13.09.2014 Views

advice in relation to external service providers (PDF 44 KB)

advice in relation to external service providers (PDF 44 KB)

advice in relation to external service providers (PDF 44 KB)

SHOW MORE
SHOW LESS

Transform your PDFs into Flipbooks and boost your revenue!

Leverage SEO-optimized Flipbooks, powerful backlinks, and multimedia content to professionally showcase your products and significantly increase your reach.

THE UNIVERSITY OF DUBLIN<br />

Tr<strong>in</strong>ity College<br />

DATA PROTECTION ACTS<br />

EXTERNAL SUPPLIERS OF SERVICES<br />

Data Protection <strong>advice</strong> note No. 1<br />

Purpose<br />

This is <strong>to</strong> advise staff regard<strong>in</strong>g the Data Protection implications for the handl<strong>in</strong>g of personal<br />

data by <strong>external</strong> suppliers of <strong>service</strong>s <strong>to</strong> the College.<br />

Background<br />

In the course of its activities Tr<strong>in</strong>ity College handles the personal data of <strong>in</strong>dividuals. The<br />

Data Protection Act 1988 and the Data Protection (Amendment) Act 2003 govern the<br />

process<strong>in</strong>g of all personal data. The purpose of these Acts is <strong>to</strong> safeguard the privacy rights<br />

of liv<strong>in</strong>g <strong>in</strong>dividuals regard<strong>in</strong>g the process<strong>in</strong>g of their personal data by those who control<br />

such data. In particular, it provides for the collection and use of data <strong>in</strong> a responsible way,<br />

while provid<strong>in</strong>g aga<strong>in</strong>st unwanted or harmful uses of data.<br />

Contracts for <strong>service</strong>s<br />

There are times when, rather than discharge a <strong>service</strong> itself, the College may wish <strong>to</strong><br />

‘outsource’ the supply of a <strong>service</strong> <strong>to</strong> an <strong>external</strong> supplier. If the <strong>service</strong> <strong>in</strong>volves the<br />

process<strong>in</strong>g of personal data on behalf of the College then there must be a written contract<br />

between the College, known <strong>in</strong> this context as a ‘Data Controller’, and the supplier of the<br />

<strong>service</strong>. As a general rule it is wise <strong>to</strong> provide for Data Protection obligations when<br />

contract<strong>in</strong>g with suppliers of <strong>service</strong>s even where the handl<strong>in</strong>g of personal data is not<br />

immediately the subject of the <strong>service</strong>. If there is no provision for Data Protection<br />

compliance an additional agreement will have <strong>to</strong> be entered <strong>in</strong><strong>to</strong> wherever necessary. Data<br />

Protection is relevant anytime where <strong>service</strong> <strong>providers</strong> would have access <strong>to</strong> the personal data<br />

of <strong>in</strong>dividual students, residents or staff, which could occur, for example, <strong>in</strong> the context of<br />

<strong>external</strong> <strong>in</strong>formation systems software development.<br />

Def<strong>in</strong>itions of Data Protection terms<br />

• Data means <strong>in</strong>formation <strong>in</strong> a form that can be processed. It <strong>in</strong>cludes both au<strong>to</strong>mated<br />

data and manual data.<br />

Au<strong>to</strong>mated data means any <strong>in</strong>formation on computer, or <strong>in</strong>formation recorded with the<br />

<strong>in</strong>tention that it be processed by computer.<br />

Manual data means <strong>in</strong>formation that is recorded as part of a relevant fil<strong>in</strong>g system or with<br />

the <strong>in</strong>tention that it form part of a system.<br />

Relevant fil<strong>in</strong>g system means any set of <strong>in</strong>formation that, while not computerised, is<br />

structured by reference <strong>to</strong> <strong>in</strong>dividuals, or by reference <strong>to</strong> criteria relat<strong>in</strong>g <strong>to</strong> <strong>in</strong>dividuals, so<br />

that specific <strong>in</strong>formation relat<strong>in</strong>g <strong>to</strong> a particular <strong>in</strong>dividual is readily accessible.<br />

• Personal data means data relat<strong>in</strong>g <strong>to</strong> a liv<strong>in</strong>g <strong>in</strong>dividual who is or can be identified either<br />

from the data or from the data <strong>in</strong> conjunction with other <strong>in</strong>formation that is <strong>in</strong>, or is likely<br />

