Jump to content

Recommended Posts

Posted

Latest question about GDPR - what does a Data Processing Agreement between our school and a third party need to contain to be GDPR compliant?

 

I've had two come up in the last few weeks, and I was just wondering what I need to be sure of before I sign them.

 

One is Google's latest terms of service, which I assume will be OK, but they are also asking for the name of our DPO, is this standard? Given it's Google, it's not like we can negotiate, but still.

 

The other is the DPA with our electrical waste disposal company, who we've previously done business with informally. I am less certain this one will be compliant, so could do with some guidance (couldn't we all in this minefield....)

Posted

Yay, more reading! Looks like that might have some helpful advice though, thanks.

 

It's a bit crazy that we're drawing up and signing contracts before anyone is clear what's supposed to be in them. I assume people like Google have had some expensive lawyers draw up their own interpretations, but smaller firms must be pulling it out of the air at the moment.

Posted
Yay, more reading! Looks like that might have some helpful advice though, thanks.

 

It's a bit crazy that we're drawing up and signing contracts before anyone is clear what's supposed to be in them. I assume people like Google have had some expensive lawyers draw up their own interpretations, but smaller firms must be pulling it out of the air at the moment.

 

Most of the clever ones are getting advice and marking where there is not enough info (or info published by the people they need it published by) so that it can sorted at a later date.

 

It is the ones that are doing nowt or who say it doesn’t apply to them (even though you know that staff have to login to access stuff)... those are the challenging ones.

Posted

Useful link, thanks @GrumbleDook

 

I'm hoping our processors will be happy to sign when asked, and some may well even help us out with template contracts as they will have them with their own (sub-)processors. I am concerned about those contracts we've already signed which will be in force in May - like many people on here, I'm sure, we run lots of our contracts from 1st September.

Posted

I was of the understanding that it's in the data processors interest to put these contracts in place, because the new rules make data controllers and data processors jointly liable for data breaches. They need to cover their arses legally now, where before it was the client / data controllers liability.

 

That was my hope anyway, that our various third party firms were going to approach us with new agreements!

Posted
I was of the understanding that it's in the data processors interest to put these contracts in place, because the new rules make data controllers and data processors jointly liable for data breaches. They need to cover their arses legally now, where before it was the client / data controllers liability.

 

You've got that backwards haven't you? Previously, it was only the processor who was liable in anything happened, now the controller is too, presumably because part of handling data responsibly is ensuring all third parties also act responsibly with the data we choose to give them.

Posted

No, previously the data controller was liable, now it is both.

 

The thing that sometimes confuses folk is that when it comes to person / home use firms like Microsoft are the data controller as you, the Data Subject, give them you data to let them provide you a service. They are also the data processor as they are doing the grunt work, or they may sub-contract work out to another data processor ... but the original firm has the responsibility and liability.

 

In a school, the data subjects (children, parents, staff) give the data to the school (the data controller) who will either process it themselves (the are the data processor) or will pass it onto someone else to process on their behalf (also a data processor), based on instructions the data controller gives.

 

In reality, schools are just interested in the outputs of the services and the inputs (what the data processor needs to deliver the service) tend to be decided on by the data processor.

 

Under the new arrangement liability will be jointly held, which is why Data Processors are having to look carefully at what they are asking for and the reasons behind it.

 

This brings up an interesting query ... would a glossary of terms be helpful, with some examples?

  • Thanks 1
  • 1 month later...
Posted

Sorry to hijack a thread but would a data processing contract be need for the likes of the IT help desk like fresh desk? As if, like many of us, we use the free edition would a company be likely to agree to a data processing contract if they are not getting paid?

 

Also, what about the likes of tools/apps staff use like Trello or Evernote? Would DPAs be needed for them as well? As sometimes attachments are forwarded or uploaded to them.

 

Is the onus on the data controller to produce a DPA or are the processors likely to have a standard one they use with many schools?

Posted
Sorry to hijack a thread but would a data processing contract be need for the likes of the IT help desk like fresh desk? As if, like many of us, we use the free edition would a company be likely to agree to a data processing contract if they are not getting paid?

 

Also, what about the likes of tools/apps staff use like Trello or Evernote? Would DPAs be needed for them as well? As sometimes attachments are forwarded or uploaded to them.

 

Is the onus on the data controller to produce a DPA or are the processors likely to have a standard one they use with many schools?

 

I've been taking the line that we need a DPA with anyone we expose personal data to, so in the case of helpdesk software I guess you'd have to evaluate whether you're putting anything personal in there. "Mary in 3A needs a new mouse", maybe not so sensitive. "Child XYZ is not appearing on the free school meals printout when they should", that is personal data. Same with any other third party service that sees your data.

