Emma Leith
Leith: The importance of adequately securing personal data will become a legal requirement

When in Rome, consider privacy regulations

BCS view: Amendments to the Rome 1 legislation put data privacy back into the limelight

Written by Emma Leith

A proposed new "Rome 1" European Union (EU) legislation demonstrates the effect EU law can have on the private sector, in particular on small and medium-sized enterprises (SMEs).

The draft regulation was presented as an update and clarification to the obligations of the Rome 1 convention. However, unfortunately it came with a price, and under the changes, all e-commerce traders would be required to settle any consumer dispute according to the laws of the country from which the product was ordered, and not the country from which the trader operates.

The draft Rome 1 proposal has since been through a series of amendments, because of significant exposure and opposition in the EU, and now provides for businesses and consumers to be able to choose the law applicable to the contract. However, it could easily have had a serious effect on UK internet traders and small businesses relying on cross border e-commerce for profitability and growth, as well as on consumers who have benefited from the increased choice that free and open internet trade has brought.

Privacy regulations are also taking centre stage. In the wake of the HM Revenue and Customs data loss incident, the European Commission is planning to introduce a security breach notification law, which will force companies to tell customers when their personal data security has been breached.

Such notifications are common in the US, but if made law over here would result in a serious shake-up for data security practices. The importance of adequately securing personal data will become a legal requirement, similar to the regulations imposed on companies processing cardholder data by the PCI Security Standards Council.

On a similar matter of privacy, there is a debate at the moment with the EU questioning whether IP addresses should be considered as personal data.

With the use of dynamic IP addressing systems, IP addresses can change or be given out to another user. However, with the move towards IPv6 it will be even easier to identify an individual by an IP address.

The outcome of this debate will have serious consequences, not just for search engines such as Google, but for European companies, and how they do business with external resources. It is important to stay up-to-date with EU and national laws and their effects on security-related topics such as corporate governance, data protection and privacy.

It is also important to protect your own interests by including security aspects of great importance to the business in supplier negotiations.

This includes client responsibilities, data protection and privacy laws, safe harbour obligations and guidelines. Making security a contractual issue is the right step forward to changing the mentality among non-security professionals that security is desirable, but not essential.

Emma Leith is information security consultant at Comsec and a BCS contributor

reader comments

related articles

Gordon BrownGovernment

Brown defends database state

Systems are vital to protecting the country against fraud and terrorism, PM insists 20 Jun 2008

 

A third of IT staff look at private data

Administrative passwords can give workers unfettered access, says study 20 Jun 2008

EU security agency calls for breach notification law

And more funding is needed to promote awareness of security issues 28 May 2008

The data protection challenge: Delivering technology to protect and secure your information

22 May 2008

Privacy watchdog criticises proposed communication database

ICO says database is a disproportionate response to terrorism 21 May 2008

Temporary workers pose security risk

Websense survey finds that temporary staff have too much access to computer systems 28 Nov 2007

HMRC data loss leaves 25 million exposed

Revenue chief Paul Gray resigns 21 Nov 2007

HMRC data loss 'completely predictable'

'Old, outdated and broken processes,' says Symantec 22 Nov 2007

today's top stories

Analysis: Will IE8 cause more problems than it solves?

Microsoft's new browser may lead to compatibility issues and affect online advertising 29 Aug 2008

CIO morale plummets as crunch hits

Fewer opportunities and less responsibility depress IT managers 27 Aug 2008

The pIT stop Q&A: Should packaged software users adopt SOA?

Our expert panel answer readers' questions 29 Aug 2008

Computing podcast 28 August 2008

CIO job satisfaction plummets, and why schools' IT spending is set to top £1bn 28 Aug 2008

The definitive guide to collaboration

Five key technologies and five best practice tips to improve your collaborative IT 28 Aug 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Job of the week

Job alerts

Sign up here

Find your next job here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you recruit a student with an IT degree?

Would you recruit a student with an IT degree?

As IT student numbers plummet - would you recruit an IT graduate?

Previous poll results

Latest audio and video articles

A stressed CIOAudio

Computing podcast 28 August 2008

CIO job satisfaction plummets, and why schools' IT spending is set to top £1bn 28 Aug 2008

Bryan Glick video whiteboardVideo

The definitive guide to collaboration

Five key technologies and five best practice tips to improve your collaborative IT 28 Aug 2008

Latest in-depth articles

Myron HrycykAnalysis

General management skills are now as important as technical ability

A selection of leading chief information officers talk about what they see as the most important aspects of the role 28 Aug 2008

Internet Explorer logoAnalysis

Analysis: Will IE8 cause more problems than it solves?

Microsoft's new browser may lead to compatibility issues and affect online advertising 29 Aug 2008

Primary Navigation