edutech4schools Posted January 31, 2013 Posted January 31, 2013 Hi, All the Bursars in our region had a meeting with our LA and another LA about a new broadband system they are rolling out. During the conference they were told not to use Google Apps for Education as it is not secure and the data is not held in the UK. How can they get away with saying this.
localzuk Posted January 31, 2013 Posted January 31, 2013 It depends on their own risk assessment - every LA and every organisation draw their 'acceptable to use' line differently. For me? I have looked into Google Apps and it is covered by the Safe Harbor agreement in the USA and has been determined to comply with EU data protection laws and UK data protection laws. So, its up to you - but you have to remember that ultimately the blame if something happens falls on you/your school if it goes wrong - which is why LAs lean on the side of caution. Not to mention that often they have a preferred supplier for such things themselves but that'd never sway their opinion of course...
maark Posted January 31, 2013 Posted January 31, 2013 Do you have to take any notice of what the LA say even if you are not an academy? Don't know how they can say it is not secure - it is the same product as google apps for business used by thousands of firms worldwide including legal companies.
sparkeh Posted January 31, 2013 Posted January 31, 2013 Well, without saying too much, from experience I have found that LAs can use scare tactics to in an effort to make people use their preferred system. Ultimately it is up to the school to decide whether they use it or not, but make sure you are aware of potential problems.
localzuk Posted January 31, 2013 Posted January 31, 2013 Do you have to take any notice of what the LA say even if you are not an academy? No. Schools have their own autonomy to make their own decisions, regardless of whether they're academies or not. However, some areas have more tightly integrated IT with their LEA than other areas. Personally, I'd tell them to keep their advice to themselves!
edutech4schools Posted January 31, 2013 Author Posted January 31, 2013 But to say it was not secure and does not meet uk law is not true and has scared a bursar at one of my schools who has requested we use Office 365 and not Google based on this info.
sparkeh Posted January 31, 2013 Posted January 31, 2013 But to say it was not secure and does not meet uk law is not true and has scared a bursar at one of my schools who has requested we use Office 365 and not Google based on this info. Ha! I was once told by an LA bod not to use 365 for the very same reasons
AngryTechnician Posted January 31, 2013 Posted January 31, 2013 Saying it is "not secure" is subjective. No computer system is completely secure. Ask to see their risk assessment. Saying the data is not held in the UK is correct. However, Google Apps is covered under the Safe Harbor framework, so storing data in Google Apps is not automatically in breach of the Data Protection Act just because the data is held outside the EU. This fact is poorly understood by many, and is probably the most frequent reason for rejection of Google Apps in local government. In short, the LA probably mean well, but they haven't done their homework. C-, must try harder, etc.
sparkeh Posted January 31, 2013 Posted January 31, 2013 In short, the LA probably mean well, but they haven't done their homework. C-, must try harder, etc. Or they have invested money in providing a platform and want people to use it? /cynicism
Arthur Posted January 31, 2013 Posted January 31, 2013 Google Apps (for Business) is now ISO 27001 certified. Would that make them change their minds? Today we are proud to announce that Google Apps for Business has earned ISO 27001 certification. ISO 27001 is one of the most widely recognized, internationally accepted independent security standards and we have earned it for the systems, technology, processes and data centers serving Google Apps for Business. Our compliance with the ISO standard was certified by Ernst & Young CertifyPoint, an ISO certification body accredited by the Dutch Accreditation Council, a member of the International Accreditation Forum (IAF). Certificates issued by Ernst & Young CertifyPoint are recognized as valid certificates in all countries with an IAF member.
edutech4schools Posted January 31, 2013 Author Posted January 31, 2013 Google Apps (for Business) is now ISO 27001 certified. Thanks for the link. Would that make them change their minds? For me it is not about changing their minds, I don't give a hoot what they think or use. My issue is with incorrect or liable information being given out to a lot of schools who would take it as fact and then pass that info on to other schools.
GrumbleDook Posted January 31, 2013 Posted January 31, 2013 The risk assessment has been talked about in other threads around DPA and cloud systems. The issue is partly around the local laws of the data centres. If the data centre is within the EEA (not EU ... There is a difference) or within the US... People are more acceptable of the risk due to understanding and control on local laws. This is why MS tend to be viewed more acceptable as you can specify the data centre as EU only (therefore it is within the EEA) ... held in Ireland or Netherlands, with no duplication elsewhere. This is not yet an option with Google Apps, and ISO27001 is superseded by local laws. Personally I would prefer that folk educate schools about the risk and help them understand why such recommendations are given. It is generally up to the school on this except where LAs are holding central data exchange agreements or where schools by into specific legal advice (eg they ask for advice, they get it but ignore it ... meaning if something goes wrong they cannot get further advice / cover). YMMV
edutech4schools Posted January 31, 2013 Author Posted January 31, 2013 and ISO27001 is superseded by local laws. So what is the local law?