<strong>to</strong> come <strong>in</strong><strong>to</strong>, the possession of the College.<br />

• Data controller is a body that processes <strong>in</strong>formation about liv<strong>in</strong>g people. The Data<br />

controller must be <strong>in</strong> a position <strong>to</strong> control the contents and use of a personal data file.<br />

• Data processor is a body that processes personal data on behalf of a Data controller.<br />

• Process<strong>in</strong>g means perform<strong>in</strong>g any operation or set of operations on data, <strong>in</strong>clud<strong>in</strong>g:<br />

- obta<strong>in</strong><strong>in</strong>g, record<strong>in</strong>g or keep<strong>in</strong>g the data;<br />

- collect<strong>in</strong>g, record<strong>in</strong>g, organis<strong>in</strong>g, s<strong>to</strong>r<strong>in</strong>g, alter<strong>in</strong>g or adapt<strong>in</strong>g the data;<br />

- retriev<strong>in</strong>g, consult<strong>in</strong>g or us<strong>in</strong>g the data;<br />

- disclos<strong>in</strong>g the data by transmitt<strong>in</strong>g, dissem<strong>in</strong>at<strong>in</strong>g or otherwise mak<strong>in</strong>g it available; or<br />

- align<strong>in</strong>g, comb<strong>in</strong><strong>in</strong>g, block<strong>in</strong>g, eras<strong>in</strong>g or destroy<strong>in</strong>g the data.


Data Protection <strong>advice</strong> note No. 1<br />

What <strong>to</strong> <strong>in</strong>clude <strong>in</strong> a contract<br />

The Office of the Data Protection Commissioner advises that this contract ‘should stipulate at<br />

least the follow<strong>in</strong>g:<br />

• the conditions under which data may be processed;<br />

• the m<strong>in</strong>imum security measures that the data processors must have <strong>in</strong> place;<br />

• some mechanism or provision that will enable the data controller <strong>to</strong> ensure that the data<br />

processor is compliant with the security requirement. (This might <strong>in</strong>clude a right of<br />

<strong>in</strong>spection or <strong>in</strong>dependent audit.)’<br />

The follow<strong>in</strong>g is an example of a general Data Protection undertak<strong>in</strong>g <strong>in</strong> the agreed terms of<br />

bus<strong>in</strong>ess with a supplier.<br />

Where [name of the supplier] (hereafter: the supplier) provides [name of school or<br />

department etc.], Tr<strong>in</strong>ity College, Dubl<strong>in</strong> (hereafter: the department) with <strong>service</strong>s, the<br />

department authorises the supplier <strong>to</strong> process personal data on behalf of the department<br />

(hereafter: the data) <strong>in</strong> accordance with the Irish Data Protection legislation and other<br />

similar legal requirements for the time be<strong>in</strong>g <strong>in</strong> force (hereafter: the relevant legislation).<br />

The supplier shall act only on the <strong>in</strong>structions of the department, and shall comply at all<br />

times with the relevant legislation whether as <strong>to</strong> the security of personal data or<br />

otherwise. The supplier shall take any and all measures which are appropriate and/or<br />

necessary <strong>to</strong> protect aga<strong>in</strong>st<br />

(a) unauthorised and/or unlawful process<strong>in</strong>g of the data,<br />

(b) damage <strong>to</strong> or loss or destruction of the data, and/or<br />

(c) any other breach of the relevant legislation.<br />

The supplier shall answer the reasonable enquiries of the department <strong>to</strong> enable the<br />

department <strong>to</strong> moni<strong>to</strong>r the supplier's compliance with this clause and the supplier shall<br />

not sub-contract or otherwise outsource their process<strong>in</strong>g of personal data without the<br />

prior consent <strong>in</strong> writ<strong>in</strong>g of the department.<br />

More particular requirements may be required depend<strong>in</strong>g on the nature of the personal data.<br />

For example, if lists of students’ names and addresses were processed <strong>external</strong>ly then it<br />

would be worthwhile <strong>to</strong> ensure that such lists were kept securely, not copied or extracts<br />

taken, used only for the purpose <strong>in</strong>tended and returned follow<strong>in</strong>g completion of the contract.<br />

