Feeds

ICO: Data blunders by your cloud provider still YOUR fault

Not always though, read on to cover your arse

Build a business case: developing custom apps

The Information Commissioner's Office (ICO) has warned businesses that they are still responsible for the safety of the data they own - even when that data is in the cloud.

The regulator put out guidelines today for businesses on keeping data safe in the cloud.

Dr Simon Rice, ICO technology policy advisor, hammered home the point:

As a business, you are responsible for keeping your data safe. You can out-source some of the processing of that data, as happens with cloud computing, but how that data is used and protected remains your responsibility.

Stay on the right side of their advice and you should be safe within Data Protection law - unlike the Scottish Borders Agency, which was slapped with a £250,000 fine for mismanaging a cloud company it had hired to store and digitise pension records.

Using the tale of the hapless Jocks as a scare story, the ICO recounted how the council did not have a contract with the contractor, and hadn’t made the necessary security checks.

Precautions that the ICO recommends include:

  • Having a written contract with the cloud services provider
  • Seeking assurances on data safety from the provider: asking about the physical security in data centres as well as plans in the case of hacks and security breaches.
  • Being aware that using a cloud provider with servers outside the UK brings a different level of data protection requirements.

A 24-page document of guidance is available from the ICO site [PDF] and gives a list of questions that businesses should ask before buying a piece of cloud.

The ICO is worried that many businesses haven't considered the data protection dangers that come with the cloud. Data storage is important and the stakes are high warned Rice:

It would be naïve for an organisation to take the attitude that these guidelines are too much effort to simply store some data in a different place. Where personal information is involved, the stakes are high and the ICO has already demonstrated it will act firmly against those who don’t meet data protection laws.

®

Build a business case: developing custom apps

More from The Register

next story
'Stop dissing Google or quit': OK, I quit, says Code Club co-founder
And now a message from our sponsors: 'STFU or else'
Top beak: UK privacy law may be reconsidered because of social media
Rise of Twitter etc creates 'enormous challenges'
Uber, Lyft and cutting corners: The true face of the Sharing Economy
Casual labour and tired ideas = not really web-tastic
Ex US cybersecurity czar guilty in child sex abuse website case
Health and Human Services IT security chief headed online to share vile images
Don't even THINK about copyright violation, says Indian state
Pre-emptive arrest for pirates in Karnataka
The police are WRONG: Watching YouTube videos is NOT illegal
And our man Corfield is pretty bloody cross about it
Oz biz regulator discovers shared servers in EPIC FACEPALM
'Not aware' that one IP can hold more than one Website
prev story

Whitepapers

Gartner critical capabilities for enterprise endpoint backup
Learn why inSync received the highest overall rating from Druva and is the top choice for the mobile workforce.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.