Jump to content

Recommended Posts

Posted

We should have in place a contract between ourselves and any company processing data on our behalf. I'm really struggling with one company we are looking at working with as the don't seem to understand GDPR. They have a Privacy Policy which I think has probably been copied and pasted from somewhere and a number of items don't make sense in the context of the relationship we would have with them.

 

In addition to that I've asked to see a copy of the contract they would want us to sign. All they seem to want to provide is an order form to sign. The order form has a sentence with a tick box which simply says I have read and accepted the Ts&Cs set out in the license agreement and Data Protection Ts&Cs.

 

Is this enough to qualify as a legally binding contract between Controller and Processor?

Posted

The contract, or other legal act, should include;

 

The duration of the processing, the nature and purpose of the processing, the type of personal data processed, the promise to only act on the written instruction of the controller, the assurance that they comply with article 32 (security) of the GDPR, that they will not engage with another sub-processor without your consent and that they will delete your data at the end of the contract.

 

If their terms and conditions include this information, then I would say you are good to go and you can use their terms and conditions instead of a specific contract.

 

I'm presuming the school is the controller in this case, so if their terms and conditions don't include this, as the controller you can stipulate the terms of the contract and get them to sign your contract to say what you expect them to do / not do.

 

There would be a further risk assessment that would need to be done though in which you would need to asses are you happy giving personal data over to an organisation that doesn't seem to understand their responsibilities. As a controller you would still be responsible for the data so this would be a judgement call that you would need to make.

  • 3 years later...
Posted

Hi, very late to the party here but as I have only just been made the DPO at my school and I don't think my predecessor did much with GDPR.

Can you just confirm (because I believe it to be the case) if our staff agree to the Terms and Conditions of Privacy Notices and it has the info about how data is processed etc we have entered into a contract albeit not on our terms?

Posted
Hi, very late to the party here but as I have only just been made the DPO at my school and I don't think my predecessor did much with GDPR.

Can you just confirm (because I believe it to be the case) if our staff agree to the Terms and Conditions of Privacy Notices and it has the info about how data is processed etc we have entered into a contract albeit not on our terms?

 

The Privacy notices are stating what you do with your data, why and who you may transfer it to etc. Staff don't need to agree to the terms of your Privacy notices. The staff have a contract of employment and as part of that they have adhere to any laws that apply to them while doing their job, data protection being one of them.

 

What's the issue you've got?

Posted
Basically, I am checking whether we have contracts between ourselves as Data Controllers and third parties we use (Data Processors). Every company I have contacted so far to see if a formal agreement/contract was put in place has told me that when we agreed to the T&Cs when we first set up with them is the contract between ourselves. Looking at them in more detail they do mention in the T&Cs about how they process our data, how long they keep it for etc. Obviously it is more a case that we are agreeing to their terms rather than them agreeing to ours. I highly doubt I will be able to get 1) our school staff to ensure they have individual contracts to anyone who processes our data and 2) have large national companies agree to contracts we provide when they have their own in place.
Posted
Basically, I am checking whether we have contracts between ourselves as Data Controllers and third parties we use (Data Processors). Every company I have contacted so far to see if a formal agreement/contract was put in place has told me that when we agreed to the T&Cs when we first set up with them is the contract between ourselves. Looking at them in more detail they do mention in the T&Cs about how they process our data, how long they keep it for etc. Obviously it is more a case that we are agreeing to their terms rather than them agreeing to ours. I highly doubt I will be able to get 1) our school staff to ensure they have individual contracts to anyone who processes our data and 2) have large national companies agree to contracts we provide when they have their own in place.

 

So you don't need individual contracts in place with companies specifically about data. As a data controller you have a responsibility to ensure the company you are using will process your data safely and within the law etc. They are processing data on your behalf. You have to do all the check s to ensure they have the correct policies in place and that they are correct and meet your requirements (data processed within the EU, meets certain security standards, etc). Once you are happy and have recorded all the areas they meet data protection compliance etc. then you would go ahead and sign whatever contract you are taking out with them. Most contracts would refer to their data protection policies.

 

I would highly recommmend using a product such as GDPRiS. They maintain lists of companies and software supplied to schools which you can select if you use them. Most also have the required policies attached etc. GDPRiS also has a number of other features to help you managing SARs, Breaches, Impact Assessments etc.

 

I'd also highly recommend you do some training. Browne Jacobson LLP do some fantastic training which is tailored for schools.

Posted
Just to add to that, a data processor is processing data on your behalf. You are the data controller and you are essentially in charge of how they process that data (within reason!). You mentioned about how long they process your data for. So they will probably have something standard in place in their policies like they will hold the data for 3 months following termination of contract but regardless of that you can tell them at any time you want data removing as it is your data and you are in control of it.
Posted

A few things for all reading this ... you will get a very mixed response from many EdTech vendors when you approach them.

 

As mentioned previously, the school (in general) will be the Data Controller and the vendor will be the Data Processor. If they have someone doing something for them (but still within the contract for you), then these will be sub-processors. The term 'third party', whilst correct in some aspects of contract law, is completely wrong within Data Protection. A third party is a separate Data Controller and if you hand over data to them, they can do with it as they deem fit.

 

If you see the term third party in any T&Cs, Data Processing Agreement or Contract, get them to clarify if they mean sub-processors or do they really mean they will hand your data over to some additional company to do with as they want.

 

And yes, T&Cs can for the bulk of your contract or agreement of service.

 

Realistically though, you will be looking for someone who can give you a clear picture on what is going on and not a bunch of legalese.

Have a look at the following for what we are moving to over at NetSupport

 

https://classroom.cloud/data-processing-agreement/ is an example of a plain English Data Processing Agreement.

https://classroom.cloud/wp-content/uploads/2021/11/classroom.cloud-Security-Request-for-Information.pdf is a standard response for details on Information Security.

https://classroom.cloud/privacy-by-design/ even helps you understand how to take a privacy-first approach when you are setting up and running software.

 

Feel free to share these examples with other vendors.

 

If anyone is interested in training around GDPR I can recommend you to some good folk.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...