kennysarmy Posted January 23, 2018 Posted January 23, 2018 I've been tasked with emailing all our "data processors"! I was going to just confirm what data I believe they "process" that is ours and then confirm that they ONLY process it in accordance with our wishes and that they do not sell it to any 3 parties. Is there anything else I need to confirm or request? Do I need to get them to sign a formal contract? Thanks.
IrritableTech Posted January 23, 2018 Posted January 23, 2018 I believe we will need formal contracts with processors yes. Our wish is that processors will sign our contracts, however in practice I suspect we will need to agree to theirs. I'm contacting companies this week as well. I intended to start the ball rolling with the following What information do you hold on our subjects What actions are you taking to prepare for GDPR What technical and organisational security measures are in place to protect data What policies and procedures are in place and how do they ensure they are followed Who has access to the data regarding our subjects Where is the data stored regarding our subjects Now much of this was probably covered before we subscribed to a service under the DPA, however I think it is best to double check moving forward. Looking forward to hearing everyone else's input.
Andycat Posted January 23, 2018 Posted January 23, 2018 I was hoping that the central spreadsheet on here was going to provide this info for all of us?
enjay Posted January 24, 2018 Posted January 24, 2018 I think we need formal contracts, although I'm not entirely sure why - we already have a signed/clicked-on agreement with them, and they have a published privacy and data handling policy. I'm not sure what a new contract would say which these don't cover... As for what to check, I took the ICO's data processors checklist (page 26 of https://ico.org.uk/media/about-the-ico/consultations/2014789/draft-gdpr-contracts-guidance-v1-for-consultation-september-2017.pdf), and checked their privacy policies against that, emailing them asking them to fill in any gaps.
kennysarmy Posted January 24, 2018 Author Posted January 24, 2018 Surely we're not all meant to create our OWN contracts? There must be something "standard" which we tweak for our own suppliers?
atcoates Posted January 24, 2018 Posted January 24, 2018 (edited) I'm sure most comapnies will just post a statement on their website rather than replying to individual emails. https://www.educationcity.com/sites/default/files/Cloud_Software_Services_for_Schools_Checklist_EducationCity_Ltd.pdf This statement will be updated before GDPR deadline to reflect new legislation. Edited January 24, 2018 by atcoates
kennysarmy Posted January 25, 2018 Author Posted January 25, 2018 I'm sure most comapnies will just post a statement on their website rather than replying to individual emails. https://www.educationcity.com/sites/default/files/Cloud_Software_Services_for_Schools_Checklist_EducationCity_Ltd.pdf This statement will be updated before GDPR deadline to reflect new legislation. Possibly right...but that does n't help us if we believe we need to enter in to a contract... I've had the following responses back this morning: Room Booking System Hi, Our products are fully compliant with the Data Protection Act 1998, and all other current relevant regulation. We are currently assessing the implications of the introduction of General Data Protection Regulation (GDPR) and will ensure that any changes required will be in place before GDPR comes into effect in May 2018. Our current Data Protection Statements can be found by following these links: Room Booking System Parents Evening System If you have any other questions, please let me know. Yours sincerely & OverNet Hi, We do not yet have an agreement. I believe our team is currently working on GDPR and so if any agreement is required they will be in touch. Regards, Claudio. So many companies are not exactly ahead of the game!
ITGuyWestMidlands Posted January 25, 2018 Posted January 25, 2018 Sims (for Ssm services) point you to their privacy notice also
kennysarmy Posted January 25, 2018 Author Posted January 25, 2018 and this one more positive from Tucasi: Many thanks for the email. Below is Tucasi's statement on GDPR: Tucasi will continue to be bound by UK data protection law, and will fully comply with its responsibilities under GDPR. We will be making organisational and product changes to ensure we, and our customers, remain compliant with data protection law. Below is a brief overview of the main changes we are making: Organisational: Tucasi has engaged with solicitors and the Information Commissioners Office (ICO) to assist Tucasi with ensuring its GDPR compliance, and have started implementing organisational changes to ensure we are compliant by the GDPR deadline of May 2017. Tucasi will be approaching schools early in 2018 with data processor contracts, that will set our responsibilities, liabilities, and commitments with regard to the processing of data. All clauses in our data processor contracts will be passed on to our sub-processor, by way of sub-processor contracts. Tucasi will be updating its privacy policy in line with GDPR. All required information will be presented to end users (parents and users of Tucasi applications) at the point of data collection. Tucasi will provide schools with information flows, including a list of sub-processors to enable schools to perform a DPIA (Data Protection Impact Assessment). Alongside this, Tucasi will maintain its own record of data processing activities and DPIAs. Product: Tucasi will be implementing changes to our applications to assist our customers with their own GDPR compliance. Our Development Team have started designing and implementing changes. The main enhancements to our product are: Scopay.com (Online Payment Website) - Right to be forgotten - Functionality will be added to our online payment website to enable parents to close their account, and have any personal data removed. - Updated privacy statements will be added to the website. Schools Cash Office (v 2.4) - Retention – A secure erasure of data will be implemented into Schools Cash Office 2.4 - Subject Access Requests – Schools Cash Office does provide reports that can be used to respond to Subject Access Requests - Data Portability – Functionality to export data in a machine readable format will be added to Schools Cash Office Glossary of terms used in this email: Data Controller – The natural or legal person, public authority, agency or any other body which alone or jointly with others determines the purposes and means of the processing of personal data (The School) Data Processor – An entity that processes personal data under the controller’s instruction (Tucasi) Data Processor contracts – A written contract between the Data Controller and the Data Processor. The contract lists responsibilities and liabilities. Information Flows – A description of the data items (e.g. name, email address) processed, for what purpose it is processed, any sub processors used, who has access to data, location of data, format of data and security controls surrounding data. Data Protection Impact Assessment – An impact assessment of the data being processed; enabling an organisation to identify risk and apply mitigating controls to minimise privacy risks. ICO – Information Commissioner’s Office; the UK’s independent authority set up to uphold information rights in the public interest Kind Regards Will Dawe Customer Support Analyst Tucasi Ltd
oddgical Posted January 26, 2018 Posted January 26, 2018 Hi folks I am in the process or looking into the GDPR minefield. Was wondering if anyone has come across some kind of central register of GDPR authorised companies. I have looked at the ICO and the have a register of Data Processors, but according to the ICO after May it will not be necessary to register with the ICO. Any thoughts?
tinkerbotsict Posted January 26, 2018 Posted January 26, 2018 If any of you are members of the school bus website they have create SLA agreement you can edit and use. It’s really good we going to use it.
synaesthesia Posted January 26, 2018 Posted January 26, 2018 Hi folks I am in the process or looking into the GDPR minefield. Was wondering if anyone has come across some kind of central register of GDPR authorised companies. I have looked at the ICO and the have a register of Data Processors, but according to the ICO after May it will not be necessary to register with the ICO. Any thoughts? GDPR authorised for what? Surely that's just a list of companies, period.
forkies Posted January 26, 2018 Posted January 26, 2018 Just went with GDPRis for our data maps, they have a good list of our software/system suppliers so most information ready for us. Thought it was reasonably priced too for all it does.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now