SimpleSi Posted September 20, 2011 Posted September 20, 2011 Assuming A Cloud Service doesn't loose/sell/hack our data: Do I have to worry about anything? Well - they are not going to sell it and I'd be amazed if the year 7 cat scores ended up in the Guardian Si
CyberNerd Posted September 20, 2011 Posted September 20, 2011 1) There is a law in the UK (and equivalent laws within the EU which are compatible with it) called the Data Protection Act. This is a very clear law as to what people can and can't do with data and information of belonging to others, how you let others know you are going to use / handle their data and supported by 8 clear principles. What this means : The 8 principles are pretty simple to follow and the key areas of concern with cloud based systems is where the data is stored, how it gets there and how access to it is controlled. This is not about risk management where you can be willing to accept the risk, as the law says you *must* comply with all aspects of it. This seems contrary to the ICO link you posted earlier in the thread, which actually says that you can store data in 'non-approved' countries by doing a risk assessment. ie - it is about risk management. Clearly it is easier to 'prove' to a court that you are satisfied if X were safeharbour, but DPA doesn't prohibit use of non-EU non-Safeharbour sites. It does seem to be directed more towards the county they are stored in, rather than the company though. Obviously you couldn't assess that dropbox's servers have an adequate level of protection if you don't know what country they are stored in. the ICO page says this: How do I assess adequacy? You will need to be satisfied that in the particular circumstances there is an adequate level of protection. For UK personal data the Act sets out the factors you should take into account to make this decision. These relate to: the nature of the personal data being transferred; how the data will be used and for how long; and the laws and practices of the country you are transferring it to. This means doing a risk assessment. You must decide whether there is enough protection for individuals, in all the circumstances of the transfer. This is known as an assessment of adequacy. To assess adequacy you should look at: the extent to which the country has adopted data protection standards in its law; whether there is a way to make sure the standards are achieved in practice; and whether there is an effective procedure for individuals to enforce their rights or get compensation if things go wrong. 1
GrumbleDook Posted September 20, 2011 Author Posted September 20, 2011 I had hoped that now referring back to previous posts would have worked ... I didn't quite put enough information in it. I should have repeated that this is in reference to Dropbox and Safe Harbor. The countries which have been assessed and show an adequate level of protection is covered within the same page. The US is not in the list but Although the United States of America (US) is not included in the European Commission list, the Commission considers that personal data sent to the US under the “Safe Harbor” scheme is adequately protected. When a US company signs up to the Safe Harbor arrangement, they agree to: follow seven principles of information handling; and be held responsible for keeping to those principles by the Federal Trade Commission or other oversight schemes. Certain types of companies cannot sign up to Safe Harbor. View a list of the companies signed up to the Safe Harbor arrangement on the US Department of Commerce website. In the example you have given (assessment of adequacy) is an assessment of whether they comply with the law. This differs from a Risk Assessment where there is risk that they might not comply with the law yet you are happy to accept this. Apologies if I didn't explain that bit fully. In the US a company is deemed adequate if they have signed up and been certified under Safe Harbor (remembering to check what they have agreed to within that agreement ... as they may not be covered for everything you want), although it is a voluntary scheme and some sections are restricted from being part of this (and covered under other acts and regulations to do with finance and telecommunications) a company who has not signed up to it (never mind the wooliness of the T&Cs) gives no guarantee of adequacy. Paraphrasing from a conversation with a DP expert who worked on the Becta advice ... If you go down the route of trusting to a contract which has the terms to dictate adequacy then you take the responsibility on yourself as you can only deal with them for breach of contract and not breach of law. At that point the school itself cannot guarantee the law is being complied with. The school has a responsibility to ensure all who process the data comply with the law ... (I forget the exact section of the act but part of principles 7 & 8) and if this cannot be guaranteed then the school is in breach. The example given to me (and pretty relevant) is if you have an insecure online form you don't have to lose data to be in breach ... the fact that it is possible means you have not done your job right. This is pretty relevant right now since this is what CEOP got collared for recently and had to sign an undertaking. I have probably mangled the explanation a bit now ... (might have to clean it up tomorrow when awake) but I'm just trying to point out the difference between accepting risk and assessing adequacy. Drawing the line of how you then firm up that is looking like a grey area, but all the advice I have had so far (Becta, ICO, Cabinet Office) has been that for US they have to have signed Safe Harbor for the relevant data uses you want. Since Dropbox can't even guarantee using US data centres, have a history of security problems, then I don't think it would be beyond the realms of acceptance to say it is doubtful whether we could say they are taking the right measures to allow users / schools to regard them as adequate. Especially since they will not respond to questions on their forums about it and have yet to respond to 5 requests that I am aware of asking them this question (3 from me and 2 from teachers looking at the same issue). We can only work with hard facts at this point ... Sleep calls ... out tomorrow so I'll look at any response tomorrow night. 1
CyberNerd Posted September 20, 2011 Posted September 20, 2011 That does make sense to me, although it does seem like a minefield, even without taking into account what actually constitutes private data! I've already given SLT advice against using dropbox, although we use a google apps domain. I believe that I've made the correct decisions so far with regards to google, dropbox. And MS's track record for complying with the law (assessment of adequacy) kind of put them out of the frame anyway, regardless of where there data sits.
