Feeds

ICO targets lost laptop breaches under tougher fine regime

Watchdog bares teeth at encryption refuseniks

Beginner's guide to SSL certificates

The deputy commissioner of the Information Commissioner's Office said that it is no longer a "toothless tiger" and has the resources and resolve to apply enhanced powers to data protection miscreants.

David Smith said increased fines of £500K, introduced in April, for the worse case of privacy breaches would "concentrate minds on getting it right". He stressed that the watchdog would far rather work with organisations towards this than resort to enforcement.

Experienced IT lawyer Dai Davis, of Brooke North, predicted that the increased fines would result in a handful of high-profile enforcement actions while resulting in little real change. He also argued that the ICO lacks the resources to mount a strong legal assault in the event of a corporation contesting a legal action. He cited the enforcement case against Halifax Bank over the use of credit reference agencies that went all the way to the House of Lords and culminated in failure back in the mid 1990s. The ICO avoided legal action for years afterwards.

Smith responded to questions on resources by saying that recent increases in data protection registration fees to £500 for larger firms would finance enforcements while also bankrolling greater use of audits. "We have to be effective. there is provision in legislation for us to ask for greater fees, if necessary," Smith told The Register.

"We are keen to use our new powers but will not act recklessly," he added. Smith added that firms that lost laptops that were not encrypted would be among the prime candidates for enforcement action, predicting a "handful" of cases over coming months.

During a keynote speech at InfoSecurity Europe 2010, Smith cited figures that showed the health service was responsible for almost a third of all reported data breaches in the UK. However, since the scheme is voluntary the picture it presents is incomplete. European legislation means that mandatory breach notification laws will be applied to telecom carriers within 18 months.

"Data protection is a widespread problem not confined to the public sector," Smith commented. Lost data or hardware and stolen data or hardware were the two most common causes of data protection problems. Lack of awareness about data protection, failure to take responsibility and use of legacy systems (such as unencrypted laptops) and policies were among the problems holding back better protection of public data, Smith said.

Smith wants to see mandatory notification in cases where personal data might have been exposed but not in situations where an encrypted laptop was lost, for example. He also wants to see private investigators who used trickery to obtain confidential records jailed. ®

Remote control for virtualized desktops

More from The Register

next story
MI6 oversight report on Lee Rigby murder: US web giants offer 'safe haven for TERRORISM'
PM urged to 'prioritise issue' after Facebook hindsight find
Assange™ slumps back on Ecuador's sofa after detention appeal binned
Swedish court rules there's 'great risk' WikiLeaker will dodge prosecution
You think the CLOUD's insecure? It's BETTER than UK.GOV's DATA CENTRES
We don't even know where some of them ARE – Maude
NSA mass spying reform KILLED by US Senators
Democrats needed just TWO more votes to keep alive bill reining in some surveillance
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Designing and building an open ITOA architecture
Learn about a new IT data taxonomy defined by the four data sources of IT visibility: wire, machine, agent, and synthetic data sets.
How to determine if cloud backup is right for your servers
Two key factors, technical feasibility and TCO economics, that backup and IT operations managers should consider when assessing cloud backup.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?