Related Links

Related Stories

  • UK data losses will now result in half a million pound penalties
    As widely expected, the government has given the Information Commissioner's Office much sharper teeth when dealing with UK data losses, as, from April 6 onwards, firms found to be in breach of the Data Protection Act can now be fined £500 000.
  • ICO to make data protection compliance easier
    The Information Commissioner’s Office (ICO) has released a new guide on data protection containing practical advice on data protection compliance. New Information Commissioner Christopher Graham also talked to Infosecurity on the challenges facing ICO.
  • UK CIOs reported 356 data loss incidents last year
    A Freedom of Information (FOI) request to the Information Commissioner's Office (ICO) has turned up the revelation that there were 356 data loss incidents reported in the 11 months to September of this year. The figures compare to 190 data loss incidents in the period October 2007 to November 2008.
  • ICO seeks to place a value on privacy protection
    The Information Commissioner's Office (ICO) has appointed Watson Hall and John Leach Information Security (JLIS) to undertake a three-month research project with the aim of producing a comprehensive business case for investing in proactive privacy protection.
  • ISACA backs power increase for Information Commissioner
    ISACA, the not-for-profit organisation that seeks to encourage best practice in the IT security industry, has given the `thumbs up' to plans to significantly increase the powers of the Information Commissioner's Office (ICO) later this year.

News

ISACA welcomes strengthening of UK penalties on data breaches

21 January 2010

ISACA, the not-for profit international association of 86 000 IT security, audit and governance professionals, has welcomed news that the UK government has beefed up the penalties the Information Commissioner's Office (ICO) can impose on errant companies causing major data breaches.

According to Rolf von Roessing, ISACA's international vice president, news that an extension to the Data Protection Act that imposes fines of up to £500,000 for a data breach – and which can be applied from the start of the new UK financial year – will start to get the message across that data losses are now unacceptable.

"The passing of the new statute and its approval by Jack Straw MP, the Secretary of State for Justice, is good news for anyone who has been affected by company data breaches," he said. "Whilst it's good to know that the size of the fine will be determined after an investigation to assess the gravity of the breach and the size and finances of the organisation at fault, this legislation brings the UK into line with the rest of Europe in giving the regulator real teeth to tackle what is becoming a growing problem," he added.

It is, von Roessing explained, a major worry for responsible citizens to find that their private data – or even worse, that of their children – has been released into the public domain.

Security issues such as identity theft, job application refusals and all manner of public embarrassment can result from the disclosure of private data, he went on to say, adding that what can be shrugged off by one person can result in major concerns for another.

"It has been more than 25 years since the original Data Protection Act came into force, in which time computers and the Internet have changed our lives largely for the better," von Roessing said. "It is to be hoped these changes will send a strong message that data losses are no longer acceptable and carry real consequences."

"Whilst there are likely to be a number of high-profile data loss prosecutions this year, it is to be hoped that business leaders will now start giving privacy and data protection issues the attention they deserve," he added.

 

This article is featured in:
Compliance and Policy Data Loss

 

Comment on this article

You must be registered and logged in to leave a comment about this article.