
DPA needs updating in light of recent data debacles
By Tom Espiner
Published: 31 January 2008 08:00 GMT
The Information Commissioner's Office (ICO) has called for amendments to UK data-protection laws, including making "reckless" data breaches an offence.
Security from A to Z
Click on the links below to find out more...
A is for Antivirus
B is for Botnets
C is for CMA
D is for DDoS
E is for Extradition
F is for Federated identity
G is for Google
H is for Hackers
I is for IM
J is for Jaschan (Sven)
K is for Kids
L is for Love Bug
M is for Microsoft
N is for Neologisms
O is for Orange
P is for Passwords
Q is for Questions
R is for Rootkits
S is for Spyware
T is for Two-factor authentication
U is for USB sticks/devices
V is for Virus variants
W is for Wi-fi
X is for OS X
Y is for You
Z is for Zero-day
In a document submitted to government, information commissioner Richard Thomas called for the Data Protection Act (DPA) to be amended to include a penalty for data controllers "knowingly or recklessly failing to comply with the principles" of the DPA.
The document said: "The Commissioner is proposing the introduction of a new penalty, limited to breaches that are avoidable, that give rise to a serious data-protection risk and where a criminal state of mind exists. [Currently] there is no effective punishment or deterrent available for those who knowingly or recklessly disregard the requirements of data-protection law in a way that causes a significant risk of harm."
Recent data breaches include the loss of 25 million details by HM Revenue & Customs, reported last November, and the more recent loss of a Ministry of Defence laptop containing 3,700 people's bank details, as well as other data on up to 600,000 people.
The powers of the ICO are limited. For the most part, the ICO cannot impose a penalty for a breach that has occurred. While individuals can be prosecuted for unlawfully obtaining personal data, current sanctions are designed to make an organisation that has suffered a breach liable to a penalty only if it continues to act in a way that contravenes the DPA.
Moreover, government departments are not liable for prosecution under the DPA. Individuals within government can be prosecuted under the law, but only if they act outside their remit by unlawfully obtaining personal data.
The ICO is also seeking greater inspection and enforcement powers. The information commissioner would like to be able to spot-check organisations, stop "seriously unlawful" data-processing immediately, and take enforcement action to prevent breaches of the DPA that haven't occurred, but are likely.
However, legal experts said that major changes to data-protection laws are not likely in the near future. Louise Townsend, a senior associate at Pinsent Masons solicitors, was not convinced that the proposals would lead to radical changes in the law any time soon.
Townsend said: "While we may see some changes, such as the power to audit government departments, changes such as a data-breach notification law or a new offence for gross negligence are unlikely to be imminent."
She added: "The government rejected proposals for a data-breach notification law, and the new offence would have to become government policy, and once it was on the agenda would take time to go through [Parliament]."
Nevertheless, said Townsend, the publicity surrounding data protection at the moment is "at least getting the information commissioner's concerns on the table, and getting the issue talked about."
Original article: Watchdog calls for 'reckless data-breach' offence from ZDNet UK
nice to see Mr Thomson hasn't lost his sense of hu...
Karen Challinor
The Seventh DPA Principle states:
“Appropriate ...
Adrian Asher
Project Controller As part of a multidisciplinary team, the project controller is responsible for pro-actively contributing to the economic success ...
Technical Strategy Manager Fully accountable for effective management of the UK-based SME (Subject Matter Expert) teams, and for their governance in ...
Industrialisation Engineer Working as part of Mechanical Platform MSC's Industrialisation Team, an Industrialisation Engineer is required to work ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Is Your Enterprise Architected for Tomorrow's Growth?
Improving IT service delivery through an integrated approach to software asset management...
The Real Reason Executive Participation Creates IT Project Success
Information Management, BPM and Integration: Achieving Cost Efficiency in the Financial...
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
silicon.com staff Inbox: Social networking can help you secure a job Plus: Open source advocates hit back at CIOs and netbooks fail 'fit for work' test
Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead