it via Legal Services, and so will the company ... and that gets expensive on both sides.

 

To be honest, a chunk of these questions are likely to be relevant to the DPA, so perhaps it is better to ask how they are updating their present contract, etc. in light of the changes the GDPR will bring.

  • Thanks 1
Posted

Doh, I went through it so many times and I would have sworn blind I had written EU!!

 

I was wondering if we could just ask them a generic "what are you doing", but my concern is that they will just say it is in hand and give no real information, which in my mind isn't good enough.

 

Most of the questions are just to get a response to show we have made an effort for a CYA document. My intention is to compile them to go alongside the data audit.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...