Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

I am struggling to find a clear answer to this one... If we are using a third party company whose data centres are based outside the EU - what additional measures do we need to take to ensure compliance with GDPR?

 

Are we still able to use 'Public interest' as our lawful basis if this is a day to day function required to run our school?

Posted

Does the country have an EU adequacy decision, if so you can transfer to these countries as you would within the EU. (Andorra, Argentina, Switzerland, Faroe Islands, Guernsey, Isreal, Isle of Man, Jersey, Uruguay, New Zealand and Canada.)

 

Also if the company is in the US then they can self certify to the privacy shield.

 

Article 46 says you can transfer the data to a third country that does not have an adequacy decision only if you provide appropriate safeguards and on the condition that enforceable data subject rights and effective legal remedies are available. I think appropriate safeguards would need to be a contract between the controller and processor with standard data protection clauses and I think the ICO would need to approve the clauses. (I'm not 100% on this bit though)

 

 

There are derogations in place, such as you can transfer the data on the bases of consent but it is explicit that public authorities can not rely on consent or contract derogation. Infrequent transfers can take place but again the controller must not be a public authority.

  • Thanks 1
Posted

Thanks for the response @rom1984 - there are a couple of US companies we currently use.

 

Just to confirm if a company self certifies to the privacy shield are they complaint with GDPR or would we still be required to create a contract between ourselves and the company?

 

I know one company certainly is certified under the EU-US Privacy Shield but another may not be.

 

 

Posted

Yeah the company that self certifies to the privacy shield would be Ok to use in regards to the GDPR.

 

My understanding is that because the US company has adhered to an approved code of conduct or approved certification mechanism (i.e the privacy shield) then that demonstrates sufficient guarantees that they will implement appropriate technical and organisations measures and the data subject would have enforceable rights and effective legal remedies through the Federal Trade Commission who oversee the Privacy Shield.

  • Thanks 1
Posted
Article 46 says you can transfer the data to a third country that does not have an adequacy decision only if you provide appropriate safeguards and on the condition that enforceable data subject rights and effective legal remedies are available. I think appropriate safeguards would need to be a contract between the controller and processor with standard data protection clauses and I think the ICO would need to approve the clauses. (I'm not 100% on this bit though)

 

The highlighted text is the sticking point we have with a couple of processors. They are outside the EEA, haven't self-certified to Privacy Shield etc. but their privacy policy ticks all the right boxes about how they handle data. Are we okay to use them, or should we stop since there is no legal recourse should they mess up?

Posted

How big of a pain would it be to stop using them? If they aren't offering something critical I'd be tempted to stop using them. As you say the issue would be if something went wrong you'd be limited to what legal remedies you can do to enforce them of your rights.

 

Also you'd have to risk asses that you are giving personal data to a company that won't self-certify to the privacy shield. That in its self would be a risk and you'd need to show how you mitigated against that risk.

 

I always think that because schools are in the public domain and are dealing with personal data belonging to children, if something does goes wrong the spotlight shines really bright on them so I'd always go on the side of caution.

Posted
How big of a pain would it be to stop using them? If they aren't offering something critical I'd be tempted to stop using them.

 

The Year 7-9 Computing curriculum uses it, not much but it is key when it is used

 

Also you'd have to risk asses that you are giving personal data to a company that won't self-certify to the privacy shield. That in its self would be a risk and you'd need to show how you mitigated against that risk.

 

They're in South Africa, isn't Privacy Shield just a US thing? For me, the alarm bell is that I've asked them twice to confirm a few things to do with GDPR and they've either not responded or responded saying "we'll get back to you soon". This reminds me to chase them again!

Posted

Yeah sorry Privacy Shield is just for US companies.

 

Is it just the forename and surname that the company needs? If you wanted to carry on using it would it be feasible to pseudonymise the name? So the company just gets student1, student2 etc. Or even their initials so studentRP, studentJS rathen than John Smith etc

Posted
The general message that came out of my training is that the privacy shield is ok and data controllers shouldn’t panic come May, it will still be legitimate to use. You may want to put a contract in place so there is a clear understanding between the controller and processor of what your expectations are but generally speaking the Privacy Shield will still be respected as giving appropriate safeguards.
Posted
Yeah sorry Privacy Shield is just for US companies.

 

Is it just the forename and surname that the company needs? If you wanted to carry on using it would it be feasible to pseudonymise the name? So the company just gets student1, student2 etc. Or even their initials so studentRP, studentJS rathen than John Smith etc

 

Forename, surname, school email address (which is also their login name for the service). We could pseudonymise (is that a word?!) but the teacher would need to keep a list somewhere mapping student1, student2 etc. against real names.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...