<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/information-governance"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Information-governance ]]></title>
                <link>https://www.itpro.com/uk/tag/information-governance</link>
        <description><![CDATA[ All the latest information-governance content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Mon, 19 Dec 2022 11:05:15 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ IRS mistakenly publishes 112,000 taxpayer records for the second time ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/369747/irs-mistakenly-publishes-112000-taxpayer-records-for-the-second-time</link>
                                                                            <description>
                            <![CDATA[ A contractor is thought to be responsible for the error, with the agency reportedly reviewing its relationship with Accenture ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jLKdssgQDZn1HZqN2VnayD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QNarkRG5gtSpoMpcVY3y2D-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 19 Dec 2022 11:05:15 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ncLkbsDMZ6b76Lc5iS6mZh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QNarkRG5gtSpoMpcVY3y2D-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An IRS building in Washington DC]]></media:description>                                                            <media:text><![CDATA[An IRS building in Washington DC]]></media:text>
                                <media:title type="plain"><![CDATA[An IRS building in Washington DC]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QNarkRG5gtSpoMpcVY3y2D-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The IRS accidentally republished 112,000 taxpayer data records in November after they were initially published as a result of a technical error earlier this year.</p><p>Blame for the incident has reportedly fallen on an outside contractor working on behalf of the IRS and tasked with managing a database for the government department.</p><p>The incident relates to the upload of 990-T forms which contain private information used by tax-exempt entities, including government entities and retirement accounts, to pay income tax on income that comes from specific investments or that which is unrelated to their exempt purpose, according to a letter sent to congressional leaders, <a href="https://news.bloombergtax.com/daily-tax-report/irs-accidentally-releases-112-000-taxpayers-private-data-again" target="_blank"><em>Bloomberg Tax</em></a> reported.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/369690/telstra-blames-it-blunder-for-130000-customer-record-data-leak" data-original-url="/security/data-breaches/369690/telstra-blames-it-blunder-for-130000-customer-record-data-leak">Telstra blames IT blunder for leak of 130,000 customer records</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/369706/uber-says-compromised-third-party-to-blame-for-data-breach" data-original-url="/security/data-breaches/369706/uber-says-compromised-third-party-to-blame-for-data-breach">Uber says compromised third-party to blame for data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/368974/tiktok-reportedly-suffers-data-breach" data-original-url="/security/data-breaches/368974/tiktok-reportedly-suffers-data-breach">TikTok reportedly suffers data breach</a></p></div></div><p>In September 2022, the IRS said that some Form 990-T data had been made available for bulk download in its Tax Exempt Organization Search (TEOS), which shouldn't have been made public. At the time, it removed the files and was set to replace them with updated files in the future.</p><p>However, this time a contractor reuploaded older files to the <a href="https://www.itpro.com/cloud/367937/best-cloud-databases-in-2022" data-original-url="https://www.itpro.com/cloud/367937/best-cloud-databases-in-2022">database</a> with the original data, instead of new ones which ensured the forms were set to be kept private. The IRS had given the corrected data to the contractor on 23 November, but the contractor had not removed the old files from their system.</p><p>The IRS was only made aware of the files being available again on their website when a third-party researcher reached out. The IRS then told the contractor to remove them immediately. </p><p>Around 104,000 of 106,000 forms previously shared in September were reuploaded to the site. Some forms contained names or business contact information, and the IRS is currently contacting people affected by the <a href="https://www.itpro.com/security/data-breaches/357941/how-much-will-a-data-breach-really-damage-your-organisations" target="_blank" data-original-url="https://www.itpro.com/security/data-breaches/357941/how-much-will-a-data-breach-really-damage-your-organisations">data breach</a>. When more than 100,000 forms suffer a disclosure, the IRS is forced by the law to inform Congress.</p><p>The revenue service is also reportedly reconsidering its <a href="https://www.itpro.com/channel/366273/how-to-maintain-the-three-pillars-of-channel-relationships" data-original-url="https://www.itpro.com/channel/366273/how-to-maintain-the-three-pillars-of-channel-relationships">relationship</a> with contractor Accenture on this project. <em>IT Pro</em> has contacted the company for comment.</p><p>“The IRS is continuing to review the situation to identify opportunities to establish additional controls and strengthen existing controls to protect taxpayer information,” said US Treasury spokesperson John Rizzo.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Amazon accused of lying to Congress about using third-party sellers' data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/information-governance/355453/report-congress-questions-if-amazon-lied-about</link>
