Jump to content

Recommended Posts

Posted (edited)

Hi All,

 

I currently work for a Academy who have purchased the latest Adobe Creative Cloud with Shared Device Licensing. We have however hit a bit of a stumbling block as we have been in touch with the MAT's Data Protection Officer and they have sent us a list of questions we need to answer as part of a Data Processor Due-Diligence Checklist.

 

I have been in contact with our re-sellers and also Adobe directly who have both provided me with links to answer common GDPR queries. However, the information contained within the links doesn't particularly give a straight forward answer with regards to some of the questions asked by the DPO.

 

Does anyone on here have any experience approaching the GDPR side of things? I'll post the questions being asked below on a separate post.

 

 

Many Thanks

Davey

Edited by db2995
Posted

Questions:

- Where is the Processor based?

 

- Where is the personal data stored?

 

- Who can access the data?

 

- Does the Processor have a data protection officer?

 

- Does the Processor inform the School before it transfers data elsewhere?

 

- Does the Processor transfer data outside of the EEA? If so, where and why?

 

- What controls does the Processor have in place to reduce risk and what are their risk management processes?

 

- Does the Processor have security breach notifications in place?

 

- Does the Processor use any sub-processors (including server or application hosts)? If so, who and for what purposes?

 

- Can the Processor comply with all of the Data Subject rights, including the right to be forgotten?

 

- Can the Processor provide copies of its Data Protection Policy and Privacy Notice?

Posted

Their GDPR page covers:

 

1. In the EU, we deal with "Adobe Systems Software Ireland Limited" as the controller

2. They're a little unclear with this one - they don't specify where, but state that data is transferred outside the EU using model contract clauses and the Privacy Shield agreement. So, I would put this down as the USA

3. Don't think I've really seen this question asked before - it certainly isn't one that is included in most Privacy Policies. Usually the question would be "what data is collected?" and "how is the data used?"

4. Yes, they have a Chief Privacy Officer, EU Data Protection Officer and a privacy team ([email protected])

5. No, as this is unnecessary so long as the transfer complies with their privacy policy

6. Yes, Switzerland and USA. Why is again, another odd question - because they are processing it in those locations is about as much of an answer you can get from Adobe. Their document is https://www.adobe.com/uk/privacy/eudatatransfers.html

7. No idea, those would be internal company workings and not normally published in my experience - "yes, here's how we prevent people stealing data"...

8. No idea. Don't think I've ever seen this question asked. Certainly wasn't on the training materials I've had when querying companies about GDPR compliance

9. Yes, subsidiaries, parent company, resellers, and others - https://www.adobe.com/uk/privacy/policy.html (section "Does Adobe share my personal information?")

10. Their privacy policy states that "Under the law of some countries, you may have the right to ask us for a copy of your personal information; to correct, delete or restrict (stop any active) processing of your personal information", and that you can exercise the rights by contacting the DPO.

11. https://www.adobe.com/uk/privacy/policy.html https://www.adobe.com/uk/privacy/eudatatransfers.html and more generally https://www.adobe.com/privacy/general-data-protection-regulation.html

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...