information management

ICO welcomes data breach notification laws

The UK's data watchdog has joined calls for a US-style data loss reporting law

Written by Phil Muncaster

The UK’s privacy watchdog the Information Commissioner’s Office has welcomed recent calls for US-style data breach notification laws, but urged firms to act now to protect their systems rather than wait until current proposals become law.

Speaking at the opening session of this year’s RSA Conference Europe in London, deputy information commissioner, David Smith, said that a law forcing firms to disclose if customers' personal details have been stolen or exposed “would be welcome", but he cautiously added, "it must be a good one”.

“If we have a law, can we have it simple and easy to understand, not like the laws we have to administer at the moment?” he pleaded. “It mustn’t be notification for the sake of it, or put a disproportionate burden on business.”

Smith also warned firms not to wait for current proposals being discussed by the EU to be implemented. He argued that the investigative power of the media, coupled with current data protection laws in the UK and industry-specific regulations, mean organisations should have processes in place already to manage data breaches, or risk being exposed.

The comments echoed RSA Security president Art Coviello’s opening keynote, where he urged firms to take a holistic, information-centric approach to IT security, concentrating not just on technology but also the processes that underpin it.

“In reality not enough time or money is spent on understanding the risks, setting policies and having an organised, methodical approach,” he added. “Data is dynamic and… protecting information should be about process, not just products.”

Elsewhere, Christopher Kuner, head of the international privacy and information management practice at lawyers Hunton and Williams, argued that data breach notification laws could be slotted into existing EU legislation fairly easily, although he warned that customers may become desensitised if notified of every breach.

“If the Commission thinks that sending notifications alone will solve the problem they’ll probably be wrong,” he said.

He added that individual data protection agencies like the ICO could play an important role in being a first port of call for an organisation after a breach, advising them on the right course of action to take.

However the ICO’s Smith warned firms: “don’t ask us to do your job for you”.

Data breach notification laws were also a major recommendation of the recent House of Lords science and technology committee report on personal internet security.

Lord Erroll, one of the contributors to the report, said they recommended data breach notification laws not with a view to naming and shaming large corporations, but in order to get a clear idea of the scale of the problem.

“If things are encrypted properly then they are unusable [by criminals],” he added. “Technology helps us to do things properly, but when companies say they can’t encrypt their databases because there are too many legacy systems it worries me.”

Phil Dunkelberger, chief executive of encryption specialist PGP Corporation added that firms should be aware the criminal community is now concentrating its efforts onto mining highly valuable corporate data rather than individuals’ personal data.

Tags:

reader comments

related articles

How to stay on the right side of the law

Firms are under increasing regulatory pressure to safeguard sensitive data 08 Oct 2007

 

ICO launches info-sharing consultation

Information Commissioner seeks feedback on new data sharing code of practice 15 Aug 2007

ICO mulls tougher action on privacy

Annual report findings could lead to an increase in fines for Data Protection Act breaches 20 Jul 2007

Lack of privacy endangers the internet

If we aren’t careful, people will stop venturing online and will warn others against doing so too 16 Jul 2007

Tech industry launches initiative to boost software security

A major new industry initiative could ensure the quality and security of software 23 Oct 2007

Data protection watchdog calls for breach notification law

Any new rules must apply to government as well as business, says deputy information commissioner 23 Oct 2007

Lose data and you go to jail

Act amendments could mean jail terms for losing or trading in data 08 May 2008

today's top stories

Analysis: The true cost of printing

Organisations need to get a better sense of how much they spend on printing before finding ways to reduce it 05 Sep 2008

Computing podcast 4 September 2008

Find out what Michael Dell told Computing, and listen to our take on the latest browser wars 04 Sep 2008

Looking to the future - exclusive Michael Dell interview

Dell's chief executive talks to Computing about the way the company continues to adapt to major changes in the industry 04 Sep 2008

Interview: Delivering power where it's needed at Betfair

The online gambling firm is putting its money on grid computing and virtualisation to underpin global expansion 04 Sep 2008

Taking a Baracking

I’ve been away for a while driving around the US. I stayed in a different hotel every night for two weeks and... 04 Sep 2008

Most commented stories

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use a mobile phone as an alternative to cash?

Would you use a mobile phone as an alternative to cash?

When mobile phones include inbuilt payment technology - would you use one instead of cash?

Previous poll results

Latest audio and video articles

BlackBerry BoldVideo

Video Review: BlackBerry Bold

Technology editor Daniel Robinson takes a hands-on look at the latest device from Research in Motion 01 Sep 2008

Podcast imageAudio

Computing podcast 4 September 2008

Find out what Michael Dell told Computing, and listen to our take on the latest browser wars 04 Sep 2008

Latest in-depth articles

Betfair blimpAnalysis

Interview: Delivering power where it's needed at Betfair

The online gambling firm is putting its money on grid computing and virtualisation to underpin global expansion 04 Sep 2008

Michael DellAnalysis

Looking to the future - exclusive Michael Dell interview

Dell's chief executive talks to Computing about the way the company continues to adapt to major changes in the industry 04 Sep 2008

Primary Navigation