Showing posts with label encryption. Show all posts
Showing posts with label encryption. Show all posts

Thursday, March 11, 2010

Big Fines Coming in UK for Data Breaches

By Susan Foster, Mintz Levin London

As of April 6, 2010, the UK’s Information Commissioner’s Office (ICO) can levy fines of up to £500,000 for breaches of the Data Protection Act 1998 that are:
• serious in nature
• deliberate or reckless, and
• likely to cause substantial damage or distress to an individual.

The standard for “reckless” non-compliance may take some by surprise: Did the data controller know, or should it have known, that there was a risk of a breach of a kind likely to cause substantial damage or distress? If so, were reasonable steps were taken to prevent the breach?

The ICO has given a specific example that may make IT and privacy officers flinch, but will come as no surprise to those in the U.S. who have been dealing with the likes of Massachusetts 201 CMR 17.00 or the HITECH Act: Does the company have appropriate policies and procedures in place such as the encryption of all laptops and removable media (such as flash drives) to avoid loss of personal data if an employee’s laptop or removable media is stolen? Failing to do so might be considered “reckless” depending on the likely consequences of the loss of personal data contained in the unsecured devices.

Further Information
For more information, see our our Mintz Levin Client Alert. Also, the ICO has published detailed guidance concerning when fines will be issued, the process for trying to get fines withdrawn or reduced, how to appeal, and payment.

Friday, August 21, 2009

Changes to the Massachusetts Data Security Regulations: What do they really mean?

Now that the dust has settled after this week’s “Breaking News” regarding the proposed changes to the Massachusetts data security regulations, here is an analysis of what the changes actually mean to the business community.

Some other interesting commentary is linked below:

Evan Schuman - Storefront Backtalk

Friday, August 14, 2009

To Encrypt or Not To Encrypt…….An Incentive Rather than a Mandate From Michigan

Add Michigan to the list of states that are proposing that adoption of comprehensive data security safeguards will provide a safe harbor for data breaches.

The Information Security Program Standards Act introduced last week differs a bit from Massachusetts and Nevada (and other pending legislation) in that it would not require the implementation of detailed security measures --- the Michigan act provides a carrot to those who do: Breach liability immunity.