Update DPIA Report Google Workspace for Education
Total Page:16
File Type:pdf, Size:1020Kb
Update DPIA report Google Workspace for Education 2 August 2021 By Sjoera Nas and Floor Terra, senior advisors Privacy Company 1 / 46 UPDATE DPIA REPORT GOOGLE WORKSPACE FOR EDUCATION | 2 August 2021 CONTENTS SUMMARY ........................................................................................................................ 3 INTRODUCTION ................................................................................................................ 6 OUTCOME OF NEGOTIATIONS 8 JULY 2021 ............................................................... 10 1.1. ROLE OF GOOGLE AS DATA PROCESSOR ...................................................................... 10 1.2. ROLE OF GOOGLE AS DATA CONTROLLER FOR ADDITIONAL SERVICES ................................ 11 1.3. ROLE OF GOOGLE AS INDEPENDENT DATA CONTROLLER ................................................. 12 1.4. COMPLIANCE WITH THE PRINCIPLE OF PURPOSE LIMITATION ............................................ 14 1.5. LEGAL GROUND OF CONSENT WITH REGARD TO MINORS ................................................. 14 1.6. LACK OF TRANSPARENCY ABOUT THE DIAGNOSTIC DATA ................................................ 15 1.7. RETENTION PERIODS OF PSEUDONYMISED PERSONAL DATA ............................................ 16 1.8. USE OF SUBPROCESSORS ........................................................................................ 18 1.9. FUNDAMENTAL RIGHT FOR DATA SUBJECTS TO ACCESS THEIR PERSONAL DATA .................... 18 1.10. RISKS OF TRANSFER OF PERSONAL DATA OUTSIDE OF THE EEA ........................................ 19 FULL LIST OF MITIGATING MEASURES BY GOOGLE .......................................................... 24 CHECKLIST MITIGATING MEASURES BY SCHOOLS AND UNIVERSITIES ............................. 27 SPECIFIC RISKS AND MEASURES FOR CHILDREN ............................................................. 31 APPENDIX 1: LIST OF ADDITIONAL SERVICES .................................................................. 36 APPENDIX 2: CHROME BROWSER AND OS ....................................................................... 37 2 / 46 UPDATE DPIA REPORT GOOGLE WORKSPACE FOR EDUCATION | 2 August 2021 Summary This Update DPIA report describes the successful outcomes of the negotiation process with Google to mitigate the high data protection risks resulting from the use of Google Workspace for Education. In the Netherlands 52% of primary schools and 36% of secondary schools use Google Workspace, as well as some faculties at 4 of the 14 universities, and at 4 of the 36 government-funded universities of applied sciences.1 This can be either the free or the paid (Plus) version. Thanks to the positive outcome of the negotiations, possible enforcement by the Dutch Data Protection Authority was averted. The Dutch DPA warned the educational sector on 31 May 2021 to stop using Google Workspace if the high risks could not be mitigated before the start of the new school year (21 August 2021). Results Google will mitigate the risks through a number of measures. The risks will be mitigated for both the free (Fundamental) and the paid (Standard and Plus) versions of the services. The only two privacy relevant differences between the free and paid version is that paying customers can choose to store content data for certain Core Services in data centres in the EU, and have access to more security features, such as device management. Google’s contractual, organizational and technical measures to lower the 8 high data protection risks are summarised in a table at the end of this Update report. Four highlights are: 1. Google has agreed to act as data processor for the Diagnostic Data about the individual use of the services. In a role as data processor Google may only process the personal data for the three (fixed) purposes authorised by the schools and universities, instead of the current 17 dynamic purposes. Google will only process Customer Personal Data and the Google Account Data in the Core Services as data processor, for the three purposes mentioned below, and only when necessary: 1. to provide, maintain and improve the Services and Technical Support Services subscribed to by Customer; 2. to identify, address and fix security threats, risks, bugs and other anomalies 3. to develop, deliver and install updates to the Services subscribed to by Customer (including new functionality related to the Services subscribed to by Customer). This improvement lowers three of the high known data protection risks: 1. loss of control over the Diagnostic Data, because Google’s purposes were unspecific and vague, and could be changed anytime, 2. lack of purpose limitation of the Diagnostic Data, because schools and universities could not instruct Google to only process for purposes they allowed, plus Google 1 These statistics were collected through questionnaires from SIVON and SURF in July 2021. 