Showing posts with label GDPR. Show all posts
Showing posts with label GDPR. Show all posts

Thursday, 6 October 2016

Yahoo: Directors liability for cyber breach : IP protection in the Digital Age

With only 20 months until the implementation of the GDPR large organisations such as Barclays have already put big teams and resources in place to meet the new requirements. With breach fines up to 4% of turnover and the requirements to maintain a personal data inventory and report breaches within 72 hours this will be a big challenge for the SME and Mid Size community. The requirements of explicit consent for processing sensitive personal data (likely to include video and voice) and a linked right to be forgotten will require significant resource commitment and expertise.

TalkTalk were fined a record £400,000 yesterday by the ICO for a very poor level of cyber security which is close to the maximum under current UK legislation. This is a wake up call for businesses handling personal data in the UK as fines will be much higher under the new regime. Dido Harding may be regretting that she did not obtain an independent view of her cyber safety levels and allowed her IT team to mark their own homework.

The Yahoo hack has made the news but most of the focus has been around its scale in terms of numbers of email addresses. The class action suit available HERE  alleges under Count V Negligence. The specific wording is "Defendant owed a duty to Plaintiffs and the other class members to exercise reasonable care in safeguarding and protecting their PI and financial information in its possession from being compromised, lost, stolen, misused, and/or disclosed to unauthorised parties".

Further in the suit it is suggested that that the identity thieves may wait for years to use the information gained and that therefore class members will need to be vigilant for years or decades to come.

The combination of negligence and the potential for decades of required monitoring points to a potentially huge damages number. This could be the end of the road for Yahoo and open the way for personal negligence claims against Directors in this area.


Taken together the regulatory regime in terms of personal data is significantly tightening up and the associated risk level is beginning to become clear. 

Wednesday, 16 December 2015

EU starts to get to grips with the Digital Age - new data protection rules text agreed

Despite a lot of lobbying activity from "big data" the EU has managed to agree the text of a new data protection framework with new rules to come into force in 2018.

The previous directive was established in 1995 which is now a world away in terms of technology and data storage.

The key difference is that companies can be fined up to 4% of turnover for failing to comply and in particular for failing to keep personal data safe.

The chain of liability also extends beyond the data controller to any data processors and third parties involved. The significance of the latest hacks would be much greater and more financially punitive for those attacked and their suppliers if they had failed to adequately protect data.

Other elements are the right to be forgotten (or erasure), the need for a data protection officer, the requirement to report breaches, parental consent for 13-16 year olds to use social media, a single supervisory authority and some rights regarding portability of content.

No doubt much will be lost in translation into local legislation and if the UK votes to exit the EU this will be rather irrelevant.

However hats off to MEP Jan Philipp Albrecht for guiding this through the European Parliament. It is far from perfect but does seem a reasonable attempt to bring legislation up to date with the Digital Age and force companies who harvest our data to take reasonable steps to protect it.