How the Data Protection Act's death will punish the UK economy
By Tom Brewster,
COMMENT The Data Protection Act is on death's door. When it goes, it won't just radically alter how information is processed and protected in the UK, it will have serious, pejorative consequences for our economy too.
That was what IT Pro heard this week from two leading data protection lawyers – lawyers who have seen drafts of what the European Commission is planning. In the coming months, they believe the EC will not propose a directive for nations to use as guidance, but will devise European-wide regulation for all member states to adhere to.
Despite the Commission's best intentions, however, the laws look set to bring more red tape to constrain companies working in Europe, the same red tape the Coalition has promised to cut. A host of requirements will be placed on businesses, which will likely deter many from investing in the UK. It will bring over-regulation of the most pernicious order.
The laws look set to bring more red tape to constrain companies working in Europe, the same red tape the Coalition has promised to cut.
This week, the EU again outlined its aggressive stance. Viviane Reding, vice-president of the European Commission, told delegates at a GSMA Europe conference that under her proposals there would be a strong focus on privacy by design.
"Businesses will have to pay utmost attention to security of information and privacy by design. These features should be well-integrated in the design of cloud computing products and services," Reding said. "The real winners will be those companies and service providers – no matter where they are from – that understand the competitive advantage of having built-in privacy features.
"When a data breach happens, a company will have to inform the national supervisory authority immediately and the individual whose data has been compromised or stolen."
That latter statement confirmed what appeared in a Financial Times report late last week, which hinted companies would have just 24 hours to confess to a breach. That same report suggested the EC was hoping to gain powers to fine businesses up to five per cent of their revenue for data snafus.
Furthermore, the Commission wants companies with 250 or more employees to have a data protection officer in place. SMEs will not be pleased.
So, businesses in the EU will be forced to employ more personnel, be threatened with massive fines and have to spend more money on development to ensure privacy-as-default in everything they do.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security News
UK regulator shuts down Angry Birds scam
Victims of fake apps will have £15 charge refunded by PhonepayPlus.
Latest Security Tutorials
How to protect a group of office PCs from viruses
Safeguarding multiple office computers from malware doesn't have to be difficult or expensive, as Simon Edwards shows in our step-by-step guide.
advertisement
Most popular
- UK regulator shuts down Angry Birds scam
- Apple iPad 3 vs iPad 2 head-to-head review
- IBM bans use of Siri on iPhones
- Chromebooks: What's gone wrong?
- HP plans massive job cuts
- EMC World 2012: Tucci declares Documentum is here to stay
- Dell EqualLogic PS6100XS review
- Macs and Android under malware threat
- RIM loses its head of sales
- Local fibre broadband needs common standards
Latest Analysis & Insight Videos in Security
Why security should top the cloud agenda
Security should always be paramount in business, but with a cloud based infrastructure it’s arguably even more important. Steve Cassidy and...






Buried nuggets
There may be some validity to this argument but its hard to find as they are buried under emotional invectives, distortions and worn out and discarded cliches. The meat of the argument seems to rely on the potentiality of 'if' and 'may be'. It sounds more like a complainer's pub closing time call to arms than a thoughtful reasoned argument.
Coming from engineering background a few facts, figures, and examples would carry more weight.
But thanks for raising awareness of the issue, I'll look into it for myself.
By Ip5_a20f7c4425b on Friday Dec 9
FALSE ALARM
Businesses have a duty to keep confidential data secure.
If they collect it {by cookie collection and tracking and data mining} this could impinge with security and ID Theft, as well as unwarranted intrusion into privacy.
Any data breach can severely damage any company, be it personnel, trade figures, or trade secrets. It pays a company to have an officer who is security conscious and has dual roles.
The basic error is UK method of Law. A person in UK has to Opt IN to opt OUT of targeted advertising. That is a denial of rights for a person wishes to be anonymous and does not want cookies in the first case.
In this page I note the ICO has hit London Council with £70,000 data breach fine. The fine is equally shared to the council taxpayers, who's very data was lost.
I also make note that the ICO is suggesting fines will not be issues if company's have made some progress but still not manage to comply with the cookie deadline (Postponed for 12 months a year ago!!!).
In my opinion the ICO is not fit for purpose. They are supposed to be stalwarts of Digital Law, yet cast a blind eye to such a degree that they may be perverting the course of justice.
By Lenmontieth on Saturday May 19