1 university and 3 universities of applied sciences answered they expect to completely stop using Google Workspace before the end of 2021. As far as is known, none of the MBOs (equivalent of junior college education) use Google Workspace. 3 / 46 UPDATE DPIA REPORT GOOGLE WORKSPACE FOR EDUCATION | 2 August 2021 reserved the right to ask pupils and students for consent for unknown new purposes; 3. the lack of a legal ground, because schools cannot obtain valid freely given consent from the (parents of the) children, and prior to the negotiations, legally the schools and universities were joint controllers with Google, but nor Google nor the institutions could base the data processing on a different legal ground from consent. The full adaptation of the data processor role requires significant technical and organisational changes to Google’s systems and processes and can therefore not be implemented overnight. However, the high risks will be mitigated before the start of the new school year. 2. Until Google releases a processor-version of the Chromebooks with the Chrome browser and a separate processor-version of the Chrome browser schools and universities can take risk-mitigating technical measures as listed at the end of this blog post. The commitment from Google to create a processor version is an important risk mitigating measure, in particular for primary schools in the Netherlands, as many of them use Chromebooks in school, and many parents have bought Chromebooks at home during the pandemic. As data controller Google permits itself to process the personal data processed on the Chromebook and collected through the browser about the web surfing behaviour from children, students and teachers for 33 broad commercial purposes, including many marketing purposes, behavioural advertising, business development and research. 3. Google remains a data controller for the services it calls Additional Services such as YouTube, Search, Scholar, Photos and Maps. As mentioned above, a data controller Google permits itself to process the personal data for 33 broad commercial purposes. Google does protect children and students when they use Search: they are automatically signed-out when they visit Search when they are logged-in with their Google Workspace for Education account. This means Google treats those data as if they were from an anonymous user, and Google cannot use the data for behavioural advertising. Unfortunately, Google does not offer this privacy protective easure for YouTube, Photos, Scholar or Maps. That is why schools and universities must use the option to technically prohibit end users from accessing the Additional Services. Children and students can still use Search after such blocking, but if they want to use other Additional Services, they have to create a separate (private) Google account. Schools can only continue to use YouTube if they embed selected videos in the Core Services, such as Classroom or Slides. Google to confirmed that any cookies in such embedded videos comply with the agreed measures ultimately by the beginning of the new school year. 4. Google has agreed to become more transparent. Google will publish significantly more documentation about the different kinds of personal data it collects about the individual use of its services (the Diagnostic Data), develop a data inspection tool for admins to compare the documentation with the data actually stored by Google, make it easier for system administrators to comply with data subject access requests from pupils and students and provide detailed information about the subprocessors for the Diagnostic Data. 4 / 46 UPDATE DPIA REPORT GOOGLE WORKSPACE FOR EDUCATION | 2 August 2021 The complete list of agreed measures sufficiently mitigates all known high privacy risks identified in the original DPIA, but only if schools and universities also take the following measures: sign up for the contract with the new privacy amendment, implement the recommended (technical and organisational) measures at the end of this Update report, and assess if there are specific additional risks related to their type of school and deployment. Role of SIVON and SURF The negotiations were conducted by SURF on behalf of all higher education institutions in the Netherlands, and by SIVON for all primary and secondary education schools in the Netherlands. In parallel, negotiations were conducted by the supplier management office for the Dutch central government (SLM Rijk). This Update DPIA report should be read in conjunction with the original DPIA on Google Workspace for the Amsterdam University of Applied Sciences (HvA) and the University of Groningen