Showing posts with label data protection. Show all posts
Showing posts with label data protection. Show all posts
Friday, 16 September 2016
Amazon Echo raises the stakes on privacy in the home and IP protection in the digital age.
Is it safe or is there a storm coming over the horizon ? Difficult to tell. Great excitement about the new Amazon Echo (new to the UK) which is a voice activated networked microphone and speaker which allows interaction with the web via voice command. It is intended to sit in the home and answer questions, play selected music, adjust smart devices in the home order things online etc.
It works by constantly monitoring sounds in the home and responding to its name Alexa. However in order to recognise the word Alexa it needs to listen to everything and the microphones are so good that it can listen across the room and filter our loud music.
The convenience is very appealing but the loss of privacy substantial. Who owns the data that is collected by Alexa and the profiling that results from that data ? Who will carry the liability if that data is misplaced or stolen or for example voice activated financial transactions are carried out by the wrong people ?
A company with the scale of Amazon will have worked through these issues no doubt but the significance of networked always on audio monitoring in the home may not fully register with a technology enthusiast simply looking for an easier way to stream music in the home.
Thursday, 8 September 2016
There is no data cloud, only somebody else's computer
Perhaps because digital data has negligible physical presence we often struggle to view it as property.
If we stored our valuable physical possessions in a facility with no security people would think we were crazy and possibly partly to blame if our stuff went walkabout.
The penny is starting to drop however that remote digital storage of our valuable digital IP needs to be evaluated in respect of its security and that contracts need to deal with the sticky subject of liability in the event of data breach or loss. This is particularly the case when the IT company who are in theory holding your data are in fact outsourcing it to another third party. It seems likely that aside from contractual terms the tort of negligence may have a part to play here when the basic requirements of cyber security have been ignored by those handling personal data.
If we stored our valuable physical possessions in a facility with no security people would think we were crazy and possibly partly to blame if our stuff went walkabout.
The penny is starting to drop however that remote digital storage of our valuable digital IP needs to be evaluated in respect of its security and that contracts need to deal with the sticky subject of liability in the event of data breach or loss. This is particularly the case when the IT company who are in theory holding your data are in fact outsourcing it to another third party. It seems likely that aside from contractual terms the tort of negligence may have a part to play here when the basic requirements of cyber security have been ignored by those handling personal data.
Tuesday, 30 August 2016
Kim Dotcom LIVE
Kim Dotcom has been successful in insisting that his current trial can be viewed live on YouTube.
DotCom seems pleased with this outcome as he insists that when people realise the basis of the case against him they will support him.
He insists that MegaUpload was blindly storing copyright infringing material and as such should not be held responsible. In the same way that a man who makes or sells a knife or a car is not held responsible if that object is later used to break the law.
The analogy breaks down a bit as the servers remained under the control of MegaUpload whereas the other objects mentioned do not - but that is for another day.
However, when this case is settled we will be one step closer to understanding where liability rests online and the degree of responsibility a hosting company, or third party provider, must take. This is also relevant for data protection and the GDPR.
Hold onto your hats - this is showtime !
DotCom seems pleased with this outcome as he insists that when people realise the basis of the case against him they will support him.
He insists that MegaUpload was blindly storing copyright infringing material and as such should not be held responsible. In the same way that a man who makes or sells a knife or a car is not held responsible if that object is later used to break the law.
The analogy breaks down a bit as the servers remained under the control of MegaUpload whereas the other objects mentioned do not - but that is for another day.
However, when this case is settled we will be one step closer to understanding where liability rests online and the degree of responsibility a hosting company, or third party provider, must take. This is also relevant for data protection and the GDPR.
Hold onto your hats - this is showtime !
Thursday, 17 December 2015
The liability aspect of handling personal data - 4% of turnover
It seems that Europe has had enough of companies processing personal data without appropriate consideration and safeguards in place.Earlier this week wording was agreed for new data protection legislation which is expected to come into force in 2 years.
Key wording is that personal data must be "processed in a way that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures".
