Jump to content

Recommended Posts

Posted

Hi, All the Bursars in our region had a meeting with our LA and another LA about a new broadband system they are rolling out. During the conference they were told not to use Google Apps for Education as it is not secure and the data is not held in the UK.

 

How can they get away with saying this.

Posted

It depends on their own risk assessment - every LA and every organisation draw their 'acceptable to use' line differently. For me? I have looked into Google Apps and it is covered by the Safe Harbor agreement in the USA and has been determined to comply with EU data protection laws and UK data protection laws. So, its up to you - but you have to remember that ultimately the blame if something happens falls on you/your school if it goes wrong - which is why LAs lean on the side of caution.

 

Not to mention that often they have a preferred supplier for such things themselves but that'd never sway their opinion of course...

Posted

Do you have to take any notice of what the LA say even if you are not an academy?

Don't know how they can say it is not secure - it is the same product as google apps for business used by thousands of firms worldwide including legal companies.

Posted

Well, without saying too much, from experience I have found that LAs can use scare tactics to in an effort to make people use their preferred system.

Ultimately it is up to the school to decide whether they use it or not, but make sure you are aware of potential problems.

Posted
Do you have to take any notice of what the LA say even if you are not an academy?

 

No. Schools have their own autonomy to make their own decisions, regardless of whether they're academies or not. However, some areas have more tightly integrated IT with their LEA than other areas. Personally, I'd tell them to keep their advice to themselves!

Posted
But to say it was not secure and does not meet uk law is not true and has scared a bursar at one of my schools who has requested we use Office 365 and not Google based on this info.

Ha! I was once told by an LA bod not to use 365 for the very same reasons ;)

Posted

Saying it is "not secure" is subjective. No computer system is completely secure. Ask to see their risk assessment.

 

Saying the data is not held in the UK is correct. However, Google Apps is covered under the Safe Harbor framework, so storing data in Google Apps is not automatically in breach of the Data Protection Act just because the data is held outside the EU. This fact is poorly understood by many, and is probably the most frequent reason for rejection of Google Apps in local government.

 

In short, the LA probably mean well, but they haven't done their homework. C-, must try harder, etc.

Posted

In short, the LA probably mean well, but they haven't done their homework. C-, must try harder, etc.

Or they have invested money in providing a platform and want people to use it?

/cynicism

Posted

Google Apps (for Business) is now ISO 27001 certified. Would that make them change their minds? :confused:

 

Today we are proud to announce that Google Apps for Business has earned ISO 27001 certification. ISO 27001 is one of the most widely recognized, internationally accepted independent security standards and we have earned it for the systems, technology, processes and data centers serving Google Apps for Business. Our compliance with the ISO standard was certified by Ernst & Young CertifyPoint, an ISO certification body accredited by the Dutch Accreditation Council, a member of the International Accreditation Forum (IAF). Certificates issued by Ernst & Young CertifyPoint are recognized as valid certificates in all countries with an IAF member.
Posted
Google Apps (for Business) is now ISO 27001 certified.

 

Thanks for the link.

 

Would that make them change their minds?

 

For me it is not about changing their minds, I don't give a hoot what they think or use. My issue is with incorrect or liable information being given out to a lot of schools who would take it as fact and then pass that info on to other schools.

Posted

The risk assessment has been talked about in other threads around DPA and cloud systems. The issue is partly around the local laws of the data centres.

 

If the data centre is within the EEA (not EU ... There is a difference) or within the US... People are more acceptable of the risk due to understanding and control on local laws. This is why MS tend to be viewed more acceptable as you can specify the data centre as EU only (therefore it is within the EEA) ... held in Ireland or Netherlands, with no duplication elsewhere.

 

This is not yet an option with Google Apps, and ISO27001 is superseded by local laws.

 

Personally I would prefer that folk educate schools about the risk and help them understand why such recommendations are given.

 

It is generally up to the school on this except where LAs are holding central data exchange agreements or where schools by into specific legal advice (eg they ask for advice, they get it but ignore it ... meaning if something goes wrong they cannot get further advice / cover).

