Popular Post Arthur Posted October 11, 2017 Popular Post Posted October 11, 2017 Just received the following e-mail from Google regarding G Suite and the GDPR and thought it would be worth posting. Hello Administrator, We are sending you this message because your organization is operating G Suite account , and the G Suite Data Processing Amendment currently governs how we process personal data on behalf of your organization, and/or according to our records, your organization is established in the European Economic Area or Switzerland. On 25 May 2018, the most significant piece of European data protection legislation in 20 years will come into force when the European Union's (EU) General Data Protection Regulation (GDPR) replaces the 1995 Data Protection Directive. We know that preparing for this regulatory change is a priority for many of our customers. It is a priority for us, too. Today, we are pleased to roll out version 2.0 of our Data Processing Amendment (DPA), which has been specifically updated to reflect the GDPR. How opting in to DPA version 2.0 works If you opt in to DPA version 2.0, the updated terms will take effect with the GDPR on 25 May 2018. If you opt in before 25 May, you will benefit from DPA version 1.6 until then. Details Google is required to obtain from you The GDPR requires Google to maintain records of certain information, including the contact details of your EU representative (if your organization is not established in the EU) and Data Protection Officer (DPO), where applicable. What you need to do Sign in to the Google Admin console. Go to Company profile > Profile. Opt in to DPA version 2.0 In the Legal & compliance section, enter details for your EU representative and DPO as needed. You might need to click Show more to see Legal & compliance. Click Save. Where to find information or direct questions Further information regarding Google Cloud and the GDPR is available on our Cloud GDPR website. If you're also a Google Cloud Platform (GCP) customer, you will receive a separate communication concerning the rollout of updated terms for the relevant GCP products to reflect the GDPR. You might also receive similar communications concerning any other Google products you are using If you have any questions, sign in to the Admin console and contact Google's Cloud Data Protection Team. Sincerely, The G Suite Team FAQ Why are you rolling out DPA version 2.0 now? Why aren't you waiting until 25 May 2018? Google is committed to GDPR compliance and to helping its customers with their own compliance journey. We are rolling out DPA version 2.0 well in advance to facilitate your compliance assessment and GDPR readiness when using G Suite services. DPA version 2.0 takes effect on 25 May 2018, but what happens in the meantime? DPA version 1.6 will apply in the meantime. My company already opted in to an earlier version of the DPA. Do we need to opt in again to benefit from the new terms? Yes. Earlier versions of the DPA don't mention the GDPR. DPA version 2.0 specifically addresses GDPR changes. For more information about the GDPR and how you should begin preparing for it, see the Cloud GDPR website. You can opt in to version 2.0 in the Google Admin console (see directions above). My company already opted in to G Suite Model Contract Clauses (MCCs). Will those remain in force if we opt in to DPA version 2.0? Yes. If you previously opted in to G Suite MCCs, they'll remain in force whether or not you opt in to DPA version 2.0. What is a data controller? What is a data processor? A data controller determines the purposes and means of processing of personal data. A data processor processes personal data on behalf of a data controller. G Suite customers will typically act as the data controller for any personal data they provide to Google in connection with their use of G Suite. Google is a data processor and processes personal data on behalf of the data controller when the data controller is using G Suite. What are my obligations as a customer and data controller? Data controllers are responsible for implementing appropriate technical and organizational measures to ensure and demonstrate that any data processing is performed in compliance with the GDPR. Controllers' obligations relate to principles such as lawfulness, fairness and transparency, purpose limitation, data minimisation, and accuracy, as well as fulfilling data subjects' rights with respect to their data. You can find guidance related to your responsibilities under the GDPR by regularly checking the website of your national or lead data-protection authority under the GDPR (as applicable), as well as by reviewing publications by data-privacy associations, such as the International Association of Privacy Professionals (IAPP). You should also seek independent legal advice relating to your status and obligations under the GDPR, as only a lawyer can provide you with legal advice specifically tailored to your situation. What is a Data Protection Officer or DPO? A Data Protection Officer (DPO) is the person designated, where applicable, to facilitate compliance with the provisions of the GDPR. The GDPR defines the criteria and the conditions under which a DPO must be designated. What is a Customer EU Representative? A Customer EU Representative is the person designated, where applicable, to represent customers not established in the EU with regard to their obligations under the GDPR. 5
GrumbleDook Posted October 11, 2017 Posted October 11, 2017 I’ve just been sent this over as well and it is interesting to see the work they have been doing. I’m looking forward to their update of the DfE cloud services document as a result. There are still some elements on the data mapping to iron out but there is time for us all on that. 2
Andycat Posted October 12, 2017 Posted October 12, 2017 I like the way they want to know our DPO. I've forwarded this on as, of course, the SLT still haven't really worked this out!
