Jump to content

Recommended Posts

Posted

Someone at work discussed the housing association as an example of bad practice in general and ICO action, and I thought it might be of interest here as I think the ICO may see housing associations and schools trusts as similar in some ways.

 

Reprimand: https://ico.org.uk/action-weve-taken/enforcement/clyde-valley-housing-association/

Press release: https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2024/04/housing-association-reprimanded-for-exposing-personal-information-on-online-portal/

 

This is something I might wave at a service provider whose procedures seem lax or use to justify better training and procedures if I were responsible for data protection in a trust...

  • Thanks 2
Posted
Thats very reminiscent of the classcharts data breech?

 

I did wonder if someone would think that. From the outside looking in, it certainly looks similar.

Posted
I did wonder if someone would think that. From the outside looking in, it certainly looks similar.

 

But don't worry the classcharts data breech wasn't a data breech according to classcharts so the ICO won't investigate or take any remedial action.

Posted
I wonder if the difference here is that Classcharts rectified it within hours wheras Clyde appear to have taken almost a week to do anything?
Posted
I wonder if the difference here is that Classcharts rectified it within hours wheras Clyde appear to have taken almost a week to do anything?

 

Doesnt matter how long it takes to rectify it is still a breech.

  • 3 weeks later...
Posted

So did anything happen with that classcharts breach? I never recieved any evidence of any of our pupils data going to an incorrect receipient so assumed I didn't have to do anything. But if classcharts can just say that it wasn't a ransomware breach if our secretary gets hit and all her e-mails leaked does that mean I can just decide it wasn't really a breach and the ICO won't care? or is it because classcharts are (or are owned by) a large corporation wheres we are just a podunk school which is how they could get away with it whereas I likely wouldn't?

 

BTW I've seen shocking third party setups where access level security was non existent (e.g. anyone could access anyone elses data trivially if they tried) so always be cautious around this stuff.

Posted
or is it because classcharts are (or are owned by) a large corporation wheres we are just a podunk school which is how they could get away with it whereas I likely wouldn't?

.

 

That's exactly correct.

 

They successfully buried their heads in the sand and pretended nothing happened.

 

Which adds them onto my list of completely untrustworthy companies not to deal with - along with other famous ones like capita and ESS

Posted
Funnily enough I got a tes survey come through so I let rip on why I couldn't recommend them. Funnily enough, even though I ticked the box, I haven't had any contact to get further feedback.
Posted
But if classcharts can just say that it wasn't a ransomware breach if our secretary gets hit and all her e-mails leaked does that mean I can just decide it wasn't really a breach and the ICO won't care?

 

What does your contract with Classcharts say about your data. If you are the data controller and they're merely processing your data for you, then one could well say that it's up to them to report an issue to you, then it's up to you to decide if there has been a breach, then it's your responsibility to report the breach to the ICO, not them.

 

https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/contracts-and-liabilities-between-controllers-and-processors-multi/responsibilities-and-liabilities-for-controllers-using-a-processor/

Posted

As @Roberto has pointed out, if you are the data controller, only you can really decide if it was a breach. If you believe it was, then raise it to the ICO, and you might even want to point out that your Data Processor has tried to insist that it is not a breach.

This is a very serious thing and I know some school DPOs and DPOaS providers who have been pretty shocked by the approach taken.

Posted (edited)

This is a bet peeve of mine Grumbledooky.. It's almost like the data processors believe they are totally exempt from any of the responsibility within the data protection act etc and that it's all up to the data controller to deal with.

 

Ironically it is the opposite - they are the trusted method of processing our data so they inherit the same responsibility to protecting our data! In fact they should legally have more responsibility as they're not just protecting one schools data but hundreds or even thousands of schools worth of data, millions of parents and pupils.

Edited by PotNoodleTech
Posted (edited)
This is a bet peeve of mine Grumbledooky.. It's almost like the data processors believe they are totally exempt from any of the responsibility within the data protection act etc and that it's all up to the data controller to deal with.

 

You are always responsible for your users data when you are the data controller IIRC. You can have a contract that requires your data processors to enforce a very stringent set of processes and all kinds of penalites for breach but you can't abrogate responsibility for your users' data. The processor is responsible to you, you are responsible to your data subjects.

 

 

Ironically it is the opposite - they are the trusted method of processing our data so they inherit the same responsibility to protecting our data! In fact they should legally have more responsibility as they're not just protecting one schools data but hundreds or even thousands of schools worth of data, millions of parents and pupils.

 

They have the same responsibility to each individual school or other org to which they have a contract to be a data processor (I am making a lot of assumptions about their agreement with schools here but my assumptions being broadly correct would explain their attitude). Their level of responsibility, whatever it is, whatever you or I think it is, does not stack because they have more customers - they have an individual contract with each of their clients to do an individual job for each client. You say they are "trusted" - how are you making that determination? What does your contract say? What audit controls do you have in place to ensure that you can trust them? Have you got a SOC 2 Type 2 report for them?

