Jump to content

Recommended Posts

Posted

Hi All, appreciate this has been done to death with a lot of basic questions and protocols, but I've searched and cannot find the answer.

 

I thought we had to have a Data Sharing agreement with suppliers/processors, which to me is a signed agreement with both parties signing it. Staff have been emailing suppliers/processors DPO asking for their agreement form and they are just getting sent their Privacy Notices and GDPR policies etc.

 

Is this enough? Should I be creating a form? Why should I be doing it and not the processors?

 

Appreciate any help, and if anyone has an agreement done, any chance of sharing it?

 

Many thanks

Posted

The GDPR (Article 28) says that processing by a processor should be governed by a contract or other legal act - which as you said would normally be a signed agreement.

 

I'm pressuming it has already been established that the school are the controller of the personal data. If they are then they are ultimatly responsible for the data so it would be up to them to tell the processor what there expections are and not the other way round.

 

This gives the school the opportunity to create the standard that they want the data to be processed under. It also allows the school to set out how long the data will be processed for, what kinds of data they can have and the purpose of processing.

 

If the processor had a data breach, then the school would be able to lay out their own agreement in which the processor agreed to obey to, to show the regulator that they ultimaty took control of the data but the breach was caused because the processor went against the agreement.

Posted
We drafted our own agreement meeting the GDPR's minimum terms and basically when the processor replies to our request for an updated agreement with just their privacy /policy we send them our agreement and tell them that since they haven't supplied us with terms we need them to agree to ours. Our agreement specifies that by continuing to provide us with whatever service they're providing, that counts as acceptance of the terms we sent to them.
  • Thanks 1
Posted

I'm pressuming it has already been established that the school are the controller of the personal data. If they are then they are ultimatly responsible for the data so it would be up to them to tell the processor what there expections are and not the other way round.

 

This gives the school the opportunity to create the standard that they want the data to be processed under. It also allows the school to set out how long the data will be processed for, what kinds of data they can have and the purpose of processing.

 

Meanwhile, on planet reality, I don't see we have an option but to accept our processors' privacy policies. Google are not about to enter into a unique agreement with each customer, they will say "these are our terms, take them or leave them".

  • Thanks 1
Posted
Meanwhile, on planet reality, I don't see we have an option but to accept our processors' privacy policies. Google are not about to enter into a unique agreement with each customer, they will say "these are our terms, take them or leave them".

 

Clearly in some cases you need to apply a smidge of common sense and have some exceptions to the rule! :D This is where an experienced data protection officer is valuable, that knows how to interpret regulations and apply them in practise rather than just know what the GDPR etc says. I did privacy agreements for all my schools, apart from Google Apps for edu, every other company we said these our are terms for dealing with our data, if you want our money, you need to agree to them!

Posted
Clearly in some cases you need to apply a smidge of common sense and have some exceptions to the rule! :D

 

I guess where I come unstuck is, if we don't need an agreement with Google but will accept their Ts&Cs, why are %SmallEdTechProvider% any different? The regulations surely either require us to have individual signed agreements with all processors, or they don't. I think if we can prove we reviewed a processor's terms and were happy with them, we'd pass muster with the ICO. Indeed, one company's revised data sharing agreement wasn't acceptable and we've gone back to them about it.

Posted (edited)

I think the point is you do need an agreement with Google as per the GDPR, but the reality is it's not going to happen. So you risk asses the situation and decide do we accept the risk or do we go elsewhere.

 

You can mitigate the risk by looking at their privacy agreement etc and seeing if it matches up with what your contract would have said. But there will still be an element of residual risk that is left because the processor dictated to the controller rather than the other way around.

 

My opinion is unless your dealing with serious data (i.e military, secret gov etc) then it is a risk worth accepting, because in reality if Google had a data breach or didn't comply with someone's data subjects rights, the regulator would be more interested in them then us because of how big they are.

 

You can apply the same logic to any supplier, you can ignore what the GDPR says about getting a contract in place and just check their privacy policy to see if it matches up with your expectations. But there would be an element of risk involved with this when doing this with a smaller suppliers because if there was a data breach, the ICO would likely look at both the supplier and the school.

Edited by Edutech98
Posted
You can apply the same logic to any supplier, you can ignore what the GDPR says about getting a contract in place and just check their privacy policy to see if it matches up with your expectations. But there would be an element of risk involved with this when doing this with a smaller suppliers because if there was a data breach, the ICO would likely look at both the supplier and the school.

