What is SaaS-service and what risks the services have?
SaaS stands for "Software as a Service". SaaS services are software's that runs in the cloud and is subject to service fees. Usually, the pricing of service fees is based on the amount of users and time of use of the service. The service works through a web browser, but can also act as an application or a hybrid. Metropolia uses several SaaS services. For example. Microsoft Office 365, Adobe, E-Form and Zoom.
Note!
1. International transfer of personal data
The biggest risk in SaaS services comes from data processing, especially if the company operates outside the EU / EEA. In that case, the company will not be able to comply with the agreement on the processing of personal data pursuant to Article 28 of the GDPR. If the service provider operates outside the EU / EEA, it is necessary to assess the need for the service. Metropolia's data protection and information security experts recommend the use of European service providers.
According to the GDPR, personal data may in principle be transferred outside the EU Member States and / or the EEA (to a third country where the GDPR does not exist) only if that third country ensures an adequate level of data protection for these data.
2. Take at least these risks into account before purchasing the SaaS service
- Disclosure to third parties is risky. Who processes the data and what does the service provider do with the data? Is the data stored outside the EU / EEA?
- If the SaaS service business is not productive, it can lead to a deterioration in the security of the service. There is a risk of changes in service prices or, in the worst case, data leakage due to poor data security.
- The service provider is exposed to security risks just like any other company. At worst, it could cause the Metropolia data in the service to be leaked, destroyed or altered.
- When you stop using the SaaS service, Metropolia's data may remain on the service provider's servers.
- The promises made by the SaaS provider are not fulfilled as agreed or the service does not meet expectations.
3. Successful implementation of SaaS service
4. Useful information about SaaS-service can be found in the links below.
- 10 SaaS Security Risks And Concerns Every User Has
- Risks You Need to Consider When Using SaaS Providers
Mikä on SaaS-palvelu ja mitä riskejä palvelun käyttöönottoon kohdistuu?
- Created by Unknown User (kimmosv), last modified on 18.2.2022