 

I'm not trying to have a go at you here, and speaking hypothetically rather than any particular vendor, I would take a dim view of anyone who I thought might be trying to baffle education customers, who may not have experienced DPOs to hand, with BS and legalese rather than being open and clear and would place the blame with them rather than with the schools for things like this... but that doesn't change the obligations on the schools as data controllers for their pupils, staff or parents' data.

Edited by Roberto
  • Thanks 1
Posted

Yes you are totally correct and I am not arguing there at all!

 

I suppose am trying to get at is the law is inadequate and needs improving as the data controller HAS to put a certain level of trust in the data processors, and this level of trust is certainly being abused and not taken seriously and the various acts and laws etc don't seem to really guard against a processor that does not take it's responsibility seriously and single handedly hemorrhages a thousands schools data? There's no responsibility no accountability their side, the school gets 100% dumped with the blame, bad press, possibly fine - even though the school could not actually have done anything at all to stop that potential data leak other than to not use any data processors at all, which in this day and age is clearly an imposibility?

 

Even my cat is disappointed with these data processors

 

trust.JPG

  • Thanks 3
Posted (edited)
Yes you are totally correct and I am not arguing there at all!

 

I suppose am trying to get at is the law is inadequate and needs improving as the data controller HAS to put a certain level of trust in the data processors, and this level of trust is certainly being abused and not taken seriously and the various acts and laws etc don't seem to really guard against a processor that does not take it's responsibility seriously and single handedly hemorrhages a thousands schools data? There's no responsibility no accountability their side, the school gets 100% dumped with the blame, bad press, possibly fine - even though the school could not actually have done anything at all to stop that potential data leak other than to not use any data processors at all, which in this day and age is clearly an imposibility?

 

Even my cat is disappointed with these data processors

 

[ATTACH=CONFIG]71563[/ATTACH]

 

yeah exactly what exactly are us schools supposed to do? we kind of have to trust these data processors or we can't use any of the software they supply. So we should just get rid of all the cloud apps entirely and go back to entirely on prem document storage everyone using shared drives with MS office and on prem SIMS db and nothing else at all? It sounds total BS to me.

And regarding how we determine how trustworthy a data provider is, how exactly Roberto do we determine that? will they show us their internal processes so we can see how they handle our data?

Edited by mikes
Posted

Am I misunderstanding or is the law there, it is up to us to enact it? So as long as we have done everything we should have done, DPIAs, risk assessments and the like, then we pass the breach on to ICO and they go after Class Charts for the breach if it is found they have not acted properly.

 

How many schools have cancelled their subscription? How many are willing to cancel it if no answers are forthcoming? So, at that point we know Class Charts do not look after our data, we know they do not take responsibility for their own security or actions and we know they do not properly communicate with us as data controller when there is an issue, and we have continued with them, which makes the schools responsible and liable for them. We have all made a conscious decision to keep using them so we have made our selves liable for their actions.

Posted (edited)

And regarding how we determine how trustworthy a data provider is, how exactly Roberto do we determine that? will they show us their internal processes so we can see how they handle our data?

 

I'm feeling a little upset by the way you've phrased this like a challenge to me - like it's my fault it's difficult to do, or something. I'm not associated with any organisation mentioned in this post just to be clear.

 

So... I can absolutely agree that its a difficult and expensive exercise for schools. We have a team of specialists that handle this where I work. I'm not one of those people though I do work closely with them on some things. These are resources your average school will not have, or even a small to medium MAT. Of course when LEAs were still a thing, then you'd have access to a specialist team in the council...

 

In any case, it's absolutely on you (well, your org) to make your own determination based on your own needs and appetite for risk. I would suggest you should be doing something like a DPIA for every project or service you have that holds or processes data. Good vendors should have details on how they store and process data available either publically or as part of the proposed contract you sign with them. They may have things like a SOC 2 Type 2 report that detail some of their services and competencies.

 

It's not easy. But it's doable.

Edited by Roberto
Posted
yeah exactly what exactly are us schools supposed to do? we kind of have to trust these data processors or we can't use any of the software they supply. So we should just get rid of all the cloud apps entirely and go back to entirely on prem document storage everyone using shared drives with MS office and on prem SIMS db and nothing else at all? It sounds total BS to me.

And regarding how we determine how trustworthy a data provider is, how exactly Roberto do we determine that? will they show us their internal processes so we can see how they handle our data?

 

It just so happens that this is one of the areas a DPO can help.

 

I can't talk specifically from the viewpoint of the vendor in question, but as a sponsor and an EdTech vendor I can tell you what we do to help you decide if we are trustworthy. It is also worth saying that this is not just a task that gets done once. You can go and recheck any (all!) your Data Processors when you want and annually is a good option.

 

Having a template Request for Information (RfI) may help to send to vendors, and your DPO may have a template for that. If not, there is an Open Source one available on GitHub that can be used. Some vendors might even have it pre-filled and available to customers as part of their DPA.

 

If people would like to hear more about what good can look like, I am sure I can sort something out with a DPOaaS provider to talk with me, to get both school and vendor points of view.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...