All the latest UK technology news, reviews and analysis

Infosec: New EU data protection laws still years away

by Phil Muncaster

20 Apr 2011

Be the first to comment

  • Tweet this
Deputy information commissioner David Smith

New EU-wide data protection laws are still at least two to three years away, but are likely to mandate data breach notifications for all organisations, according to the deputy information commissioner David Smith.

Speaking at the Infosecurity Europe event in London today, Smith explained that the Data Protection Directive is currently under review by the European Commission, which will announce a set of initial proposals in the summer.

"However, this is a sensitive and difficult area so don't hold your breath," he added. "It could be two or three years before the final proposals come out, but we will see changes."

One of these changes is likely to be data breach notification laws "across the board", according to Smith.

From May this year notification will become mandatory for service providers under UK law, but the European proposals would stretch to all firms in a similar way to those enforced in the US.

"We're keen to ensure its proportionality ... so only the ones which are significant [are notified]," said Smith.

Other areas likely to be included in the forthcoming update include data minimisation rules, privacy by design and the ‘right to be forgotten', i.e. the deletion of personal data from social networking and other sites.

Smith also defended the £500,000 cap on fines that the ICO is allowed to levy on organsations found to be in serious breach of the Data Protection Act.

"I don't think that any company would see a £500,000 fine as a bit of a joke, although for multinational businesses it would not necessarily have a huge financial impact," he argued.

"But there's always the trust, confidence and reputation damage which is a key driver for businesses. What we've got is proportionate and if [the fines] fail to deliver improved data protection we will be knocking on the door of government."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

38%

0%

10%

52%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Java Developer, Algo Trading, FX, Trading Strategies

Java Deveoper/Programmer/Software Engineer, Algo Trading...

Lead and Senior Developers Wanted

Austin Fraser has the pleasure of appointing a number...

Java Developer - Great move up for a Junior Developer

Austin Fraser has the pleasure of appointing a Java Developer...

Senior J2EE Application Developer

Austin Fraser has the pleasure of appointing a Senior...

To send to more than one email address, simply separate each address with a comma.