Emma Leith
Leith: The importance of adequately securing personal data will become a legal requirement

When in Rome, consider privacy regulations

BCS view: Amendments to the Rome 1 legislation put data privacy back into the limelight

Written by Emma Leith

A proposed new "Rome 1" European Union (EU) legislation demonstrates the effect EU law can have on the private sector, in particular on small and medium-sized enterprises (SMEs).

The draft regulation was presented as an update and clarification to the obligations of the Rome 1 convention. However, unfortunately it came with a price, and under the changes, all e-commerce traders would be required to settle any consumer dispute according to the laws of the country from which the product was ordered, and not the country from which the trader operates.

The draft Rome 1 proposal has since been through a series of amendments, because of significant exposure and opposition in the EU, and now provides for businesses and consumers to be able to choose the law applicable to the contract. However, it could easily have had a serious effect on UK internet traders and small businesses relying on cross border e-commerce for profitability and growth, as well as on consumers who have benefited from the increased choice that free and open internet trade has brought.

Privacy regulations are also taking centre stage. In the wake of the HM Revenue and Customs data loss incident, the European Commission is planning to introduce a security breach notification law, which will force companies to tell customers when their personal data security has been breached.

Such notifications are common in the US, but if made law over here would result in a serious shake-up for data security practices. The importance of adequately securing personal data will become a legal requirement, similar to the regulations imposed on companies processing cardholder data by the PCI Security Standards Council.

On a similar matter of privacy, there is a debate at the moment with the EU questioning whether IP addresses should be considered as personal data.

With the use of dynamic IP addressing systems, IP addresses can change or be given out to another user. However, with the move towards IPv6 it will be even easier to identify an individual by an IP address.

The outcome of this debate will have serious consequences, not just for search engines such as Google, but for European companies, and how they do business with external resources. It is important to stay up-to-date with EU and national laws and their effects on security-related topics such as corporate governance, data protection and privacy.

It is also important to protect your own interests by including security aspects of great importance to the business in supplier negotiations.

This includes client responsibilities, data protection and privacy laws, safe harbour obligations and guidelines. Making security a contractual issue is the right step forward to changing the mentality among non-security professionals that security is desirable, but not essential.

Emma Leith is information security consultant at Comsec and a BCS contributor

reader comments

related articles

Gordon BrownGovernment

Brown defends database state

Systems are vital to protecting the country against fraud and terrorism, PM insists 20 Jun 2008

 

A third of IT staff look at private data

Administrative passwords can give workers unfettered access, says study 20 Jun 2008

EU security agency calls for breach notification law

And more funding is needed to promote awareness of security issues 28 May 2008

The data protection challenge: Delivering technology to protect and secure your information

22 May 2008

Privacy watchdog criticises proposed communication database

ICO says database is a disproportionate response to terrorism 21 May 2008

MEP denies 'three strikes' rule for persistent illegal downloaders

Proposals for reform of EU directive on electronic communications do not include a three strikes and you're out penalty clause 16 Sep 2008

Financial firms' data security found wanting

New PwC research urges increased vigilance 09 Jan 2009

Legislators under fire over heavy-handed security rules

Firms being forced to spend unnecessarily on perceived IT security risks, say experts at RSA show 27 Oct 2008

related whitepapers

today's top stories

Lack of enterprise appeal takes shine off Chrome OS

Enterprise buyers unlikely to ditch Windows for Chrome OS in the near term, say experts 09 Jul 2009

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Open source bites back

Recession-hit companies are tired of vendors holding a gun to their heads over software licensing, says CEO of Ingres 09 Jul 2009

"We will ensure Britain remains at the forefront of the digital revolution"

As new trials of superfast broadband get under way, minister Pat McFadden explains the government’s digital vision 09 Jul 2009

Put social networks to work on your career

Increasing numbers of IT professionals using sites such as LinkedIn to grow contacts and find jobs 09 Jul 2009

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use social networking sites to look for a job?

Would you use social networking sites to look for a job?

Tell us what you think about job hunting through LinkedIn, Facebook, Twitter etc

View poll results

Latest audio and video articles

network cablesVideo

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

green footprintsVideo

How to manage enterprise energy use - and the role IT can play

A panel of experts explore how firms can get to grips with their carbon footprint and make smarter use of energy 01 Jul 2009

Latest in-depth articles

Google ChromeAnalysis

Lack of enterprise appeal takes shine off Chrome OS

Enterprise buyers unlikely to ditch Windows for Chrome OS in the near term, say experts 09 Jul 2009

Satyam CEO CP GurnaniNews

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Advertisement

Primary Navigation