mjk Posted November 8, 2017 Posted November 8, 2017 (edited) I'm writing the IT Teams list of personal data collected and created by us, the purpose it is used for and who it is shared with. eg: Data Type Document metadata (number of documents, ownership, access permissions, creation time/date, access time/date , deletion time/date, edit time/date, document GUID, document location, IP address edited from) Purpose of data retention: Diagnostics, Security, behaviour management, disciplinary processes,Capacity management Where data originated: Generated by IT systems when user interacts with a document Who the data is shared with: Google Inc First question is is this the format that I need, or does it need more detail. Second question is regarding external contractors who come on site. If the data is accessed remotely do I need to list these contractors and have GDPR compliant contracts with all of them or does this only concern those who hold the data ? Edited November 8, 2017 by mjk
enjay Posted November 9, 2017 Posted November 9, 2017 Second question is regarding external contractors who come on site. If the data is accessed remotely do I need to list these contractors and have GDPR compliant contracts with all of them or does this only concern those who hold the data ? As I see it, how/where data is accessed doesn't matter. I wouldn't let contractors or support providers near our data without assurances about how it is handled.
mjk Posted November 10, 2017 Author Posted November 10, 2017 As I see it, how/where data is accessed doesn't matter. I wouldn't let contractors or support providers near our data without assurances about how it is handled. An example would be a contractor who set up an maintains our external gate system: They don't hold any data or take it off-site but they have access to personal data when they come on site because the system syncs from our SIMS.
enjay Posted November 10, 2017 Posted November 10, 2017 An example would be a contractor who set up an maintains our external gate system: They don't hold any data or take it off-site but they have access to personal data when they come on site because the system syncs from our SIMS. So they have access to personal data? In that case, you need to check they're compliant. It really is that simple. You need measures in place to ensure they don't access everyone's home addresses then mail-shot them with adverts for home security systems, for example. 1
mjk Posted November 10, 2017 Author Posted November 10, 2017 ok. Makes perfect sense to me. Don't think our sites manager will like the answer.
enjay Posted November 10, 2017 Posted November 10, 2017 ok. Makes perfect sense to me. Don't think our sites manager will like the answer. Perhaps not. Would they prefer the £20m fine instead? Ensuring compliance in that instance is probably fairly simple - put together an agreement form which states they will only access the data for the purpose of supporting the gate system and will not take any data off site. Any data printed off or written down while on site will be securely destroyed or returned to you for disposal.
mjk Posted November 10, 2017 Author Posted November 10, 2017 I think the problem is with who creates the contract, not whether the site manager wants to be complaint. We already have GDPR compliant contracts from Google et al, but with tiny local companies are they expected to create the contract or are we ?
enjay Posted November 10, 2017 Posted November 10, 2017 We already have GDPR compliant contracts from Google et al, but with tiny local companies are they expected to create the contract or are we ? You're the Data Controller, so I think it is down to you to write a contract for your appointed Data Processors telling them what you expect of them.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now