claireadams Posted February 27, 2018 Posted February 27, 2018 So, I don't work in Education anymore but I do need to shoot off some emails to our hosted systems to find out if they are compliant, and prove via a policy/statement. Would you list a load of questions and ask them for evidence in the first case eg: Where are your data and applications stored? Is that data ever moved out of the EEA? Do you ever transfer data between data centers outside of the EU? Do you always inform me when my data is being transferred? Do you have a Data Protection Officer? What data controls and risk management processes do you have in place? What is your formal procedure for reporting out on data leaks? How do you manage the version release process on your platform to ensure adequate level of data protection? Who can access my data, under what circumstances and what can they see? Is this access tracked? Do you currently adhere to Binding Corporate Rules? Do you have measures in place to become GDPR compliant in time for May 2018? Or would you ask them if they are compliant and could they provide a statement/policy as evidence then question more as above if you aren't happy with the response?
ShellfishClive Posted February 27, 2018 Posted February 27, 2018 I think both ways work, if you need proof that they are complient you're better off just asking the questions and getting responses. That way you are more thorough.
rom1984 Posted February 27, 2018 Posted February 27, 2018 I'd either look on their website for their privacy policy or if it isn't online ask for it, you may find most of your questions are addressed in the privacy policy. Then if there are any areas that aren't addressed in the policy you can specifically ask them.
Sylv3r Posted February 27, 2018 Posted February 27, 2018 We struggled to get a list of answers to questions asked. Most of the companies I e-mailed just gave me a generic response back.
ShellfishClive Posted February 28, 2018 Posted February 28, 2018 We struggled to get a list of answers to questions asked. Most of the companies I e-mailed just gave me a generic response back. I don't think you are liable then. They will have to give you clear answers and instructions on what they want otherwise they fail, not you.
rom1984 Posted February 28, 2018 Posted February 28, 2018 I don't think you are liable then. They will have to give you clear answers and instructions on what they want otherwise they fail, not you. If the school is the data controller and they still choose to use that supplier though, then the school would still be liable for any breaches. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now