R E L A T E D   C O N T E N T
ADVERTISEMENT

MPs call to criminalise data loss

Justice Select Committee demands heavy fines and/or jail terms

Iain Thomson, vnunet.com 03 Jan 2008
ADVERTISEMENT

MPs on the Justice Select Committee have called for new laws to protect the integrity of personal data.

The move was prompted by critical government data losses over the past few months, such as the loss of computer disks at HM Revenue & Customs.

The committee called for a breach law that would make it a legal obligation for companies to notify customers if their data has been accessed and to create a system of fines for repeat offenders.

"The scale of the data loss by government bodies and contractors is truly shocking, but the evidence we have had points to further hidden problems," said committee chairman Alan Beith.

"It is frankly incredible, for example, that the measures put in place at HM Revenue & Customs were not already standard procedure."

The Committee also called for the Information Commissioner to have powers to make spot checks on government departments to ensure that correct practice is being followed.

"These latest proposals to punish reckless data leakage with large fines and/or prison sentences will go some way in encouraging organisations from the top down to be compliant or at least be able to prove they took the necessary steps to protect their data," said Alan Bentley, vice president of Lumension Security.

"The UK is not without laws surrounding this issue as we already have the Computer Misuse Act 1990 and the Data Protection Act. The question is how far this new law is taken.

"There is a very fine line that needs to be balanced which ensures that all our personal data is secure but does not hamper the efficiency of a business."

However, some are questioning the government's approach. "The government is moving closer to implementing US-style data breach notification laws, but making data loss a criminal offence may be a step too far," said Jamie Cowper, marketing director at PGP Europe.

"Before we go for the nuclear option, perhaps we should look at how current security regimes can be tightened up with stricter enterprise data policies, for instance.

"We should also test the power of simply naming and shaming organisations as a deterrent to lax attitudes to data protection, as it has certainly worked in the US."

See also:

As little as £1 buys you an active bank account  03 Dec 2007
Website farce exposes details of 50,000 applicants  15 Nov 2007
CSIA steps up lobbying  04 Oct 2007
Stolen laptop contained 11 million client records  15 Feb 2007
Average cost now $182 per compromised record  23 Oct 2006

All Privacy & Data

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Bicester, Oxfordshire, United Kingdom | EDS
Position # 398435 Test Manager - EDS - Bicester Must be eligable for security clearance Short Description: EDS's Defence Logistics (DL) testing group tests a range of logistics information systems for the MOD. The Test ... more >
Canary Wharf, Greater London, United Kingdom | EDS
Position # 398441 Responsibilities - Testing Consultant * Under broad direction, interacts with EDS project teams and clients to gain an understanding of the business environment, technical context, and testing objectives for a project as ... more >
Central London, United Kingdom | MI5 Security Service
Communications Centre Engineer - Competitive salaries + excellent benefits - Central London Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use your skills and experience to ... more >
London, United Kingdom | The Moving Picture Company
Web Developer - London   MPC's continued success is dependent on a continued investment in technology so that its clients continue to enjoy the highest possible quality of work and service. Key to MPC's offering is ... more >
More job opportunities