 

I had assumed the data processors would want to update / implement DPAs, as they will now be jointly liable for data breaches, but I must say I've not heard squat from most of our contractors yet!

  • Thanks 1
Posted
.

 

This brings up an interesting query ... would a glossary of terms be helpful, with some examples?

 

Yes please.

 

Don't really know why I didn't say so six weeks ago....

Posted
Sorry to hijack a thread but would a data processing contract be need for the likes of the IT help desk like fresh desk? As if, like many of us, we use the free edition would a company be likely to agree to a data processing contract if they are not getting paid?

 

Also, what about the likes of tools/apps staff use like Trello or Evernote? Would DPAs be needed for them as well? As sometimes attachments are forwarded or uploaded to them.

 

Is the onus on the data controller to produce a DPA or are the processors likely to have a standard one they use with many schools?

Yes, you'll need an agreement. It should be part of their T&C's.

 

I'm not familiar with Trello, but I don't think the consumer version of Evernote would be suitable for personal data. Any system you use for storing or sharing data in a school should have an administrator in the school rather than lots of personal accounts. Otherwise the data controller doesn't have a means of controlling the data - bear in mind that they have a responsibility to maintain access to data as well as stop it from being leaked or held too long.

  • Thanks 1
Posted
The draft consultation by the ICO on this has only just closed so you won’t get a definitive answer yet, but you can review the draft guidance.

 

https://ico.org.uk/about-the-ico/ico-and-stakeholder-consultations/consultation-on-gdpr-guidance-on-contracts-and-liabilities-between-controllers-and-processors/

 

Regarding the contents of contracts with data processors, I'm just sitting down today to fire off emails to all our suppliers to request copies of their/our DPAs. My evaluation procedure will essentially be the checklist on page 27 of the draft ICO guidance mentioned above.

 

It's not the definitive answer yet, but it looks to be the best working document we'll get for a while!

  • Thanks 1
Posted
Regarding the contents of contracts with data processors, I'm just sitting down today to fire off emails to all our suppliers to request copies of their/our DPAs. My evaluation procedure will essentially be the checklist on page 27 of the draft ICO guidance mentioned above.

 

It's not the definitive answer yet, but it looks to be the best working document we'll get for a while!

 

Don't forget that some cloud service providers have already done a lot to provide guidance against DPA ... the DfE Cloud Service self-certification is a really good place to look.

  • Thanks 1
Posted
If you use a service that processes data you need a DPA. You cannot be compliant without it.

 

At what point is a service considered to be processing personal data? For example, there are several websites we use that just get sent a list of pupil's names & year groups. Will we need a DPA for all of these?

 

I'm assuming those that get given additional information like pupil emails, dates of birth etc. will need a DPA.

Posted
At what point is a service considered to be processing personal data? For example, there are several websites we use that just get sent a list of pupil's names & year groups. Will we need a DPA for all of these?

 

I'm assuming those that get given additional information like pupil emails, dates of birth etc. will need a DPA.

 

From the ICO

 

“Personal data means data which relate to a living individual who can be identified –

 

(a) from those data, or

 

(b) from those data and other information which is in the possession of, or is likely to come into the possession of, the data controller,

 

and includes any expression of opinion about the individual and any indication of the intentions of the data controller or any other person in respect of the individual.”

 

The names are personal data. You will need a DPA.

Posted
Which is the message we are hearing from a number of schools.

 

Especially as I assume this will extend to external coaches who are not employees, who take after school activities...

Posted
Especially as I assume this will extend to external coaches who are not employees, who take after school activities...

 

Yes, and I’m trying to put together more advice on this before we all break up.

Posted
Especially as I assume this will extend to external coaches who are not employees, who take after school activities...

 

Indeed. Basically, it extends to anyone who you tell anything to.

Posted
At what point is a service considered to be processing personal data? For example, there are several websites we use that just get sent a list of pupil's names & year groups. Will we need a DPA for all of these?

 

A point to consider with some of these services is that it's not just the information you share with them, but the information they create. For instance, we use MyMaths for maths homework, and whilst we've only shared class lists, those class lists are to create individual student users who then use the system and generate attainment and assessment data.

  • Thanks 3
Posted
A point to consider with some of these services is that it's not just the information you share with them, but the information they create. For instance, we use MyMaths for maths homework, and whilst we've only shared class lists, those class lists are to create individual student users who then use the system and generate attainment and assessment data.

 

So in this example would this make MyMaths a Data Processor and Controller? i.e because they are generating new data based on data provided? in which case they would need to cover all bases on the Contracts and liabilities lists?

 

I haven't been given any information as to who will be the DPO here but like many of you I'm starting work on things like this as it will be my leg work to do regardless of who becomes the DPO. I think I need to do a bit more reading on the ICO site.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...