TwistedHelixis Posted September 4, 2017 Posted September 4, 2017 One of my schools would like to start using a new online pupil profiling system, and I wanted to find out if they will be compliant with the new GDPR laws, but not sure how I should word the email. Is simply asking if they will be compliant enough, or do I need to ask specific questions? They do have the following info but I don't think it meets the incoming requirements - https://help.seesaw.me/hc/en-us/articles/204472519-Where-is-my-data-stored- Thanks
FN-GM Posted September 4, 2017 Posted September 4, 2017 You could use the DFE templates? https://www.gov.uk/government/publications/cloud-software-services-and-the-data-protection-act This one Google filled out https://drive.google.com/file/d/0B3f6ReLrNvlgV0NES2VCazQtOVk/view
TwistedHelixis Posted September 5, 2017 Author Posted September 5, 2017 Would someone mind taking a very quick look at the sites current data info page and letting me know if it is already compliant with GDPR. https://help.seesaw.me/hc/en-us/articles/204472519-Where-is-my-data-stored- Thanks
gshaw Posted September 5, 2017 Posted September 5, 2017 At present the guidance I've had is that no US-based companies are safe for GDPR. It's UK, EU or nowt for products we're using at the moment, others may have different views though.
DJ-1701 Posted September 5, 2017 Posted September 5, 2017 At present the guidance I've had is that no US-based companies are safe for GDPR. It's UK, EU or nowt for products we're using at the moment, others may have different views though. Interesting... looking here https://www.pivotpointsecurity.com/blog/gdpr-privacy-shield-regulations/ it seems that US based companies that are under the Privacy Shield need to conform with GDPR.
gshaw Posted September 5, 2017 Posted September 5, 2017 At a seminar it was said that Privacy Shield isn't up to scratch either. US companies will have to make some pretty specific changes to get up to GDPR standard (at which point they may as well host the services in Europe). What I was told was that EU companies haven't got this figured out yet so what chance US ones?
enjay Posted September 5, 2017 Posted September 5, 2017 At present the guidance I've had is that no US-based companies are safe for GDPR. It's UK, EU or nowt for products we're using at the moment, others may have different views though. That's some guidance I can see being changed in time, otherwise it would be bye-bye Google Apps.
gshaw Posted September 5, 2017 Posted September 5, 2017 That's some guidance I can see being changed in time, otherwise it would be bye-bye Google Apps. Funny you mention that, Google Apps is one that's on the risky list for some Unis etc. as they won't commit to storing data solely in the EU. Some places I talked to are comfortable using it for resources etc. but not for storing personal data. Interesting times ahead...
TwistedHelixis Posted September 6, 2017 Author Posted September 6, 2017 Funny you mention that, Google Apps is one that's on the risky list for some Unis etc. as they won't commit to storing data solely in the EU. I am also a bit confused about Google apps & GDPR. All my primary schools are using it, although drive is currently being used for the odd file by only a few teachers, as we still have a file server with remote access. One of the schools has asked me to completely lose the file server over the next few months, and get everyone using G drive. With so many schools using G Apps (and businesses) are we going to be pushed in to a position of not being able to use them, or will they buckle and offer an EU data storage solution????
TwistedHelixis Posted September 6, 2017 Author Posted September 6, 2017 Just found the following which seems to imply that the likes of Google and the company in my OP are OK to hold EU data outside the EU provided they meet specific data requirements, like privacy shield. EU-US Privacy Shield: implications for businesses Am I reading that correctly?? TBH I am finding this very confusing
enjay Posted September 6, 2017 Posted September 6, 2017 Just found the following which seems to imply that the likes of Google and the company in my OP are OK to hold EU data outside the EU provided they meet specific data requirements, like privacy shield. That's my reading of it too, also Google have signed the EU modified clauses, or whatever they're called, so they are holding data as if it were in the EU even though it isn't. That isn't a guarantee for all non-EU-based hosts of course.
TwistedHelixis Posted September 6, 2017 Author Posted September 6, 2017 OK - My problem is that this week I need to let the school know if they can use the software in my OP or not. They really want to use it as apparently its the best thing since sliced bread. So based on the fact that they (Seesaw) are signed up to the Privacy Shield Framework do you think I can give the go ahead? The reason they have asked me to find out about the Seesaw software is the schools Data protection / e-safety officer left, they need to start using this software now, and the person that will be GDPR office will be learning it in due time. Its just a very small primary school so I like to help out as much as I can.
