Feeds

ICO: Data blunders by your cloud provider still YOUR fault

Not always though, read on to cover your arse

Secure remote control for conventional and virtual desktops

The Information Commissioner's Office (ICO) has warned businesses that they are still responsible for the safety of the data they own - even when that data is in the cloud.

The regulator put out guidelines today for businesses on keeping data safe in the cloud.

Dr Simon Rice, ICO technology policy advisor, hammered home the point:

As a business, you are responsible for keeping your data safe. You can out-source some of the processing of that data, as happens with cloud computing, but how that data is used and protected remains your responsibility.

Stay on the right side of their advice and you should be safe within Data Protection law - unlike the Scottish Borders Agency, which was slapped with a £250,000 fine for mismanaging a cloud company it had hired to store and digitise pension records.

Using the tale of the hapless Jocks as a scare story, the ICO recounted how the council did not have a contract with the contractor, and hadn’t made the necessary security checks.

Precautions that the ICO recommends include:

  • Having a written contract with the cloud services provider
  • Seeking assurances on data safety from the provider: asking about the physical security in data centres as well as plans in the case of hacks and security breaches.
  • Being aware that using a cloud provider with servers outside the UK brings a different level of data protection requirements.

A 24-page document of guidance is available from the ICO site [PDF] and gives a list of questions that businesses should ask before buying a piece of cloud.

The ICO is worried that many businesses haven't considered the data protection dangers that come with the cloud. Data storage is important and the stakes are high warned Rice:

It would be naïve for an organisation to take the attitude that these guidelines are too much effort to simply store some data in a different place. Where personal information is involved, the stakes are high and the ICO has already demonstrated it will act firmly against those who don’t meet data protection laws.

®

Beginner's guide to SSL certificates

More from The Register

next story
Facebook pays INFINITELY MORE UK corp tax than in 2012
Thanks for the £3k, Zuck. Doh! you're IN CREDIT. Guess not
Facebook, Apple: LADIES! Why not FREEZE your EGGS? It's on the company!
No biological clockwatching when you work in Silicon Valley
Happiness economics is bollocks. Oh, UK.gov just adopted it? Er ...
Opportunity doesn't knock; it costs us instead
Sysadmin with EBOLA? Gartner's issued advice to debug your biz
Start hoarding cleaning supplies, analyst firm says, and assume your team will scatter
YARR! Pirates walk the plank: DMCA magnets sink in Google results
Spaffing copyrighted stuff over the web? No search ranking for you
Microsoft EU warns: If you have ties to the US, Feds can get your data
European corps can't afford to get complacent while American Big Biz battles Uncle Sam
Don't bother telling people if you lose their data, say Euro bods
You read that right – with the proviso that it's encrypted
prev story

Whitepapers

Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.