enjay Posted July 14, 2017 Posted July 14, 2017 Up until now, our onsite VMs have been backed up into our remote datacentre. Our datacentre provider has now decided they want to store that data in the cloud using another supplier. Under either the DPA or current understanding of GDPR, can they do this(I'll check our contract separately)? Is it down to them or me to vet the new cloud provider's compliance? Should there be a data breach at the cloud storage, is that our breach or our datacentre providers'?
GrumbleDook Posted July 14, 2017 Posted July 14, 2017 They are sub-contracting the storage. You already host on the cloud (someone else's computer) so check the contract to see if they are obliged to only host it on their computers or can they put it on a sub-contractor's.
enjay Posted July 14, 2017 Author Posted July 14, 2017 You're right the data is already on Someone Else's Computer, but the difference is I have approved that Someone Else and contracted them to store my data. As I said, I will check the contract but my concern is about the DP/GDPR implications of the sub-contracting, and where the buck stops if Something Bad happens.
enjay Posted July 14, 2017 Author Posted July 14, 2017 Okay, I've got a bit more information now, and I'm actually not concerned now. Apparently, they are just changing the management interface to a web-based one, the data itself will still reside in the datacentre and go directly there. It might be worth keeping this thread going though so we all have the information should this happen to any of us in the future.
MrWrighty Posted July 26, 2017 Posted July 26, 2017 (edited) You have answered your own question but add to this, my understanding is that Data in the cloud must reside in a country that is affected by GDPR i.e the 28 countries of the EU. Any company outside of the EU such as the USA that wants to provide cloud storage for EU citizens must abide by the GDPR directive but it is not clear how this will be implemented in countries outside of EU control. GDPR is not about data breaches but how data is collected, stored and protected and whether you should even be collecting the data you have in the first place. You will have to have very strict consent about the data you collect. You will be able to use the data you have now up until the 25th May 2018 but after that date, if you do not have consent for that data to be stored you may have to destroy it or ask specifically for consent to retain that data. You cannot have a tick box asking for consent, you have to be very specific about what data you will be collecting and how it will be stored/shared. I also understand there is no grace period for failure to meet the needs of GDPR. If you fail you get fined and the fines can be large. You will not receive a warning about your failures or weaknesses to meet GDPR. Obviously no one knows what will happen after Brexit and whether these rules will still apply and whether all data subject to GDPR will have to be kept in the UK after this point. Edited July 26, 2017 by MrWrighty
GrumbleDook Posted July 26, 2017 Posted July 26, 2017 In reality though, no school has ever been fined by the ICO, so for schools to suddenly get a massive fine would be a PR disaster for ICO. However, that should not be an excuse not to get it sorted, but we are yet to see what OFSTED are saying about failure to meet GDPR as a safeguarding issue, or a failure to meet legal requirements (puts note in notebook to go ask again). Undertakings will still exist (may be named differently) and an Undertaking may end up having more of an impact to a school than a fine. There are too many companies out there selling their advice on the basis that you *will* be fined ... when criteria for this has yet to be published by any DPA in the EU (admittedly the IE DPA have said they will come down hard from word go but have yet back that up with anything concrete). If nothing else, the fact the London's Royal Free hospital did not get fined for their data breach of 1.6 million patients (Deepmind anyone), just goes to show that you cannot predict anything.
matt40k Posted July 28, 2017 Posted July 28, 2017 In reality though, no school has ever been fined by the ICO, so for schools to suddenly get a massive fine would be a PR disaster for ICO. However, that should not be an excuse not to get it sorted, but we are yet to see what OFSTED are saying about failure to meet GDPR as a safeguarding issue, or a failure to meet legal requirements (puts note in notebook to go ask again). Publicly... no school has been fined or put into special measures publicly. I wouldn't be surprised if they kept those sort of things quiet.
MrWrighty Posted July 28, 2017 Posted July 28, 2017 The ICO will have to be seen to be abiding by the rules. If a company can be fined for not meeting the requirements of GDPR, then it would be seen as favouritism if educational establishments were let off. I don't think I would want to be responsible for saying to the school head, GDPR, it doesn't matter we won't get fined.
GrumbleDook Posted July 28, 2017 Posted July 28, 2017 Publicly... no school has been fined or put into special measures publicly. I wouldn't be surprised if they kept those sort of things quiet. Schools that are put in special measures have the reasons included in the OFSTED report. That is a requirement. No relevant information is excluded. All ICO decisions are published and are available for inspection. You will even see notices where they had a go at folk like CEOP. If you are aware of anything that has not been published please PM me.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now