Feeds

ICO targets lost laptop breaches under tougher fine regime

Watchdog bares teeth at encryption refuseniks

Choosing a cloud hosting partner with confidence

The deputy commissioner of the Information Commissioner's Office said that it is no longer a "toothless tiger" and has the resources and resolve to apply enhanced powers to data protection miscreants.

David Smith said increased fines of £500K, introduced in April, for the worse case of privacy breaches would "concentrate minds on getting it right". He stressed that the watchdog would far rather work with organisations towards this than resort to enforcement.

Experienced IT lawyer Dai Davis, of Brooke North, predicted that the increased fines would result in a handful of high-profile enforcement actions while resulting in little real change. He also argued that the ICO lacks the resources to mount a strong legal assault in the event of a corporation contesting a legal action. He cited the enforcement case against Halifax Bank over the use of credit reference agencies that went all the way to the House of Lords and culminated in failure back in the mid 1990s. The ICO avoided legal action for years afterwards.

Smith responded to questions on resources by saying that recent increases in data protection registration fees to £500 for larger firms would finance enforcements while also bankrolling greater use of audits. "We have to be effective. there is provision in legislation for us to ask for greater fees, if necessary," Smith told The Register.

"We are keen to use our new powers but will not act recklessly," he added. Smith added that firms that lost laptops that were not encrypted would be among the prime candidates for enforcement action, predicting a "handful" of cases over coming months.

During a keynote speech at InfoSecurity Europe 2010, Smith cited figures that showed the health service was responsible for almost a third of all reported data breaches in the UK. However, since the scheme is voluntary the picture it presents is incomplete. European legislation means that mandatory breach notification laws will be applied to telecom carriers within 18 months.

"Data protection is a widespread problem not confined to the public sector," Smith commented. Lost data or hardware and stolen data or hardware were the two most common causes of data protection problems. Lack of awareness about data protection, failure to take responsibility and use of legacy systems (such as unencrypted laptops) and policies were among the problems holding back better protection of public data, Smith said.

Smith wants to see mandatory notification in cases where personal data might have been exposed but not in situations where an encrypted laptop was lost, for example. He also wants to see private investigators who used trickery to obtain confidential records jailed. ®

Top 5 reasons to deploy VMware with Tegile

More from The Register

next story
Phones 4u slips into administration after EE cuts ties with Brit mobe retailer
More than 5,500 jobs could be axed if rescue mission fails
Driving with an Apple Watch could land you with a £100 FINE
Bad news for tech-addicted fanbois behind the wheel
Special pleading against mass surveillance won't help anyone
Protecting journalists alone won't protect their sources
Phones 4u website DIES as wounded mobe retailer struggles to stay above water
Founder blames 'ruthless network partners' for implosion
Radio hams can encrypt, in emergencies, says Ofcom
Consultation promises new spectrum and hints at relaxed licence conditions
Big Content Australia just blew a big hole in its credibility
AHEDA's research on average content prices did not expose methodology, so appears less than rigourous
EMC, HP blockbuster 'merger' shocker comes a cropper
Stand down, FTC... you can put your feet up for a bit
Vodafone to buy 140 Phones 4u stores from stricken retailer
887 jobs 'preserved' in the process, says administrator PwC
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.