Ceegac Posted March 28, 2018 Posted March 28, 2018 Hi I am in the process of contacting our suppliers to see if they are GDPR Compliant. One has come back saying this is the first they have heard of GDPR (EEK!) - any thoughts on the best document / website to point them in the direction of to explain it simply? It's an educational website that the languages department use - kids do log into it. Thanks
stevec_ Posted March 28, 2018 Posted March 28, 2018 You probably want to point them to this: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/accountability-and-governance/contracts/
Ceegac Posted March 28, 2018 Author Posted March 28, 2018 Thanks for this - just when I think I'm getting a handle on things it seems to snowball. Do we therefore need to get contracts in place with all our suppliers eg MIS, school photographer jumps out as those that would be important, but there's also so many websites that we sign up for use in one subject or another. Some of them say they are GDPR compliant but do we need to have some kind of written contract? I'm thinking about everything from kahoot, quizlet, dofe, ucas and then the small companies who are just used for one subject. What do we actually NEED in writing? Thanks!
djrscally Posted March 28, 2018 Posted March 28, 2018 Thanks for this - just when I think I'm getting a handle on things it seems to snowball. Do we therefore need to get contracts in place with all our suppliers eg MIS, school photographer jumps out as those that would be important, but there's also so many websites that we sign up for use in one subject or another. Some of them say they are GDPR compliant but do we need to have some kind of written contract? I'm thinking about everything from kahoot, quizlet, dofe, ucas and then the small companies who are just used for one subject. What do we actually NEED in writing? Thanks! https://ico.org.uk/media/about-the-ico/consultations/2014789/draft-gdpr-contracts-guidance-v1-for-consultation-september-2017.pdf Page 13 outlines what needs to be written into the contracts
Ceegac Posted March 28, 2018 Author Posted March 28, 2018 Would you suggest that we should be writing a standard contract that we ask companies / websites to sign up to, or that we should expect them to have a standard contract that we just 'agree' to when we are satisfied with it?
fiza Posted March 28, 2018 Posted March 28, 2018 Would you suggest that we should be writing a standard contract that we ask companies / websites to sign up to, or that we should expect them to have a standard contract that we just 'agree' to when we are satisfied with it? I would think they would have a standard Data Sharing Policy that Schools sign up to.
djrscally Posted March 28, 2018 Posted March 28, 2018 Would you suggest that we should be writing a standard contract that we ask companies / websites to sign up to, or that we should expect them to have a standard contract that we just 'agree' to when we are satisfied with it? Mostly the latter I expect, and you'll have to review and ensure that the DP terms in their standard contract include everything necessary to comply with the GDPR. The ICO will likely publish some default terms to be included (something not yet done but specifically allowed for in the GDPR) at some point in the future, and at that point I'd probably auto-reject any contract not including those published terms. 1
MYK-IT Posted March 28, 2018 Posted March 28, 2018 @Ceegac See other posts that may help.... @maturelady from GDPRiS is the GDPR Guru http://www.edugeek.net/forums/data-protection-information-handling/193652-offer-help-suppliers.html http://www.edugeek.net/forums/data-protection-information-handling/194313-free-resources-school-dp-leads-gdpr-information-share-parents.html https://www.gov.uk/government/publications/data-protection-changes-letter-to-the-supplier-community
Tammie Posted April 25, 2018 Posted April 25, 2018 This is something I want to find out too - do we have to send new GDPR compliant contracts to processors or do I just find a contract that they've already sent us (somewhere!!) and comb through them to see if they comply? I think it's the latter, reading @djrscally's post.
djrscally Posted April 25, 2018 Posted April 25, 2018 This is something I want to find out too - do we have to send new GDPR compliant contracts to processors or do I just find a contract that they've already sent us (somewhere!!) and comb through them to see if they comply? I think it's the latter, reading @djrscally's post. Yep, we're doing the latter. Where they're not compliant, we've just contacted them asking for refreshed terms. Haven't found a company yet that isn't already on it. 1
Tammie Posted April 25, 2018 Posted April 25, 2018 Thanks - so excuse my ignorance, you're not actually asking them for another contract in the traditional sense of the word? I saw some companies suggesting that new contracts needed to be written, for GDPR, and they were a legal agreement between x and y etc and I thought we'd have to write one of those for every processor. You've looked at the Ts&Cs that they sent you when you signed up to see if they were compliant (and asked for updated ones if necessary) rather than looking for a privacy notice that they have online or similar?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now