Pressure builds for one rule for all
By Nick Heath
Published: 28 October 2008 12:26 GMT
Banks, other businesses and authorities could soon be forced to confess to data breaches according to the EU privacy tsar.
European data protection supervisor Peter Hustinx said there is growing pressure within the European Parliament to create a data breach notification law as part of a shake-up of privacy law.
Amendments to the EU ePrivacy Directive are currently being debated by the EU Parliament and are expected to be passed in six months' time.
These amendments would force ISPs and telecoms companies to notify customers and authorities when they lose their customers' personal data.
And speaking at the RSA Conference in London, Hustinx said there are increasing demands from the European Parliament for the amendments to require all companies and public sector organisations with an online presence to also come under the law.
Hustinx said: "I would be very much in favour of making data security breach an element of general data protection arrangements.
"It doesn't make sense to exclude an internet banking site, a hospital with a web site or other businesses collecting sensitive data online, and just to impose it only on the telcos and the ISP."
Hustinx went on to say that the powers of the UK Information Commissioner's Office (ICO) were lagging behind equivalents in the rest of Europe and welcomed consultations to give the ICO more powers.
He said: "Inspection and sanction powers are rather weak in the UK compared to other countries in the EU.
"But [information commissioner] Richard Thomas being given more powers is looking more probable."
But Hustinx added "there is no reason to presume that the UK is worse than other countries".
MoD breach: Data goes missing from "secure location"
Security expert slams Home Office data-sharing guide
Lost data total nears 30 million records
Is short-termism holding back public sector outsourcing?
Prisoner data breach firm paid £100m
Home Office loses data on 84,000 prisoners
Key Words: Data Privacy, Data Protection, Banking, Law, Consultancy (Orgtel Limited acts as an Employment A Data Privacy expert is required for a ...
The purpose of the role is to develop strategy, policy and guidance to promote and develop 'best practice' as defined by the Information Governance ...
These include Project Managers, technical authorities and developers. Your details will be stored on our database in the strictest of confidence with ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Nick Heath
Let's shine a light into the public sector IT money pit
With £16bn being spent, why is productivity still falling?
Tim Ferguson
BBC is taking tech seriously, so give it a break!
Auntie is the envy of the world but doesn't get the credit it deserves at home...
Peter Cochrane
Peter Cochrane's Blog: Open info for all?
Government stonewalling citizens
Nick Heath
Home Office CIO on taming tech and why ID cards are good news
Interview: Annette Vernon, Home Office CIO
Nick Heath
NHS records, Google and Microsoft: Where do you want your data?
Politicians: Heal thyself
Alan Hunt
NHS network: Time to get secure
Patient data in need of a check up