There have been a number of high profile data breaches by members of staff in organisations.
From the disgruntled Morrison's employee who leaked the salaries of staff onto the internet and was subsequently jailed for 8 years to the Tesco employee who was emailing details of customers to his personal email account and the Enterprise car rental employee who was selling customer information to a claims company, the main weaknesses in most organisations are the staff.
So what do you do about it? The cases shown above have been high profile and widely reported but organisations are probably suffering breaches on a regular basis and may not even be aware of them. We get used to what we see and do and so often we forgot to stand back and view the situation with fresh eyes.
When I start to work with organisations, I am that fresh pair of eyes. I often also represent your clients. Are you collecting information to help you communicate effectively with them? We can easily identify the areas in your business where there is potential for losing your business information.
If you want to find out more, we offer a free initial consultation so you can see how we would work with you. Contact us today to book a meeting.
Showing posts with label DPA. Show all posts
Showing posts with label DPA. Show all posts
Sunday, 3 April 2016
Monday, 4 January 2016
Thinking of selling your email list? - think again
I have had an enquiry this week from a business owner who has been approached to sell their email list. Sounds simple doesn't it?
It is simple if you have collected the information in the right way and sought permission to share the information with other companies. If you haven't it can be a costly mistake to make, as Pharmacy2U found out. Pharmacy2U was fined £130,000 for selling its mailing list and other details without having the correct permissions to do so. A sobering and costly exercise.
So how do you know if you can sell your list? Broadly, when you collected the information, did you ask the subscriber whether they would be happy to have their information passed to a third party? If you didn't, then you shouldn't be selling the information. If you did and they agreed to the information being shared, then you can. I would suggest that you get a professional Data Protection Officer to review how the information was collected before you go through with the sale just to be sure that you have the correct permissions. You wouldn't want a request for £130,000 dropping through the letterbox.
If you need to discuss how you are collecting information, please contact me.
It is simple if you have collected the information in the right way and sought permission to share the information with other companies. If you haven't it can be a costly mistake to make, as Pharmacy2U found out. Pharmacy2U was fined £130,000 for selling its mailing list and other details without having the correct permissions to do so. A sobering and costly exercise.
So how do you know if you can sell your list? Broadly, when you collected the information, did you ask the subscriber whether they would be happy to have their information passed to a third party? If you didn't, then you shouldn't be selling the information. If you did and they agreed to the information being shared, then you can. I would suggest that you get a professional Data Protection Officer to review how the information was collected before you go through with the sale just to be sure that you have the correct permissions. You wouldn't want a request for £130,000 dropping through the letterbox.
If you need to discuss how you are collecting information, please contact me.
Sunday, 20 December 2015
Data loss - the obvious ways your business can avoid it
The top reasons cited for data loss from small businesses
aren’t international hacking or grand scale cybercrime - they are obvious, easily rectified things that
would have been avoidable with a little advance attention to detail, proper
training and a staff data security policy.
According to surveys, a staggering more than 78 per cent of
organisations worldwide report that they have suffered from one or more data
breaches in just the last two years. If you want to avoid your business being
affected by careless data loss, you need to make sure that all employees -
including you - are fully aware of the risks.
Surprisingly, one of the top reasons businesses lose data is
that many employees (and their managers) still don’t understand the importance
of not opening unexpected or suspicious attachments or clicking links embedded
in spam emails. Other basic measures such as leaving systems unattended,
visiting restricted websites and not changing passwords regularly also led to critical
business data becoming at risk from data-stealing cybercriminals and malicious
insiders.
It’s estimated that cyber criminals steal as much as US$1
billion a year from SMEs in the US and Europe. This is partly down to
inadequate or poorly enforced data security policies, leaving companies at a
risk of losing vital and sensitive data, as well as costing money through lost
productivity, revenue and of course, if the breach becomes public, the business
reputation too.
Working from home and being able to take work out of the
office makes working life easier but can be a nightmare for data security. With
an estimated 56 per cent of employees reporting that they either very
frequently or frequently stored sensitive data on their laptops, smartphones,
tablets, and other mobile devices, the chances of confidential information
getting lost or into the wrong hands are very high. Protecting data on mobile
devices can be as simple as encrypting it and/or password protecting it - it
won’t stop the devices being lost but IT admin will be able to selectively
remove sensitive encrypted data and the chances of someone using it maliciously
are much smaller if it’s not possible to get straight into any files that may
be sensitive.
Do you back up your data on a regular basis or just when you
remember? Regular backups are a vitally important part of a good data security
policy, so make it a regular daily, weekly or at least regular task. Automate
it if possible so that it doesn’t get missed. Without an automated backup and
recovery strategy in place, your business may well be devastated if the worst
happens, and if you want to avoid unnecessary downtime, loss of revenue and
more in the event of a serious incident, you need a contingency plan in place
at all times.
Lastly - even if you have a top notch data security policy,
it’s of no use unless you enforce it.
If you need advice on up to date data security procedures
and policies that keep your sensitive data safe, or want to know more about
staff training, contact me and I will be delighted to provide you with guidance
and advice.
Sunday, 14 June 2015
Paper Forms - Do you have the basics in place?
It's been a busy week and whilst I have been out and about I have needed to complete some forms. I completed three different forms and not one of them met the requirements of the Data Protection Act with regard to collection notices.
Most of the forms were collecting basic details - the usual - name, address, DOB. The forms were being used by a health professional, charity and college.
So what did I learn this week. Ultimately most of the organisations who collected information about me did not even meet the basic requirements of a collection notice on the form. A collection notice tells the person providing the information what their information will be used for, how it will be stored and for how long and if it is going to be shared with anyone. I have asked each of the organisations for whom I have completed a form what they intend to use my information for. It is worrying that if an organisation cannot even collect the information properly, how are they storing it and who has access to it. Given the significant rise in identify theft, I have provided enough information for this to happen.
Remember that regardless of whether you are registered with the ICO you have to comply with the Data Protection Act so any forms that you use for the collection of information MUST have a data collection notice on it. Without a valid collection notice you are breaking the law!
If you need help to produce a collection notice or require a review of your forms, please contact me.
Most of the forms were collecting basic details - the usual - name, address, DOB. The forms were being used by a health professional, charity and college. So what did I learn this week. Ultimately most of the organisations who collected information about me did not even meet the basic requirements of a collection notice on the form. A collection notice tells the person providing the information what their information will be used for, how it will be stored and for how long and if it is going to be shared with anyone. I have asked each of the organisations for whom I have completed a form what they intend to use my information for. It is worrying that if an organisation cannot even collect the information properly, how are they storing it and who has access to it. Given the significant rise in identify theft, I have provided enough information for this to happen.
Remember that regardless of whether you are registered with the ICO you have to comply with the Data Protection Act so any forms that you use for the collection of information MUST have a data collection notice on it. Without a valid collection notice you are breaking the law!
If you need help to produce a collection notice or require a review of your forms, please contact me.
Subscribe to:
Posts (Atom)