enjay Posted October 12, 2017 Posted October 12, 2017 I like the way they want to know our DPO. I wondered about that too, I don't see why companies need a name, phone number and email address of our DPO. I've no principled objection to telling them, of course, although there is a facetious part of me which is wondering if I can decline telling them.
enjay Posted October 12, 2017 Posted October 12, 2017 I also don't entirely see the point of this. We can opt in now, but this won't take effect until May anyway, and presumably if we haven't closed our account by May, we'll be subject to the new terms anyway. So what are we actually being asked to do now?
IrritableTech Posted October 12, 2017 Posted October 12, 2017 One of the twelve steps to take now from the ICO is raising awareness. I'd put it down to that at the moment. Also it puts them ahead of the game against many other suppliers - Google look pretty proactive and may gain a few customers. The more skeptical side of me might suggest they are expecting a backlash on the finer details before 25th May they may announce agreement 2.1! I also don't entirely see the point of this. We can opt in now, but this won't take effect until May anyway, and presumably if we haven't closed our account by May, we'll be subject to the new terms anyway. So what are we actually being asked to do now?
Ditto Posted October 12, 2017 Posted October 12, 2017 I'm 'me too' for the email, but it was forward to me from a founder/governor. It will be interesting to see how we handle the question who is the DPO but useful to raise the profile of this topic.
pcstru Posted October 13, 2017 Posted October 13, 2017 There are still some elements on the data mapping to iron out but there is time for us all on that. I've read through a lot of the detail now and I don't see anywhere where they supply information on the data they hold; we are assumed to know and be able to work it out via the tools in the domain control panel. If you know different - please say. I'm concerned about data which can be grabbed by google when (say) setting up a new device. So if they use their android tablet and set it up using their school GAE account and have the device set to back up settings to the cloud, is that data that we control as the data controller of the service?
enjay Posted October 13, 2017 Posted October 13, 2017 I'm concerned about data which can be grabbed by google when (say) setting up a new device. So if they use their android tablet and set it up using their school GAE account and have the device set to back up settings to the cloud, is that data that we control as the data controller of the service? Finally, an advantage of our SSO login, which prevents them from registering devices to their school GAFE account!
gshaw Posted October 13, 2017 Posted October 13, 2017 (edited) This is interesting, why aren't Google offering UK \ EU only storage of data? 10.1. Data Storage and Processing Facilities. Customer agrees that Google may, subject to Section 10.2 (Transfers of Data Out of the EEA), store and process Customer Data in the United States and any other country in which Google or any of its Subprocessors maintains facilities. Microsoft seem well ahead in terms of being in control of where data is located. Makes for an interesting discussion on the suitability of OneDrive vs Google Drive for personal data. INTERNATIONAL DATA TRANSFERS The GDPR provides for several mechanisms to facilitate transfers of personal data outside of the EU. These mechanisms are aimed at confirming an adequate level of protection or ensuring the implementation of appropriate safeguards when personal data is transferred to a third country. Appropriate safeguards can be provided for by model contract clauses. An adequate level of protection can be confirmed by adequacy decisions such as the ones that supports the EU-U.S. Privacy Shields. We contractually commit under our current data processing agreements to maintain a mechanism that facilitates transfers of personal data outside of the EU as required by the Data Protection Directive, and will offer a corresponding commitment from 25 May 2018, when the GDPR comes into force. Google’s certification under the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks includes G Suite and Google Cloud Platform. We have also gained confirmation of compliance from European Data Protection Authorities for our model contract clauses, affirming that our current contractual commitments for G Suite and Google Cloud Platform fully meet the requirements under the Data Protection Directive to legally frame transfers of personal data from the EU to the rest of the world. Hmmm so rather than just keeping data within the EU Google are taking the view that Privacy Shield is sufficient, debatable... Edited October 13, 2017 by gshaw
enjay Posted October 13, 2017 Posted October 13, 2017 This is interesting, why aren't Google offering UK \ EU only storage of data? Well, for one, they don't have a datacentre in the UK... https://www.google.com/about/datacenters/inside/locations/
FN-GM Posted October 13, 2017 Posted October 13, 2017 Why would they host it in the UK if they don't need to?
