Hi Teresa,
As far as I am aware the FPN should be telling the customer of any ways in which their data is going to be used which is not obvious to the customer. It does not need to tell them exactly how a firm is internally going to process and store that data (I don't tell my customers that their data is going to be held on internal servers and also externally hosted servers as a back up). I also do not believe there is any requirement to tell an individual that their data may be transferred outside of the EU.
What you do need to do however, is ensure that sufficient due diligence is carried out on all 3rd party processors and that, where the data is being transferred outside of the EU, that the data is adequately protected. I believe the EU has set out some standard terms that should be used in contracts of this type.
If anyone believes this to be incorrect, I would like to know for future reference as this may be something which I am asked to look at more and more as time goes on.
Thanks
James
-----Original Message-----
From: This list is for those interested in Data Protection issues [mailto:[log in to unmask]] On Behalf Of Teresa Gudge
Sent: 03 November 2014 11:32
To: [log in to unmask]
Subject: [data-protection] Collection / Transfer / Storage of data
Hello all,
I've been on the periphery of data protection for a couple of years - but have recently changed jobs and would just like some reassurance from jismailers if possible :-)
I have been asked a question about an IT solution to a situation where completed web forms are submitted and subscriptions requested. The solution is for the webforms to be held in a cloud - and of course that cloud is in the states (signed up to safe harbour).
My first response is that if the fair processing notice states categorically that the data will be held in a cloud, in the states and the subscriber agrees to that then all is well.
Obviously existing data has the issue of transferring securely - and again retrospective consent from the contributors.
Am I missing anything ? I know that these two statements sounds pretty simple and obviously there are issues such as risk assessments, agreement from management etc. etc. but I just want to be sure.
Thanks for your help
Teresa
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
All archives of messages are stored permanently and are
available to the world wide web community at large at
http://www.jiscmail.ac.uk/lists/data-protection.html
If you wish to leave this list please send the command
leave data-protection to [log in to unmask] All user commands can be found at http://www.jiscmail.ac.uk/help/commandref.htm
Any queries about sending or receiving messages please send to the list owner
[log in to unmask]
Full help Desk - please email [log in to unmask] describing your needs
To receive these emails in HTML format send the command:
SET data-protection HTML to [log in to unmask]
(all commands go to [log in to unmask] not the list please)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
All archives of messages are stored permanently and are
available to the world wide web community at large at
http://www.jiscmail.ac.uk/lists/data-protection.html
If you wish to leave this list please send the command
leave data-protection to [log in to unmask]
All user commands can be found at http://www.jiscmail.ac.uk/help/commandref.htm
Any queries about sending or receiving messages please send to the list owner
[log in to unmask]
Full help Desk - please email [log in to unmask] describing your needs
To receive these emails in HTML format send the command:
SET data-protection HTML to [log in to unmask]
(all commands go to [log in to unmask] not the list please)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
|