Information on data protection obligations is available from the Office of the Data Protection<br />

Commissioner and copies of relevant booklets published by the Commissioner are also<br />

available from the College Information Compliance Officer. Service <strong>providers</strong> should be<br />

given this <strong>in</strong>formation.<br />

Relevant extracts from the Data Protection Acts 1988 and 2003<br />

Section 2C(3):<br />

(3) Where process<strong>in</strong>g of personal data is carried out by a data processor on behalf of a data<br />

controller, the data controller shall—<br />

(a) ensure that the process<strong>in</strong>g is carried out <strong>in</strong> pursuance of a contract <strong>in</strong> writ<strong>in</strong>g or<br />

<strong>in</strong> another equivalent form between the data controller and the data processor and<br />

that the contract provides that the data processor carries out the process<strong>in</strong>g only on<br />

and subject <strong>to</strong> the <strong>in</strong>structions of the data controller and that the data processor<br />

complies with obligations equivalent <strong>to</strong> those imposed on the data controller by<br />

section 2(1)(d) of this Act,<br />

(b) ensure that the data processor provides sufficient guarantees <strong>in</strong> respect of the<br />

technical security measures, and organisational measures, govern<strong>in</strong>g the process<strong>in</strong>g,<br />

and<br />

(c) take reasonable steps <strong>to</strong> ensure compliance with those measures.


Data Protection <strong>advice</strong> note No. 1<br />

Section 2(1)(d):<br />

2.-(1) A data controller shall, as respects personal data kept by him or her, comply with the<br />

follow<strong>in</strong>g provisions:<br />

…<br />

(d) appropriate security measures shall be taken aga<strong>in</strong>st unauthorised access <strong>to</strong>, or<br />

unauthorised alteration, disclosure or destruction of, the data, <strong>in</strong> particular where the<br />

process<strong>in</strong>g <strong>in</strong>volves the transmission of data over a network, and aga<strong>in</strong>st all other<br />

unlawful forms of process<strong>in</strong>g.<br />

Other responsibilities of <strong>external</strong> Data Processors<br />

The Data Processors are responsible for register<strong>in</strong>g themselves with the Data Protection<br />

Commissioner, where necessary, and for comply<strong>in</strong>g with the terms of the legislation.<br />

Freedom of Information and <strong>external</strong> suppliers<br />

All those who hold or held contracts for <strong>service</strong>s are covered by the Freedom of Information<br />

Acts 1997 and 2003 <strong>in</strong>sofar as their records relate <strong>to</strong> the <strong>service</strong>s provided. Please see the<br />

Freedom of Information Advice Note No.4 Contracts for Services which is available at the<br />

College’s Freedom of Information website, www.tcde.ie/foi/.<br />

Procurement procedures<br />

College procurement procedures are set out at www.tcd.ie/Treasurers_Office/procure1.htm.<br />

Further <strong>in</strong>formation is available from the Procurement Officer.<br />

Disclaimer<br />

The forego<strong>in</strong>g <strong>in</strong>formation does not purport <strong>to</strong> be a legal <strong>in</strong>terpretation of the Data<br />

Protection Acts.<br />

College’s Data Protection website<br />

The College Data Protection website, http://www.tcd.ie/dataprotection/, <strong>in</strong>cludes <strong>advice</strong><br />

notes and other resources on Data Protection matters, <strong>in</strong>clud<strong>in</strong>g a l<strong>in</strong>k <strong>to</strong> the website of the<br />

Data Protection Commissioner.<br />

Contact <strong>in</strong>formation<br />

The Information Compliance Officer may be contacted<br />

by post <strong>to</strong><br />

by E-mail <strong>to</strong><br />

by FAX <strong>to</strong><br />

The Secretary’s Office,<br />

West Theatre,<br />

Tr<strong>in</strong>ity College,<br />

Dubl<strong>in</strong> 2;<br />

tturp<strong>in</strong>@tcd.ie;<br />

(01) 6710037 or<br />

by telephone <strong>to</strong> (01) 896 2154.<br />

T. Turp<strong>in</strong><br />

Information Compliance Officer July, 2005<br />

Ref: DPAdviceNo1-ContractsForServices(a)

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!