Jump to content

Recommended Posts

Posted

I've been tasked with emailing all our "data processors"!

 

I was going to just confirm what data I believe they "process" that is ours and then confirm that they ONLY process it in accordance with our wishes and that they do not sell it to any 3 parties.

 

Is there anything else I need to confirm or request?

 

Do I need to get them to sign a formal contract?

 

Thanks.

Posted

I believe we will need formal contracts with processors yes. Our wish is that processors will sign our contracts, however in practice I suspect we will need to agree to theirs.

 

I'm contacting companies this week as well. I intended to start the ball rolling with the following

 

What information do you hold on our subjects

What actions are you taking to prepare for GDPR

What technical and organisational security measures are in place to protect data

What policies and procedures are in place and how do they ensure they are followed

Who has access to the data regarding our subjects

Where is the data stored regarding our subjects

 

Now much of this was probably covered before we subscribed to a service under the DPA, however I think it is best to double check moving forward.

 

Looking forward to hearing everyone else's input.

Posted

I think we need formal contracts, although I'm not entirely sure why - we already have a signed/clicked-on agreement with them, and they have a published privacy and data handling policy. I'm not sure what a new contract would say which these don't cover...

 

As for what to check, I took the ICO's data processors checklist (page 26 of https://ico.org.uk/media/about-the-ico/consultations/2014789/draft-gdpr-contracts-guidance-v1-for-consultation-september-2017.pdf), and checked their privacy policies against that, emailing them asking them to fill in any gaps.

Posted
I'm sure most comapnies will just post a statement on their website rather than replying to individual emails.

 

https://www.educationcity.com/sites/default/files/Cloud_Software_Services_for_Schools_Checklist_EducationCity_Ltd.pdf

 

This statement will be updated before GDPR deadline to reflect new legislation.

 

Possibly right...but that does n't help us if we believe we need to enter in to a contract...

 

I've had the following responses back this morning:

 

Room Booking System

Hi,

 

Our products are fully compliant with the Data Protection Act 1998, and all other current relevant regulation. We are currently assessing the implications of the introduction of General Data Protection Regulation (GDPR) and will ensure that any changes required will be in place before GDPR comes into effect in May 2018.

 

Our current Data Protection Statements can be found by following these links:

 

Room Booking System

 

Parents Evening System

 

If you have any other questions, please let me know.

 

Yours sincerely

 

&

 

OverNet

Hi,

 

We do not yet have an agreement.

I believe our team is currently working on GDPR and so if any agreement is required they will be in touch.

 

Regards,

Claudio.

 

 

So many companies are not exactly ahead of the game!

Posted

and this one more positive from Tucasi:

 

 

Many thanks for the email. Below is Tucasi's statement on GDPR:

 

Tucasi will continue to be bound by UK data protection law, and will fully comply with its responsibilities under GDPR. We will be making organisational and product changes to ensure we, and our customers, remain compliant with data protection law. Below is a brief overview of the main changes we are making:

 

Organisational:

 

Tucasi has engaged with solicitors and the Information Commissioners Office (ICO) to assist Tucasi with ensuring its GDPR compliance, and have started implementing organisational changes to ensure we are compliant by the GDPR deadline of May 2017.

 

Tucasi will be approaching schools early in 2018 with data processor contracts, that will set our responsibilities, liabilities, and commitments with regard to the processing of data. All clauses in our data processor contracts will be passed on to our sub-processor, by way of sub-processor contracts. Tucasi will be updating its privacy policy in line with GDPR. All required information will be presented to end users (parents and users of Tucasi applications) at the point of data collection. Tucasi will provide schools with information flows, including a list of sub-processors to enable schools to perform a DPIA (Data Protection Impact Assessment). Alongside this, Tucasi will maintain its own record of data processing activities and DPIAs.

 

Product:

 

Tucasi will be implementing changes to our applications to assist our customers with their own GDPR compliance. Our Development Team have started designing and implementing changes. The main enhancements to our product are:

 

Scopay.com (Online Payment Website)

 

- Right to be forgotten - Functionality will be added to our online payment website to enable parents to close their account, and have any personal data removed.

- Updated privacy statements will be added to the website.

 

Schools Cash Office (v 2.4)

- Retention – A secure erasure of data will be implemented into Schools Cash Office 2.4

- Subject Access Requests – Schools Cash Office does provide reports that can be used to respond to Subject Access Requests

- Data Portability – Functionality to export data in a machine readable format will be added to Schools Cash Office

 

 

Glossary of terms used in this email:

 

Data Controller – The natural or legal person, public authority, agency or any other body which alone or jointly with others determines the purposes and means of the processing of personal data (The School)

Data Processor – An entity that processes personal data under the controller’s instruction (Tucasi)

Data Processor contracts – A written contract between the Data Controller and the Data Processor. The contract lists responsibilities and liabilities.

Information Flows – A description of the data items (e.g. name, email address) processed, for what purpose it is processed, any sub processors used, who has access to data, location of data, format of data and security controls surrounding data.

Data Protection Impact Assessment – An impact assessment of the data being processed; enabling an organisation to identify risk and apply mitigating controls to minimise privacy risks.

ICO – Information Commissioner’s Office; the UK’s independent authority set up to uphold information rights in the public interest

 

Kind Regards

 

Will Dawe

Customer Support Analyst

Tucasi Ltd

Posted

Hi folks

 

I am in the process or looking into the GDPR minefield.

 

Was wondering if anyone has come across some kind of central register of GDPR authorised companies. I have looked at the ICO and the have a register of Data Processors, but according to the ICO after May it will not be necessary to register with the ICO.

 

Any thoughts?

Posted
Hi folks

 

I am in the process or looking into the GDPR minefield.

 

Was wondering if anyone has come across some kind of central register of GDPR authorised companies. I have looked at the ICO and the have a register of Data Processors, but according to the ICO after May it will not be necessary to register with the ICO.

 

Any thoughts?

 

GDPR authorised for what?

Surely that's just a list of companies, period.

Posted
Just went with GDPRis for our data maps, they have a good list of our software/system suppliers so most information ready for us. Thought it was reasonably priced too for all it does.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...