Privacy and Data Protection Volume 17 Issue 7 (July/August 2017) provided information about the first international strategy to come from the Information Commissioner’s Office.
International Strategy 2017-2021
To effectively protect the UK public’s personal information in a digital global environment, the ICO needs to co-operate and act internationally. This International Strategy seeks to enhance privacy protection for the UK public.
Recognising that the ICO needs to be agile in an ever-changing world, it will be regularly reviewed and updated in response to new challenges and opportunities.
This international strategy supports our 2017 Information Rights Strategic Plan.
Part one sets out the main challenges we face and their associated priorities.
Part two covers ICO structure and resourcing, engagement and evaluation.
A copy of the Strategy is available at www.pdpjournals.com/docs/88774 (PDF 8pp)
Showing posts with label data_protection. Show all posts
Showing posts with label data_protection. Show all posts
Saturday, 28 October 2017
Saturday, 26 August 2017
What small businesses need to know about the General Data Protection Regulation
via Bytestart by Stuart Crook a data protection expert and Associate at the national law firm, Stephensons.

Despite Brexit, the UK government has confirmed it will abide by the new General Data Protection Regulation (GDPR), which is due to come into effect on 28 May 2018.
The aim of General Data Protection Regulation is to encourage companies across the European Union to think seriously about data protection. In practice, the new GDPR lays down some fairly stringent legislation, for both large and small businesses, governing the standards by which personal data is collected and stored.
To help UK businesses understand the new laws, and avoid the heavy punishments failure to abide by them bring, here’s a guide to the GDPR legislation.
Continue reading
Despite Brexit, the UK government has confirmed it will abide by the new General Data Protection Regulation (GDPR), which is due to come into effect on 28 May 2018.
The aim of General Data Protection Regulation is to encourage companies across the European Union to think seriously about data protection. In practice, the new GDPR lays down some fairly stringent legislation, for both large and small businesses, governing the standards by which personal data is collected and stored.
To help UK businesses understand the new laws, and avoid the heavy punishments failure to abide by them bring, here’s a guide to the GDPR legislation.
Continue reading
Thursday, 6 April 2017
Trump Order prompts panic that Privacy Shield will be invalidated
An Executive Order signed by US President Trump during his first few days in office may jeopardise the recently agreed EU/US Shield.
The Enhancing Public Safety in the Interior of the United States Order – aimed at enhancing domestic enforcement of US immigration laws – reads that: “agencies shall, to the extent consistent with applicable law, ensure that their privacy policies exclude persons who are not United States citizens or lawful permanent residents from the protections of the Privacy Act regarding personally identifiable information”.
MEP Jan Philipp Albrecht, the European Parliament’s Rapporteur on data protection regulation, suggested that this wording in the Order could be a major problem for the Shield, and that there might also be ramifications for the EU/US Umbrella agreement governing law enforcement. Other EU officials played down the impact of the Order.
So far so good from an article in “Privacy and Data Protection” (Volume 17 Issue 3 (January/February 2017)) and probably as far as I should go with copy typing.
I admit that my first reading of the section of the Order quoted above was to think that I am not a citizen of the United States of America therefore my personally identifiable information is not covered by the laws of the said United States.
I wonder.
I found the Business Insider site that has information on 45 Orders signed by the President but none seemed to be right for the quote above.
Perhaps I’m missing something. Brain has obviously slowed down since I was reading this sort of stuff on a regular basis.
The Enhancing Public Safety in the Interior of the United States Order – aimed at enhancing domestic enforcement of US immigration laws – reads that: “agencies shall, to the extent consistent with applicable law, ensure that their privacy policies exclude persons who are not United States citizens or lawful permanent residents from the protections of the Privacy Act regarding personally identifiable information”.
MEP Jan Philipp Albrecht, the European Parliament’s Rapporteur on data protection regulation, suggested that this wording in the Order could be a major problem for the Shield, and that there might also be ramifications for the EU/US Umbrella agreement governing law enforcement. Other EU officials played down the impact of the Order.
So far so good from an article in “Privacy and Data Protection” (Volume 17 Issue 3 (January/February 2017)) and probably as far as I should go with copy typing.
I admit that my first reading of the section of the Order quoted above was to think that I am not a citizen of the United States of America therefore my personally identifiable information is not covered by the laws of the said United States.
I wonder.
I found the Business Insider site that has information on 45 Orders signed by the President but none seemed to be right for the quote above.
Perhaps I’m missing something. Brain has obviously slowed down since I was reading this sort of stuff on a regular basis.
Tuesday, 13 August 2013
Ruling shows that deleting personal data can remove burdens brought by data subject access requests, says expert
via Out-Law.com
A ruling by the High Court on the issue of dealing with data subject access requests highlights the positives that can be derived by businesses that decide to dispose of personal data records they no longer need, an expert has said.
Continue reading
A ruling by the High Court on the issue of dealing with data subject access requests highlights the positives that can be derived by businesses that decide to dispose of personal data records they no longer need, an expert has said.
Continue reading
Thursday, 4 July 2013
Google not always a 'data controller' of data processed by search engines, says legal advisor
via Out-Law.com
Internet search engine providers do not have to delete personal data from their index where that information has been published on third party websites, a legal advisor has said.
Continue reading
Internet search engine providers do not have to delete personal data from their index where that information has been published on third party websites, a legal advisor has said.
Continue reading
Friday, 17 May 2013
Separate data protection law for employment relations recommended
via Out-Law News
New laws should be drafted to set specific rules around data protection in employment relations, a new report has recommended.