gshaw Posted October 13, 2017 Posted October 13, 2017 Why would they host it in the UK if they don't need to? For customers who aren't happy with data being sent to the US in any form?
FN-GM Posted October 13, 2017 Posted October 13, 2017 For customers who aren't happy with data being sent to the US in any form? Probably not enough people to consider opening up a new data centre. When organisations like the Cabinet Office, HMRC and local authorities are using G Suite with the current situation there can't be many big players who have an actual requirement (not preference) to have it in the UK.
Ditto Posted October 14, 2017 Posted October 14, 2017 Does this centre not offer the option? Reduce latency sounds a positive also.
FN-GM Posted October 14, 2017 Posted October 14, 2017 Thats for the Google Cloud Platform not G Suite. (yes it is confusing!)
DavR Posted October 16, 2017 Posted October 16, 2017 I also don't entirely see the point of this. We can opt in now, but this won't take effect until May anyway, and presumably if we haven't closed our account by May, we'll be subject to the new terms anyway. So what are we actually being asked to do now? My thought was that the positive opt-in was part of the new active consent requirements of GDPR, ie, you can't be assumed to consent to their T&Cs, you have to actively tick a box to say you've read them. We will all read them, of course... Not sure what happens if you don't confirm your consent by May 2018, maybe it will lock out your organisation until you agree to T&Cs? It's all very well changing the method of consent, but at the end of the day you will have to agree to their terms if you want to use their service.
enjay Posted October 16, 2017 Posted October 16, 2017 It's all very well changing the method of consent, but at the end of the day you will have to agree to their terms if you want to use their service. Yes, but that's not as much of a strong arm as it might sound. I don't have to agree to their terms, I could go to their competition. For the likes of Google, Microsoft, Apple, SIMS, etc. this would be a big move so only under exceptional circumstances, but other smaller providers can't play hard-ball in the same way. I can think of examples of companies who have lost our business because they wouldn't agree to our Ts&Cs.
DavR Posted October 16, 2017 Posted October 16, 2017 It would be interesting to see if anyone did switch major suppliers during the GDPR switchover, it's potentially a time when people would re-evaluate their suppliers for big services like MIS and online office platforms. I suspect most people will just agree to the new terms to avoid the hassle of changing though.
enjay Posted October 16, 2017 Posted October 16, 2017 Like you, I suspect many of us will stick with the same supplier for big services, but this will hopefully make schools think about the many many many other organisations with whom we share data. Even if we continue sharing the data, it will prompt us to consider what we share and why, and limit it solely to what they actually need. Why, for example, does VocabExpress ask for a child's gender?
DavR Posted October 16, 2017 Posted October 16, 2017 Yeah, it's definitely a good time to re-evaluate our data sharing. I know for us Junior Librarian really needs re-evaluating, they take name, DOB, home address, email, UPN even! Not required to run a library database.
FN-GM Posted October 16, 2017 Posted October 16, 2017 Yeah, it's definitely a good time to re-evaluate our data sharing. I know for us Junior Librarian really needs re-evaluating, they take name, DOB, home address, email, UPN even! Not required to run a library database. You can change this yourself in the exporter tool.
DavR Posted October 16, 2017 Posted October 16, 2017 You can change this yourself in the exporter tool. We're using Integris and running a built in report, I haven't seen any options on this point. But that's off topic, just mentioning as an example.
enjay Posted October 16, 2017 Posted October 16, 2017 That's an interesting coincidence. Our library system asks for more than it needs, too. I accept you were just giving an example though - we need to review this for all third parties, having identified who those third parties even are - are you confident you know every company who has been sent an export from SIMS? Go and have conversations with the finance team to see who gets paid for subscription services, then speak to all Heads of Department to ask them too.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now