Information Age: News, analysis & insight for IT & business leaders

ICO calls for data protection law update

13 May 2009  

“Data protection must become a top-level corporate governance issue,” says Information Commissioner’s Office

The Data Protection Directive, the European Union’s statement of principles upon which the UK’s data protection laws are based, is out of date, according to a new report commissioned by the Information Commissioner’s Office.

The report, coordinated by policy think tank RAND Europe, acknowledged that the Directive has successfully fostered consensus among European countries on how personal data must be treated.

But the Directive, which was written in 1995, fails to address the practical concerns of the day, the report said, and the way it defines the various parties involved in data transfer is outmoded.

“As we move toward a globally networked society, the Directive as it stands will not suffice in the long term,” the report reads. “While the widely applauded principles of the Directive will remain as a useful front-end, they will need to be supported by a harms-based back-end in order to cope with the growing challenge of globalisation and international data flows.”

It added that the Directive's recommendations fail to address the risks facing private individuals, and are often found to be overly “prescriptive and burdensome”.

Information Commissioner Richard Thomas called for a reassessment of the Directive. “We are hoping that [this report] will stimulate debate and encourage people to think about what 21st century data protection law should look like,” he said in a statement.

He added that the weakness of the Data Protection Directive meant that organisations must pay greater attention to privacy and data protection. “Organisations must embed privacy by design and data protection must become a top-level corporate governance issue,” he said.

Thomas’s comments imply that the responsibility for improving data protection regulation lies with Europe. However, another report published earlier this year found that many UK government databases contravene European human rights regulation.

One of the Database State report’s criticisms was that the Information Commissioner’s role was limited to upholding the Data Protection Act. This, the report said, is by itself insufficient to protect the rights of individuals.


Comments 

There are currently no comments on this article

People who read this also read...

Platform Computing - Category winner

Since 1992, Platform has established a reputation as an industry leader in High Performance Computing (HPC) management software, bringing the most powerful commercial HPC solutions to leading global enterprises.

Security laws have not made businesses safe, say hackers

Government regulation has had no affect on hackers’ ability to access corporate networks, according to hacker conference poll

Away from prying eyes

Businesses and government struggle to handle private data safely. Now two new industry initiatives offer some sorely needed guidance

 

White Papers

Read article

'Think Lean' When Developing Management System Documentation

Learn how to efficiently and effectively implement a document management system for your organization.

Read article

11 Hiring Trends for 2011

In this document, you'll get the insider info you need to give potential employers what they want and beat your competition in 2011. You'll learn about the most valuable certifications and the game-changing skills that can lead to more job security and stability.

Read article

12 Hiring Manager Secrets to Getting the IT Job You Want

Learn how you can make yourself a more attractive candidate now with PrepLogic's free 12 Hiring Manager Secrets to Getting the Job You Want.

More
Advertisement
div class="banner">