HMRC building
The KTN hope the guidelines will prevent information loses on the scale of HMRC

Cyber Security KTN issues privacy guidelines

Businesses should examine privacy implications at all stages of a project lifecycle

Written by Tom Young

Businesses must meet privacy requirements at four stages of any project lifecycle that may involve personal information, according to a report from the Cyber Security Knowledge Transfer Network (KTN).

In order to protect customer and employee details, privacy must examined at the initiation, planning, execution and closure of a generic project lifecycle.

This will ensure organisations comply with any future guidelines as well as current ones, according to Nigel Jones, head of KTN.

"Trying to engineer privacy as an afterthought never works," he said. "This is the only way organisations can be sure they are doing the right thing."

The paper recommends that:

- At the project initiation stage high level privacy objectives need to be set - project owners need to be aware of applicable privacy laws and regulations, such as the EU Data Protection Directive and the US Safe Harbour agreement.

- Technology envisaged for use by the project should also be subject to a high level review to ensure that appropriate privacy controls can be implemented.

- At The project-planning stage technologies such as encryption should be considered to protect consumer and client data on storage media, and Privacy Imapct Assessments should be carried out.

- Audits and change control procedures should continue after the closure of a project to ensure privacy requirements are continually addressed.

- Organisations should ensure that a senior role is established with overall responsibility for privacy, and ensure that responsibility is not delegated, as in the case of the HM Revenue and Customs lost discs fiasco.

- When a project is decommissioned all relevant information needs to be carefully destroyed.

- Customers should also as far as possible be given the choice of opting out of services that require the collection of additional personal information.

- Systems should have strong access controls, to ensure that personal information is only accessed by those who are authorised to do so. Access should be logged, and logs regularly audited.

- Where possible, personal information should be stored together with metadata that describes it and its intended use.

- Organisations should implement transparent procedures for remediation of errors in personal information, or privacy breaches.

The Cyber Security KTN is run by QinetiQ on behalf of the government’s Technology Strategy Board.

reader comments

related articles

Richard Thomas

Privacy watchdog to get new powers

Office will be given ability to spot check central government 22 Apr 2008

 

Phorm must be opt in

Controversial system must be opt in and keep information anonymous, says ICO 10 Apr 2008

Data watchdog to keep an eye on BT's Phorm trial

Information Commissioner's Office wants experts to scrutinise the technology 07 Apr 2008

Gateway reviews must look at privacy, says Information Commissioner

But Office of Government Commerce rejects use of assessments as standard 06 Mar 2008

M&S breached Data Protection Act

Watchdog rules loss of 26,000 employees' details on unencrypted laptop breaks the law 25 Jan 2008

Security research challenge gets £250,000 funding

Vendor backed network to provide rewards for tackling particular security issues 08 Apr 2008

Information Commissioner says database threatens way of life

Calls for public debate about Government plans 16 Jul 2008

Second-hand gadgets pose data security risk

Sensitive information left on mobile devices could be used by criminals 25 Sep 2008

related whitepapers

today's top stories

Solid as a rock - business continuity in a global manufacturer

From power supply problems in Nigeria to email availability in Stockport, PZ Cussons is prepared for anything 02 Dec 2008

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

IT staff desperate to keep their jobs

Most would work longer hours for less pay 02 Dec 2008

VMware View 3 enhances virtual desktops

Virtual clients now take up less storage space and can be 'checked out' to a laptop 02 Dec 2008

Technology and privacy

Watch part one of a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 01 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Parcel being packedFeatures

Case study: eSpares and business continuity

Online electricals business has managed to decrease its downtime 02 Dec 2008

Royal Blackburn HospitalFeatures

NHS trust recovers from server overdose

Virtualisation technology breathed new life into East Lancashire's cost-intensive system 02 Dec 2008

Advertisement

Primary Navigation