znova Posted September 21, 2011 Posted September 21, 2011 Just to add my twopenneth - did a fair ammount of research on DPA & US Safe Harbor, and I have a BIG issue with Safe Harbor - unlike the DPA, it NOT legally enforcable. So if anyone wanted to be picky, your data stored in a data centre in US is pretty vulnerable. Grumbledook is correct in saying that you do not need to store data in the EU PROVIDED you can insure it will receive the same level of protection. But if Safe Harbor isn't legally enforcable and trigger-happy US government can raid data centres at any time, US for me isn't really an option. The other point which came up during discussions on this issue in my uni course; what happens to the data which crosses country boundaries? That data will have to be encrypted to the level on lowest common denominator between the countries it crosses during the transfer. If I remember correctly, one of our lecturers (from States) was travelling to the States with an encrypted memory stick but the encryption was higher than the US goverment permits and he could have been tried under some obscure weapons law (can't remember which one though) To be honest, it is a maze, I was thinking about all the cloud-centred software schools use (mymaths springs to mind) and we really don't have a clue where these companies really store the data...
SimpleSi Posted September 21, 2011 Posted September 21, 2011 I was thinking about all the cloud-centred software schools use (mymaths springs to mind) and we really don't have a clue where these companies really store the data... so lets stop bothering worrying about it then Si
PiqueABoo Posted September 21, 2011 Posted September 21, 2011 Re. "trumping" I posted an angle on thatl last Dec. Re: SkyDrive I thought MS explicitly said data stored there could end up anywhere in the world (unlike Live@edu which is, and Office365 sharepoint which is supposed to bee EU)? Have they changed that?
SlimBUK Posted September 22, 2011 Posted September 22, 2011 I use sugarsync, but not for any sensitive information. (sorry if it's already been mentioned, I've not read the whole thread)
zag Posted September 22, 2011 Posted September 22, 2011 Well I'm going to continue to use dropbox as my main storage area. Will take my chances I think! Its just too convenient. 1
localzuk Posted September 22, 2011 Posted September 22, 2011 Well I'm going to continue to use dropbox as my main storage area. Will take my chances I think! Its just too convenient. I'll continue storing all my money in a big box outside my door. Its just too convenient... 1
SimpleSi Posted September 22, 2011 Posted September 22, 2011 I'll continue storing all my money in a big box outside my door. ..and the url for that is? Si
GrumbleDook Posted September 22, 2011 Author Posted September 22, 2011 After speaking with ICO, OFSTED and legal advice I have the following ... again paraphrased until I have agreement on text to stick up. As far as the ICO is concerned there is a risk about Safe Harbour and the Patriot Act, but to some extent this is negated because data can be seized / released anyway under section 35 of the DPA. The key thing is that you need to tie in any contract arranged within the EU with companies that might be affected by The Patriot Act with breach of contract should any data be released. It can then become a civil matter, but backed up by DPA should it not fall within section 35 exemptions. As far as OFSTED are concerned they do not deal directly with looking at DPA policies / procedures within Section 5 or Section 8 inspections, and it does not look as if this would change even should an Undertaking be signed between the school and the ICO. They would, however, be looking at other safeguarding aspects so should it be linked in with that (including loss of data about children in care) or should a concern be raised by the Local Safeguarding Children's Board then it would be looked at. I have asked OFSTED to confirm that they would not change any approach to inspection should an Undertaking have been signed, and in a manner I can share with schools. So ... it looks as if I will have to change some of my stance on this as it seems as if no matter what some bodies say in meetings or seminars, they are not willing to back it up with real authority. Oh well ... I am sure that this would go down well with the Daily Fail! 1
