Hi !
As part of the systematic description of processing activities in the DPIA, the National DPIA Project has created a proposal for a record of processing activities.
You can download the proposal in Norwegian here!
A Systematic Description of Processing Activities
A part of any DPIA is to systematically describe the processing activities. The Norwegian Data Protection Authority (Datatilsynet) has a guide that explains what such a systematic description should include. And it closely resembles what should be in a record of processing:
- What personal data is processed
- What is the purpose of the processing
- Who are the data subjects
-
How long will the personal data be stored
- What security measures are implemented
- Data flow, meaning where from where the personal data is collected, whether it is disclosed to anyone, and any potential transfers to third countries
That's why we decided it would be useful to create a record of processing under the aegis of the National DPIA Project.
You can download our proposal and use it if you haven't created a record of processing for the core services in Google Workspace for Education. And if your municipality already has a record of processing, you can use our proposal for inspiration.
A curiosity is that the legal basis is not a formal requirement in a record of processing under GDPR Article 30. But it's almost always included in a record of processing because it IS a requirement that you as the data controller document that the processing is legal aka your legal basis. And it's quite simple to document it in the record of processing.
Try the Record of processing and Give Us Feedback
One of the things we're aiming for in the National DPIA Project, is that we should share what we create as we go along. When we decide how we are going to do something, we will share it with you continuously. This is a fundamental part of our communication strategy. The goal is that if you keep track of what we do via this newsletter, none of our conclusions should come as a surprise.
This is why we are now publishing the record of processing for the core services in Google Workspace for Education.
So use it, and give us feedback on how it is to use. And if it can be improved, we will, with your feedback, adjust it so that the final version becomes better than it would have been if we had created it in a vacuum.
We specifically seek your insights on the legal grounds you and YOUR municipality rely upon to process students' profile pictures as personal information. Alternatively, please inform us if you have opted not to permit the use of profile pictures, and we would appreciate an explanation of the reasons behind such a decision.
Invitation to LinkedIn Live About the Record of processing
We will present the record of processing in a LinkedIn Live. We will walk you through the record, discuss the challenges we've faced, the choices we made, and what we believe are areas for improvement.
If you join us live, you can also ask us questions, and we will answer to the best of our ability. Or, you can give us direct feedback on the protocol.
Join us on LinkedIn Live Tuesday, October 17, 2023, from 12:00 to 13:00!
Can't make it at this time? That's okay! You can watch the recording afterward via the link above.
I wish you a wonderful, privacy-friendly week-end!
Best regards,
Ida Thorsrud
Project manager national DPIA
This newsletter was translated from Norwegian to English with assistance from ChatGPT by OpenAI. While it guided our translation, we made independent editorial choices. Any discrepancies result from this combined approach.