Jump to content

Recommended Posts

Posted

Company 1 - Salamander (syncing SIMS to AD and Google). The data processing happens on our servers not theirs meaning the data never actually leaves our network, but they do have logins for our servers, SIMS and Google Apps.

 

Company 2 - provider of online helpdesk for Site Team. It is unlikely, although not impossible, any sensitive data would be recorded in the premises helpdesk, but the company do have a login to our network which enables SSO authentication.

 

Company 3 - provider of technical support to Music Department. There is no data sharing, however they do have unattended access to a PC via Team Viewer and a local admin user on the Music computers (no domain admin access).

 

All companies have agreed to a code of conduct, if you will, stating they won't access our systems without prior consent and only for the purposes of support.

 

So, I think the questions are:

* Are they data processors?

* Do they need to sign a data processing agreement?

* Does the "code of conduct" satisfy the requirements of a privacy impact assessment?

  • 2 weeks later...
Posted
Company 1 - Salamander (syncing SIMS to AD and Google). The data processing happens on our servers not theirs meaning the data never actually leaves our network, but they do have logins for our servers, SIMS and Google Apps.

 

Contractor / sub-contractor.

 

They are providing tools that allow you to process data, and have access to logins to allow this to happen. A) make sure you can audit when they have used those accounts, b) you know what those accounts provide access to and c) have a sufficently robust contract with them to ensure that follow *your* data handling policies.

 

Company 2 - provider of online helpdesk for Site Team. It is unlikely, although not impossible, any sensitive data would be recorded in the premises helpdesk, but the company do have a login to our network which enables SSO authentication.

 

This is where your data audit comes in .

 

The online heldpesk will have the information of *your staff* possibly including contact information (email address, phone number). How is that data handled? Is there any automation on there? What does their privacy notice say they will do with your data that they hold?

 

Company 3 - provider of technical support to Music Department. There is no data sharing, however they do have unattended access to a PC via Team Viewer and a local admin user on the Music computers (no domain admin access).

 

As with scenario 1 - access control and audit of actions is important here. What data is held on those devices? Is anoy of it Personal Identifiable Information? If not then they are not going to be handling relevant data. The things you have to make sure of is that they *only* have access to that device and that staff know *not* to put PII on there.

 

All companies have agreed to a code of conduct, if you will, stating they won't access our systems without prior consent and only for the purposes of support.

 

So, I think the questions are:

* Are they data processors?

* Do they need to sign a data processing agreement?

* Does the "code of conduct" satisfy the requirements of a privacy impact assessment?

 

The above comments are mainly based on how they would also be covered under ISO 27001 as well (the data audit and risk management crosses over) but only you know whether there is any PII being processed.

If they are processing PII, then yes, a contract / agreement is needed.

We would need to see the code of conduct to see where it sits within the PIA. Remember, organisational as well as technical methods are suitable, but you have to assess the risk ... If you have a code of conduct, you need to show that it is understood, that it is being followed and that you check on a regular basis. Historically, organisations have used technical measures as it is cheaper and less risky than organisational measures. Nowadays it has to be a blend, but we won't know how much until we start seeing cases on breaches under the new Act.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...