mikemcsharry Posted February 6, 2018 Posted February 6, 2018 I can't find a definitive answer to this, maybe you folks can help.. Microsoft claim (and Google claim similar) that when you save to 365 it's immediately duplicated over several servers and also backed up. I've been asked by a very knowledgeable bursar 'how do we know that the data is retained in UK? if it's retained / copied elsewhere what does that do to GDPR compliance". This is one of the schools who still enjoy the benefit of SIMS ID and their response of 'we'll have a document in April' isn't really helping. Does anyone know the answer to this? With UK out of EU soon, does that also mean the EU/US safe harbour agreement is meaningless?
Marci Posted February 6, 2018 Posted February 6, 2018 (edited) Looked at https://products.office.com/en-GB/where-is-your-data-located ?? Safe Harbour agreement was declared invalid and rendered meaningless in 2015, replaced with Privacy Shield. Edited February 6, 2018 by Marci 1
mikemcsharry Posted February 6, 2018 Author Posted February 6, 2018 Brilliant link Marci - thank you for that.
foofighterjim Posted February 6, 2018 Posted February 6, 2018 I've been asked by a very knowledgeable bursar 'how do we know that the data is retained in UK? if it's retained / copied elsewhere what does that do to GDPR compliance". Have a look at: https://www.microsoft.com/en-us/trustcenter/privacy/where-your-data-is-located It should state (somewhere) in your global admin account what geo location your data is stored.
mikemcsharry Posted February 6, 2018 Author Posted February 6, 2018 Hi Foofighterjim - thank you for that - the link from marci had a pop up which showed the detail about checking the admin account
GrumbleDook Posted February 6, 2018 Posted February 6, 2018 With cloud services we also have to remember that you need where providers are working under the EU Model Contract Clauses rather than Privacy Shield. Both Microsoft and Google can cover that, but as already mentioned the data residency can be sorted for you in O365. To be honest, the bigger risk is not where it is stored, but where it is accessed from ... staff mobile devices with no pin codes, laptops that have no timeout to screensaver and lockout ... you know the sort of thing.
foofighterjim Posted February 7, 2018 Posted February 7, 2018 To be honest, the bigger risk is not where it is stored, but where it is accessed from ... staff mobile devices with no pin codes, laptops that have no timeout to screensaver and lockout ... you know the sort of thing. Some of this can be mitigated with the O365 security centre but it is really basic. It looks to me; to really have control of the data you need InTune.
mikemcsharry Posted February 7, 2018 Author Posted February 7, 2018 Thanks Tony.. must stop leaving laptops / reports etc etc on train... 1
free780 Posted February 7, 2018 Posted February 7, 2018 You need Ems which gives you Azure Information Protection. You can deploy Windows Information Protection via SCCM. Of course encrypt your laptops. But as Tony says an Auto lock is really needed.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now