enjay Posted September 7, 2017 Posted September 7, 2017 OK - My problem is that this week I need to let the school know if they can use the software in my OP or not. They really want to use it as apparently its the best thing since sliced bread. So based on the fact that they (Seesaw) are signed up to the Privacy Shield Framework do you think I can give the go ahead?. If it were me making the decision, I'd allow it. Revisit once GDPR terms are clarified, of course. 1
Arthur Posted September 18, 2017 Posted September 18, 2017 Google Apps is one that's on the risky list for some Unis etc. as they won't commit to storing data solely in the EU. www.blog.google/topics/google-cloud/google-cloud-our-commitment-general-data-protection-regulation-gdpr/ Our users can count on the fact that Google is committed to GDPR compliance across G Suite and Google Cloud Platform (GCP) services when the GDPR takes effect on 25 May 2018. We'll make important updates to contractual commitments that directly address GDPR requirements. We're also a committed partner in customers’ GDPR compliance efforts. Users can leverage Google Cloud services with confidence understanding the robust data protection capabilities built-in to Google Cloud. What’s next We’re working to make additional operational changes in light of the new legislation, and will collaborate closely with our customers, partners and regulatory authorities throughout this process. We have a global team of regulatory compliance specialists, product managers, engineers, counsel and public policy specialists who continue to carefully monitor GDPR implementation guidance, and will update our contractual commitments accordingly. We'll make our updated data processing amendment available to our customers soon. We're also producing additional materials to assist customers with their due diligence efforts as they prepare for GDPR. At Google Cloud, we work to earn the trust of our users every day. As such, protecting the privacy and security of our customers’ information is a top priority, and compliance is central to this mission. We'll continue to evolve our capabilities in accordance with the changing regulatory landscape and work with you to help facilitate your GDPR compliance efforts. 1
nathan Posted September 19, 2017 Posted September 19, 2017 (edited) Just some information on Microsoft and the GDPR https://blogs.microsoft.com/on-the-issues/2017/04/17/earning-trust-contractual-commitments-general-data-protection-regulation/#sm.0010os6561a1ud6wrgc2m3gwwlkuz I've found this a useful website. https://www.microsoft.com/en-us/TrustCenter/Privacy/gdpr/default.aspx Edited December 7, 2017 by elsiegee40
nathan Posted September 19, 2017 Posted September 19, 2017 on a side note, does anyone have any resources for retention times of data?
GrumbleDook Posted September 19, 2017 Posted September 19, 2017 A consultation has just started by the ICO about contracts and liabilities between data controllers (e.g. The school) and data processors (e.g. Microsoft). https://ico.org.uk/about-the-ico/consultations/consultation-on-gdpr-guidance-on-contracts-and-liabilities-between-controllers-and-processors Many suppliers are waiting for guidance around this to see what needs to be updated in contracts, etc. To some extent, the best you can do for some companies is ask "Are you doing something to ensure compliance with GDPR and if so, what?" If they fail to respond or say it isn't relevant then point out that it is relevant and give them one more chance ... most will respond ...
GrumbleDook Posted September 19, 2017 Posted September 19, 2017 on a side note, does anyone have any resources for retention times of data? IRMS are pretty much your best place for that. 1
mjk Posted September 19, 2017 Posted September 19, 2017 Nevermind the U.S companies, are UK companies compliant? I'm thinking SIMS esp with respect to data deletion. Or is this how the marketing strategy forweb based SIMS will go ?
GrumbleDook Posted September 19, 2017 Posted September 19, 2017 To be honest ... as we said at the conference ... *NO* company is compliant right now. There are still some things to tease out, a specially on contracts, but the best thing you can do is ask if they are working on it.
enjay Posted September 19, 2017 Posted September 19, 2017 Many suppliers are waiting for guidance around this to see what needs to be updated in contracts, etc. To some extent, the best you can do for some companies is ask "Are you doing something to ensure compliance with GDPR and if so, what?" The problem there of course is many of us have already signed agreements which will still be in force in May - how many of us renewed loads of annual subscriptions on 1st Sept?! So, we're already under contract with suppliers who may not be compliant in time and/or may refuse to sign any new terms until the current subscription/agreement expires.
GrumbleDook Posted September 19, 2017 Posted September 19, 2017 Check in the contract for the clauses about complying with local laws. Also, it would be a brace EdTech supplier that doesn't sort themselves out ... remembering that if they don't they will not be able to sell their service into EU at all!
jenatddm Posted September 20, 2017 Posted September 20, 2017 You really need your responsible DPO to do this but there is not really any such thing as a firm 'being compliant' as it depends on how your organisation, your students' personal data, parents/students communication, and the company and their processsing interact, and that is not fixed. Questions you need to be asking include, What age are the children from whom the data will be collected? What do you mean when you say 'profiling'? Are you planning on using the free or paid version? What data are collected? On what legal basis will you collect and process each of those data? What processing do you expect the company to do? What is their security set up? What is their data retention and destruction policy? 2
atcoates Posted September 26, 2017 Posted September 26, 2017 Two of my schools have now asked for this and i'm a bit cautious about this as well as they don't really understand or care where the data goes! They just like the app and want it.
mjk Posted September 26, 2017 Posted September 26, 2017 You really need your responsible DPO to do this but there is not really any such thing as a firm 'being compliant' as it depends on how your organisation, your students' personal data, parents/students communication, and the company and their processsing interact, and that is not fixed. True, but there are also some very broken pieces of software (I'm thinking SIMS): for example if I needed to delete a students data when they became offroll because that was the policy, how would I retrospectively get an attendance report for the entire yeargroup and include that data. I'm pretty sure SIMS currently deletes it, but if it were compliant it would anonymise it.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now