The ICO have recently issued an enforcement notice to the Alzheimers Society for various breaches of the Data Protection Act. There are 10 issues which the Alzheimers Society has six months to remedy. Although these need to be actioned by the Alzheimers Society, they apply to all businesses processing personal information. So here is the test, how many are you already doing?
1. Information is not kept for longer than necessary. Do you have a process in place to identify information which is no longer necessary and can be destroyed? Do you have a retention policy and a secure method of destroying all information that is no longer required?
2. There is mandatory data protection training for staff (and volunteers) who have access to personal information and refresher training at least every two years.
3. The training that is undertaken is monitored and recorded. You should be able to identify the staff who have attended and what the training course covered.
4. Policies and procedures relating to data protection and information governance are brought to the attention of staff (and volunteers) who have access to personal information. Do you have comprehensive data protection policies and procedures and can you demonstrate that they have been effectively communicated to all those staff (and volunteers) who have access to personal information?
5. Portable and mobile devices including laptops, mobile phones, memory cards and other portable media used to transmit and store personal data, the loss of which could cause damage or distress to individuals are all encrypted using encryption software which meets the current standard or equivalent.
6. Secure email accounts are provided for all staff (and volunteers) who use email to transmit personal information. This means a business account is available for all staff (and volunteers) and they are not using their personal email accounts for business purposes.
7. Secure storage is available for staff (and volunteers) who need to hold hard copy records which contain personal information. Is there lockable filing space for hard copy records?
8. Penetration testing is undertaken on the website on a regular basis and any weaknesses highlighted are remedied.
9. Appropriate security is implemented to protect information from being disclosed to those who do not need to have access to it, this includes to staff members, contractors, visitors and volunteers. This includes passwords, lockable cabinets, encryption, etc.
10.Where processing of personal information is carried out your behalf, for example, by a subcontractor, (IT support, HR, payroll etc) you must have a written contract in place which clearly states that the subcontractor will take steps to protect the information from accidental loss, damage or destruction. The contract should also cover the role of the subcontractor, what they can do with the information, what happens when the information is no longer required and that they will only act on your instructions. You need to make sure that any contract you enter into clearly states the responsibility for data protection.
So what's your score? How many of the above do you need to action to protect the personal information you hold and your company's reputation?
Showing posts with label outsourcing. Show all posts
Showing posts with label outsourcing. Show all posts
Sunday, 7 February 2016
Sunday, 10 January 2016
The top three business security risks - and what to do about them
Businesses have been aware for many years of the very real
threat to their business from security breaches, distributed denial-of-service
(DDoS) attacks and more, but despite warnings from concerned security
professionals about keeping better control over their sensitive data, many
small businesses still aren’t taking security as seriously as they should.
If you have a feeling that this may well be you, what can
you do to up your game when it comes to protecting sensitive data from security
threats? First, you need to look at the most common causes - here’s our top
three.
1: Resentful or disgruntled employees
A disgruntled member of staff can do a lot of damage to your
internal security, especially one that has access to your networks, data
centres and IT admin accounts. However hard you try, you’re not going to be able to
eliminate staff dissatisfaction, so you need to mitigate the risks by
identifying privileged accounts and credentials and deleting any that are
connected to ex-employees who may have an axe to grind. Privileged accounts
should be routinely monitored and there should also be a protocol in place to
track, log and record activity on these accounts so that anything suspicious or
malicious can be quickly spotted and dealt with.
2. Human error & lack of training
An employee who leaves their laptop unlocked and on a train
is just as dangerous as an ex-employee who maliciously breaches your security. If your employees aren’t properly trained in
data security, they also pose a risk. Make sure that your employees are up to date on cyber
security. Hold regular, mandatory training sessions so that they know the risks
of weak passwords, unencrypted or non-password protected portable memory, and
even basics such as not opening suspicious email attachments. It’s vital to drive the point home about passwords; they are
the first line of data defence and so staff members need to know about basic
rules; choosing a password with upper
and lowercase letters, numbers and symbols, keeping separate passwords for different
sites and devices and changing them regularly. Encrypting data is another way of avoiding data breaches
through human error; even if an employee hasn’t locked their phone, you can get
the IT department to wipe any selected data just by revoking decryption keys
specifically used for company data. You can then go a step further and use
authentication methods like a One Time Password (OTP), smart card, fingerprint
reader or even retina scanning if you need an extra layer of security.
