Richard Thomas
R E L A T E D   C O N T E N T
ADVERTISEMENT

Firms woken up by HMRC breach, says ICO

Data watchdog, the Information Commissioner, says that the HMRC breach could have a positive outcome

Rosalie Marshall, IT Week 05 Dec 2007
ADVERTISEMENT

The fallout from the HMRC fiasco could turn out to be positive for security in the UK after the Information Commissioner, Richard Thomas, reported that organisations have gone to his office with questions about security processes in the wake of the massive data breach.

During a House of Commons Justice Committee meeting this week on data privacy issues, Thomas said, “A number of organisations, both public and private sector have come to me saying they think they have found a problem …[and] bringing to our attention problems they have with security inside their own organisations.”

He added: “None appear to be on anything like the same scale as anything like that involving the HMRC, but there is certainly more to come out of the wash as we move forward. This incident has been a massive wake-up call to the very top of organisations … who are at long last asking questions to make sure that proper arrangements are in place. If they are not being given the reassurances that they require where problems come to light, they are starting to share those with us and take remedial action. Already there are some signs of projects being put on hold, or that a freeze is put on a transfer of data.”

Thomas also said there had been a “tripartite arrangement” between auditor PricewaterhouseCoopers, the Independent Police Complaints Commission (IPCC) and his own office, to have “sensible coordination” between thr groups over data privacy matters. PricewaterhouseCoopers is currently undertaking a review of the HMRC breach.

Malcolm Etchells, managing director of email monitoring vendor Waterford Technologies, argued that the ICO should be looking for ways to encourage firms to comply with DPA and implement best practices rather than seeking greater punitive powers.

"There's no problem with enforcing the law where criminality is suspected but I'd argue that most firms do their best efforts to comply," he added. "Instead of the 'stick' approach of frequent audits, they should maybe think about awarding firms for the best DPA compliance or best practices implementation."

He added that any spot checks should be focused initially on firms which handle a high volume public data, such as telemarketing firms, rather than private businesses which handle mainly employee data.

See also:

data theft logoData watchdog the Information Commissioners' Office is confident of new powers  27 Nov 2007
id cardsFollowing the loss of 25m records ID card alternatives are coming to the fore  26 Nov 2007
Information Commissioner’s Office given power to carry out spot checks on government departments  23 Nov 2007
an ID cardThe data loss scandal could knock confidence in the UK ID card scheme  22 Nov 2007

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Reading, Berkshire, United Kingdom | EDS
Position # 397874 IP Network Administrator Location - Reading Job Description: There is a requirement for an IP network administrator to join the Infrastructure Services operational support team to manage the movement of network resources, ... more >
Telford, Shropshire, United Kingdom | EDS
EDS are currently looking to recruit a PMO Support Analyst to join our Project Management Defence team in Telford, Shropshire. Summary: Within DII Service Management. To perform the PMO function for SM Service Introduction. This ... more >
Reading, Berkshire, United Kingdom | EDS
Position # 395423 Environment Manager Location - Reading, Berkshire Job Description: There is a requirement for an Environmental Manager for the Sandpits environment. This position is to act as the single point of contact for ... more >
London, Haringey, United Kingdom | Haringey Council
PMO Support Officer - Haringey, London - £32,289 - £37,542 pa   Experienced project support officer required by the internal IT services organisation of a London borough council to work within its Programme Management Office ... more >
More job opportunities