• Skip Navigation |
  • Accessibility 
IT-Director.com Logo
  • Singularity go SaaS with LiveAgility
  • User Experience Monitoring as Governance?
  • Running IT as a business: don't be daft
 

Main navigation - go to a section of this website:

  • ARCHIVE
  • PAPERS
  • EVENTS
  • NEWSWIRE
  • BLOGS

  

Member Login | Become a Member

 
DOMAINS
  • Enterprise
  • SME
  • Business Issues
  • Technology
  • Services
  • Channels
FEATURED EVENTS
  • Legal IT Show 2010
    10th February - 11th February
    London, United Kingdom
  • Data Modelling Fundamentals
    15th February - 16th February
    London, United Kingdom
POPULAR PAPERS
  • The IBM Workload Optimized Approach by Sageza Group, Inc.
  • Integrated Systems Management by Sageza Group, Inc.
  • Avoiding the Integration Tar Pit by Bloor Research
TRANSLATE PAGE



USEFUL LINKS
  • Last 7 Days
  • Archives
  • Market Place
  • Top Articles
INTERACT
  • Advertising
  • Site Feedback
  • Newsletters
  • Contact Us
  • Registration
CONTENT FEED

Sitewide
RSS Feed:

RSS Icon

What is RSS?

RANDOM QUOTE
Famous Slights - "That part of his speech was rather like being savaged by a dead sheep." - Dennis Healy, on Geoffrey Howe

ADVERTISEMENT
Analysis

Security breach legislation—Europeans, you are not immune

Fran Howarth By: Fran Howarth, Practice Leader, Bloor Research
Published: 15th October 2009
Copyright Bloor Research © 2009
Logo for Bloor Research
Page Tools

Request Reprints
Tell A Friend
Contact Author

More from author
  • January 2010
    Counting the cost
  • November 2005
    Why identity management and strong authentication are converging
  • October 2005
    nCipher buys Abridean
  • October 2005
    Deploying SSO and biometrics in the race to put out fires
  • September 2005
    Software as a service - Salesforce.com's new application shop
  • September 2005
    Not-for-profit organisations have security needs too
  • August 2005
    Grand Prairie teaches security lessons to other schools
Syndication
  • Delicious Icon Delicious
  • Digg Icon Digg
  • reddit Icon reddit
  • Facebook Icon Facebook
  • StumbleUpon Icon StumbleUpon

There are no overarching security breach regulations in Europe, right? To some extent, no. At an EU level, amendments were made to the ePrivacy Directive in May 2009 that made breach notification compulsory for internet service providers and network operators in the case of personally identifiable information about customers is lost or stolen.

So where does that leave organisations operating in other sectors? Can they afford to rest on their laurels? Certainly not. In the absence of specific laws related to security breach notification—such as SB 1386, which was the first such law put in place by the state of California and which has led to similar legislation being enacted in the majority of US states—European countries are beginning to use existing data protection laws to punish offenders.

Germany is the first EU member state to add new requirements to its existing legislation that are specifically focused on security breach notification. Already perhaps the most stringent interpretation of the EU's 1995 data protection directive, the German Federal Data Protection Act was amended in 2009 to introduce mandatory security breach notification where data is lost and that loss is likely to have a serious impact on the rights of the individual concerned. It also introduces new powers for data protection authorities to order organisations to remediate compliance failures and increases the fines and sanctions that can be imposed for non-compliance.

The UK is one country that, whilst it has not actually amended its data protection legislation, is increasingly using its powers to take enforcement action against private sector organisations and government agencies to force higher standards of data security where lapses have occurred. It is using the seventh data protection principle—which states that all data processing must be undertaken in a secure environment, including preventative measures to ensure that data is not accidentally lost, stolen or destroyed—to force bodies that have suffered data breaches to sign an undertaking that they will ensure compliance and that data is adequately protected from such breaches of security. Since end-2007, some 100 organisations and government bodies have been forced to sign such undertakings.

With laws and regulations changing and with new ones coming into force more and more regularly, the ability to keep up with the obligations that your organisations face is becoming an increasingly onerous task.

This is a synopsis of the first in a series of articles related to data security and compliance, commissioned by Tabaq Software. The full text of the article can be accessed here: The legal minefield for data protection.

Reader Comments

Sorry, we are no longer accepting comments on this item. We suggest trying to contact the author directly.

  • Site Map
  • | Terms of Use
  • | Privacy

Published by: IT Analysis Communications Ltd.
T: +44 (0)1908 880760 | F: +44 (0)1908 880761