information management

ICO welcomes data breach notification laws

The UK's data watchdog has joined calls for a US-style data loss reporting law

Written by Phil Muncaster

The UK’s privacy watchdog the Information Commissioner’s Office has welcomed recent calls for US-style data breach notification laws, but urged firms to act now to protect their systems rather than wait until current proposals become law.

Speaking at the opening session of this year’s RSA Conference Europe in London, deputy information commissioner, David Smith, said that a law forcing firms to disclose if customers' personal details have been stolen or exposed “would be welcome", but he cautiously added, "it must be a good one”.

“If we have a law, can we have it simple and easy to understand, not like the laws we have to administer at the moment?” he pleaded. “It mustn’t be notification for the sake of it, or put a disproportionate burden on business.”

Smith also warned firms not to wait for current proposals being discussed by the EU to be implemented. He argued that the investigative power of the media, coupled with current data protection laws in the UK and industry-specific regulations, mean organisations should have processes in place already to manage data breaches, or risk being exposed.

The comments echoed RSA Security president Art Coviello’s opening keynote, where he urged firms to take a holistic, information-centric approach to IT security, concentrating not just on technology but also the processes that underpin it.

“In reality not enough time or money is spent on understanding the risks, setting policies and having an organised, methodical approach,” he added. “Data is dynamic and… protecting information should be about process, not just products.”

Elsewhere, Christopher Kuner, head of the international privacy and information management practice at lawyers Hunton and Williams, argued that data breach notification laws could be slotted into existing EU legislation fairly easily, although he warned that customers may become desensitised if notified of every breach.

“If the Commission thinks that sending notifications alone will solve the problem they’ll probably be wrong,” he said.

He added that individual data protection agencies like the ICO could play an important role in being a first port of call for an organisation after a breach, advising them on the right course of action to take.

However the ICO’s Smith warned firms: “don’t ask us to do your job for you”.

Data breach notification laws were also a major recommendation of the recent House of Lords science and technology committee report on personal internet security.

Lord Erroll, one of the contributors to the report, said they recommended data breach notification laws not with a view to naming and shaming large corporations, but in order to get a clear idea of the scale of the problem.

“If things are encrypted properly then they are unusable [by criminals],” he added. “Technology helps us to do things properly, but when companies say they can’t encrypt their databases because there are too many legacy systems it worries me.”

Phil Dunkelberger, chief executive of encryption specialist PGP Corporation added that firms should be aware the criminal community is now concentrating its efforts onto mining highly valuable corporate data rather than individuals’ personal data.

Tags:

Further reading

How to stay on the right side of the law

Firms are under increasing regulatory pressure to safeguard sensitive data   More...

ICO launches info-sharing consultation

Information Commissioner seeks feedback on new data sharing code of practice   More...

ICO mulls tougher action on privacy

Annual report findings could lead to an increase in fines for Data Protection Act breaches   More...

Lack of privacy endangers the internet

If we aren’t careful, people will stop venturing online and will warn others against doing so too   More...

Related articles

RSA buys up Tablus

Improving data security portfolio   More...

MPs call to criminalise data loss

Justice Select Committee demands heavy fines and/or jail terms   More...

M&S rapped for Data Protection breach

This is not just data loss – this is your data loss   More...

Watchdog slams Skipton over data loss

Loss of 14,000 customer records breached Data Protection Act   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

18 Jul 2008

7.91 MBPodcast Special: Views from the Valley More...

17 Jul 2008

3.61 MBMalware explosion, nanotech fears and a jailed spammer More...

16 Jul 2008

4.17 MBiPhone 3G hacked, YouTube privacy deal and BT ad complaints More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Computer mouse

Computer mouse heading for extinction

Humble input device being usurped by touch screens and facial...  More...

Sony Vaio SR

Sony unveils Vaio business notebooks

Three new laptops aimed at 'out and about professionals'   More...

Advertisement

Firefox

Firefox gets security tune-up

Flaws patched for versions 2 and 3   More...

Apple iPhone 3G

Hold off on iPhone 3G, says analyst

Corporates should consider new handset a 'beta release'   More...

Advertisement