madeline bennett

Poor data protection must carry a heavy price

If firms want to avoid tougher penalties and more regulation, they must step up their data protection efforts

Written by Madeline Bennett

It was difficult to avoid the issue of IT security last month. Two of the industry’s biggest events ­ the RSA security show in San Francisco and Infosecurity Europe 2008 in London ­ took place in April, giving vendors, IT professionals and other interested parties ample opportunity to be wowed by the latest security products, advised on best practice by industry experts and debate the hottest topics.

No surprise that data breaches dominated many of the sessions at the two events. Across the pond, experts mused on the possibility of rolling out federated data breach notification legislation across the US, to replace the current piecemeal, state-by-state arrangement. Meanwhile in London, the UK’s Information Commissioner once again called for stronger powers to crack down on those neglecting their data protection responsibilities.

The latest Information Security Breaches Survey, a biennial government-sponsored study carried out by consultancy firm PricewaterhouseCoopers, was also launched at Infosec. Drilling down into the security habits and concerns of just over 1,000 UK organisations of all sizes, the research gives a pretty comprehensive overview of the current IT security landscape. And generally the picture is fairly positive, with the overall number of attacks decreasing year by year, while firms appear to be taking many aspects of IT security much more seriously.

However, one statistic that struck me was in relation to protecting against data breaches. According to the study, less than three-quarters of respondents have documented procedures in place to ensure compliance with the Data Protection Act (DPA). Granted, this has increased from less than two-thirds in the 2006 study, while the proportion rises to nine out of 10 for large businesses. But it’s still worrying that over a quarter of companies, and 10 per cent of large enterprises, admit to failing to properly manage and audit their DPA compliance measures ­ some 20 years after the legislation was first introduced.

Some people argue that the DPA negates the need for the UK to introduce US-style data breach notification laws. After all, under the DPA organisations are already required to take certain steps to restrict access to personal information, so, the argument goes, this should be sufficient to protect individuals against data losses and therefore there is no need to introduce new rules to deal with the aftermath of breaches. My concern with that theory is the limited powers possessed by the Information Commissioner’s Office (ICO) to crack down on DPA breaches. Recent court cases involving the ICO provide clear evidence of these limitations.

The Information Commissioner has prosecuted various UK companies for failing to register with the ICO as a data controller, meaning organisations that process data. The ICO is keen to point out that notification carries a nominal fee of £35, while the penalty for failing to do so in recent cases has led to the guilty party laying out anything between £700 and £1,200 in costs and fines ­ a hefty markup although still affordable even for the smallest firms.

The revelation that many companies are still failing to properly keep track of their DPA compliance emphasises that the current legislation does not provide a cast-iron guarantee that personal data is always protected from loss or exposure ­ and gives further weight to the arguments for a rethink of UK data protection laws, whether that involves strengthening the ICO’s enforcement powers or introducing US-style legislation.

Tags:

reader comments

related articles

padlock on laptop

HMRC punishes staff over data privacy issues

HM Revenues and Customs has disciplined some 300 staff in the last three years 01 May 2008

 

BCS offers government advice on data control

The British Computer Society has urged the government to boost public trust in his ability to handle data 30 Apr 2008

Security professionals aim to end data breaches

Increasing sensitivity about corporate repuations is spurring actions on leaks 25 Apr 2008

Poor processes imperil data

While malicious attacks tend to grab the headlines, the prime causes of data breaches are usually more mundane 24 Apr 2008

Updated: IT security survey opens Infosec

Firms could do more to improve security, according to survey on IT breaches 22 Apr 2008

ICO given stronger data protection powers

Lib-Dem's compromise gets data protection breaches on to the statute books 09 May 2008

ICO calls for data trading sanctions to be implemented

Tough penalties need to be used to protect personal data, says commissioner 23 Apr 2008

ICO calls for data trading sanctions to be implemented

Tough penalties need to be used to protect personal data, says commissioner 23 Apr 2008

related whitepapers

today's top stories

Solid as a rock - business continuity in a global manufacturer

From power supply problems in Nigeria to email availability in Stockport, PZ Cussons is prepared for anything 02 Dec 2008

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

IT staff desperate to keep their jobs

Most would work longer hours for less pay 02 Dec 2008

VMware View 3 enhances virtual desktops

Virtual clients now take up less storage space and can be 'checked out' to a laptop 02 Dec 2008

Technology and privacy

Watch part one of a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 01 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Parcel being packedFeatures

Case study: eSpares and business continuity

Online electricals business has managed to decrease its downtime 02 Dec 2008

Royal Blackburn HospitalFeatures

NHS trust recovers from server overdose

Virtualisation technology breathed new life into East Lancashire's cost-intensive system 02 Dec 2008

Advertisement

Primary Navigation