Computing comment logo
Data privacy is perhaps the biggest single challenge facing the technology industry
R E L A T E D   C O N T E N T
ADVERTISEMENT

Time we stopped passing the buck

All employees must realise the value of personal data and stick rigidly to data-protection rules

Computing, Computing 08 May 2008
ADVERTISEMENT

The realisation is growing that data protection is not somebody else’s responsibility.

Moves to make individuals liable for the loss or disclosure of personal information held by public sector bodies or by companies are an inevitable response to the data loss scandals we have seen in recent months.

Until now, the Data Protection Act has focused responsibility on senior executives of an organisation, who are held to task for failures of staff under their charge. But the reality is that those workers are rarely motivated by the need to protect their bosses or their employer’s reputation.

When someone else takes the blame, why should you care if you make a mistake?

The most common concern of IT leaders looking to introduce data protection or risk management policies is how to create a culture that supports the rules and regulations put in place. Having a policy is one thing ­ making staff buy into it can be quite another. Ultimately, a culture exists only in the collective hearts and minds of a group of individuals, it cannot be imposed from above or through a set of rules.

From a government perspective then, legislation appears to be the only answer.

But no law will be effective ­ other than in increasing the prison population ­ without education to go alongside it.

Data privacy is perhaps the biggest single challenge facing the technology industry. Information security is not the issue ­ technical controls exist to secure the vast volumes of electronic data being generated ­ but the access to, and authorisation of the use of that data is about people, not technology.

For every government employee who inappropriately accesses citizen records (see www.computing.co.uk/2215705), how many would protest if someone did the same to their personal details?

People need to realise the impact on others of their actions, and to be given training and advice to ensure they are aware of their responsibilities. The best way to do that is to ask the question: What if it were you?

Tags: Government, Regulation, Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Sutton, Surrey, United Kingdom | Royal Marsden Hospital NHS Trust
  The Royal Marsden NHS Foundation Trust is a centre of excellence for research, development, education and care in the treatment of cancer. Analyst Programmers, Band 6, £23,458-£31,779 plus 15% HCAS, Sutton, Surrey We are ... more >
Chichester, United Kingdom | West Sussex County Council
  Principal Application Specialist - Application Developer, Chichester, £42,100 - £44,700 (includes Market Rate Supplement) IT Services at WSCC supports and manages a variety of systems based on Oracle databases that include third party and ... more >
Maidstone, United Kingdom | Kent Police
  Forensic Computer Analyst - Police Headquarters, Maidstone, £27,891 - £38,476 Permanent Contract Digital devices and information communication technology are present in almost every investigation the police service undertakes. Kent Police Digital Forensics Unit is ... more >
United Kingdom | Data Transparency
.NET Software Developer,  £20,000 - £35,000 depending on experience About us Data Transparency is a small, rapidly growing company established in 2006 by an Oxford graduate. We create bespoke web-based data systems that are used in ... more >
More job opportunities