About RSS
Search for: in 
Emma Leith
Leith: The importance of adequately securing personal data will become a legal requirement
R E L A T E D   C O N T E N T

Free email newsletters




Jargon Buster

ADVERTISEMENT

When in Rome, consider privacy regulations

BCS view: Amendments to the Rome 1 legislation put data privacy back into the limelight

Emma Leith, Computing 26 Jun 2008
ADVERTISEMENT

A proposed new "Rome 1" European Union (EU) legislation demonstrates the effect EU law can have on the private sector, in particular on small and medium-sized enterprises (SMEs).

The draft regulation was presented as an update and clarification to the obligations of the Rome 1 convention. However, unfortunately it came with a price, and under the changes, all e-commerce traders would be required to settle any consumer dispute according to the laws of the country from which the product was ordered, and not the country from which the trader operates.

The draft Rome 1 proposal has since been through a series of amendments, because of significant exposure and opposition in the EU, and now provides for businesses and consumers to be able to choose the law applicable to the contract. However, it could easily have had a serious effect on UK internet traders and small businesses relying on cross border e-commerce for profitability and growth, as well as on consumers who have benefited from the increased choice that free and open internet trade has brought.

Privacy regulations are also taking centre stage. In the wake of the HM Revenue and Customs data loss incident, the European Commission is planning to introduce a security breach notification law, which will force companies to tell customers when their personal data security has been breached.

Such notifications are common in the US, but if made law over here would result in a serious shake-up for data security practices. The importance of adequately securing personal data will become a legal requirement, similar to the regulations imposed on companies processing cardholder data by the PCI Security Standards Council.

On a similar matter of privacy, there is a debate at the moment with the EU questioning whether IP addresses should be considered as personal data.

With the use of dynamic IP addressing systems, IP addresses can change or be given out to another user. However, with the move towards IPv6 it will be even easier to identify an individual by an IP address.

The outcome of this debate will have serious consequences, not just for search engines such as Google, but for European companies, and how they do business with external resources. It is important to stay up-to-date with EU and national laws and their effects on security-related topics such as corporate governance, data protection and privacy.

It is also important to protect your own interests by including security aspects of great importance to the business in supplier negotiations.

This includes client responsibilities, data protection and privacy laws, safe harbour obligations and guidelines. Making security a contractual issue is the right step forward to changing the mentality among non-security professionals that security is desirable, but not essential.

Emma Leith is information security consultant at Comsec and a BCS contributor

Tags: Security, Regulation, Eu, Government

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Bicester, Oxfordshire, United Kingdom | EDS
Position # 398435 Test Manager - EDS - Bicester Must be eligable for security clearance Short Description: EDS's Defence Logistics (DL) testing group tests a range of logistics information systems for the MOD. The Test ... more >
Reading, Berkshire, United Kingdom | EDS
Position - EA Integrator Location - Reading Job Description: A skilled System Integrator to integrate application Test Harnesses to support business requirements. The Candidate will possess specific experience of enterprise systems, component validation and integrating ... more >
Aylesbury, Buckinghamshire, United Kingdom | Grass Roots
SQL Database Administrator - Aylesbury - £DOE Grass Roots are one of the Sunday Times Top 100 companies to work for (2007 and 2008). Established in 1980, we're part of the Grass Roots Group, which is ... more >
London, United Kingdom | City of London
ICT Project Officer - Guildhall, London EC2 18-month fixed-term contract Bring your project management expertise to one of the country's most prestigious institutions. The City of London is the local authority for the Square Mile, ... more >
More job opportunities
Join our fight for a fair deal when shopping online