TwistedHelixis Posted May 17, 2018 Posted May 17, 2018 I have just popped into the schools (UK) Google admin \ Company profile \ Profile section, and under Security and Privacy Additional Terms are two items marked with 'Review and Accept' The first one I assume is to do with GDPR Data Processing Amendment to G Suite and/or Complementary Product (e.g. Cloud Identity) Agreement The other I have no idea what its about G Suite/Cloud Identity HIPAA Business Associate Amendment. Should we as a primary school be accepting these? Thanks
crc-ict Posted May 17, 2018 Posted May 17, 2018 Hi, As I understand it, the Data Processing Amendment needs to be agreed to. Beware though, the wording calls for it to be agreed by someone with legal responsibility to bind the school to a contract, so I would advise you don't do it without consulting your LM/Headteacher. I got a printout of the agreement signed by the HT and Chair of Governors as authority to accept. HIPAA I believe is a US regulation and is not relevant to us in the UK. Hope that helps. 1
TwistedHelixis Posted May 17, 2018 Author Posted May 17, 2018 The following seems to imply V1.6 of the agreement will become V2 automatically after the 25th Version 1.6 of the Data Processing Amendment will apply (in relation to G Suite Agreements) until 24 May 2018 inclusive and, as from 25 May 2018 (when the EU’s General Data Protection Regulation comes into force), will be replaced by Version 2.0 of the Data Processing Amendment (below). Current Version (1.6) of Data Processing AmendmentVersion 2.0 of the Data Processing Amendment will take effect from 25 May 2018 (when the EU’s General Data Protection Regulation comes into force) and replace Version 1.6 of the Data Processing Amendment (where applicable) on that date. Should we still get it signed of and agreed?
TwistedHelixis Posted May 19, 2018 Author Posted May 19, 2018 Out of interest what happens if I don't click 'Review and Accept'?
TwistedHelixis Posted May 19, 2018 Author Posted May 19, 2018 its OK, just found this. If the GDPR applies to Google’s processing of your data—for example, if you are established in the European Union, or established outside the European Union but offer goods/services to data subjects who are in the European Union—it requires your contract with Google to contain certain data processing terms. Unless you accept the DPA 2.0, your contract will lack those terms. We therefore recommend that you accept the DPA 2.0 on behalf of your organization or seek legal advice.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now