Jump to content

Recommended Posts

Posted

I’ve just been sent this over as well and it is interesting to see the work they have been doing.

 

I’m looking forward to their update of the DfE cloud services document as a result.

 

There are still some elements on the data mapping to iron out but there is time for us all on that.

  • Thanks 2
Posted
I like the way they want to know our DPO.

 

I wondered about that too, I don't see why companies need a name, phone number and email address of our DPO. I've no principled objection to telling them, of course, although there is a facetious part of me which is wondering if I can decline telling them.

Posted
I also don't entirely see the point of this. We can opt in now, but this won't take effect until May anyway, and presumably if we haven't closed our account by May, we'll be subject to the new terms anyway. So what are we actually being asked to do now?
Posted

One of the twelve steps to take now from the ICO is raising awareness. I'd put it down to that at the moment.

 

Also it puts them ahead of the game against many other suppliers - Google look pretty proactive and may gain a few customers. The more skeptical side of me might suggest they are expecting a backlash on the finer details before 25th May they may announce agreement 2.1!

 

I also don't entirely see the point of this. We can opt in now, but this won't take effect until May anyway, and presumably if we haven't closed our account by May, we'll be subject to the new terms anyway. So what are we actually being asked to do now?
Posted
I'm 'me too' for the email, but it was forward to me from a founder/governor. It will be interesting to see how we handle the question who is the DPO but useful to raise the profile of this topic.
Posted
There are still some elements on the data mapping to iron out but there is time for us all on that.

I've read through a lot of the detail now and I don't see anywhere where they supply information on the data they hold; we are assumed to know and be able to work it out via the tools in the domain control panel. If you know different - please say.

 

I'm concerned about data which can be grabbed by google when (say) setting up a new device. So if they use their android tablet and set it up using their school GAE account and have the device set to back up settings to the cloud, is that data that we control as the data controller of the service?

Posted
I'm concerned about data which can be grabbed by google when (say) setting up a new device. So if they use their android tablet and set it up using their school GAE account and have the device set to back up settings to the cloud, is that data that we control as the data controller of the service?

 

Finally, an advantage of our SSO login, which prevents them from registering devices to their school GAFE account!

Posted (edited)

This is interesting, why aren't Google offering UK \ EU only storage of data?

 

10.1. Data Storage and Processing Facilities. Customer agrees that Google may, subject to Section 10.2 (Transfers of Data Out of the EEA), store and process Customer Data in the United States and any other country in which Google or any of its Subprocessors maintains facilities.

 

Microsoft seem well ahead in terms of being in control of where data is located. Makes for an interesting discussion on the suitability of OneDrive vs Google Drive for personal data.

 

INTERNATIONAL DATA TRANSFERS

The GDPR provides for several mechanisms to facilitate transfers of personal data outside of the EU. These mechanisms are aimed at confirming an adequate level of protection or ensuring the implementation of appropriate safeguards when personal data is transferred to a third country.

Appropriate safeguards can be provided for by model contract clauses. An adequate level of protection can be confirmed by adequacy decisions such as the ones that supports the EU-U.S. Privacy Shields.

We contractually commit under our current data processing agreements to maintain a mechanism that facilitates transfers of personal data outside of the EU as required by the Data Protection Directive, and will offer a corresponding commitment from 25 May 2018, when the GDPR comes into force.

Google’s certification under the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks includes G Suite and Google Cloud Platform. We have also gained confirmation of compliance from European Data Protection Authorities for our model contract clauses, affirming that our current contractual commitments for G Suite and Google Cloud Platform fully meet the requirements under the Data Protection Directive to legally frame transfers of personal data from the EU to the rest of the world.

 

Hmmm so rather than just keeping data within the EU Google are taking the view that Privacy Shield is sufficient, debatable...

Edited by gshaw
Posted
Why would they host it in the UK if they don't need to?

For customers who aren't happy with data being sent to the US in any form?

Posted
For customers who aren't happy with data being sent to the US in any form?

 

Probably not enough people to consider opening up a new data centre. When organisations like the Cabinet Office, HMRC and local authorities are using G Suite with the current situation there can't be many big players who have an actual requirement (not preference) to have it in the UK.

Posted
I also don't entirely see the point of this. We can opt in now, but this won't take effect until May anyway, and presumably if we haven't closed our account by May, we'll be subject to the new terms anyway. So what are we actually being asked to do now?

 

My thought was that the positive opt-in was part of the new active consent requirements of GDPR, ie, you can't be assumed to consent to their T&Cs, you have to actively tick a box to say you've read them. We will all read them, of course...

 

Not sure what happens if you don't confirm your consent by May 2018, maybe it will lock out your organisation until you agree to T&Cs? It's all very well changing the method of consent, but at the end of the day you will have to agree to their terms if you want to use their service.

Posted
It's all very well changing the method of consent, but at the end of the day you will have to agree to their terms if you want to use their service.

 

Yes, but that's not as much of a strong arm as it might sound. I don't have to agree to their terms, I could go to their competition. For the likes of Google, Microsoft, Apple, SIMS, etc. this would be a big move so only under exceptional circumstances, but other smaller providers can't play hard-ball in the same way. I can think of examples of companies who have lost our business because they wouldn't agree to our Ts&Cs.

Posted

It would be interesting to see if anyone did switch major suppliers during the GDPR switchover, it's potentially a time when people would re-evaluate their suppliers for big services like MIS and online office platforms.

 

I suspect most people will just agree to the new terms to avoid the hassle of changing though.

Posted
Like you, I suspect many of us will stick with the same supplier for big services, but this will hopefully make schools think about the many many many other organisations with whom we share data. Even if we continue sharing the data, it will prompt us to consider what we share and why, and limit it solely to what they actually need. Why, for example, does VocabExpress ask for a child's gender?
Posted
Yeah, it's definitely a good time to re-evaluate our data sharing. I know for us Junior Librarian really needs re-evaluating, they take name, DOB, home address, email, UPN even! Not required to run a library database.
Posted
Yeah, it's definitely a good time to re-evaluate our data sharing. I know for us Junior Librarian really needs re-evaluating, they take name, DOB, home address, email, UPN even! Not required to run a library database.

 

You can change this yourself in the exporter tool.

Posted
You can change this yourself in the exporter tool.

 

We're using Integris and running a built in report, I haven't seen any options on this point. But that's off topic, just mentioning as an example.

Posted

That's an interesting coincidence. Our library system asks for more than it needs, too.

 

I accept you were just giving an example though - we need to review this for all third parties, having identified who those third parties even are - are you confident you know every company who has been sent an export from SIMS? Go and have conversations with the finance team to see who gets paid for subscription services, then speak to all Heads of Department to ask them too.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...