Data-breach admissions may become mandatory

By Nick Heath, Special to ZDNet Asia
Wednesday, October 29, 2008 10:37 AM

Banks, other businesses and authorities could soon be forced to confess to data breaches, according to the EU privacy tsar.

European data-protection supervisor Peter Hustinx said there is growing pressure within the European Parliament to create a data-breach notification law as part of a shake-up of privacy law.

Amendments to the EU e-privacy directive are currently being debated by the EU parliament and are expected to be passed in six months' time.

These amendments would force ISPs and telecoms companies to notify customers and authorities when they lose their customers' personal data.

And speaking at the RSA Conference in London, Hustinx said there are increasing demands from the European Parliament for the amendments to require all companies and public-sector organizations with an online presence to also come under the law.

Hustinx said: "I would be very much in favor of making data-security breach an element of general data-protection arrangements.

"It doesn't make sense to exclude an Internet banking site, a hospital with a Web site or other businesses collecting sensitive data online, and just to impose it only on the telcos and the ISP."

Hustinx went on to say that the powers of the U.K. Information Commissioner's Office (ICO) were lagging behind equivalents in the rest of Europe and welcomed consultations to give the ICO more powers.

He said: "Inspection and sanction powers are rather weak in the [United Kingdom] compared to other countries in the EU.

"But [information commissioner] Richard Thomas being given more powers is looking more probable."

However, Hustinx added: "There is no reason to presume that the [United Kingdom] is worse than other countries."

Nick Heath of Silicon.com reported from London.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Migrating DHCP from Windows 2000 Server/Windows Server 2003 to Windows Server 2008

Windows Server

With a little bit of work, it's not hard to migrate DHCP services from Windows 2000 Server or Windows Server 2003 to Windows Server 2008. Here's how.


Read more »



Do we need more delivery centers?

Blog thumbnail

As I wrote a while back in about "racing to subsidies", there certainly is an increased focus by governments to attract delivery centers to their region. To do that, many..... by Michael Rehkopf

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web