Jump to content

Recommended Posts

Posted (edited)

I'm writing the IT Teams list of personal data collected and created by us, the purpose it is used for and who it is shared with.

 

eg:

Data Type

Document metadata (number of documents, ownership, access permissions, creation time/date, access time/date , deletion time/date, edit time/date, document GUID, document location, IP address edited from)

Purpose of data retention:

Diagnostics, Security, behaviour management, disciplinary processes,Capacity management

Where data originated:

Generated by IT systems when user interacts with a document

Who the data is shared with:

Google Inc

 

 

 

First question is is this the format that I need, or does it need more detail. Second question is regarding external contractors who come on site. If the data is accessed remotely do I need to list these contractors and have GDPR compliant contracts with all of them or does this only concern those who hold the data ?

Edited by mjk
Posted
Second question is regarding external contractors who come on site. If the data is accessed remotely do I need to list these contractors and have GDPR compliant contracts with all of them or does this only concern those who hold the data ?

 

As I see it, how/where data is accessed doesn't matter. I wouldn't let contractors or support providers near our data without assurances about how it is handled.

Posted
As I see it, how/where data is accessed doesn't matter. I wouldn't let contractors or support providers near our data without assurances about how it is handled.

 

An example would be a contractor who set up an maintains our external gate system: They don't hold any data or take it off-site but they have access to personal data when they come on site because the system syncs from our SIMS.

Posted
An example would be a contractor who set up an maintains our external gate system: They don't hold any data or take it off-site but they have access to personal data when they come on site because the system syncs from our SIMS.

 

So they have access to personal data? In that case, you need to check they're compliant. It really is that simple. You need measures in place to ensure they don't access everyone's home addresses then mail-shot them with adverts for home security systems, for example.

  • Thanks 1
Posted
ok. Makes perfect sense to me. Don't think our sites manager will like the answer.

 

Perhaps not. Would they prefer the £20m fine instead?

 

Ensuring compliance in that instance is probably fairly simple - put together an agreement form which states they will only access the data for the purpose of supporting the gate system and will not take any data off site. Any data printed off or written down while on site will be securely destroyed or returned to you for disposal.

Posted

I think the problem is with who creates the contract, not whether the site manager wants to be complaint.

We already have GDPR compliant contracts from Google et al, but with tiny local companies are they expected to create the contract or are we ?

Posted
We already have GDPR compliant contracts from Google et al, but with tiny local companies are they expected to create the contract or are we ?

 

You're the Data Controller, so I think it is down to you to write a contract for your appointed Data Processors telling them what you expect of them.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...