She should push back on that, since there is no legal basis for it (except in very specific circumstances).
It would be cheaper to get competent legal advice than do a shift like this for many offices.
She should push back on that, since there is no legal basis for it (except in very specific circumstances).
It would be cheaper to get competent legal advice than do a shift like this for many offices.
To remove GDPR from the UK we'd have to change the data protection act.
I am not an expert on UK Law but I also wondered if it is possible that the reference on the GDPR would still be valid
https://en.wikipedia.org/wiki/Regulation_(European_Union)#De...
So you can make legislation around a Regulation but can't override its effects.
Is that possible with companies in USA? How?
> Trustees have overall control of a charity and are responsible for making sure it’s doing what it was set up to do. They may be known by other titles, such as:
directors
board members
governors
committee members
> Whatever they are called, trustees are the people who lead the charity and decide how it is run. Being a trustee means making decisions that will impact on people’s lives. Depending on what the charity does, you will be making a difference to your local community or to society as a whole.> Trustees use their skills and experience to support their charities, helping them achieve their aims. Trustees also often learn new skills during their time on the board.
I would advice for Nextcloud and Onlyoffice. If you are hardcore data protection.
This joins a long list of bullshit reasons to do things, that often isn't based in understanding of what The Thing is actually requiring.
"Computer says no", "health and safety", "more than my jobsworth", "data protection", "safeguarding", "the regulator says", etc etc etc.
I am in touch with other DPOs and our federal dpos - the big elefant in the room is Microsoft and Windows 10. Everybody knows that you can't use it if you follow the GDPR or at least you have to jump so many loops that it is practical impossible.
The federal DPOs advice against Teams and OneDrive so Microsoft gets the message but if the CJEU looks at Windows from a GDPR perspective Everybody had to stop using it.
Ok this is the legal stuff.
Here is the technical stuff [1]. In short: Windows 10 sends all kind of data including whole documents to Microsoft USA and you can't stop it using the OS but have to apply Firewall rules and DPI.
So if you really want to use Microsoft you have to make a Data protection impact assessment for each new version of windows 10. I know no one who does this. But if you ask the federal dpo they will tell you that they can't say if you can use windows 10 for this or that but you should asses it yourself using a data protection impact assessment.
I just hope nobody will ever touch this sticky ball
[0]https://www.microsoft.com/en-us/licensing/product-licensing/...
[1]https://www.bsi.bund.de/EN/Topics/Cyber-Security/Recommendat...
In paragraph 183 of C-311/18, the CJEU also found that US surveillance “in transit” (like “Upstream” or taps of the underwater cables) violate EU fundamental rights.
Windows is GDPR compliant. See section 3 of https://docs.microsoft.com/en-us/windows/privacy/windows-10-...
GRDP compliance isn't too bad for a company like Microsoft who has decent data auditing ability. It's pretty easy for them to give you your windows data and delete it if required, and that's what is required for basic GRDP compliance.
If there is public advice otherwise a citation would be useful.
Note that your subsequent comment claiming that FISA request make GPDR compliance impossible is also incorrect as they are explicitly excluded (as law enforcement) by the GPDR: https://ico.org.uk/for-organisations/guide-to-data-protectio...).&text=However%2C%20it%20is%20covered%20by,for%20national%20security%20and%20defence.
Official citation:
Dutch DPA
https://autoriteitpersoonsgegevens.nl/en/news/dutch-dpa-micr...
THere is a excemption for Law Enforcement but it even law enforcment has to comply with basic human rights:
In paragraph 183 of C-311/18, the CJEU also found that US surveillance “in transit” (like “Upstream” or taps of the underwater cables) violate EU fundamental rights.
"Microsoft plans to rectify the situation through the next Windows 10 update in April 2018. This will end the violations noted in the Dutch DPA’s investigation report.... Microsoft has agreed to do this, and the Dutch DPA will monitor implementation."
https://autoriteitpersoonsgegevens.nl/en/news/privacy-window...
"In transit" US surveillance applies to all providers (including non-US providers) so doesn't preclude Microsoft.
As you stated Microsoft can and will update its Practices to be more Compliant if enough pressure is applied.
I have more citations and also newer but they are in German.
Office 365 and Schools: https://datenschutz.hessen.de/pressemitteilungen/zweite-stel...
Checklist on Videoconferencing (including Teams): https://www.datenschutz-berlin.de/fileadmin/user_upload/pdf/...
And on the technical side:
https://www.bsi.bund.de/EN/Topics/Cyber-Security/Recommendat...
The Berlin DPO stated that Microsofts Data Processing Addendum is not Compliant with GDPR (second link) so wherever it is applied you are also non compliant as data controller.
Ok this is all heavy on Microsoft and I am not stating that any other company is better off. The bottom line is this: US Law violates the basic human rights guaranteed by the EU - there is no appeal for non-US citizens and the "full take" of all data is disproportionat. If you can not shield EU citizens from the regarding US Laws you can't use an US Service.
Thats the consequence from the CJEU ruling.
It says they will allow the use of Office 365 in schools.
It's not as much as allow but tollerate if certain prerequirements are met e.g. not sending any diagnosis data to Microsoft. And it sounds more like they are somewhat pressured into it. Intensive talks...