Jump to content

Recommended Posts

Posted

A spin off thread from a discussion in the 3 year ESS contract thread.

 

A interesting consideration about compliance as a processor. What are your thoughts about the storage of data in different scenarios. For example, lets look at MIS. You could have SIMS locally on your own servers, hosted SIMS or you might be fully cloud with Arbor or Bromcom or other. Do you feel the DPA considerations differ for across those?

  • Thanks 1
Posted

Looking back at the question, there would be no DPA for a locally installed build, but there may be a DPA for a support and training programme from whoever you get you MIS support from. That all depends on who is doing what and with what data.

From the options of cloud and hosted, we need to separate out if we are talking about ‘hosted’ or ‘cloud’.

 

Hosted - meaning you have it hosted somewhere u see your control … i.e. a data centre somewhere that you run the direct contract for them as hosting provider (Azure, AWS, etc). In this case you have a software/services contract with the MIS vendor and a DPA with the hosting provider (dependant on the caveat about training/support).

 

Cloud - meaning the MISaaS option, where the cloud hosting is part of the arrangement with the MIS vendor. In this case, the DPA is with the MIS vendor and they run the contract and agreements with the hosting provider as *their* sub-processor.

 

The DPIA will be on the same basis, as it is for the same purpose, but the difference technologies may require different implementations and have different risks associated with them.

 

I do have all the resources from the disbanded Education Data Matters site, which include some template DPIAs, and I’ll try to get them up as soon as I can.

  • Thanks 1
Posted
Looking back at the question, there would be no DPA for a locally installed build, but there may be a DPA for a support and training programme from whoever you get you MIS support from. That all depends on who is doing what and with what data.

From the options of cloud and hosted, we need to separate out if we are talking about ‘hosted’ or ‘cloud’.

 

Hosted - meaning you have it hosted somewhere u see your control … i.e. a data centre somewhere that you run the direct contract for them as hosting provider (Azure, AWS, etc). In this case you have a software/services contract with the MIS vendor and a DPA with the hosting provider (dependant on the caveat about training/support).

 

Cloud - meaning the MISaaS option, where the cloud hosting is part of the arrangement with the MIS vendor. In this case, the DPA is with the MIS vendor and they run the contract and agreements with the hosting provider as *their* sub-processor.

 

The DPIA will be on the same basis, as it is for the same purpose, but the difference technologies may require different implementations and have different risks associated with them.

 

I do have all the resources from the disbanded Education Data Matters site, which include some template DPIAs, and I’ll try to get them up as soon as I can.

 

Many thanks for this. Although the location of the device that ultimately hosts the database/software/service shouldn't alter the responsibility (well it does, dependent on the combined local and remote data protection regulations involved, but the school would still be the owner of said data), my confusion stems from any processing done by the 3rd party - or does that not matter as it's still done on your/the school's behalf? (and again, covered by the DPA).

I could very well be over-thinking it :D

Posted
Many thanks for this. Although the location of the device that ultimately hosts the database/software/service shouldn't alter the responsibility (well it does, dependent on the combined local and remote data protection regulations involved, but the school would still be the owner of said data), my confusion stems from any processing done by the 3rd party - or does that not matter as it's still done on your/the school's behalf? (and again, covered by the DPA).

I could very well be over-thinking it :D

 

3rd parties have a very specific definition under GDPR. They are a separate Data Controller, using the data for their own purposes. This should not be confused with a Data Processor, who processes data on your behalf, for your purposes and under your instructions. They should also not be confused with sub-processors, who are following instructions from your Data Processors, instructions that actually come from those you have issued.

 

Unfortunately, 3rd parties is also a term used in contracts and property law.

 

Yeah … it gets murky.

 

This is why I spend a lot of time explaining things to EdTech providers about how to phrase things that go into DPAs.

  • Thanks 1
Posted
You could have SIMS locally on your own servers, hosted SIMS or you might be fully cloud with Arbor or Bromcom or other. Do you feel the DPA considerations differ for across those?

 

DPA considerations definitely vary, if only because you need to consider potential access by staff at the hosting/cloud provider and also basic anti-hack security. I'm sure AWS etc. is far harder to penetrate than our own firewall, so in that sense the data might be safer, but it is would become more vulnerable to compromise by phishing attack. According to our DPO, ESS are processing some of the data outside the EEA too, and that has DPIA implications.

 

As Grumbledook has already said, neither the hosted nor cloud SaaS provider would be data controllers, so do be careful with the advice from our shared DPO about the non-compliance of ESS sharing information with the DfE, because a) ESS aren't sharing it, you are, and b) consent isn't required because you're processing and sharing it under the public task exemption. So, unless I've missed something, our DPO is massively off the mark on that one.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...