Information Age: News, analysis & insight for IT & business leaders

 
2 September 2010

Outsourcing contracts need tighter security controls, says report

13 June 2008  

Improve data control of IT outsourcing contracts or face closer regulation, trade body Intellect advises

A new report from IT trade body Intellect calls on businesses to instigate tighter security controls in their outsourcing contracts.

In failing to include clauses that make the responsibilities of data control explicitly clear, businesses are currently exposing themselves to risk, both of data breaches and of greater regulation, should such breaches continue, the report found.

“The money that outsourcers and their customers pay in data breach fines would be better spent improving data security processes, so these breaches don’t occur in the first place,” said John Higgins, Intellect’s director general.

“Companies recognise their responsibility towards consumers’ data but don’t always understand the best way to achieve this,” he added.

According to the Data Protection Act, if an organisation hands personal data of its customers over to an outsourcing provider, it is still considered to be the data controller – the outsourcer is only doing what it is told to do by its client. The company is therefore both legally obliged to know exactly what is happening to that data and culpable should it fall into the wrong hands.

Intellect’s report outlines the various data protection laws operating in different countries. India, the Philippines and China – all popular IT outsourcing destinations – have no explicit data protection legislation in place. European companies that entrust customer data to outsourcing providers in those countries must therefore meet their legal obligations through the terms of their contracts.

The trade body’s guidelines for ensuring data protection in outsourcing contracts are available to download for free here.

Further reading

Up to 38,000 credit cards stolen in Cotton Traders hack

US drives strong IT services growth

Find more stories in the Security & Continuity and IT Services Briefing Rooms


Comments 

There are currently no comments on this article

People who read this also read...

The middle class

Mid-sized businesses are now starting to receive some long-overdue attention from the upper echelons of the technology sector.

IT workers least likely to call in sick

...and the most likely to dislike their doctors

Worldwide surge in demand for IT services

IT services are increasingly in demand, although big players like IBM still take most of the pot

Unilever close to Accenture deal

£500 million contract for HR, learning and procurement on the cards.

 
Advertisement

White Papers

Read article

10 Mistakes when Buying a Business Phone System

Whitepapers

Why learn things the hard way? Here are 10 mistakes to avoid when buying your business phone system.

Read article

10 Questions to Ask Your Hosted IP PBX Provider

Whitepapers

This informative best practices will help you understand the crucial questions and the information you need to understand before you buy.

Read article

10 Steps to an Enterprise Mobility Strategy

Whitepapers

Regain control of your enterprise mobility strategy with these ten steps.

More