You are here: silicon.com > Hardware > Storage

Storage

When will organisations pay for data breaches?

Comment: The sooner the better

Tags: security, data breach, information commissioner

By Grant Campbell

Published: 2 June 2009 13:00 GMT

More than a year after appearing on the statute books, the info watchdog's power to fine is not yet operational. Lawyer Grant Campbell urges those involved not to lose momentum.

Data losses have provided the UK press with an ongoing stream of stories for more than 18 months now.

The first big story, in November 2007, was HM Revenue and Customs' loss of discs containing child benefit data on 25 million people. Since then the press has been spoilt for choice of incidents of this nature, with a wealth of embarrassing headlines affecting the government and its contractors in particular.

The role of the Information Commissioner's Office (or ICO) as the independent body charged with policing and enforcing data protection legislation is to promote good practice and ultimately, as the regulator, to take enforcement action against organisations where they are found to have fallen short.

Currently, if the ICO hears of a security breach - either because the organisation affected has notified it of the incident or as a result of a complaint - the ICO has various assessment powers to allow it to establish the facts of the case and, crucially, to form a view on whether there has been a breach of data protection legislation.

However, even where the office concludes that an organisation has failed to comply with its statutory obligations to keep our information safe, in most cases the organisation at fault will at worst be required to give a formal undertaking to the ICO to comply in full with its data protection obligations in future, provided it co-operates with the ICO in resolving the situation.

Only in extreme cases might formal enforcement action be taken and, even then, the ICO still has no 'live' power to fine the organisation for its compliance failure.

The furore created by various high-profile data security scandals forced politicians to concede that the regulatory environment was inadequate. The government commissioned various investigations and reports and brought into force certain changes designed to improve internal procedures, including mandatory rules on data security provisions in central government contracts.

In the midst of all of this, the enactment in May last year of a power for the ICO to impose monetary penalties for serious breaches of data protection legislation emerged as an unexpected - but very welcome - strengthening of the regulatory regime. Suddenly it seemed that the lack of clout that has traditionally hindered data protection would become a thing of the past, with the protection of personal information finally becoming a board-level issue.

Click here for page two

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Seb Janacek Magic Mouse - Apple's best ever? Minority Report: After years of disappointment, one Mac lover has hope

Bethan Jones Can I use a netbook as my everyday work machine? Why silicon.com's sub editor is ditching her laptop for a sprightly mini-laptop


  • Jobs
UK Sales Executive-Disk Encryption & Data Protection

JOB TITLE: UK Sales Executive-Disk Encryption & Data Protection Sales SELLING: Disk Encryption and Data Protection SELLING TO: Enterprise and Mid ...

2nd/3rd line Technical Support PKI, Hardware, Security, Data Protection

EMEA Technical Support EngineerPKI Hardware Security Data Protection 2nd/3rd line Primary product focus will be Hardware Security Modules (HSM) and ...

SAP Data Protection

My client is doing a review of the current SAP system and need a consultant who can check the Data protection compliance they have in place. I am ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: