Jump to content

Recommended Posts

Posted

Hello all

 

We're wondering about the specifics of obtaining new GDPR compliant contracts. The ICO Guidance says "You should therefore check your existing contracts to make sure they contain all the required elements. If they don’t, you should get new contracts drafted and signed." Once we've reviewed all our contracts, we're unsure as to whether we a) contact all our suppliers and ask for a new contract containing all the elements required, b) write a new contract ourselves and send it to them or c) find information that the suppliers publish themselves about their compliance and document that somewhere?

 

Any light shed would be appreciated!

Posted

In general, you should do a), unless they say they have no plans to change their contracts in which case you should do b) (with the proviso that it needn't be a contract; a "data sharing agreement" that supplants the data protection section in your contract is fine). However you probably have a bunch of processors with whom you do not have a contract (independent specialist teachers in our case), and I'd try and do b) for those (again though, can be an agreement rather than a full contract)

 

c) is not sufficient; it needs to be a legal, binding agreement between you.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...