Jump to content

Recommended Posts

Posted

I have just had the usual, "Here's a new cloud-based piece of software we have bought into", no warning.

 

From the looks of it no effort has been made to check it out from a GDPR aspect.

 

Would this be where you would carry out a risk assessment? Any templates?

 

Does anyone have a set list of questions you ask of a new supplier before agreeing to purchase software from them? If so could I have a copy?

 

Thanks

Posted
I have just had the usual, "Here's a new cloud-based piece of software we have bought into", no warning.

 

From the looks of it no effort has been made to check it out from a GDPR aspect.

 

Would this be where you would carry out a risk assessment? Any templates?

 

Does anyone have a set list of questions you ask of a new supplier before agreeing to purchase software from them? If so could I have a copy?

 

Thanks

Ask them to get DPO sign-off before you are willing to deal with it.

Posted
Whoever within the school signed off on it should have done a Data Protection Impact Assessment (DPIA). This is basically a risk assessment under GDPR. If it hasn't been completed you could raise concerns with the DPO as this will cover you should there be an issue going forward. More info and a template to use are on the ICO website.
  • Thanks 1
Posted

I've not got any specific templates but one of the things I like to look at for cloud service providers is if the company is registered on the Cloud Security Alliance's STAR register (Security Trust Assurance and Risk Register).

 

You can search them on this link;

https://cloudsecurityalliance.org/star/registry/

 

It allows an organisation to complete an assessment against the CSA's own cloud security controls. Depending on the type of organisation it is either self-assessed or via a third party audit. You can then use this as proof as your due diligence in regards to the security of the organisation.

 

You can also ask if the organisation follows a particular security model or framework, for example the NCSC Cyber Essentails, ISO2700, NIST 500 etc

 

I also like to see particular KPI or SLA that allow the organisation to monitor the security of the organisation. For example, a policy or procedure that states an annual check on the company to confirm if they are still maintain particular security certifications etc (if relevant).

 

Reference are also a good way to demonstrate due-diligence, so if you know a school that already uses the particular software you can ask them about it from a DP compliance point of view (I.e can you easily delete personal data, does it allow different levels of access etc)

 

Do you believe the new system will be processing personal data that is likely to result in a high risk? If so, as above, you will be required to do the DPIA as a requirement.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...