25 Jan 2012
The European Commission (EC) will later today publish a draft update to its Data Protection Directive, which is set to require major changes in the way in which companies manage data privacy.
Speaking about the forthcoming amendment, EC vice president Viviane Reding said that private companies will be required to notify the authorities if they suffer a data breach.
"Companies that suffer a data leak must inform the data protection authorities and the individuals concerned, within 24 hours."
Some industry insiders believe that the rules will add to organisations' costs.
David Fowler, chief operational officer at identity and access management solutions provider Courion, said that this change will force many firms to adopt new processes and technologies to manage the risks of data breach.
"Enforcing 24-hour mandatory reporting of security breaches will put significant pressure on organisations to speed up internal security auditing processes and adopt more effective tools for managing and analysing risk.
"Many of the security breaches that we witnessed last year were caused by inappropriate access to confidential data and poor compliance with data protection policies and regulations."
Fowler added that better management of who is able to access corporate data would be needed.
"To avoid this, businesses need to implement effective access risk management solutions that enable better visibility of access risk and monitor in real-time how sensitive data is being used, accessed and stored."
However, Paul Davis, director of European operations at security firm FireEye, said that many organisations will be unable to comply with the new rules due to a lack of skills and tools to detect data breaches.
"Most companies are unable to detect external targeted attacks leading to data loss.
"The protection of information is critical to business and the establishment of trust with customers and the notification of data breaches is important, but detection and blocking of exploits should take precedence."
The proposals will also aim to homogenise data protection rules across the EU, making it easier for international businesses to understand their obligations.
Reding said this will save businesses £1.9bn per year by reducing administrative costs.
Jeff Finch, security services product manager at cloud services firm Interoute, welcomed this change.
"The collation of harmonised data protection rules across 27 countries will without a doubt save organisations from a headache. Piecing together differing national data protection laws will have felt like one massive patchwork task for organisations, especially as the introduction of cloud computing placed question marks over the exact location of data."
He added that he would like to see this harmonisation extend across the Atlantic to the US.
"The next step is to look for harmonisation with laws in other countries like the US, where the Patriot Act enables authorities to search telephone, email, and financial records without a court order.
"Thus, understanding where data resides and in whose datacentre will continue to be a crucial part of corporate governance for organisations."
The EC proposals are also expected to require organisations to delete an individual's data if there is no reason why it should be kept.
"If an individual no longer wants his personal data to be processed or stored by a data controller, and if there is no legitimate reason for keeping it, the data should be removed from their system," said Reding.
both the article and the above comment point to the fact that secure or managed file transfer are becoming more and more important to organisations. Data leakage is costly in more ways than one and needs to be avoided.
Helen Adams at HANDD File Transfer Solutions
Posted by: Helen Adams 26 Jan 2012
With IT consumerisation and new technologies like cloud computing becoming more common in today’s business environment, amendments to the EU Data Protection Directive should be welcomed. Of course businesses should be obliged to acknowledge any kind of data breach as soon as possible, but responding after the fact is a little like locking the stable door after the horse has bolted. Businesses that are embracing social media and collaborative technologies need to adapt their IT security policies to address the new risks that come with them. This means not only keeping up to date with a rapidly changing technology landscape but also recognising that there is a job to be done when it comes to educating staff on their own technology usage patterns, ensuring that their organisation is never compromised when it comes to the security of their data. - Richard Turner - CEO of Clearswift
Posted by: Clearswift 25 Jan 2012
Have your say on this article
Newsletters
Latest stories from Privacy
Latest videos
You may also like
Privacy jobs
Do you think the G-Cloud will be a success?
Rubbish in... rubbish enterprise. Why proper data management is so important (video, 6 min)
This Forrester report compares the costs and benefits of legacy email and productivity software with Google Apps
Upcoming Events
Join us to meet other professionals tackling this issue, and hear from Goy Roper, interim head of ICT of Norfolk County Council how his organisation deployed a flexible and intelligent network to cope with the challenge
Date: 07 Mar 2012
Time: 9am
The implementation of robust, relevant digital strategies is more crucial than ever to the success of insurance businesses
Date: 01 Mar 2012
Time: 09:00am
Receive the latest jobs direct to your inbox
Are you being paid what you are worth?