enjay Posted January 15, 2018 Posted January 15, 2018 One of our ed tech providers has sent me their data protection policy. It is full of statements like "data held electronically should be password protected" but not IS password protected. Am I being overly fussy on the grammar, or should I be concerned?
jthompson Posted January 15, 2018 Posted January 15, 2018 If it said "might" or "may", then I'd worry, but my interpretation of "should" is that if it isn't, they're not abiding by their policy.
enjay Posted January 15, 2018 Author Posted January 15, 2018 Send over and I’ll review. Thanks. Can you PM me your email address, I can't add attachments to PMs and I don't think it fair to post their policy in open forum.
GrumbleDook Posted January 15, 2018 Posted January 15, 2018 It is worth saying that we need to think about the difference between when we are given privacy notices by suppliers based on B2B (ie we are their customer) and when we are engaging with them as a data processor, following our instructions.
enjay Posted January 15, 2018 Author Posted January 15, 2018 It is worth saying that we need to think about the difference between when we are given privacy notices by suppliers based on B2B (ie we are their customer) and when we are engaging with them as a data processor, following our instructions. I'm not sure I see what makes this company a controller when our other ed tech suppliers are just processors - unless of course lots of ed techs are also controllers and I've missed it. With this company, we have given them student names, they have created logins and then the students access information on the site. How is that different to Vocab Express or Mathswatch?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now