Jump to content

Recommended Posts

Posted

We are looking at changing our core case management system. For all extents and purposes, this is analogous to replacing your school MIS, including all the special category data you will be familiar with. We are evaluating a shortlist of 3.

 

One host its data on AWS in the UK - this one is nice and simple for GDPR.

The second and third offer Canada/US.

 

Following discussions with the latter 2, both have confirmed Canada exclusively is an option.

 

We are getting broad advice that US is the highest risk, and although not stated, I believe it is to do with the US Patriot Act.

I am aware Canada has legislation that is more in line with EU GDPR regulations, with noted updates in Summer 2023.

I have come across the term 'adequate' within UK Gov and on the ICO site. For Canada it seems to be Adequate (partial). I believe the 'partial' is due to it being stated for private businesses, which is probably what we are as we are not public.

I have also read the US may be 'adequate', but my research to date his proved inconclusive. Generally advice on US data storage is "don't".

 

The challenge we have is knowing the true situation and that it is an up to date opinion. Ultimately we know it is a risk based decision, and we plan to have a Data Sharing Agreement in place and will complete a DPIA, but I'd be grateful if anyone is familiar with this topic. I know it's more in the deep end of GDPR questions, and we are consulting with our DPO, but I have this sneaking feeling, @GrumbleDook might just be the guru we are looking for guidance from, but all thoughts welcome.

Posted (edited)

The short answer is... there is no short answer :p

 

As you said originally EU-US shield, that was dropped, then re-stuck with the new UK extensions as they added US back to the list (https://www.gov.uk/government/publications/uk-us-data-bridge-supporting-documents/uk-us-data-bridge-factsheet-for-uk-organisations)

 

From 12 October 2023, businesses in the UK can start to transfer personal data to US organisations certified to the “UK Extension to the EU-US Data Privacy Framework” (UK Extension) under Article 45 of the UK General Data Protection Regulation (GDPR) without the need for further safeguards such as those set out in Articles 46 and 49 of the UK GDPR

 

But it still relies on an opt-in from US side of things so isn't as clear cut in terms of UK hosting.

 

Might want to do a quick search under the DPF if those other two companies are listed: https://www.dataprivacyframework.gov/s/participant-search https://www.dataprivacyframework.gov/list as that would give you the quickest answer to if that's even an option under those guidelines. As an example from above for Microsoft:

DPF-Microsoft.png

 

Steve

Edited by Steve21
  • Thanks 2
Posted
Is EU hosting not an option? It seems a lot easier to navigate the legalities. It's not clear from the question why you're focusing on North America.
Posted
Is EU hosting not an option? It seems a lot easier to navigate the legalities. It's not clear from the question why you're focusing on North America.

Of the three, one is UK. The other 2 only offer US/Canada. Of those 2, one may offer UK/EU in the future but for the functionality we want now, this is the only option. It's a niche sector so options are limited.

Posted
Of the three, one is UK. The other 2 only offer US/Canada. Of those 2, one may offer UK/EU in the future but for the functionality we want now, this is the only option. It's a niche sector so options are limited.

 

Gotcha: the providers only offer UK/CAN/US

Must be pretty specialised.

Posted
Can you share what sector it's in, @Ditto? My day job company specialise in bespoke/SaaS information systems, mostly in health.

Emotional Health and Wellbeing for children and young people. We run a lot of early intervention programmes and work closely with a lot of local schools. We have a contract, along with a number of other charity partners, supporting NHS funded CAMHS work, although that's also known as Mindworks in Surrey. Whilst we have a small overlap with the medical, or more accurately clinical support, we find systems targeted at that sector are not a great fit with what we do. At its simplest it is a case management system, but needing support for both one to one tracking, but also group work and running one off events.

  • Thanks 1
Posted
That's really interesting! It does sound similar to some of our core customers - we have a handful of different systems which are used by charitable, non-profit and social prescribing organisations through to Local Authorities and NHS. And they all run on AWS in the UK :) If you're still open to considering other options, please feel free to drop me a PM or connect on LinkedIn. We don't have marketing websites/brochures for our products but more than happy to have a chat over Zoom/Teams.
  • Thanks 1
Posted
The short answer is... there is no short answer :p

 

As you said originally EU-US shield, that was dropped, then re-stuck with the new UK extensions as they added US back to the list (https://www.gov.uk/government/publications/uk-us-data-bridge-supporting-documents/uk-us-data-bridge-factsheet-for-uk-organisations)

 

 

 

But it still relies on an opt-in from US side of things so isn't as clear cut in terms of UK hosting.

 

Might want to do a quick search under the DPF if those other two companies are listed: https://www.dataprivacyframework.gov/s/participant-search https://www.dataprivacyframework.gov/list as that would give you the quickest answer to if that's even an option under those guidelines. As an example from above for Microsoft:

[ATTACH=CONFIG]72543[/ATTACH]

 

Steve

Thanks for this. Funnily enough one of the 2 overseas companies has just notified us of their presence on the DPF list. I checked and they are indeed there! I suspect our DPO is not quite up to date. Could you expand on you comment about opt-in on US site - do you mean they have if they are on the DPF list? I was a little confused by the 'UK hosting' comment.

Posted

I just mean that not all US firms are automatically covered even with the extension ruling. They need to opt in via the DPF platforms etc unlike companies in UK where they have no choice but to comply with GPDR

 

That’s good to hear that at least one of them is on the list.

 

Steve

  • Thanks 1
Posted

Some good responses so far and the only comments I would add are around adequacy and risk assessments, and these are general comments, rather than specific to the OP.

 

The DPF is a handy mechanism to allow data transfer to the US. It makes the hoop jumping around SCCs and such a lot simpler and lets you get straight to the bone of the issue. The CLOUD Act is what most people worry about and that can affect you no matter where you are.

 

https://iapp.org/news/a/questions-to-ask-for-compliance-with-the-eu-gdpr-and-the-u-s-cloud-act/ gives a good coverage of what it means, but we have to remember that law enforcement agencies regularly make requests to each other about data, and some have been known to intercept traffic anyway.

 

There are ways to mitigate this. If the vendor ensures that the data is encrypted at rest and also in transit, then it is down to who holds the keys.

 

If the sub-processor does (eg AWS) then the risk is AWS are asked for the data. If it is the Data Processor, then you need to look at whether the DPF helps to cover any requests or if they are even affected by the CLOUd act.

 

If you hold the keys (rare but it does sometimes happen) then the CLOUD act would not apply, but you are still subject to law enforcement requests. They would just come via the UK authorities on behalf of the US.

 

Then you need to consider the likelihood of a request being made. Do you have data of US citizens? Overseas visitors? Data which could be relevant to the UK’s PREVENT agenda? General fishing for data by authorities is not likely to happen (safeguards in place should help in this), but what would the impact be if it was, and the data was held by US agencies? It is not going into some adtech data lake or being sold off. Used for future profiling? A possibility but are you holding any data likely to be used for that purpose?

 

When people talk about the US with EdTech vendors, they are usually more worried about the data being shared with third parties (I.e. other data controllers such as AdTech profiling firms, looking to pool data to target individuals) rather than data being processed by processors and sub-processors. This is increasingly important as new data sources are also sought for AI training.

 

Check to see if the vendor refers to deidentified data rather than anonymised. Look to see if they will use data for R&D or live data for testing.

 

Most of these areas are relevant no matter the location, but may be particularly in need of review when considering US hosting.

 

I could never say US = good/bad as the risks need to be relevant to your own institutions or organisations, but I hope this helps.

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...