Data breach laws need more debate: Lawyer

Businesses need to get involved in the debate over whether organisations should be forced to reveal data breaches that have put personal information at risk, according to a top UK lawyer.

Earlier this month ZDNet Australia's sister site silicon.com launched its Full Disclosure campaign, calling for the government to consider legislation that would require organisations that suffer information security breaches to alert their customers if there is a chance the breach has put individuals' sensitive personal data at risk.

According to James Mullock, data protection partner at law firm Osborne Clarke, at the moment the rules around when -- and who -- to notify after a data breach vary from industry to industry.

Mullock told silicon.com: "We've got a situation where different obligations are put on some companies but not on others depending on the sector they are in, and that creates a lot of uncertainty."

He said there needs to be a wide-ranging debate and the business community needs to get involved.

Mullock said: "At the moment there is a multi-tier set of requirements and your average company director will find it extremely complex. They have so many influencing factors to think about not least the fact that they potentially face personal liability under the Data Protection Act and the Fraud Act for the failures of their company. If we have a well-managed debate and change in the law it should actually help companies decide what to do in the event of a security breach."

For there to be a change in the law the industry needs to think about when any such obligations to notify would apply, and how any change to the law would be drafted so it wouldn't become a bureaucratic nightmare, he added.

Meanwhile in Australia, there is currently, no law which makes it mandatory for businesses to reveal breaches of data. However, there is a submission before the Australian Law Reform Commission (ALRC) to make amendments to the Privacy Act which would force organisations to reveal security breaches that led to the exposure of personal data.

Like this article? Click below to send it to your mobile for free!

Advertisement

Talkback 1 comments

  1. data security Anonymous -- 25/07/07

    We are behind the times with broadband why not be behind the time with consumer rights as well.


ZDNet's CIO Vision Series

Video | Optus CIO Lawrie Turner

In this exclusive video interview, Optus chief information officer Lawrie Turner speaks to ZDNet.com.au about being the IT head for Australia's number two telco.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Renai LeMay BarCamp buzz: Let the hacking continue
    Attending last weekend's BarCamp in Sydney, it was hard to escape the conclusion that a certain "dot-com bust" flavour had seeped into the kool aid previously being drunk by Australia's web 2.0 and early stage start-up sector.
  • Array NBN needs workers on board
    Without consensus on labour issues, the eventual winner of the NBN may end up as little more than a lame duck and a cashed-up symbol of the conflict between the desire for progress and the lack of mechanisms to deliver it.
  • Array D'Ascenzo: Read p23 of security review
    Following yesterday's admission by the Australian Taxation Office that its courier had lost a CD containing the details of 3,000 self-managed super funds, it wants to review how it handles information. My suggestion: go back to the review completed in April.
  • More blogs »

Tags

Back to top

Featured