 

Fair point re. smaller suppliers. Ironically, they're the ones more likely to sign our preferred agreement anyway! This is an area I'll be raising with our DPO. Internally, we were happy to accept the risk of checking suppliers' terms against our own expectations and the ICO's checklist (page 27 of https://ico.org.uk/media/about-the-ico/consultations/2014789/draft-gdpr-contracts-guidance-v1-for-consultation-september-2017.pdf), but I would like our DPO to advise if this is sufficient.

Posted

There is also an increased risk of smaller suppliers changing their privacy terms without your knowledge compared to Google etc.

 

If Google, Microsoft etc changed something it would be widely publicised and you would find out about it pretty fast.

 

You can mitigate this risk with smaller supplier by dictating the terms of the contract, then if they do change anything they would be under breach of contract. If they had a data breach where they are in breach of contract, this would have a massive mitigating effect on the school - to a point where I would argue the school should have no punishment.

Posted
Meanwhile, on planet reality, I don't see we have an option but to accept our processors' privacy policies. Google are not about to enter into a unique agreement with each customer, they will say "these are our terms, take them or leave them".

 

Absolutely agree. The notion that individual schools will be able to dictate their own terms and conditions is absolutely pie-in-the-sky. Even with small suppliers, how are they supposed to manage having different terms with each customer. It's madness.

 

We questioned a point in the T&Cs with a well-known education-specific provider and also got the "these are our terms, take them or leave them" treatment.

 

It's just not a workable idea, too much is being left to individual schools to sort out.

Posted
great discussion, thanks all.

 

Decided to pimp one from a LA site along with some help from @djrscally

 

Another job in progress.....

 

What you going for pal? Getting a contract in place or just checking their privacy policy etc to see if it matches up to your expectations? Would be interested to hear how you get on if you decide to do the contract route as I never had an issue with getting them signed but it seems others have which I'm surprised about given its a requirement of the GDPR.

Posted
What you going for pal? Getting a contract in place or just checking their privacy policy etc to see if it matches up to your expectations? Would be interested to hear how you get on if you decide to do the contract route as I never had an issue with getting them signed but it seems others have which I'm surprised about given its a requirement of the GDPR.
I think I am going down the route of whatever benefits us, with minimal work but ensuring compliance. It seems a 'blame game' so as long as we can't be blamed for any breach or non-compliance, that'll do for me. There are so many different variables in terms of what people hold and supply, I think it is going to be a case of treating them individually depending on services.

 

Have just sent one out and had it returned and signed for a residential week, but having gone through their Privacy notices etc that they kindly sent! we were happy with their compliance anyway, but it's now recorded and good to go. We use GDPRis and apparently suppliers have been slow to provide their Contracts to them, so we have to do it ourselves until they get on with it. Once they do sort it out, we should be covered with all the suppliers on their that we use.

 

The issue I have is when and who should send the contracts out. A staff member will organise a trip and if the company's data protection policies don't match our expectations we shouldn't use them. BUt they may have ordered it all by then. Just need to suss out timings really.

 

Has anyone sussed it? :)

Posted
In a very similar position here and struggling with the lack of contracts shared on GDPRiS. Would you mind sharing what you are sending out?
Posted (edited)

We did it as part of the procurement process - so finance could not place the order until the head/business manager and the DPO which at the time was me (yes I was also the NM at the time! :D ) had signed the order.

 

I either sign to say no PD was being sent or it was and an agreement was in place.

 

It was easy for big orders like CPOMS etc because they were not particularly urgent and I had time on my side and the power of a big order. The pain one's were when the teacher needed it done literally there and then and it was a small amount of money involved. That was a case off either the business manager or me getting on the phone to them- I used to get a couple of panics saying they couldn't sign anything but once I sent it to them and went through it over the phone they didn't have a problem - they wanted the ££££ at the end of the day.

 

For trips etc where there wasn't a particular huge amount of data so the agreement was literally a couple of lines saying you won't use the data for anything else, you will delete the personal data when the trip has finished and you will keep the personal data secure. This along with there privacy policy was enough for us to feel we had complied and managed the risk effectively.

Edited by Edutech98
  • Thanks 3

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...