Jump to content

Recommended Posts

Posted
So in this example would this make MyMaths a Data Processor and Controller? i.e because they are generating new data based on data provided? in which case they would need to cover all bases on the Contracts and liabilities lists?

 

I haven't been given any information as to who will be the DPO here but like many of you I'm starting work on things like this as it will be my leg work to do regardless of who becomes the DPO. I think I need to do a bit more reading on the ICO site.

 

That's a good question actually! Most of the contracts that I've read thus far are at pains to point out that you remain the data controller, you're merely using their system to generate the data. I don't know if they would be considered the data controller at any point in this process.

Posted

I have been reviewing mymaths i personally see them as the processor and end of the day they store the data somewhere on the cloud. We as the schol even though we generate the logins etc they still store on the cloud and thats run by mymaths or contracted out. I am going to send them a letter regarding service level agree to ensure we have all the required information to continue using their services.

 

We also use callparents and they have been absolutely brillient at giving the required information regarding GDPR

Posted
I have been reviewing mymaths i personally see them as the processor and end of the day they store the data somewhere on the cloud. We as the schol even though we generate the logins etc they still store on the cloud and thats run by mymaths or contracted out. I am going to send them a letter regarding service level agree to ensure we have all the required information to continue using their services.

 

We also use callparents and they have been absolutely brillient at giving the required information regarding GDPR

 

Off topic a bit, but I'm doing contract reviews at the moment. For info, MyMaths haven't updated their DPAs and Privacy Notices for GDPR compliance yet, it's still in progress. As seems to be the case for 90% of all other suppliers!

Posted
So in this example would this make MyMaths a Data Processor and Controller? i.e because they are generating new data based on data provided? in which case they would need to cover all bases on the Contracts and liabilities lists?

 

Interesting point. If that is the case, then lots of our DPs are also DCs - VocabExpress, GCSEPod, Kahoot...

Posted
That's a good question actually! Most of the contracts that I've read thus far are at pains to point out that you remain the data controller, you're merely using their system to generate the data. I don't know if they would be considered the data controller at any point in this process.

 

This is an interesting one.

 

There are definitions about the Data Controller and the Data Processor, adn their responsibilities.

 

From the ICO -

What responsibilities and liabilities do processors have in their own right?

If a processor determines the purpose and means of processing (rather than acting only on the instructions of the controller) then it will be considered to be a controller and will have the same liability as a controller.

 

At first sight, this would make it look like most EdTech suppliers would become data controllers, but it is not quite that simple.

 

If we take where it could be considered to be shared ... the school will always be the Data Controller, but where the Data Processor is then using the service as part of their own service directly to a group of people, e.g. parents who may have children across multiple schools.

 

But what about all the other times you get 'told' what needs to be processed? You, as a customer, have purchased the product / service and so have made the decision about whether or not you will allow it ... and *this* is why seeing the data sharing agreements is so important.

Posted
At first sight, this would make it look like most EdTech suppliers would become data controllers, but it is not quite that simple.

 

If we take where it could be considered to be shared ... the school will always be the Data Controller, but where the Data Processor is then using the service as part of their own service directly to a group of people, e.g. parents who may have children across multiple schools.

 

But what about all the other times you get 'told' what needs to be processed? You, as a customer, have purchased the product / service and so have made the decision about whether or not you will allow it ... and *this* is why seeing the data sharing agreements is so important.

 

In this specific example of MyMaths though, they are generating new data based on existing data i.e. usernames. As they have created this data (regardless if they are specifically told they can do this) then surely they must be considered a Data Controller as they have independently created this data. If however you sent them a csv stipulating what the usernames should be (or providing them with a means of obtaining e.g. email address to use for usernames) then they are just Processing data.

Posted

If we take where it could be considered to be shared ... the school will always be the Data Controller, but where the Data Processor is then using the service as part of their own service directly to a group of people, e.g. parents who may have children across multiple schools.

 

So, if we the school can see the additional data they generate (test scores, date last accessed, etc.) they're a Processor; if we can't see the additional data, they're a Controller? That sounds like a good rule of thumb. On that measure, pretty much all EdTechs except Google Apps and Groupcall are just Processors not Controllers too. Yes?

Posted
So, if we the school can see the additional data they generate (test scores, date last accessed, etc.) they're a Processor; if we can't see the additional data, they're a Controller? That sounds like a good rule of thumb. On that measure, pretty much all EdTechs except Google Apps and Groupcall are just Processors not Controllers too. Yes?

 

If they are generating any new data from it, they should be sharing it with you as that is likely to be one of the criteria for you using them in the firstplace ... It is if they set out what will be processed and how, and you don't have any choice ... then they can be considered to have some data controller responsibilities. These will be rare as, generally, you are choosing whether or not to use them at all as part of your procurement process.

 

- - - Updated - - -

 

If we have given the data to them then we are the controller and they must be the processors. So they never going to know names etc unless we give it them so we are the controller

 

Schools will *always* be the Data Controller for data they ask to be processed or asked to be generated.

  • Thanks 1
Posted

Having just waded my way through a template send to our school, and modified it for our purposes, one key thing seems to be missing...

 

I'm assuming we have to get some sort of acknowledgement that the processor actually agrees to our terms? We can't just send it out and think it's all OK if we don't hear back?!

Posted
Having just waded my way through a template send to our school, and modified it for our purposes, one key thing seems to be missing...

