Showing posts with label data_protection. Show all posts
Showing posts with label data_protection. Show all posts

Saturday, 28 October 2017

ICO’s first International Strategy

Privacy and Data Protection Volume 17 Issue 7 (July/August 2017) provided information about the first international strategy to come from the Information Commissioner’s Office.

International Strategy 2017-2021

To effectively protect the UK public’s personal information in a digital global environment, the ICO needs to co-operate and act internationally. This International Strategy seeks to enhance privacy protection for the UK public.

Recognising that the ICO needs to be agile in an ever-changing world, it will be regularly reviewed and updated in response to new challenges and opportunities.

This international strategy supports our 2017 Information Rights Strategic Plan.

Part one sets out the main challenges we face and their associated priorities.
Part two covers ICO structure and resourcing, engagement and evaluation.

A copy of the Strategy is available at www.pdpjournals.com/docs/88774 (PDF 8pp)


Saturday, 26 August 2017

What small businesses need to know about the General Data Protection Regulation

via Bytestart by Stuart Crook a data protection expert and Associate at the national law firm, Stephensons.

General Data Protection Regulation

Despite Brexit, the UK government has confirmed it will abide by the new General Data Protection Regulation (GDPR), which is due to come into effect on 28 May 2018.

The aim of General Data Protection Regulation is to encourage companies across the European Union to think seriously about data protection. In practice, the new GDPR lays down some fairly stringent legislation, for both large and small businesses, governing the standards by which personal data is collected and stored.

To help UK businesses understand the new laws, and avoid the heavy punishments failure to abide by them bring, here’s a guide to the GDPR legislation.

Continue reading


Thursday, 6 April 2017

Trump Order prompts panic that Privacy Shield will be invalidated

An Executive Order signed by US President Trump during his first few days in office may jeopardise the recently agreed EU/US Shield.

The Enhancing Public Safety in the Interior of the United States Order – aimed at enhancing domestic enforcement of US immigration laws – reads that: “agencies shall, to the extent consistent with applicable law, ensure that their privacy policies exclude persons who are not United States citizens or lawful permanent residents from the protections of the Privacy Act regarding personally identifiable information”.

MEP Jan Philipp Albrecht, the European Parliament’s Rapporteur on data protection regulation, suggested that this wording in the Order could be a major problem for the Shield, and that there might also be ramifications for the EU/US Umbrella agreement governing law enforcement. Other EU officials played down the impact of the Order.

So far so good from an article in “Privacy and Data Protection” (Volume 17 Issue 3 (January/February 2017)) and probably as far as I should go with copy typing.

I admit that my first reading of the section of the Order quoted above was to think that I am not a citizen of the United States of America therefore my personally identifiable information is not covered by the laws of the said United States.


I wonder.

I found the Business Insider site that has information on 45 Orders signed by the President but none seemed to be right for the quote above.

Perhaps I’m missing something. Brain has obviously slowed down since I was reading this sort of stuff on a regular basis.




Tuesday, 13 August 2013

Ruling shows that deleting personal data can remove burdens brought by data subject access requests, says expert

via Out-Law.com

A ruling by the High Court on the issue of dealing with data subject access requests highlights the positives that can be derived by businesses that decide to dispose of personal data records they no longer need, an expert has said.

Continue reading


Thursday, 4 July 2013

Google not always a 'data controller' of data processed by search engines, says legal advisor

via Out-Law.com

Internet search engine providers do not have to delete personal data from their index where that information has been published on third party websites, a legal advisor has said.

Continue reading


Friday, 17 May 2013

Separate data protection law for employment relations recommended

via Out-Law News

New laws should be drafted to set specific rules around data protection in employment relations, a new report has recommended.

Read all about it here


Monday, 11 February 2013

Paul Ticher's Data Protection Roundup: February 2013

via Lasa knowledgebase

Paul’s quarterly update on data protection news and issues

This quarter’s update covers:
  • European overhaul of Data Protection: any progress?
  • Cookie law: problem solved?
  • Cloud data locations
  • Increased penalties for individual Data Protection offences?
  • The data is blowing in the wind
  • E-mail marketing complaints rise
  • First monetary penalty for breach of the fourth Data Protection Principle
  • Data Protection and volunteers (a new webinar from Paul which is FREE)
Read all about it here


Friday, 16 November 2012

Latest patient data fiasco highlights need for an NHS data protection czar

To be fair it was the latest fiasco when the report was written back in April this year. I was inspired to go and find it by an article in Bulletin (of the information and records management society) (Issue 168 (July 2012)) which I managed to read in the British Library yesterday.
I thought it was too “good” not to use – which assumes that we can see anything good in reading that “10 of the 30 major data breaches the ICO handles each month involve the NHS in one shape or another”.

Is the NHS overall the largest organisation in the UK?

Not three times as large as anyone else, surely.

Cryptzone Insight by Grant Taylor


Tuesday, 2 October 2012

Cloud computing – new ICO guidance

via Panopticon Blog by Anya Proops

Cloud computing is becoming an ever more pervasive feature of the technological world. Whether one is dabbling in social networking or purchasing goods online, the truth is that we all, to a greater or lesser extent, now have our heads in the virtual clouds. However, the use of cloud computing inevitably raises important information law issues, particularly in terms of the impact on privacy rights and also under the Data Protection Act 1998. So far as the DPA is concerned, issues which fall to be considered include:
  • who actually controls the data which is being processed via the cloud (i.e. who is liable under the DPA if things go wrong in data protection terms)
  • what steps a data controller may be required to take to safeguard against misuses of personal data within the cloud
  • the security implications of processing personal data through cloud computing and, in particular, whether the processing of data via the cloud is compliant with the seventh data protection principle
  • the legality of using clouds which operate transnationally and, hence, which may bring into play the application of the eighth data protection principle on cross-border data transfers
Importantly, the Information Commissioner has today [27 September] issued guidance which is designed to help organisations navigate their way through the potentially complex DPA issues which may arise in the context of cloud computing. You can find the guidance here.

Continue reading Anya’s post here


Tuesday, 8 May 2012

ICO Warns on Redundant Equipment Disposal

How do you dispose of your old computers, hard drives and mobile phones?
Do you cleanse the hard drives and memory before disposal?
More importantly, in disposing of old equipment might you be in breach of data protection laws?

The Office of the Information Commissioner (ICO) has published new guidance to help individuals securely delete personal information from their old devices as a result of a survey that found 65% of British adults now hand on their old phones, computers and laptops to another user, with 44% giving it away to somebody else for free and around one in five (21%) selling it to somebody else.

Read the guidance on the ICO website


Monday, 21 November 2011

Data Protection Update

by Paul Ticher in Computanews 162 – November 2011

Article covers:
  • Update on security breaches
  • Cookie law
  • Data Processor contracts
  • Payment card security
  • Are your staff third parties?
Access the article here


Monday, 9 March 2009

Department of Health must improve its management of records

via ICO Press Releases on 9 March

The Information Commissioner's Office (ICO) has issued a formal practice recommendation to the Department of Health regarding its record management practice. This follows a request by the ICO, and with the agreement of the Department, for the National Archives (TNA) to conduct an assessment of records management practice at the authority.

Read the full press release

Tuesday, 20 May 2008

Rowling privacy ruling bolsters Commissioner's view of data protection law

via OUT-LAW News on 9 May

The Court of Appeal's ruling in JK Rowling's privacy case confirms that a breach of other laws can result in an automatic breach of the Data Protection Act, an expert has said.

Read the full article