MPs call to criminalise data loss

Justice Select Committee demands heavy fines and/or jail terms

Written by Iain Thomson

MPs on the Justice Select Committee have called for new laws to protect the integrity of personal data.

The move was prompted by critical government data losses over the past few months, such as the loss of computer disks at HM Revenue & Customs.

The committee called for a breach law that would make it a legal obligation for companies to notify customers if their data has been accessed and to create a system of fines for repeat offenders.

"The scale of the data loss by government bodies and contractors is truly shocking, but the evidence we have had points to further hidden problems," said committee chairman Alan Beith.

"It is frankly incredible, for example, that the measures put in place at HM Revenue & Customs were not already standard procedure."

The Committee also called for the Information Commissioner to have powers to make spot checks on government departments to ensure that correct practice is being followed.

"These latest proposals to punish reckless data leakage with large fines and/or prison sentences will go some way in encouraging organisations from the top down to be compliant or at least be able to prove they took the necessary steps to protect their data," said Alan Bentley, vice president of Lumension Security.

"The UK is not without laws surrounding this issue as we already have the Computer Misuse Act 1990 and the Data Protection Act. The question is how far this new law is taken.

"There is a very fine line that needs to be balanced which ensures that all our personal data is secure but does not hamper the efficiency of a business."

However, some are questioning the government's approach. "The government is moving closer to implementing US-style data breach notification laws, but making data loss a criminal offence may be a step too far," said Jamie Cowper, marketing director at PGP Europe.

"Before we go for the nuclear option, perhaps we should look at how current security regimes can be tightened up with stricter enterprise data policies, for instance.

"We should also test the power of simply naming and shaming organisations as a deterrent to lax attitudes to data protection, as it has certainly worked in the US."

See also:

reader comments

related articles

Bank details for sale on the web

As little as £1 buys you an active bank account 03 Dec 2007

 

UK government guilty of DPA breach

Website farce exposes details of 50,000 applicants 15 Nov 2007

US experts call for tougher data laws

CSIA steps up lobbying 04 Oct 2007

FSA slaps Nationwide with £980,000 fine

Stolen laptop contained 11 million client records 15 Feb 2007

Cost of hack attacks soars

Average cost now $182 per compromised record 23 Oct 2006

MPs call to criminalise data loss

Justice Select Committee demands heavy fines and/or jail terms 03 Jan 2008

MPs mull criminal charges for government data loss

MPs suggest new laws and penalties could be introduced for government departments that lose personal data 03 Jan 2008

Renewed calls to criminalise data loss

MPs put pressure on government following revelations of more lost data 24 Jan 2008

latest news

Wightman pushes collaboration message to Cisco channel

Cisco's new channel chief reveals collaboration focus as top partners herald her arrival 08 Aug 2008

Channel muses Ofcom probe into BT practices

Investigation into carrier’s channel practices could lead to a fairer market 08 Aug 2008

Formjet plays down conflict fears

Vendor is keen to downplay worries of conflict with partners 08 Aug 2008

poll

Tough at the top?

Tough at the top?

Is BT abusing its dominant position in the market?

Previous poll results

In The Studio With CRN: Josh Claman, Dell

In an editorial coup for CRN, Josh Claman, vice president of EMEA channels at Dell, talks to CRN TV about the vendor's channel plans

CRN Fight Night bouts are LIVE!

ALL the bouts from CRN's first ever white collar boxing event at The Brewery in Chiswell Street, are now online in their full glory for CRN readers to watch.

events

CRN Golf Challenge 2008

CRN Channel Golf Challenge 2008

CRN's annual golfing day will this year be held on 16 September at a championship course in East Sussex

CRN Reseller Leadership Forum logo

CRN Reseller Leadership Forum

An exclusive channel conference from CRN, to be held over one action-packed day in September 2008

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories