Firms 'aware of data breach consequences'
Category: Data security
24 September, 2008
Businesses in the UK are becoming more aware of the importance of
data security because of a combination of damaged reputation, financial penalties and the concern of breaking the
Data Protection Act, a report claims.
And like the government often uses private firms to handle its data, companies which decide to outsource this job should make clear the responsibility involved in a services contract, Phil Sherrell and Vinod Bange from the technology team at international law firm Eversheds tell computerweekly.com.
Security measures should be identified and achievable, basic controls need to be in place if a
data security breach does occur and the parties should work together to ensure there is no further damage, the pair advise.
Data compliance training should be provided for staff who handle consumer details, the expert claims.
"This is particularly important where a third-party supplier is handling the data of individuals on behalf of different customers, who may have different policies and needs," the lawyers warn.
PA Consulting, which handled and lost data of prisoners and other offenders, lost its contract with the Home Office after a memory stick was misplaced.