The agreed wording identifies the types of issues that companies might consider to meet this threshold;
1. Pseudonymisation / encryption of personal data
2. Ability to ensure ongoing confidentiality, integrity, availability and resilience
3. Data restoration post breach
4. Regular testing
The bottom line is that the profitability of data processing will drop as the costs of maintaining a secure digital environment are material and most businesses will face additional compliance costs. As a minimum companies who process personal data will require either in house or as a contractor an individual who can assess digital security risks sensibly and address problems (a data protection officer).
Amusingly the governments have secured broad exceptions to these rules even though they tend to make the greatest howlers in this area - see Edward Snowden.
On that note a clip from Catch 22...............
Wednesday, 16 December 2015
EU starts to get to grips with the Digital Age - new data protection rules text agreed
Despite a lot of lobbying activity from "big data" the EU has managed to agree the text of a new data protection framework with new rules to come into force in 2018.The previous directive was established in 1995 which is now a world away in terms of technology and data storage.
The key difference is that companies can be fined up to 4% of turnover for failing to comply and in particular for failing to keep personal data safe.
The chain of liability also extends beyond the data controller to any data processors and third parties involved. The significance of the latest hacks would be much greater and more financially punitive for those attacked and their suppliers if they had failed to adequately protect data.
Other elements are the right to be forgotten (or erasure), the need for a data protection officer, the requirement to report breaches, parental consent for 13-16 year olds to use social media, a single supervisory authority and some rights regarding portability of content.
No doubt much will be lost in translation into local legislation and if the UK votes to exit the EU this will be rather irrelevant.
However hats off to MEP Jan Philipp Albrecht for guiding this through the European Parliament. It is far from perfect but does seem a reasonable attempt to bring legislation up to date with the Digital Age and force companies who harvest our data to take reasonable steps to protect it.
Thursday, 3 December 2015
Proposed EU Data Protection regulations grow some serious teeth in the Digital Age
It is amazing what people will do to get noticed as this young lady in Thailand demonstrates. At the other end of the scale the smooth law makers within the EU gently slide obligations towards us almost unnoticed.The Digital Single Market and the associated Data Protection regulations are scheduled to come into force in December 2017 and bring with them a very different regime for managing personal data. Within the UK the Data Protection Act 1998 requires six core principles to be followed. One of these principles is that personal data is kept safe and secure.
The maximum fine under the DPA is £500,000 and therefore while this is a substantial sum it is possibly less than the cost of required data security for a large organisation such as Talk Talk (just for example).
Under the proposed new regime fines can be between 2% and 5% of turnover up to a maximum of £100 million. Using Talk Talk as an example with a turnover of £1.8 billion the maximum theoretical liability would be £90 million. Possibly worth addressing the SQL injection issues then ?
The guiding principle under the proposed new regime looks to be that companies or individuals handling personal data (which is pretty much anything) need to meet "reasonable expectations of data privacy" and liability follows if they do not.
The suggestion is made that encryption is one potential way to meet this requirement but this is not a given. If an encryption system is found to be flawed or have a back door it presumably does not meet this threshold ? Implementing one encryption system is tricky enough but having to change systems in a hurry is breakdown material if encryption is cracked.
Another aspect to the proposed legislation is the right to erasure. This immediately brings to mind the popular club music duo of Andy Bell and Vince Clarke but this was probably not the aim of the law makers involved. The serious point is that information will need to be actively managed so it does not remain for ever which will impose a layer of further cost.
Massive organisations such as Banks, Telcos and ISP's who hold personal data are looking at chunky liabilities and costs as are the the service providers who manage the data.
Within the SME community this will be even more challenging as the IT systems and suppliers often fit into the cheap and cheerful category and don't have much resource to direct at IP and Cyber protection and data management.
For about 15 years there has been a relaxed attitude to IP protection in the Digital Age but post Snowden, Sony Pictures and TalkTalk this is drawing to a close and regulation (with cost) is on its way.
Subscribe to:
Posts (Atom)