 

YMMV

Posted
Hi, All the Bursars in our region had a meeting with our LA and another LA about a new broadband system they are rolling out. During the conference they were told not to use Google Apps for Education as it is not secure and the data is not held in the UK.

 

How can they get away with saying this.

 

The fact they've stated it's not secure, I'd have to agree it's a bogus statement. Would Google really jeopardise their reputation this easily? I very much doubt it.

 

The data doesn't have to be held in the UK, it has or is recommended to be physically located anywhere in the EU, as all countries in the EU adhere to Data Protection Act(s).

 

I think the problem will get worse as there's a conflict of interest at heart. LAs have invested money in providing services such as e-mail, however, there are a growing number of cloud services being offered for free such as Office 365 and Google Apps which are far superior. LAs can't compete with this, end of whether they like it or not.

Posted
Your data isn't secure anyway because your teachers use terrible passwords, and your pupils use even worse passwords. At least google has free 2 factor auth.
Posted (edited)
The fact they've stated it's not secure, I'd have to agree it's a bogus statement. Would Google really jeopardise their reputation this easily? I very much doubt it.

 

The data doesn't have to be held in the UK, it has or is recommended to be physically located anywhere in the EU, as all countries in the EU adhere to Data Protection Act(s).

 

I think the problem will get worse as there's a conflict of interest at heart. LAs have invested money in providing services such as e-mail, however, there are a growing number of cloud services being offered for free such as Office 365 and Google Apps which are far superior. LAs can't compete with this, end of whether they like it or not.

 

I doubt Google gives an excrement, they can coast on their ad revenue for a decade or so, it will be as private as it needs to be to collect sundry information on you and your users. If they trip up a little as has happened a few hundred thousand users will lose their 'privacy' and the story will helpfully be scrubbed from search engines.

 

Companies operate for profit, you just need to stay in their profit margin and you'll probably be fine but drop out of the scope of profit and your for it. This is not limited to Google or even companies, large groups will also send you packing for some market share, Ubuntu anyone.

Edited by SYNACK
Posted

 

So what is the local law?

 

Whatever local (country / state / regional) laws apply in the country where that data centre is hosted, eg Australia, Japan, Brazil, etc. Most companies will have this within their T&Cs (which everyone always reads)!

Posted

As mentioned by many above, it's about risk management and an understanding of what the risk is, how likely it is to occur and what the impact would be should the identified risk occur is poorly understood as a concept, never mind applying to a specific situation. This goes for everything in school, from Data Protection, to allowing children to run in the playground. For DP, you need to consider the benefits of the facility you are providing, alongside the degree of risk you are currently exposing yourselves to with whatever system you currently have in place.

 

If it helps to make your case, a specific example of use of Google is Norfolk County Council. They use them widely in schools and for County Council business.

Posted (edited)

Safe Harbor is trumpted by the PATRIOT Act. But the UK ICO has a view on that scenario:

https://www.google.co.uk/url?sa=t&rct=j&q=&esrc=s&source=web&cd=2&cad=rja&ved=0CDkQFjAB&url=http%3A%2F%2Fwww.ico.gov.uk%2Fconference2012%2F~%2Fmedia%2Fdocuments%2Fdpo_conference_2012%2Fafternoon_workshop_e1_notes.ashx&ei=AMALUb6fFpD14QTxrYDgBw&usg=AFQjCNFz2OGuad33cuP5uuS2sRfisPPgWQ&sig2=MFz364fWo84JlqTLLy-8pw

 

Basically: every government anywhere has provision to snoop. Don't worry about it..... ....however if you have strong audit requirements surrounding your storage and use of data and you use a cloud provider that wont customize their T+C's to meet your audit requirements, then you do have a problem.

 

My reading of the advice (and IANAL) is that the Safe Harbor and various external security certifications google have submitted themselves to should be adequate for Education.

 

What is more interesting (and potentially troublesome) is that accessing your MIS/email while you are abroad qualifies as a data transfer... and so if you are outside of the EEA you need a policy in place to cover it.

 

It appears that the crucial thing is that you have policies in place and that you have documented evidence that you have taken steps to ensure that they and the local relevent laws, protect the data as per EU Directives covering them.

Edited by psydii

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...