Jump to content

Recommended Posts

Posted

Simple question I hope

 

Our LA has decided to appoint a central Data Processing Officer to serve all (113?) local schools. That person isn't appointed yet.

 

In reference to the ICO guidelines below, who should we data processors be getting this written contract from?

https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/accountability-and-governance/contracts/

 

"Whenever a controller uses a processor it needs to have a written contract in place."

 

I presume the directive to provide pupil and staff data doesn't come from our head teacher. Is it the local authority or a government department? Is it actually devolved to our HT?

 

Thanks

Posted

It would be the data controller that provides the contract to the data processor.

 

In most cases I would imagine the school would be the data controller so it would be the school that provides the contract to the data processor. Examples of this would be if the school uses a third party to process any personal data (for example text message service, child protection service, payment services)

 

There may be times when the school is acting as a data processor on behalf of a controller in which case it would be up to the controller to provide the contract to the school. I think if the LA asks the school to provide it with certain data every month then this could be an example of the LA being the controller and the school being the processor.

 

 

This link gives some guidance on the difference between a controller and a processor and how to determine if the school is either;

 

https://ico.org.uk/media/for-organisations/documents/1546/data-controllers-and-data-processors-dp-guidance.pdf

 

 

The contract would be between "organisation to organisation" rather than "organisation to individual" if that makes sense!

  • Thanks 1
Posted
Many thanks rom. That seems clear. The bulk of our processing carried out in SIMS must be prescribed by the local authority as they chose to buy that for all schools and take funds directly.
  • Thanks 1
  • 2 weeks later...
Posted (edited)
We've recently received a document asking for Docu-sign sign-off from our MIS provider (not SIMS) with what they refer to as a GDPR Addendum. Its is marked as coming from their DPO. Apart from the fact they've sent it to our exams officer (completely the wrong person), surely this is the processor asking the controller to agree to their terms. I think there is another thread on this sort of thing in relation to Google's T&C's. Additionally this addendum says continuing to use their systems and not signing that you will 'have deemed to agree with it'. Doesn't that contradict another part of GDPR? Thoughts? Edited by Ditto
Posted

The school is always the Data Controller up until the point the data is shared to another agreed party as a permanent transference (e.g. the DfE).

 

In other circumstances, the school is the Data Controller and the company processing it on behalf of the school is the data processor. The data processor will, as @rom1984 points out, will update their contract or update a schedule in it or add an addendum, to provide the data sharing agreement.

 

If *you* set out what is being processed then they may ask you to input that before it is updated.

 

An example would be ZenDesk (who use the Model Contract Clauses) will ask you to describe what you are asking them to process as you jointly put together the DSA.

 

There are some scenarios where you could end up with being a joint Data Controller ... and that could be where the data subject has a direct relationship with both you and the supplier ...

 

By rights, you are deciding what is being processed and when a processor dictates that you agree to their terms then the initial instinct is that you have no choice ... making them a joint Data Controller. However, you do have a choice ... you have a market choice and can go elsewhere.

 

Once you understand that, you realise that yes ... a data processor can say they need to work with x, y and z data ... as it is to deliver a service that requires it. If you don’t want to ... then other suppliers are available.

 

So. A summary. Where you are making the choice about what is being processed a good data processor will ask you what *you* are putting in and giving you a chance to put it within the contract or DSA. Where a data processor needs set data for their service to work they will be transparent about it in their DSA and/or contracts/T&Cs. Where they use a sub-processor they will be clear (including where sub-processors may use contractors and the like ... ) and make sure any sub-processors go through them and not directly to you (unless instructed).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...