CyberNerd Posted September 23, 2011 Posted September 23, 2011 It seems that if any company that stores your private data goes bankrupt - they can just sell off your private data. Not specifically a cloud issue, just thinking about some of those flakey cashless catering systems.... To perhaps to no one's surprise, Borders bookstore collected a ton of consumer information - such as personal data including records of particular book and video sales - during its normal course of business. Such personal information Borders promised never to share without consumer consent. But now that the company is being sold off as part of its bankruptcy filing, all privacy promises are off. Reuters wrote this week that Barnes & Noble, which paid almost $14 million for Borders intellectual assets including customer information at auction last week, said it should not have to comply with certain customer privacy standards recommended by a third-party ombudsman. In court papers, Barnes & Noble said that its own privacy standards are sufficient to protect the privacy of customers whose information it won during the auction. Layer 8: Privacy stink erupts over Borders bankruptcy deal
GrumbleDook Posted October 13, 2011 Author Posted October 13, 2011 (edited) Well, I have a few more answers now and it covers a range of areas. 1 - After some discussions with a Duty Inspector at OFSTED I had a partial response to the theoretical question about what affect having to sign an Undertaking with the ICO would have on an inspection. Unfortunately I am only allowed to paraphrase the response as no individual answer can be published at the risk of it seeming to be policy advice, which can only be gained from the relevant DfE page on Safeguarding Children and Safer Recruitment (which is a reference to the 2006 paper on this subject https://www.education.gov.uk/publica...FES-04217-2006 ). OFSTED do not, for Section 5 or Section 8 inspections, check compliance with the DPA as this is the job of the ICO. However, they will look at how well the governing body and the school leadership fulfils its responsibilities in relation to statutory requirements and/or statutory codes of practice or guidance, including the relevant Health & Safety legislation. They will also evaluate any non-compliance with relevant legislation, including DPA, on pupils' safety, care and well-being. Putting it bluntly, if this leads to Safeguarding to be found to be inadequate, then the 'overall effectiveness' judgment for the school is also likely to be judged inadequate. So ... an Undertaking is not just a slap on the risks but can risk OFSTED judging your school inadequate. I will be watching those schools who have recently had to sign Undertakings to see what happens at their next inspections. 2 - The Patriot Act has been a bit of a concern for a few of us ... after all, there is nothing wrong with a bit of paranoia ... it is what we get paid for ... and just because you aren't paranoid it doesn't mean the world *isn't* out to get you! After a bit more delving with the ICO (again ... that paraphrasing thing) I got the following. The Patriot Act and The DPA do match quite well. We have our own equivalent section, section 35, and co-operation between Law Enforcement Agencies and Governments around the world will mean information is disclosed as required. In fact there was a darned good article which @rayfleming refers to in his blog How safe is my cloud data? And what which links to another good article from Jeff Bullwinkel. Whilst it is related to Australia it does also cover a number of similar concerns from the UK too. So ... to summarise. Breaches of DPA are bad, Undertakings are not just a slap on the wrist as they put you at risk of issues during OFSTED inspections, and The Patriot Act is a bit of a Red Herring that should not overshadow the other concerns around Data Protection. Official strategy and guidance is limited, open to interpretation (think 'rope to hang yourself' stuff) and no matter what anyone says you will find people taking on a lot of risk. The key messages ... If you want to take a risk then be aware of the possible implications, there is still a matter of the law, but make sure people are as informed as possible because ignorance is no excuse in the eyes of the Law. Thanks to everyone who has taken part in this discussion... Edited October 14, 2011 by ZeroHour 2
smithson83 Posted October 14, 2011 Posted October 14, 2011 (edited) Kinda expensive... $299 a year for 3 users. There is a free option, you just have to look for it, click sign up, go down to the bottom. You get 5GB of storage. It has to be registered to an individuals email account, but as far as I'm aware there nothing stopping each teacher setting up a Free account for themselves. https://www.sugarsync.com/signup?startsub=5 Edited October 14, 2011 by smithson83
gshaw Posted October 17, 2011 Posted October 17, 2011 Only seen a few pages of this but what data are people looking to store on Dropbox? I'd never put anything with student names, reports, grades etc up there, too risky but resources and learning materials would be OK... although that relies on users understanding the restrictions which I guess could be as dangerous as allowing anything up there?
