Badaz52 Posted June 5, 2018 Posted June 5, 2018 (edited) I just wanted to ask this question in the hope that there is a simple yes/no answer lol, difficult I know. If we are allowing removable USB storage devices on our entire network without encryption are we 100% breaking GDPR? Our DPO instructed me to not enable BitLocker because she was concerned that contents of existing sticks could still be read, I explained that if the stick is already lost then there is nothing we can do to stop unauthorised access and if the stick is in the rightful posession of its owner who is allowed to view the contents they would likely be using it frequently so would need to encrypt to be able to write to it. Edited June 5, 2018 by Badaz52
colly72 Posted June 5, 2018 Posted June 5, 2018 I don't think there is anything in GDPR that dictates that USB sticks must be encrypted but without encryption or other controls you risk a breach, so best practice would be to either enforce encryption, or block them altogether. 1
Badaz52 Posted June 5, 2018 Author Posted June 5, 2018 (edited) Thank you. I'm tempted to just enforce encryption but I'm going to face a back lash if I do from the DPO. Edited June 5, 2018 by Badaz52
smarties11 Posted June 5, 2018 Posted June 5, 2018 If your DPO cannot see the necessity of encrypting data in transit, such as on a USB stick, then you need a new DPO. With BitLocker it isn't possible to prevent non-encrypted sticks to be read from, but you have to start somewhere. It's better to start the ball rolling than to put your head in the sand. Issue staff with BitLocker encrypted drives and then mandate them by policy to use these and stop using any non-school issued removable storage. Have a look at the ICO guidance here https://ico.org.uk/for-organisations/guide-to-data-protection/encryption/scenarios/transferring-personal-data-by-usb-device/
Badaz52 Posted June 5, 2018 Author Posted June 5, 2018 (edited) If your DPO cannot see the necessity of encrypting data in transit, such as on a USB stick, then you need a new DPO. With BitLocker it isn't possible to prevent non-encrypted sticks to be read from, but you have to start somewhere. It's better to start the ball rolling than to put your head in the sand. Issue staff with BitLocker encrypted drives and then mandate them by policy to use these and stop using any non-school issued removable storage. Have a look at the ICO guidance here https://ico.org.uk/for-organisations/guide-to-data-protection/encryption/scenarios/transferring-personal-data-by-usb-device/ We have an inappropriate DPO anyway as they handle personal data (staff wages) and fill in other roles from time to time (Personel) so have a clear conflict of interest which is why making a decision on this is a problem. I've been told it is down to be discussed next week. That's 2 weeks since compliance!! this isn't right but I'm not sure whether I can make an "executive" decision or not. What a nightmare! Edited June 5, 2018 by Badaz52
djrscally Posted June 6, 2018 Posted June 6, 2018 The easy answer to this is "Yes". Alright the GDPR doesn't technically say they must be, but realistically if the ICO finds out they're not and have personal data on you'll be getting fined. If you're getting fight back on it I would trawl through the ICO's list of enforcement actions, download all the reports of hefty fines where people lost media that wasn't encrypted and send those to her. Like... https://ico.org.uk/action-weve-taken/enforcement/crown-prosecution-service/ https://ico.org.uk/action-weve-taken/enforcement/humberside-police/
XiJ Posted June 6, 2018 Posted June 6, 2018 I don’t think two weeks is cause for alarm to be honest. Get your research and evidence together - from here, the ICO etc. Then present your reasons for encrypting. Depending on your position / status you might be able to make a decision post meeting even if they decide against. But if not I would go on record - in writing - to say you strongly recommend usb encryption. For what it’s worth we are telling all our schools it needs to be done on usb devices and teacher laptops at least.
mikkydoos Posted June 6, 2018 Posted June 6, 2018 (edited) Allowing the potential for unencrpypted data to be copied from your premises and taken outside is not against GDPR. Unless it actually happens. Then it is and should be reported to the ICO as a breach. So.. preventing a potential breach should be in your data protection policy and should be enforced (by encryption/banning USB's/whatever). Otherwise you aren't taking reasonable steps to protect your data.... Which is a breach of GDPR. Edited June 6, 2018 by mikkydoos
mthomas08 Posted June 6, 2018 Posted June 6, 2018 For those who want to consider not encrypting USBs: https://www.bbc.co.uk/news/uk-england-kent-44371759 We encrypt all our staff laptops and USBs, without encryption staff can't write to them on site. We also do quite a few emails, weekly news and reminders in briefings to staff by SLT. It's important not just for encryption but to be aware of what data they have and where. It will be interesting to see if this school is fined. Although they have no reason to believe the data has been copied or accessed.. there's still that possibility though. I see a lot more cases like this appearing because we can no longer sweep it under the carpet. At the end of the day it's your schools decision to be safe or not. 1
MartinT Posted June 6, 2018 Posted June 6, 2018 Encryption of USB sticks was strongly recommended in two GDPR seminars I attended. We enforce BitLocker encryption for writing to USB sticks, but there is no need for reading from, so it shouldn't inconvenience staff using their own sticks who don't want to encrypt them. A pop-up asks if you want to encrypt when you insert one - if you answer 'no' then it's read-only. We've had very little issue with it and staff know they need an encrypted stick if they're going to write any document to it.
smarties11 Posted June 6, 2018 Posted June 6, 2018 Encryption of USB sticks was strongly recommended in two GDPR seminars I attended. We enforce BitLocker encryption for writing to USB sticks, but there is no need for reading from, so it shouldn't inconvenience staff using their own sticks who don't want to encrypt them. A pop-up asks if you want to encrypt when you insert one - if you answer 'no' then it's read-only. We've had very little issue with it and staff know they need an encrypted stick if they're going to write any document to it. Bear in mind that if you allow staff to use their own encrypted memory sticks, it's difficult for you to recall these if that member of staff leaves. We felt it better to issue our own encrypted sticks, and use the BitLocker identification field to prevent staff writing to BitLocker drives that don't have our unique identifier set. We also prevent staff from encrypting removable storage on school devices. It would be possible for staff to encrypt at home and use the same identifier but 99% wouldn't know how to do this. This way we can recall the sticks (and the data) when they leave, and our Staff AUP states that they should never save personal information onto their own privately owned devices and removable storage. It's the only way we could come up with that shows we have done everything we can to prevent loss of sensitive data when using removable storage.
MartinT Posted June 6, 2018 Posted June 6, 2018 Yes, all fair points. It's always going to be a balance between trusting the staff and being procedurally difficult (which inevitably means more support required from us). Our staff pretty much only encrypt USB drives that we provide, they don't like encrypting their own and some have Macs at home for which it's a non-starter. I don't want to be too anal about it as they could always take printouts home if they really wanted sensitive information for nefarious reasons.
peej2k Posted June 8, 2018 Posted June 8, 2018 There is nothing in the GDPR law that states you specifically have to encrypt anything, but you'd be seriously foolish if you didn't with USB sticks. Theres arguments about whether you need to with staff mobiles accessing data as long as you can enforce a pin number and retract the data remotely, but USB is a different matter entirely.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now