Michael Posted January 31, 2013 Posted January 31, 2013 Hi, All the Bursars in our region had a meeting with our LA and another LA about a new broadband system they are rolling out. During the conference they were told not to use Google Apps for Education as it is not secure and the data is not held in the UK. How can they get away with saying this. The fact they've stated it's not secure, I'd have to agree it's a bogus statement. Would Google really jeopardise their reputation this easily? I very much doubt it. The data doesn't have to be held in the UK, it has or is recommended to be physically located anywhere in the EU, as all countries in the EU adhere to Data Protection Act(s). I think the problem will get worse as there's a conflict of interest at heart. LAs have invested money in providing services such as e-mail, however, there are a growing number of cloud services being offered for free such as Office 365 and Google Apps which are far superior. LAs can't compete with this, end of whether they like it or not.
mavhc Posted January 31, 2013 Posted January 31, 2013 Your data isn't secure anyway because your teachers use terrible passwords, and your pupils use even worse passwords. At least google has free 2 factor auth.
SYNACK Posted January 31, 2013 Posted January 31, 2013 (edited) The fact they've stated it's not secure, I'd have to agree it's a bogus statement. Would Google really jeopardise their reputation this easily? I very much doubt it. The data doesn't have to be held in the UK, it has or is recommended to be physically located anywhere in the EU, as all countries in the EU adhere to Data Protection Act(s). I think the problem will get worse as there's a conflict of interest at heart. LAs have invested money in providing services such as e-mail, however, there are a growing number of cloud services being offered for free such as Office 365 and Google Apps which are far superior. LAs can't compete with this, end of whether they like it or not. I doubt Google gives an excrement, they can coast on their ad revenue for a decade or so, it will be as private as it needs to be to collect sundry information on you and your users. If they trip up a little as has happened a few hundred thousand users will lose their 'privacy' and the story will helpfully be scrubbed from search engines. Companies operate for profit, you just need to stay in their profit margin and you'll probably be fine but drop out of the scope of profit and your for it. This is not limited to Google or even companies, large groups will also send you packing for some market share, Ubuntu anyone. Edited January 31, 2013 by SYNACK
GrumbleDook Posted January 31, 2013 Posted January 31, 2013 So what is the local law? Whatever local (country / state / regional) laws apply in the country where that data centre is hosted, eg Australia, Japan, Brazil, etc. Most companies will have this within their T&Cs (which everyone always reads)!
jmak Posted January 31, 2013 Posted January 31, 2013 As mentioned by many above, it's about risk management and an understanding of what the risk is, how likely it is to occur and what the impact would be should the identified risk occur is poorly understood as a concept, never mind applying to a specific situation. This goes for everything in school, from Data Protection, to allowing children to run in the playground. For DP, you need to consider the benefits of the facility you are providing, alongside the degree of risk you are currently exposing yourselves to with whatever system you currently have in place. If it helps to make your case, a specific example of use of Google is Norfolk County Council. They use them widely in schools and for County Council business.
Gaz Posted January 31, 2013 Posted January 31, 2013 Google will be secure as anyone is these days, but its things like this that they are scared of. BBC News - Experts warn on wire-tapping of the cloud Leading privacy expert Caspar Bowden has warned Europeans using US cloud services that their data could be snooped on.
AngryTechnician Posted January 31, 2013 Posted January 31, 2013 Indeed, Microsoft have in fact confirmed in the past that because they are a US company, the Patriot Act can be used by the US government to access any data they store, even in the Ireland datacentre. Microsoft admits Patriot Act can access EU-based cloud data | ZDNet
edutech4schools Posted January 31, 2013 Author Posted January 31, 2013 Thanks for all the info and links. Very handy.
psydii Posted February 1, 2013 Posted February 1, 2013 (edited) Safe Harbor is trumpted by the PATRIOT Act. But the UK ICO has a view on that scenario: https://www.google.co.uk/url?sa=t&rct=j&q=&esrc=s&source=web&cd=2&cad=rja&ved=0CDkQFjAB&url=http%3A%2F%2Fwww.ico.gov.uk%2Fconference2012%2F~%2Fmedia%2Fdocuments%2Fdpo_conference_2012%2Fafternoon_workshop_e1_notes.ashx&ei=AMALUb6fFpD14QTxrYDgBw&usg=AFQjCNFz2OGuad33cuP5uuS2sRfisPPgWQ&sig2=MFz364fWo84JlqTLLy-8pw Basically: every government anywhere has provision to snoop. Don't worry about it..... ....however if you have strong audit requirements surrounding your storage and use of data and you use a cloud provider that wont customize their T+C's to meet your audit requirements, then you do have a problem. My reading of the advice (and IANAL) is that the Safe Harbor and various external security certifications google have submitted themselves to should be adequate for Education. What is more interesting (and potentially troublesome) is that accessing your MIS/email while you are abroad qualifies as a data transfer... and so if you are outside of the EEA you need a policy in place to cover it. It appears that the crucial thing is that you have policies in place and that you have documented evidence that you have taken steps to ensure that they and the local relevent laws, protect the data as per EU Directives covering them. Edited February 1, 2013 by psydii
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now