Read all about it here
New laws should be drafted to set specific rules around data protection in employment relations, a new report has recommended.
Read all about it here
Monday, 11 February 2013
Paul Ticher's Data Protection Roundup: February 2013
via Lasa knowledgebase
Paul’s quarterly update on data protection news and issues
This quarter’s update covers:
Paul’s quarterly update on data protection news and issues
This quarter’s update covers:
- European overhaul of Data Protection: any progress?
- Cookie law: problem solved?
- Cloud data locations
- Increased penalties for individual Data Protection offences?
- The data is blowing in the wind
- E-mail marketing complaints rise
- First monetary penalty for breach of the fourth Data Protection Principle
- Data Protection and volunteers (a new webinar from Paul which is FREE)
Friday, 16 November 2012
Latest patient data fiasco highlights need for an NHS data protection czar
To be fair it was the latest fiasco when the report was written back in April this year. I was inspired to go and find it by an article in Bulletin (of the information and records management society) (Issue 168 (July 2012)) which I managed to read in the British Library yesterday.
I thought it was too “good” not to use – which assumes that we can see anything good in reading that “10 of the 30 major data breaches the ICO handles each month involve the NHS in one shape or another”.
Is the NHS overall the largest organisation in the UK?
Not three times as large as anyone else, surely.
Cryptzone Insight by Grant Taylor
I thought it was too “good” not to use – which assumes that we can see anything good in reading that “10 of the 30 major data breaches the ICO handles each month involve the NHS in one shape or another”.
Is the NHS overall the largest organisation in the UK?
Not three times as large as anyone else, surely.
Cryptzone Insight by Grant Taylor
Labels:
Cryptzone,
data_protection,
data_security_breaches,
lost_identity,
NHS
Tuesday, 2 October 2012
Cloud computing – new ICO guidance
via Panopticon Blog by Anya Proops
Cloud computing is becoming an ever more pervasive feature of the technological world. Whether one is dabbling in social networking or purchasing goods online, the truth is that we all, to a greater or lesser extent, now have our heads in the virtual clouds. However, the use of cloud computing inevitably raises important information law issues, particularly in terms of the impact on privacy rights and also under the Data Protection Act 1998. So far as the DPA is concerned, issues which fall to be considered include:
Continue reading Anya’s post here
Cloud computing is becoming an ever more pervasive feature of the technological world. Whether one is dabbling in social networking or purchasing goods online, the truth is that we all, to a greater or lesser extent, now have our heads in the virtual clouds. However, the use of cloud computing inevitably raises important information law issues, particularly in terms of the impact on privacy rights and also under the Data Protection Act 1998. So far as the DPA is concerned, issues which fall to be considered include:
- who actually controls the data which is being processed via the cloud (i.e. who is liable under the DPA if things go wrong in data protection terms)
- what steps a data controller may be required to take to safeguard against misuses of personal data within the cloud
- the security implications of processing personal data through cloud computing and, in particular, whether the processing of data via the cloud is compliant with the seventh data protection principle
- the legality of using clouds which operate transnationally and, hence, which may bring into play the application of the eighth data protection principle on cross-border data transfers
Continue reading Anya’s post here
Tuesday, 8 May 2012
ICO Warns on Redundant Equipment Disposal
How do you dispose of your old computers, hard drives and mobile phones?
Do you cleanse the hard drives and memory before disposal?
More importantly, in disposing of old equipment might you be in breach of data protection laws?
The Office of the Information Commissioner (ICO) has published new guidance to help individuals securely delete personal information from their old devices as a result of a survey that found 65% of British adults now hand on their old phones, computers and laptops to another user, with 44% giving it away to somebody else for free and around one in five (21%) selling it to somebody else.
Read the guidance on the ICO website
Do you cleanse the hard drives and memory before disposal?
More importantly, in disposing of old equipment might you be in breach of data protection laws?
The Office of the Information Commissioner (ICO) has published new guidance to help individuals securely delete personal information from their old devices as a result of a survey that found 65% of British adults now hand on their old phones, computers and laptops to another user, with 44% giving it away to somebody else for free and around one in five (21%) selling it to somebody else.
Read the guidance on the ICO website
Monday, 21 November 2011
Data Protection Update
by Paul Ticher in Computanews 162 – November 2011
Article covers:
Article covers:
- Update on security breaches
- Cookie law
- Data Processor contracts
- Payment card security
- Are your staff third parties?
Monday, 9 March 2009
Department of Health must improve its management of records
via ICO Press Releases on 9 March
The Information Commissioner's Office (ICO) has issued a formal practice recommendation to the Department of Health regarding its record management practice. This follows a request by the ICO, and with the agreement of the Department, for the National Archives (TNA) to conduct an assessment of records management practice at the authority.
Read the full press release
The Information Commissioner's Office (ICO) has issued a formal practice recommendation to the Department of Health regarding its record management practice. This follows a request by the ICO, and with the agreement of the Department, for the National Archives (TNA) to conduct an assessment of records management practice at the authority.
Read the full press release
Tuesday, 20 May 2008
Rowling privacy ruling bolsters Commissioner's view of data protection law
via OUT-LAW News on 9 May
The Court of Appeal's ruling in JK Rowling's privacy case confirms that a breach of other laws can result in an automatic breach of the Data Protection Act, an expert has said.
Read the full article
The Court of Appeal's ruling in JK Rowling's privacy case confirms that a breach of other laws can result in an automatic breach of the Data Protection Act, an expert has said.
Read the full article
Subscribe to:
Posts (Atom)