Jump to content

LiamR

Members
  • Posts

    2
  • Joined

  • Last visited

Reputation

25 Excellent

About LiamR

Personal Information

  • Homepage
    http://www.5thutility.co.uk

Employer (optional)

  • Company Represented
    5th Utility
  1. Hi all. Back to the original posters question about USB memory sticks. My suggestion is not to consider the medium, but the data. So, any device (USB stick, filing cabinet, server share, cloud storage, etc) does not in itself require protection (encryption, policy or otherwise). However, personal data (the definition is in the regulation, a bit too long winded for this answer unless you want me to find it) requires protection regardless of where it is stored. So if the USB device contains personal information, then yes it is absolutely covered by GDPR. As for the question about the schools responsibility when using a 3rd party, the answer is yes. Generally speaking the School that collected the info is defined in GDPR as the 'Data Controller' and the 3rd party is the 'Data Processor'. Under GDPR both can be liable, which differs from the 1998 Data Protection Act. In the post above, we see Microsoft's approach. This is becoming quite a standard approach with Software Providers (especially those with a SaaS service). In effect the vendor will be responsible for making sure that their software is compliant. But the customer (in this case the school) will be responsible for the policies, configurations, access, reporting etc. Thus resulting in 'shared responsibility'. As per the earlier post, the ICO's 12 point plan is a great place to start. https://ico.org.uk/media/1624219/preparing-for-the-gdpr-12-steps.pdf Regards, Liam.
  2. Sorry for joining the thread late in the day... To answer the earlier questions, Yes it has been confirmed that we the UK will proceed regardless of any exit of the EU. Plus, at the point GDPR becomes law in May 2018, we will still be in the EU. In regards to encryption. The report does articulate that encryption may mitigate the risk of data loss, for example the breach notification rules do not apply to encrypted data. However I think it is important to consider the specific use case/risk you are planning to mitigate. For example, full disk encryption on your servers will mitigate the risk of the servers or their disks being stolen. However it does nothing to prevent the data being leaked unintentionally by somebody with access to the server, who then uploads a file to dropbox. So for me, encryption is a good step, but should be used in conjunction with other approached. As the ICO have discretion over the penalties they impose, I think that the most important first step, is to be able to provide a plan of action, including staff at all levels. As per Charli's comments, there is some good info on the Gemalto site (vendor websites can be a great source of info, though they will tend to look for the areas that coincidently they can address). However, I would also start by taking a look at the ICO's own 12 step guide here: https://ico.org.uk/media/1624219/preparing-for-the-gdpr-12-steps.pdf Thanks Liam.
×
×
  • Create New...