07 Mar 2000
The biggest data protection obligation for an IT manager is making sure the company is registered under the Data Protection Act - well, it was until last week.
New data protection rules became law on 1 March, and the IT manager is now faced with a much more complex job.
Despite a 16-month delay in implementing the Act, many businesses have failed to use the extra time to get up to speed with the new rules. Nine out of 10 company directors are currently unaware of the impact that the legislation will have on their business processes, according to a survey by GB Information Management.
However, companies may still be able to avoid costly and damaging publicity and court action - if they start work now. A complicated transitional timeframe imposed by the new laws may benefit businesses by buying them time.
The rules
Before assessing the impact of the legislation, it is vital that you understand your company's obligations. Here are the most important aspects of the Act:
It also worth remembering that the laws will apply not just to information held on computers but any data that identifies a living individual. None of this information can be used by a company unless it is compliant with the Act.
What to do next
You need to ensure that you understand the data storing and processing methods used by every department in your company. Here's how you should start:
The transferral of data abroad, plus supplying information to individuals before their details can be used, are the most onerous obligations now facing companies in the UK. Both will affect how information is gathered, and can require that consent has to be obtained before personal data can be processed.
The already ubiquitous tick box is a useful way round this. However, a word of warning: the Registrar (now the Data Protection Commissioner) and the courts will not look kindly upon tick boxes that are ambiguously worded, or worded so that consent can be implied from a failure to respond. Informed explicit consent should be obtained wherever possible. In relation to certain sensitive information (for example, political opinion, ethnic origin and criminal record) it is an absolute requirement.
Other action points to consider include:
Carrying out a compliance audit can help ensure the risks associated with the use of personal data are well managed.
When to do it
Although the Act came into force at the start of the month, it contains transitional provisions that may buy you time.
Briefly, use of personal details (whether in a machine-readable form or on paper records) will be exempt from some of the Act's significant obligations until 23 October 2001 if processing is said to have been under way before 24 October 1998 (when the law should have been introduced). Any processing begun after that date must now meet the obligations of the new law.
Ask yourself this question: since 24 October 1998 what information about individuals has my business started to use, used for a new purpose, or used in a way which produces new results?
One thing that might inspire you - and your board of directors - to act swiftly are the potential penalties. Managers or directors can be made personally and criminally liable, and can be fined if their company fails to observe the new requirements.
With 88 per cent of consumers vowing that they will pursue their rights - as revealed by the GB Information Management survey - getting a headstart is definitely a smart move.
Latest stories from Public Sector
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
TFL director of Games transport Mark Evers discusses how the public transport network is preparing for this summer's event
Connect with V3.co.uk
The wrong printers, for the wrong tasks on the wrong contracts
Who leads the BI pack and who should we be watching out for?
My client, a large local government organisation are...
Web Developer - ASP.NET/SQL Server/Ajax/ecommerce- up...
My client (a large blue chip with offices near Chester...
Position: EMEA & HQ IT Controller Reference...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?