Richard Thomas
R E L A T E D   C O N T E N T
ADVERTISEMENT

Firms woken up by HMRC breach, says ICO

Data watchdog, the Information Commissioner, says that the HMRC breach could have a positive outcome

Rosalie Marshall, IT Week 05 Dec 2007
ADVERTISEMENT

The fallout from the HMRC fiasco could turn out to be positive for security in the UK after the Information Commissioner, Richard Thomas, reported that organisations have gone to his office with questions about security processes in the wake of the massive data breach.

During a House of Commons Justice Committee meeting this week on data privacy issues, Thomas said, “A number of organisations, both public and private sector have come to me saying they think they have found a problem …[and] bringing to our attention problems they have with security inside their own organisations.”

He added: “None appear to be on anything like the same scale as anything like that involving the HMRC, but there is certainly more to come out of the wash as we move forward. This incident has been a massive wake-up call to the very top of organisations … who are at long last asking questions to make sure that proper arrangements are in place. If they are not being given the reassurances that they require where problems come to light, they are starting to share those with us and take remedial action. Already there are some signs of projects being put on hold, or that a freeze is put on a transfer of data.”

Thomas also said there had been a “tripartite arrangement” between auditor PricewaterhouseCoopers, the Independent Police Complaints Commission (IPCC) and his own office, to have “sensible coordination” between thr groups over data privacy matters. PricewaterhouseCoopers is currently undertaking a review of the HMRC breach.

Malcolm Etchells, managing director of email monitoring vendor Waterford Technologies, argued that the ICO should be looking for ways to encourage firms to comply with DPA and implement best practices rather than seeking greater punitive powers.

"There's no problem with enforcing the law where criminality is suspected but I'd argue that most firms do their best efforts to comply," he added. "Instead of the 'stick' approach of frequent audits, they should maybe think about awarding firms for the best DPA compliance or best practices implementation."

He added that any spot checks should be focused initially on firms which handle a high volume public data, such as telemarketing firms, rather than private businesses which handle mainly employee data.

See also:

data theft logoData watchdog the Information Commissioners' Office is confident of new powers  27 Nov 2007
id cardsFollowing the loss of 25m records ID card alternatives are coming to the fore  26 Nov 2007
Information Commissioner’s Office given power to carry out spot checks on government departments  23 Nov 2007
an ID cardThe data loss scandal could knock confidence in the UK ID card scheme  22 Nov 2007

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Greythorn IT
Leading Mobile Network vendore is currently seeking a Process consultant for a positions based either in the Middle east or Africa. We are looking for around 10 years experience with at least 5 years business ... more >
| Greythorn IT
Tier 1 Network solutions provider is currently seeking an experienced Telecommunications sales manager to work in their Abu Dhabi office. There is a brilliant benefits package as well as an attractive salary available for the ... more >
| Greythorn IT
Leading network solutions provider in Egypt is currently seeking and experienced Egyptian Network Operation /Supervision Engineer. There are competitive packages and attractive benefits package on offer for the right candidate. You will be responsible to ... more >
| Greythorn IT
A leading network Solutions vendor is currently seeking an Egyptian national to act as a Service Assurance manager out of their Egyptian office. Ideally we are looking for someone with Vendor based experience however other ... more >
More job opportunities