Jump to content

Recommended Posts

Posted

Do you need a DPA for a company where you use their software but the data doesn't leave your servers? e.g. Capita SIMS. Their software manipulates the data but doesn't leave our server.

 

Other cases such as 4Matrix. Software processes the data but doesn't leave our server?

Posted (edited)
Software processes the data but doesn't leave our server?

 

You could say "are you sure it doesn't leave?". Granted, it doesn't need to leave, but can you be certain there isn't a backdoor written in by an unscrupulous company? With SIMS, we can probably trust there isn't, but could we say that for all the companies we work with?

 

Also, and more realistically, you need to consider their support processes - do they ever remotely connect to your server when you log a ticket? Do they ask for exports so they can work on a problem?

 

What about future updates or new version? Might one of those start extracting data?

 

Personally, I would get a statement from the company confirming the data doesn't leave site.

Edited by enjay
  • Thanks 1
Posted
Support is something you'd potentially need a DPA for. The amount of times I've had to upload SIMS databases to Capita in the past to diagnose and fix errors.
Posted
The other aspect is that for some solutions, although they are hosted and run on your own servers, you might not understand what data is processed and how. You need assistance with understanding that side of things.
Posted
Exactly the issue which why we need to audit our school know what data is we store what we share and who with and what they do with it etc also how they protect our data

 

Did you not do that anyway when signing up for a service from a new company?

Posted
My school won’t have bothered asking that question but me knowing what do tech wise I know our systems are secure with encryption and that have suitable security but when you only one who understands technology it can had to explain
Posted
My school won’t have bothered asking that question but me knowing what do tech wise I know our systems are secure with encryption and that have suitable security but when you only one who understands technology it can had to explain

 

I hear that. Having been aware of a few skeletons here when I started, one of the things I made sure I did was a review of each of our service providers as we renewed - if only I'd kept records of that, I could have saved myself some time with the DPIAs I've just done for GDPR-prep!

Posted
But until I’m officially the data protection officer I can’t do that I made sure the IT system upto scratch as I deal with the tech support we have but everything else I can’t touch yet but I’m aware that the biggest job and educating staff
Posted
But until I’m officially the data protection officer

 

You're the IT Manager, you can't officially be the Data Protection Officer...

Posted
Not it manager I don’t deal with tech side I just play middle ground I make sure the head and business manager understand what the IT people are saying. I also fix the odd whiteboard, sound I don’t have access to servers or anything like that I go off what recommended us my understanding to accept it or not then feedback to head which don’t understand
  • 2 months later...
Posted

I had a query today that I wondered if anyone could advise what they would do. Girls are due to get their HPV vaccination and the NHS employee doing the admin for it contacted us to ask for girls names, dob and addresses.

 

Do we just send them to them via email or would you want a data processing agreement in place or at least confirmation for why they require dob and addresses? I'm guessing to update their medical records but wasn't sure what "recommended" advice would be. Spent so long looking at systems we have in place where it's easier to get a contract or data processing agreement in place.

 

I know this isn't strictly IT related but interested to see what other people would advise. Our privacy policy does state we may share data with relevant healthcare providers.

 

Thanks

Posted

Only send the info via email if you're encrypting/securing it, of course. Otherwise, no reason not to share - NHS need it to verify whether the children have already been vaccinated elsewhere and to update records afterwards; your privacy policy says you will share it; it probably comes under legal obligation so consent to share not needed.

 

No idea if you need separate consent from the parents in order to get the child vaccinated while in school, but the NHS staff should know about that.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...