Hi !
We recently released a processing protocol for the core services in Google Workspace for Education.
In light of this, we find it useful to highlight other compliance documents that might be relevant.
DPIA (Data protection impact assessment)
DPIA, in Norwegian "personvernkonsekvensvurdering", is a process that assists data controllers in identifying and minimizing the privacy risks when processing personal data poses a high risk to the data subjects' rights and freedoms. The goal of a DPIA is to ensure you, as the data controller, that you can protect the privacy of data subject.
Are we conducting this as part of the national DPIA project?
Absolutely! The primary objective of the project is to conduct a DPIA for Google Workspace for Education.
Risk assessment
A risk assessment is a systematic procedure to evaluate the likelihood and consequences of potential incidents affecting the protection of valuable information, such as personal data. The purpose of a risk assessment is to identify potential threats and vulnerabilities, assess the risk, and decide on appropriate measures to mitigate the risk to an acceptable level.
Is this something we are doing in the national DPIA project?
No, a risk assessment is different from a DPIA. As we mentioned in our previous newsletter, their purposes differ slightly. While risk assessments focus on protection against external threats, a DPIA helps data controllers safeguard the data subjects' privacy.
This DPIA doesn't technically evaluate how "secure" Google Workspace for Education is against external threats.
While information security principles ARE something you need to adhere to when ensuring privacy, a DPIA goes beyond that.
There is also overlap between privacy legislation requirements and other mandates a municipality must uphold. For instance, under the GDPR, you are obliged to demonstrate compliance, typically achieved through internal controls, which you're also mandated to maintain as per regulations such as eForvaltningsforskriften § 15, concerning internal control and information security.
Record of processing
A record of processing is a summary detailing the personal data you, as a data controller, process and the reasons why. The objective is to maintain control over the personal data you handle.
Are we doing this in the national DPIA project?
Yes, as mentioned at the start, we've created a record of processing for the core services in Google Workspace for Education.
While it isn't part of a DPIA, a record of processing provides an overview of what you do with personal data, which aligns closely with what should be in a DPIA's first section. Hence, we saw the value in crafting one under the national DPIA project.
This serves a dual purpose: it gives us a foundation to describe the processessing activities in Google Workspace for Education's core services and at the same time as we can offer a record of processing for you as a data controller can utilize.
Data processing agreement
This is an agreement between you, the data controller, and your data processor (supplier). As a data controller, you bear the primary responsibility for the privacy of the individuals whose data you process, and your data processor cannot handle your data without instructions.
A data processing agreement provides these instructions, detailing how your supplier should handle personal data on your behalf. Its aim is to ensure your supplier processes personal data in compliance with privacy requirements.
Is this something we're doing in the national DPIA project?
Yes and no. Google offers a standard data processing agreement that you must accept when procuring the solution. You can't truly negotiate its content with Google.
A part of the Norwegian Data Protection Authority's guidance on using Google Workspace for Education emphasizes that data controllers should be aware of all terms and agreements related to its use.
We'll provide an overview of these agreements as part of our DPIA guidance.
For more on data processing agreements and other compliance documents, check out SkoleSec's step-by-step guide: "What do I need to do before using a new digital service?".
I wish you a wonderful, privacy-friendly week-end!
Best regards,
Ida Thorsrud
Project manager national DPIA
This newsletter was translated from Norwegian to English with assistance from ChatGPT by OpenAI. While it guided our translation, we made independent editorial choices. Any discrepancies result from this combined approach.