What's Up Docs?
A Google spokesperson has told ThisWeekinFM: “We realise people are concerned about their Google accounts and we're now able to give a fuller explanation after...
Read Full ArticleIn a statement of intent (made on Monday 7), the government has committed to updating and strengthening data protection laws through a new Data Protection Bill.
The data protection regulator, the Information Commissioner’s Office (ICO), will also be given more power to defend consumer interests and issue higher fines, of up to £17 million or 4 per cent of global turnover, in cases of the most serious data breaches.
Matt Hancock, Minister of State for Digital said: Our measures are designed to support businesses in their use of data and give consumers the confidence that their data is protected and those who misuse it will be held to account.
"The new Data Protection Bill will give us one of the most robust, yet dynamic, set of data laws in the world. The Bill will give people more control over their data, require more consent for its use. We have some of the best data science in the world and this new law will help it to thrive."
Clearer rules
Data protection rules will also be made clearer for those who handle data but they will be made more accountable for the data they process with the priority on personal privacy rights. Those organisations carrying out high-risk data processing will be obliged to carry out impact assessments to understand the risks involved.
The Bill will bring the European Union’s General Data Protection Regulation (GDPR) into UK law, helping Britain prepare for a successful Brexit.
At a personal level
Research shows that more than 80 per cent of people feel that they do not have complete control over their data online.
Under the Bill, individuals will have more control over their data by having the right to be forgotten and ask for their personal data to be erased. This will also mean that people can ask social media channels to delete information they posted in their childhood. The reliance on default opt-out or pre-selected ‘tick boxes’, which are largely ignored, to give consent for organisations to collect personal data will also become a thing of the past.
The Data Protection Bill will:
New criminal offences will be created to deter organisations from either intentionally or recklessly creating situations where someone could be identified from anonymised data.
Elizabeth Denham, Information Commissioner, said: “We are pleased the government recognises the importance of data protection, its central role in increasing trust and confidence in the digital economy and the benefits the enhanced protections will bring to the public.”
Julian David, CEO of techUK, said: “This statement of intent is an important and welcome first step in that process. techUK supports the aim of a Data Protection Bill that implements GDPR in full, puts the UK in a strong position to secure unhindered data flows once it has left the EU, and gives businesses the clarity they need about their new obligations."
Network and Information Systems
The Network and Information Systems directive (which the UK and all EU members have 21 months to bring in to national laws) is likely to be incorporated in to the Bill (or as an adjunct).
The Directive requires:
Justin Coker, Vice President EMEA at Skybox Security comments: “A UK consultation is welcome on NIS because, to comply, many organisations will need to review their own systems to keep pace with its requirements. The government is saying severe fines will be levied unless an organisation can prove it assessed the risks adequately. But, too often there is no visibility of where the threats and vulnerabilities are. The attack surface is now more complex than ever, so organisations need to move away from traditional thinking and develop a clear picture of the long-term security goals and plan the security program in a structured and logical way.
“Protecting and securing critical digital national infrastructure presents a real challenge because end-to-end access analysis must be done across hybrid IT and Operational Technology networks. To do this, organisations must obtain accurate visibility of the assets, security controls, policies and any potential vulnerabilities – the attack surface. They need to know when their security has been compromised and redress attack vectors before they can be exploited.”
Picture: The government is to strengthen UK data protection law and thus bring the European Union’s General Data Protection Regulation in to British Law
Article written by Cathryn Ellis | Published 09 August 2017
A Google spokesperson has told ThisWeekinFM: “We realise people are concerned about their Google accounts and we're now able to give a fuller explanation after...
Read Full ArticleConnected toys with Bluetooth, wi-fi and mobile apps may seem like the perfect gift for Christmas. But Which? has found that, without appropriate safety...
Read Full ArticleYahoo has announced (week ending Oct 6) that it is providing notice to additional user accounts affected by an August 2013 data theft previously disclosed by the company...
Read Full ArticleRelying on 'auto-fill' to complete the login process for websites as well as storing bank card details to shopping sites such as eBay and Amazon can make for...
Read Full ArticleThe UK public has been left feeling vulnerable following an increase in highly personalised cybercrimes according to Get Safe Online, the joint public private internet...
Read Full ArticleThe UK's national Crime Agency (NCA) yesterday announced a two week opportunity to reduce a threat from a powerful new computer attack. It urged businesses and...
Read Full ArticleOn November 29, the Federal Bureau of Investigation, in close cooperation with the Luneburg Central Criminal Investigation Inspectorate in Germany, Europol’s...
Read Full ArticleThursday evening, November 30, McDonalds Restaurants discovered the hard way that a relationship with a contractor - in this case, employing cheap, untrained security...
Read Full ArticleIn an unprecedented move, the National Cyber Security Centre has commented specifically on the Uber data breach - with a coded reference to the fact that Uber tried to...
Read Full ArticleThe Government will soon be introducing its new Data Protection Bill to Parliament. With this almost certain to come into effect next May, implementing the General Data...
Read Full Article