iTnews
  • Home
  • News
  • Technology
  • Security

How the UK got data breach notification over the line

By Andrew Colley on Nov 26, 2013 6:54AM
How the UK got data breach notification over the line

Australian adoption remains uncertain.

UK organisations took privacy more seriously after the country's Information Commissioner's Office made data breach notification "best practice", according to former commissioner Richard Thomas CBE.

Thomas, who was information commissioner between 2002 and 2009, told iTnews that the British regulator took the step after several embarrassing, high profile government and bank breaches in 2007.

Making senior executives of banks personally responsible for enforceable undertakings after breaches also inspired the UK business community to change its attitude to data protection, he added.

"I insisted that the undertakings be signed by the chief executives of the banks personally. I have no doubt that really raised the profile of the issue inside the banks. From that point on they took it more seriously. Other financial services and commercial operations took it more seriously the same way that government was taking it more seriously," he said.

"There are still too many lapses. It's by no means perfect, although it has got better."

During Thomas's tenure, the UK information commissioner had no powers to impose fines for breaching privacy laws.

In addition, the ability to use enforcement orders against organisations was only a theoretical possibility that has never been tested.

However, the commissioner could resort to audits and name-and-shame measures, he said.

"We made it clear that if we had discovered a breach and that we hadn't been told about it then we would take it more seriously," Mr Thomas said.

Australian uncertainty

Thomas' comments come amid uncertainty over whether Australia's new federal government will proceed with the former Labor government's plan to pass laws forcing organisations to notify regulators and the public of serious data breaches.

The legislation was among a handful of bills that failed to pass the Senate before parliament was prorogued in June.

Yesterday, long-time champion of the mandatory notification bill, Australian federal Privacy Commissioner Timothy Pilgrim, declined to reveal whether he had discussed the bill with federal Attorney-General George Brandis.

Arguably, Australia's privacy commissioner is in a good position to adopt the UK practice of recommending that organisations notify the regulator of data breaches rather than making it law.

From March next year the Australian privacy commissioner will have the power to impose hefty financial penalties on organisations for serious and repeated breaches. Compliance with the UK commission's best practice recommendation became riskier for organisations after it was given powers to impose fines.

"I think you would either be a very brave or foolish organisation to notify now," Thomas said.

In the last two to three years of Thomas's tenure the UK commission received 515 voluntary notifications. He estimates that since then it has received about 1500 voluntary notices.

However, Thomas said he was sceptical of laws requiring notices to individual consumers. His view, he said, had been coloured by the experience of North American privacy regulators.

"People just get bored by it, almost. They don't understand its relevance to them personally and they're not sure what they're supposed to do about it so I've always thought that the value of notification was to regulators.

"The top priority is to stop the breach. When I was commissioner we put out a lot of advice on our web site as to what you should be doing".

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
australiabreachdatalawsnotificationsecurityuk

Partner Content

Accenture and Google Cloud team up to create a loveable, Australian-first, renewable energy product
Promoted Content Accenture and Google Cloud team up to create a loveable, Australian-first, renewable energy product
Security: Understanding the fundamentals of governance, risk & compliance
Promoted Content Security: Understanding the fundamentals of governance, risk & compliance
How to turn digital complexity into competitive advantage
Promoted Content How to turn digital complexity into competitive advantage
Why Genworth Australia embraced low-code software development
Promoted Content Why Genworth Australia embraced low-code software development

Sponsored Whitepapers

Extracting the value of data using Unified Observability
Extracting the value of data using Unified Observability
Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see
Beyond FTP: Securing and Managing File Transfers
Beyond FTP: Securing and Managing File Transfers
NextGen Security Operations: A Roadmap for the Future
NextGen Security Operations: A Roadmap for the Future
Video: Watch Juniper talk about its Aston Martin partnership
Video: Watch Juniper talk about its Aston Martin partnership

Events

  • Micro Focus Information Management & Governance (IM&G) Forum 2022
  • CRN Channel Meets: CyberSecurity Live Event
  • IoT Insights: Secure By Design for manufacturing
  • Cyber Security for Government Summit
By Andrew Colley
Nov 26 2013
6:54AM
0 Comments

Related Articles

  • Qld gov proposes mandatory data breach reporting for agencies
  • Law firm mulls class action over NDIS software provider data breach
  • NDIS case management system provider breached
  • India mandates data breach notification within six hours
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Qantas calls time on IBM, Fujitsu in tech modernisation

Qantas calls time on IBM, Fujitsu in tech modernisation

Service NSW hits digital services goal two years early

Service NSW hits digital services goal two years early

NBN Co taking orders for 'non-premises' connections

NBN Co taking orders for 'non-premises' connections

NSW Police scores $100m to connect body-cams to firearms, tasers

NSW Police scores $100m to connect body-cams to firearms, tasers

Digital Nation

The security threat of quantum computing
The security threat of quantum computing
IBM global chief data officer on the rise of the number crunchers
IBM global chief data officer on the rise of the number crunchers
COVER STORY: Operationalising net zero through the power of IoT
COVER STORY: Operationalising net zero through the power of IoT
Crypto experts optimistic about future of Bitcoin: Block
Crypto experts optimistic about future of Bitcoin: Block
Integrity, ethics and board decisions in the digital age
Integrity, ethics and board decisions in the digital age
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.