Mervinskiy 516

Page 83

DPIA Google G Suite Enterprise for SLM Rijk | 9 July 2020, with update 12 February 2021

purposes are quoted between brackets, to indicate they only apply to the Diagnostic Data. 1. 2. 3. 4. 5. 6. 7. 8.

9.

10.

11. 12.

Help end users share content by suggesting recipients from their contacts; Maintaining the service by tracking outages; Provide recommendations For example, Security Check-up provides security tips adapted to how you use Google products; Provide personalised content, for example based on information like apps you’ve already installed (…) to suggest new apps you might like; Customizing our services to provide you with a better end user experience, provide customised search results; Optimize product design, For example, we analyze data about your visits to our sites to do things like optimize product design; Communicate with you to interact with you directly. For example, we may send you a notification if we detect suspicious activity;181 Improve the reliability of our services. We use automated systems that analyze your content to provide you with things like customized search results, [personalized ads], or other features tailored to how you use our services; Use cookies for many purposes. We use them, for example, to remember your safe search preferences, [to make the ads you see more relevant to you’], to count how many visitors we receive to a page, to help you sign up for our services, to protect your data, or to remember your ad settings.182; To allow specific partners to collect information from your browser or device for [advertising] and measurement purposes using their own cookies or similar technologies; When necessary for legitimate business or legal purposes such as financial record-keeping; Other purposes not covered in the Privacy Policy, we’ll ask for your consent.

In sum, this DPIA identifies 6 purposes for which Google processes personal data in Customer Data and 10, sometimes different, purposes for which Google processes Diagnostic Data from the Core Services. Given the lack of transparency about what Google qualifies as ‘Provide the Services and TSS’, it cannot be excluded that Google processes personal data and Diagnostic Data from the Core Services for 12 other purposes. For the avoidance of doubt, the purposes listed in this Section 4 only describe the factual findings of this DPIA. The assessment of whether these purposes are specific and explicit is made in Section 13. 4.3

Purposes Additional Services and Google Account, when not used in a Core Service The processing of personal data in connection with Additional Services is explicitly excluded from the scope of the G Suite DPA. Google explains that its consumer Terms of Service and its (consumer) Privacy Policy apply to such processing: “For clarity, this Data Processing Amendment does not apply to the processing of personal data in connection with the provision of any Additional Products installed or used by Customer, including personal data transmitted to or from such Additional Products. Customer may use the functionality of the Services to enable or disable

According to Google, this relates to the use of contact data. It is still included in this list because it is plausible that Google will use Diagnostic Data to detect suspicious activity. 182 Google, How Google uses cookies, URL: https://policies.google.com/technologies/cookies?hl=en 181

p. 75/162


Turn static files into dynamic content formats.

Create a flipbook

Articles inside

Conclusions

2min
page 170

17.4 Google measures 12 February 2021

19min
pages 161-169

16.3 Summary of risks

2min
pages 155-156

16.2 Assessment of Risks

36min
pages 142-154

15.7 Right to file a complaint

0
page 139

15.3 Right to access

5min
pages 136-137

14.3 Assessment of the subsidiarity

2min
page 134

14.1 The principle of proportionality

2min
page 130

14.2 Assessment of the proportionality

8min
pages 131-133

12.1 Transfer of special, sensitive, secret and confidential data to the USA

5min
pages 128-129

11.3 Google’s own legitimate business purposes

5min
pages 126-127

all Diagnostic Data

5min
pages 124-125

Services

22min
pages 116-123

Part B. Lawfulness of the data processing

2min
page 115

8.1 Anonymisation

15min
pages 106-111

6.3 Joint interests

11min
pages 101-105

6.2 Interests of Google

2min
page 100

6.1 Interests of the Dutch government organisations

2min
page 99

5.2 Data processor

5min
pages 88-89

5.3 Data controller

18min
pages 90-96

5.4 Joint controllers

5min
pages 97-98

4.4 Specific purposes Chrome OS and the Chrome browser

2min
page 86

5.1 Definitions

2min
page 87

4.3 Purposes Additional Services and Google Account, when not used in a Core Service

8min
pages 83-85

4.2 Purposes Google

13min
pages 77-82

4.1 Purposes government organisations

2min
page 76

2.5 Types of personal data and data subjects

7min
pages 60-62

3.2 Privacy controls administrators

7min
pages 70-75

3.1 Privacy controls G Suite account for end users

9min
pages 63-69

2.3 Outgoing traffic analysis

8min
pages 52-55

2.4 Results access requests

10min
pages 56-59

2.2 Diagnostic Data

7min
pages 47-51

Related services that may send Customer Data to Google, such as the Feedback form and the Enhanced Spellchecker in the Chrome browser.

4min
pages 13-15

2.1 Definitions of different types of personal data

7min
pages 44-46

Part A. Description of the data processing

0
page 25

The enrolment framework for G Suite Enterprise

2min
pages 42-43

G Suite Core Services, Google Account, Support Services, Additional Services, and Other related services

23min
pages 28-41

Functional Data

2min
page 27

Introduction

7min
pages 16-18

1 Legal framework and contractual arrangements between government organisations and

4min
pages 23-24
Issuu converts static files into: digital portfolios, online yearbooks, online catalogs, digital photo albums and more. Sign up and create your flipbook.