Government databases should be judged on privacy
Should the UK follow Canada’s lead and ensure that every government database undergoes a privacy assessment?
The public has a right to be concerned over large-scale databases leaking personal information, and it needs to consider mandatory privacy impact assessments (PIAs).
So claims David Wright of Trilateral Research and Consulting, speaking this week at the annual ENISA conference in Greece.
He claimed that there was genuine public fear over governments keeping large databases of information, and people needed to be made certain that privacy wasn't being breached.
He referenced ContactPoint, a database that holds information on 11 million children in the UK, created after the abuse and death of an eight-year old child.
After it became clear that Victoria Climbie had been visited by several social services organisations before her death, public outcry lead the government to look into ways her death could have been prevented. This resulted in the formation of ContactPoint, with the aim of trying to better protect vulnerable children.
He said: "Unfortunately, the database that was set up to control one problem created another set of problems, in particular criticism over privacy and data protection."
Wright said that concerns were justified, given that 330,000 people would have access to the database. He added that making sure initiatives like these underwent PIAs could enable better decision-making and address any privacy concerns.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
He described PIAs as a "systematic process for evaluating the potential effects on privacy of a project, system or scheme, legislation or technology and ways to mitigate or avoid adverse affects."
In the UK, PIAs are still voluntary. But in other countries such as Canada, all government initiatives that could raise privacy risks need to be looked at, with the results shared with a privacy commissioner.
"There has been discussion about making PIAs mandatory for government agencies in the UK, but so far this hasn't happened," Wright said.
-
What does modern security success look like for financial services?Sponsored As financial institutions grapple with evolving cyber threats, intensifying regulations, and the limitations of ageing IT infrastructure, the need for a resilient and forward-thinking security strategy has never been greater
-
Yes, legal AI. But what can you actually do with it? Let’s take a look…Sponsored Legal AI is a knowledge multiplier that can accelerate research, sharpen insights, and organize information, provided legal teams have confidence in its transparent and auditable application
-
Datadog Database Monitoring extends to SQL Server and Azure database platformsNews The tool offers increased visibility into query-level metrics and detailed explanation plans
-
Oracle and Microsoft announce Oracle Database Service for AzureNews Azure users can now easily provision, access, and monitor enterprise-grade Oracle Database services in Oracle Cloud Infrastructure
-
Elastic expands cloud collaboration with AWSNews Partnership aims to ease migration to Elastic Cloud on AWS, as well as simplify onboarding and drive go-to-market initiatives
-
Manage the multiple database journeyWhitepaper Ensuring efficient and effective operations across multiple databases
-
Automating the modern data warehouseWhitepaper Freedom from constraints on your data
-
Freedom from manual data managementWhitepaper Build a data-driven future with Oracle
-
Oracle’s modern data platform strategyWhitepaper Freedom from manual data management
-
Oracle autonomous database for dummiesWhitepaper Freedom from mundane, manual database management