All the latest UK technology news, reviews and analysis

Users to get help with data protection

by Lisa Kelly

10 Apr 2000

Be the first to comment

  • Tweet this

Systems designers are being encouraged to incorporate privacy-friendly features into IT products to help end users comply with data protection laws.

The UK Data Protection Commissioner is planning to produce a guide to help systems designers incorporate such features into IT systems. The guide will explain how designers can build systems that allow users to meet their obligations under data protection law, and encourage the application of Privacy Enhancing Technologies (Pets).

Recently introduced data protection laws in the UK place duties on users rather than designers. Including Pets at the design stage would help avoid costly systems changes when IT systems are found not to comply with data protection law.

The law says that processing of personal data should be limited to that which is necessary to achieve an objective, so systems should not process identifiable data where it can be reasonably avoided.

David Smith, assistant data protection registrar, said: "It could save a lot of time and expense." Achieving privacy compliance is "a lot cheaper if it is built in at the beginning rather than bolted on afterwards on discovering a system breaches to the Data Protection Act".

Recently, there have been privacy fears over hardware and software products that can assist in identifying users on the internet. Last year, for example, concerns were raised over the processor serial number in Intel's Pentium III chip. The Registrar says early recognition of privacy and data protection considerations at the design stage might have resolved these problems.

Smith said a classic example of a privacy design mistake was the poll tax system. It had a mandatory 'date of birth' field built into it which was later judged excessive under the Act, so the fields had to be rewritten.

Systems can help achieve data protection compliance by ensuring accuracy of personal data, for example, or including on-screen prompts and record responses to ensure that explicit consent is obtained to processing sensitive data.

Identity protectors, which control the release of the individual's true identity to the various processes in the information system, could be implemented in software, or as a physical token held by the individual, such as a smartcard.

The regulator hopes that the guide will lead to the incorporation of its principles in recognised design methodologies, such as the structured systems analysis and design method.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

31%

1%

12%

56%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Scrum Master

Want to work for one of the most dynamic, creative environments...

Interactive & Mobile QA Engineer

Want to work for one of the most dynamic, creative environments...

Enterprise Architect - London - £100k - £120k

Roc Search is currently recruiting for an Infrastructure...

IP Services Project Engineer (Alcatel/Cisco)

Want to work for one of the most dynamic, creative environments...

To send to more than one email address, simply separate each address with a comma.