3: Unpatched - or Unpatchable - Devices
If you have hardware such as servers, routers or printers
that use software or firmware for which there’s no patch for vulnerability, or
their hardware isn’t designed to enable
them automatic updating if a vulnerability is detected, it leaves you open to
attack. Out of date servers are especially vulnerable; Microsoft no longer
supports Windows Server 2003 and with an estimated 10 million or more Windows
2003 servers still being used, outdated servers are prime targets.
Put a patch management program in place to make sure that
all of your hardware and software is constantly updated. Vulnerability
management technology is available to check your network for anything that’s
out of date, and a policy of taking anything that hasn’t been updated for a
long time offline will also minimise the risk.
Do you know where your business is vulnerable? If you need
advice on procedures and policies that keep your sensitive data safe, or want
to know more about staff training, contact me and I will be delighted to
provide you with guidance and advice.
Wednesday, 24 June 2015
How good is your mailing company?
Just had an interesting phone call with a company about their spam emails. This company has emailed me about one of their "special offers", needless to say I never signed up to receive said offers. When I rang to ask to be removed from the mailing list, the person answering the phone said they had received lots of complaints about the emails. Apparently I have been lucky because I only have two emails, some of the people they have been emailing have been receiving 2 an hour for days! According to the company, they outsourced their email marketing to a company in China and they haven't been following the instructions they were given. A number of people who have been getting the emails have been complaining to the ICO.

So where has this company gone wrong (this is my speculation based on the phone call).
1. Breach 1 - I never gave them permission to email market to me. Never heard of them before the email came through so definitely didn't sign up. You need to have a persons permission to be able to electronically market to them. You should also record where the sign up information was gathered. Lots of people don't remember signing up and the ICO, if they investigate, will look for confirmation you have permission.
2. Breach 2 - The emails did not have an unsubscribe option on the bottom, so gave me no choice but to call to cancel it. Given the person didn't take my email address, I expect more emails from them in the future. There is certain criteria that has to be met when email marketing, one of which is that there is the ability to unsubscribe from future contact. It is an offence to fail to remove someone from your mailing list when they ask.
3. Potential Breach 3 - IF I had given them permission for email marketing, did they also ask my permission to send my details outside of the EEA (to their marketing company in China), probably not. If you are sharing personal information outside the EEA, you have to tell the provider of the information at the time of collection.
4. Potential Breach 4 - Sending the information to China, which is not an approved country, the company needed a specific clause in place to protect individuals information. As China is not an approved country for data transfers, they company needed a specific clause and contract in place. Seems unlikely in this case that they complied. https://ico.org.uk/for-organisations/guide-to-data-protection/principle-8-international/
Needless to say this company is already getting attention from the ICO regarding the level of complaints. If you need help to avoid a similar situation, contact me to discuss how we can help. ask@audit-and-risk.co.uk

So where has this company gone wrong (this is my speculation based on the phone call).
1. Breach 1 - I never gave them permission to email market to me. Never heard of them before the email came through so definitely didn't sign up. You need to have a persons permission to be able to electronically market to them. You should also record where the sign up information was gathered. Lots of people don't remember signing up and the ICO, if they investigate, will look for confirmation you have permission.
2. Breach 2 - The emails did not have an unsubscribe option on the bottom, so gave me no choice but to call to cancel it. Given the person didn't take my email address, I expect more emails from them in the future. There is certain criteria that has to be met when email marketing, one of which is that there is the ability to unsubscribe from future contact. It is an offence to fail to remove someone from your mailing list when they ask.
3. Potential Breach 3 - IF I had given them permission for email marketing, did they also ask my permission to send my details outside of the EEA (to their marketing company in China), probably not. If you are sharing personal information outside the EEA, you have to tell the provider of the information at the time of collection.
4. Potential Breach 4 - Sending the information to China, which is not an approved country, the company needed a specific clause in place to protect individuals information. As China is not an approved country for data transfers, they company needed a specific clause and contract in place. Seems unlikely in this case that they complied. https://ico.org.uk/for-organisations/guide-to-data-protection/principle-8-international/
Needless to say this company is already getting attention from the ICO regarding the level of complaints. If you need help to avoid a similar situation, contact me to discuss how we can help. ask@audit-and-risk.co.uk
Labels:
Charity.,
China,
Company,
Data Protection,
email,
outsourcing,
PECR,
spam
Subscribe to:
Posts (Atom)