 

I'm assuming we have to get some sort of acknowledgement that the processor actually agrees to our terms? We can't just send it out and think it's all OK if we don't hear back?!

 

I think as a general rule, the Data Processing Agreement is something that forms part of your contract with the company. It's not for you to draw up and them to agree to, it's the T&Cs of what you've signed up to when buying / using their service.

Posted
I'm assuming we have to get some sort of acknowledgement that the processor actually agrees to our terms? We can't just send it out and think it's all OK if we don't hear back?!

 

This is where the signed data processing agreements come in.

Posted
I think as a general rule, the Data Processing Agreement is something that forms part of your contract with the company. It's not for you to draw up and them to agree to, it's the T&Cs of what you've signed up to when buying / using their service.

 

Understand that Dave, this is for companies we already have an existing contract with so it needs to be added in to the current agreement.

Posted
Understand that Dave, this is for companies we already have an existing contract with so it needs to be added in to the current agreement.

 

That's something which plays on my mind in my darker moments too ("what if an existing EdTech supplier refuses to sign our processing agreement mid-term?") then I remember they want to work with us and want us to renew, so it is unlikely they actually will refuse - unless you add some other weird clauses into your agreement, it will largely just reflect their current privacy policy anyway.

Posted
That's something which plays on my mind in my darker moments too ("what if an existing EdTech supplier refuses to sign our processing agreement mid-term?") then I remember they want to work with us and want us to renew, so it is unlikely they actually will refuse - unless you add some other weird clauses into your agreement, it will largely just reflect their current privacy policy anyway.

 

Hang on.... are you writing up your own Data Processing Agreements and sending them to suppliers, as well as the T&Cs on their contracts?

 

This sounds a bit OTT, and surely the big players like Capita or Google aren't going to sign up to the customers T&Cs.

Posted
Yeah you have to have an agreement with all companies and services and ones that don’t process data to state they don’t. You have to have a map of where your data is and where it’s being used or not.
Posted
Hang on.... are you writing up your own Data Processing Agreements and sending them to suppliers, as well as the T&Cs on their contracts?

 

This sounds a bit OTT, and surely the big players like Capita or Google aren't going to sign up to the customers T&Cs.

 

Haven't done much with Data Processing Agreements yet. To be honest, they confuse me a bit - the suppliers are already bound by their Ts&Cs and privacy policies (on which I've already done DPIAs and nothing scared me), so I'm not actually sure what we need to do re. processing agreements...

Posted
Haven't done much with Data Processing Agreements yet. To be honest, they confuse me a bit - the suppliers are already bound by their Ts&Cs and privacy policies (on which I've already done DPIAs and nothing scared me), so I'm not actually sure what we need to do re. processing agreements...

 

My understanding was that your contract / T&Cs with the company constituted your Data Processing Agreement.

 

It would seem a bit of an unnecessary doubling up and conflict to have two legal documents covering the same thing.

Posted
Yeah but those contacts that don’t have gdpr in mind are pointless and if your to data breach you wouldn’t stand a chance. As you won’t have found out certain info I show you an example. We will accept in terms and condition as we but we have to be proactive
Posted (edited)

This the sort of thing we have been sending out depending on the supplier the second part but the most useful is the top part.

 

As I’m sure you’re aware, the General Data Protection Regulation (GDPR) comes into force in May 2018. As part of our preparations we are conducting due diligence on all suppliers with which we share individuals’ personal data to make sure they, and therefore we, are compliant.

 

We would appreciate it if you could answer the following questions to help us do this:

 

 

  • What action are you taking to prepare for the GDPR?
  • What technical and organisational security measures do you have in place to protect personal data?
  • What policies and procedures do you have in place to protect personal data?
  • How secure are your systems?
  • Do you have any information management accreditation?

 

We could expand this more but by getting this information that would mean we have made the effort to get information and filed under the supplier so if we were ever ask to provide information about what our processes do with data we could show them this. So far i have a number of suppliers which have answered the questions and we are happy.

 

In addition, as you process personal data that we share with you, we need to create a contract to set out:

 

 

  • The subject matter, duration, nature and purpose of the processing
  • The type of personal data being processed
  • The categories of the data subjects
  • The obligations and the rights of the data controller (the school)
  • That the data processer (you, the supplier) processes data only on the documented instructions of the school
  • That the people who process the data are committed to confidentiality
  • That you take measures to ensure secure processing
  • That you will not engage another processor without prior written authorisation from the school, and that if you do so, that processor will also be bound by the same data protection conditions as are in your contract with us
  • That you help the school comply with requirements regarding the data rights of individuals (e.g. to access, delete or rectify data), secure processing, the reporting and communication of data breaches, and the conducting of impact assessments where relevant
  • That you delete or return the personal data to the school at the end of your provision of services
  • That you make information available to us to demonstrate your compliance with the obligations in our contract, and allow us or a third party instructed by us to conduct audits and inspections

 

Kindly confirm that you are willing to meet or speak with us to arrange the updating of our contract, and we will be in touch in due course.

Edited by tinkerbotsict
  • Thanks 1
Posted
Are we confusing Data Processing Agreements and Data Protection Impact Assessments here? The questions @tinkerbotsict poses are things we reviewed under our DPIAs and most of the information was available in their privacy policies so we didn't need to contact them. Where the information was absent, we contacted them and have kept their responses.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...