Jump to content

Recommended Posts

Posted

One of my schools would like to start using a new online pupil profiling system, and I wanted to find out if they will be compliant with the new GDPR laws, but not sure how I should word the email.

 

Is simply asking if they will be compliant enough, or do I need to ask specific questions?

 

They do have the following info but I don't think it meets the incoming requirements - https://help.seesaw.me/hc/en-us/articles/204472519-Where-is-my-data-stored-

 

Thanks

Posted
At present the guidance I've had is that no US-based companies are safe for GDPR. It's UK, EU or nowt for products we're using at the moment, others may have different views though.
Posted

At a seminar it was said that Privacy Shield isn't up to scratch either.

 

US companies will have to make some pretty specific changes to get up to GDPR standard (at which point they may as well host the services in Europe). What I was told was that EU companies haven't got this figured out yet so what chance US ones?

Posted
At present the guidance I've had is that no US-based companies are safe for GDPR. It's UK, EU or nowt for products we're using at the moment, others may have different views though.

 

That's some guidance I can see being changed in time, otherwise it would be bye-bye Google Apps.

Posted
That's some guidance I can see being changed in time, otherwise it would be bye-bye Google Apps.

Funny you mention that, Google Apps is one that's on the risky list for some Unis etc. as they won't commit to storing data solely in the EU.

 

Some places I talked to are comfortable using it for resources etc. but not for storing personal data. Interesting times ahead...

Posted
Funny you mention that, Google Apps is one that's on the risky list for some Unis etc. as they won't commit to storing data solely in the EU.

 

I am also a bit confused about Google apps & GDPR. All my primary schools are using it, although drive is currently being used for the odd file by only a few teachers, as we still have a file server with remote access. One of the schools has asked me to completely lose the file server over the next few months, and get everyone using G drive.

 

With so many schools using G Apps (and businesses) are we going to be pushed in to a position of not being able to use them, or will they buckle and offer an EU data storage solution????

Posted
Just found the following which seems to imply that the likes of Google and the company in my OP are OK to hold EU data outside the EU provided they meet specific data requirements, like privacy shield.

 

That's my reading of it too, also Google have signed the EU modified clauses, or whatever they're called, so they are holding data as if it were in the EU even though it isn't. That isn't a guarantee for all non-EU-based hosts of course.

Posted

OK - My problem is that this week I need to let the school know if they can use the software in my OP or not. They really want to use it as apparently its the best thing since sliced bread.

 

So based on the fact that they (Seesaw) are signed up to the Privacy Shield Framework do you think I can give the go ahead?

 

The reason they have asked me to find out about the Seesaw software is the schools Data protection / e-safety officer left, they need to start using this software now, and the person that will be GDPR office will be learning it in due time. Its just a very small primary school so I like to help out as much as I can.

Posted
OK - My problem is that this week I need to let the school know if they can use the software in my OP or not. They really want to use it as apparently its the best thing since sliced bread.

 

So based on the fact that they (Seesaw) are signed up to the Privacy Shield Framework do you think I can give the go ahead?.

 

If it were me making the decision, I'd allow it. Revisit once GDPR terms are clarified, of course.

  • Thanks 1
  • 2 weeks later...
Posted
Google Apps is one that's on the risky list for some Unis etc. as they won't commit to storing data solely in the EU.

 

www.blog.google/topics/google-cloud/google-cloud-our-commitment-general-data-protection-regulation-gdpr/

 

Our users can count on the fact that Google is committed to GDPR compliance across G Suite and Google Cloud Platform (GCP) services when the GDPR takes effect on 25 May 2018. We'll make important updates to contractual commitments that directly address GDPR requirements. We're also a committed partner in customers’ GDPR compliance efforts. Users can leverage Google Cloud services with confidence understanding the robust data protection capabilities built-in to Google Cloud.

 

What’s next

We’re working to make additional operational changes in light of the new legislation, and will collaborate closely with our customers, partners and regulatory authorities throughout this process. We have a global team of regulatory compliance specialists, product managers, engineers, counsel and public policy specialists who continue to carefully monitor GDPR implementation guidance, and will update our contractual commitments accordingly. We'll make our updated data processing amendment available to our customers soon. We're also producing additional materials to assist customers with their due diligence efforts as they prepare for GDPR.

 

At Google Cloud, we work to earn the trust of our users every day. As such, protecting the privacy and security of our customers’ information is a top priority, and compliance is central to this mission. We'll continue to evolve our capabilities in accordance with the changing regulatory landscape and work with you to help facilitate your GDPR compliance efforts.

  • Thanks 1
Posted

A consultation has just started by the ICO about contracts and liabilities between data controllers (e.g. The school) and data processors (e.g. Microsoft).

https://ico.org.uk/about-the-ico/consultations/consultation-on-gdpr-guidance-on-contracts-and-liabilities-between-controllers-and-processors

 

Many suppliers are waiting for guidance around this to see what needs to be updated in contracts, etc.

 

To some extent, the best you can do for some companies is ask "Are you doing something to ensure compliance with GDPR and if so, what?"

 

If they fail to respond or say it isn't relevant then point out that it is relevant and give them one more chance ... most will respond ...

Posted

Nevermind the U.S companies, are UK companies compliant? I'm thinking SIMS esp with respect to data deletion.

Or is this how the marketing strategy forweb based SIMS will go ?

Posted
To be honest ... as we said at the conference ... *NO* company is compliant right now. There are still some things to tease out, a specially on contracts, but the best thing you can do is ask if they are working on it.
Posted
Many suppliers are waiting for guidance around this to see what needs to be updated in contracts, etc.

 

To some extent, the best you can do for some companies is ask "Are you doing something to ensure compliance with GDPR and if so, what?"

 

The problem there of course is many of us have already signed agreements which will still be in force in May - how many of us renewed loads of annual subscriptions on 1st Sept?! So, we're already under contract with suppliers who may not be compliant in time and/or may refuse to sign any new terms until the current subscription/agreement expires.

Posted

Check in the contract for the clauses about complying with local laws.

 

Also, it would be a brace EdTech supplier that doesn't sort themselves out ... remembering that if they don't they will not be able to sell their service into EU at all!

Posted
You really need your responsible DPO to do this but there is not really any such thing as a firm 'being compliant' as it depends on how your organisation, your students' personal data, parents/students communication, and the company and their processsing interact, and that is not fixed. Questions you need to be asking include, What age are the children from whom the data will be collected? What do you mean when you say 'profiling'? Are you planning on using the free or paid version? What data are collected? On what legal basis will you collect and process each of those data? What processing do you expect the company to do? What is their security set up? What is their data retention and destruction policy?
  • Thanks 2
Posted
Two of my schools have now asked for this and i'm a bit cautious about this as well as they don't really understand or care where the data goes! They just like the app and want it.
Posted
You really need your responsible DPO to do this but there is not really any such thing as a firm 'being compliant' as it depends on how your organisation, your students' personal data, parents/students communication, and the company and their processsing interact, and that is not fixed.

 

True, but there are also some very broken pieces of software (I'm thinking SIMS): for example if I needed to delete a students data when they became offroll because that was the policy, how would I retrospectively get an attendance report for the entire yeargroup and include that data. I'm pretty sure SIMS currently deletes it, but if it were compliant it would anonymise it.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...