Jump to content

Recommended Posts

Posted (edited)

I just wanted to ask this question in the hope that there is a simple yes/no answer lol, difficult I know.

 

If we are allowing removable USB storage devices on our entire network without encryption are we 100% breaking GDPR?

 

Our DPO instructed me to not enable BitLocker because she was concerned that contents of existing sticks could still be read, I explained that if the stick is already lost then there is nothing we can do to stop unauthorised access and if the stick is in the rightful posession of its owner who is allowed to view the contents they would likely be using it frequently so would need to encrypt to be able to write to it.

Edited by Badaz52
Posted
I don't think there is anything in GDPR that dictates that USB sticks must be encrypted but without encryption or other controls you risk a breach, so best practice would be to either enforce encryption, or block them altogether.
  • Thanks 1
Posted (edited)
Thank you. I'm tempted to just enforce encryption but I'm going to face a back lash if I do from the DPO. Edited by Badaz52
Posted

If your DPO cannot see the necessity of encrypting data in transit, such as on a USB stick, then you need a new DPO.

 

With BitLocker it isn't possible to prevent non-encrypted sticks to be read from, but you have to start somewhere. It's better to start the ball rolling than to put your head in the sand. Issue staff with BitLocker encrypted drives and then mandate them by policy to use these and stop using any non-school issued removable storage.

 

Have a look at the ICO guidance here https://ico.org.uk/for-organisations/guide-to-data-protection/encryption/scenarios/transferring-personal-data-by-usb-device/

Posted (edited)
If your DPO cannot see the necessity of encrypting data in transit, such as on a USB stick, then you need a new DPO.

 

With BitLocker it isn't possible to prevent non-encrypted sticks to be read from, but you have to start somewhere. It's better to start the ball rolling than to put your head in the sand. Issue staff with BitLocker encrypted drives and then mandate them by policy to use these and stop using any non-school issued removable storage.

 

Have a look at the ICO guidance here https://ico.org.uk/for-organisations/guide-to-data-protection/encryption/scenarios/transferring-personal-data-by-usb-device/

 

We have an inappropriate DPO anyway as they handle personal data (staff wages) and fill in other roles from time to time (Personel) so have a clear conflict of interest which is why making a decision on this is a problem. I've been told it is down to be discussed next week. That's 2 weeks since compliance!! this isn't right but I'm not sure whether I can make an "executive" decision or not. What a nightmare!

Edited by Badaz52
Posted

The easy answer to this is "Yes". Alright the GDPR doesn't technically say they must be, but realistically if the ICO finds out they're not and have personal data on you'll be getting fined.

If you're getting fight back on it I would trawl through the ICO's list of enforcement actions, download all the reports of hefty fines where people lost media that wasn't encrypted and send those to her. Like...

 

https://ico.org.uk/action-weve-taken/enforcement/crown-prosecution-service/

https://ico.org.uk/action-weve-taken/enforcement/humberside-police/

Posted

I don’t think two weeks is cause for alarm to be honest. Get your research and evidence together - from here, the ICO etc. Then present your reasons for encrypting.

Depending on your position / status you might be able to make a decision post meeting even if they decide against. But if not I would go on record - in writing - to say you strongly recommend usb encryption.

 

For what it’s worth we are telling all our schools it needs to be done on usb devices and teacher laptops at least.

Posted (edited)

Allowing the potential for unencrpypted data to be copied from your premises and taken outside is not against GDPR.

 

Unless it actually happens. Then it is and should be reported to the ICO as a breach.

 

So.. preventing a potential breach should be in your data protection policy and should be enforced (by encryption/banning USB's/whatever). Otherwise you aren't taking reasonable steps to protect your data.... Which is a breach of GDPR.

Edited by mikkydoos
Posted

For those who want to consider not encrypting USBs:

 

https://www.bbc.co.uk/news/uk-england-kent-44371759

 

We encrypt all our staff laptops and USBs, without encryption staff can't write to them on site. We also do quite a few emails, weekly news and reminders in briefings to staff by SLT. It's important not just for encryption but to be aware of what data they have and where.

 

It will be interesting to see if this school is fined. Although they have no reason to believe the data has been copied or accessed.. there's still that possibility though.

 

I see a lot more cases like this appearing because we can no longer sweep it under the carpet. At the end of the day it's your schools decision to be safe or not.

  • Thanks 1
Posted

Encryption of USB sticks was strongly recommended in two GDPR seminars I attended.

 

We enforce BitLocker encryption for writing to USB sticks, but there is no need for reading from, so it shouldn't inconvenience staff using their own sticks who don't want to encrypt them. A pop-up asks if you want to encrypt when you insert one - if you answer 'no' then it's read-only. We've had very little issue with it and staff know they need an encrypted stick if they're going to write any document to it.

Posted
Encryption of USB sticks was strongly recommended in two GDPR seminars I attended.

 

We enforce BitLocker encryption for writing to USB sticks, but there is no need for reading from, so it shouldn't inconvenience staff using their own sticks who don't want to encrypt them. A pop-up asks if you want to encrypt when you insert one - if you answer 'no' then it's read-only. We've had very little issue with it and staff know they need an encrypted stick if they're going to write any document to it.

 

Bear in mind that if you allow staff to use their own encrypted memory sticks, it's difficult for you to recall these if that member of staff leaves. We felt it better to issue our own encrypted sticks, and use the BitLocker identification field to prevent staff writing to BitLocker drives that don't have our unique identifier set. We also prevent staff from encrypting removable storage on school devices. It would be possible for staff to encrypt at home and use the same identifier but 99% wouldn't know how to do this. This way we can recall the sticks (and the data) when they leave, and our Staff AUP states that they should never save personal information onto their own privately owned devices and removable storage. It's the only way we could come up with that shows we have done everything we can to prevent loss of sensitive data when using removable storage.

Posted

Yes, all fair points. It's always going to be a balance between trusting the staff and being procedurally difficult (which inevitably means more support required from us).

 

Our staff pretty much only encrypt USB drives that we provide, they don't like encrypting their own and some have Macs at home for which it's a non-starter.

I don't want to be too anal about it as they could always take printouts home if they really wanted sensitive information for nefarious reasons.

Posted

There is nothing in the GDPR law that states you specifically have to encrypt anything, but you'd be seriously foolish if you didn't with USB sticks.

Theres arguments about whether you need to with staff mobiles accessing data as long as you can enforce a pin number and retract the data remotely, but USB is a different matter entirely.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...