zag Posted October 17, 2011 Posted October 17, 2011 Yeh I can understand not using dropbox for Student details but I use it for everything else. I was hoping to do the same for students one day.
gshaw Posted October 17, 2011 Posted October 17, 2011 Yeh I can understand not using dropbox for Student details but I use it for everything else. I was hoping to do the same for students one day. BYOD will make this interesting... if a student brings their own laptop \ tablet and wants to use a personal Dropbox account then at that point the agreement isn't related to the school... only one step removed from the organisation provisioning the accounts but yet in theory completely different application of DPA (or maybe it's not, hence raising the point )
GrumbleDook Posted October 17, 2011 Author Posted October 17, 2011 The original article was sparked off by a number of folks on twitter and at meetings I had been to talking about how DropBox could replace the USB Memory Stick as a way of storing and transferring files around *including* stuff that would have SIROs fuming! Sharing of files as stimulus for curriculum activities is one of several good examples of using dropbox, but staff using it for mark sheets, contact databases, etc ... *shudder* On the note of BYOD/BYOT/BYOC (I wish someone would make a definitive choice about which it is) this is linked to a serious of conversations about eSafety law in Education that some folk may have seen or been part of. The idea that if you instruct a child to use a tool or resource, even if it isn't the school's, can mean the school takes on the responsibility for what happens with it. This part of the discussion is around eSafety but I suppose it can readily be pointed to similar issues with data protection.
SYNACK Posted October 17, 2011 Posted October 17, 2011 The idea that if you instruct a child to use a tool or resource, even if it isn't the school's, can mean the school takes on the responsibility for what happens with it. Off topic but this whole idea (above) is based on the same flawed premise that demands internet filters be 100% and that everything be fixable with technology. A view usually held and promoted by those least qualified to understand the technology and most aversed to people taking responcibility for themselves.
GrumbleDook Posted October 17, 2011 Author Posted October 17, 2011 Off topic but this whole idea (above) is based on the same flawed premise that demands internet filters be 100% and that everything be fixable with technology. A view usually held and promoted by those least qualified to understand the technology and most aversed to people taking responcibility for themselves. The discussion being held is purely based on the Law involved, and it is quite extensive. It has been an eye-opener for me and whilst I still view some of the position unrealistic the points of law still have to be looked at and followed.
SYNACK Posted October 17, 2011 Posted October 17, 2011 The discussion being held is purely based on the Law involved, and it is quite extensive. It has been an eye-opener for me and whilst I still view some of the position unrealistic the points of law still have to be looked at and followed. Ah, yes, some laws do have tend to have that issue, my above point stands just pointed at the lawmakers which seems to be where the blame lies.
GrumbleDook Posted October 17, 2011 Author Posted October 17, 2011 Ah, yes, some laws do have tend to have that issue, my above point stands just pointed at the lawmakers which seems to be where the blame lies. The focus on the discussions tends to be around identifying what the Law is, how it is checked for ALARP, where the responsibility lies and what the impact is of breaking the Law or following the Law. Dr Bandey is looking to do some stuff at BETT around it (supported by our friends at SmoothWall) so that will be interesting for folk to follow.
danielstucke Posted February 16, 2012 Posted February 16, 2012 So I guess this helps matters along a lot with Dropbox? The Dropbox Blog » Blog Archive » US-EU Safe Harbor Certification now safe harbor compliant. 2
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now