Personal Information Promise
The stakes are higher for organisations with web-enabled systems who sign up to the new Personal Information Promise.
The Information Commissioner's Office (ICO) launched their Personal Information Promise which intends to demonstrate an organisation's senior level commitment to data protection.
The promise creates a public obligation, amongst other things, to:
have effective safeguards in place to make sure personal information is kept securely and does not fall into the wrong hands
It will be interesting to see how e-enabled organisations build this into their own policies, put it into practice and "regularly check that we are living up to our promises" i.e. audit where the personal information is and who accessed it. Some may be considering implementing a personal information management system (PIMS) - see Protection of Personally Identifiable Information concerning the draft British Standard. I suspect very few web sites have a sufficient level of logging and monitoring built in yet, and fewer still are audited against data protection requirements.
Posted on: 06 February 2009 at 08:21 hrs

Comments are filtered automatically and should appear shortly after they been checked.