                                                                            <description>
                            <![CDATA[ Firm allegedly used data related to independent sellers to help develop competing products. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9zoVhmNA1GDamg4JdL7Xbg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EayyoqpebiTRPeP7ggcFYd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 27 Apr 2020 15:41:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sarah Brennan ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EayyoqpebiTRPeP7ggcFYd-1280-80.jpg">
                                                            <media:credit><![CDATA[Big Stock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Amazon logo on a window]]></media:description>                                                            <media:text><![CDATA[Amazon logo on a window]]></media:text>
                                <media:title type="plain"><![CDATA[Amazon logo on a window]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EayyoqpebiTRPeP7ggcFYd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Congress is questioning if Amazon was misleading about its use of third-party seller data to develop products.</p><p>According to a <a href="https://www.wsj.com/articles/amazon-scooped-up-data-from-its-own-sellers-to-launch-competing-products-11587650015?mod=hp_lead_pos2">recent <em>Wall Street Journal</em> report</a>, Amazon staff members claimed the company used insider data related to independent sellers to help develop its own competing products. </p><p>The report states that, in one case, the company allegedly went so far as to analyze a third-party car-trunk organizer’s sales and profit margins to decide if launching a competing product was in its best interest.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/90817/city-in-two-minds-over-amazon-and-sun-results" data-original-url="/90817/city-in-two-minds-over-amazon-and-sun-results">City in two minds over Amazon and Sun results</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/636733/is-amazon-a-threat-to-apple" data-original-url="/636733/is-amazon-a-threat-to-apple">Is Amazon a threat to Apple?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/136440/amazon-offers-red-hat-on-demand" data-original-url="/136440/amazon-offers-red-hat-on-demand">Amazon offers Red Hat on-demand</a></p></div></div><p>The House Judiciary Committee has spent the last few months engaged in an <a href="https://www.itpro.com/network-internet/32796/google-faces-another-hefty-eu-antitrust-fine" data-original-url="https://www.itpro.com/network-internet/32796/google-faces-another-hefty-eu-antitrust-fine">antitrust investigation</a> that includes Amazon and many other large <a href="https://www.itpro.com/business-strategy/careers-training/354916/top-15-tech-companies-to-work-for-in-the-us" data-original-url="https://www.itpro.com/business-strategy/careers-training/354916/top-15-tech-companies-to-work-for-in-the-us">tech companies</a>. In July 2019, an Amazon lawyer told the subcommittee the company doesn't use individual seller data to compete with third-party sellers.</p><p>After this report, leading members of the subcommittee, Reps. Jerry Nadler (D-NY) and David Cicilline (D-RI), were steadfast in responding to Amazon’s latest transgressions. </p><p>“It is deeply concerning that, beginning with the hearing last year, they may have misled Congress rather than be fully forthcoming on this matter, notwithstanding our repeated requests in this regard,” Nadler said <a href="https://judiciary.house.gov/news/documentsingle.aspx?DocumentID=2931">in a statement</a> shared to the House Judiciary Committee’s website.</p><p>“At best, Amazon’s witness appears to have misrepresented key aspects of Amazon’s business practices while omitting important details in response to pointed questioning,” Cicilline added. “At worst, the witness Amazon sent to speak on its behalf may have lied to Congress.”</p><p>Amazon responded to the lawmakers’ calls for clarification and announced it would launch an internal investigation to address these accusations. </p><p>“It’s simply incorrect to say that Amazon was intentionally misleading in our testimony,” a company spokesperson told <em><a href="https://www.theverge.com/2020/4/24/21234522/democrats-david-cicilline-jerry-nadler-amazon-bezos">The Verge</a></em>. “While we don’t believe these claims made by the Wall Street Journal are accurate, we take these allegations very seriously and have launched an internal investigation.”</p><p>The <em>WSJ</em> report is one of many controversies to have overshadowed Amazon recently. The company has also faced concern after <a href="https://gothamist.com/news/amazon-workers-strike-demand-coronavirus-protections-toxic-workplace">the alleged mistreatment of workers</a> led to strikes at a number of warehouse facilities.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Radio station sanctioned after guest blames coronavirus on China's 5G rollout ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/5g/355203/radio-station-punished-for-linking-coronavirus-to-chinese-5g-rollout</link>
                                                                            <description>
                            <![CDATA[ Guest introduced as a 'nurse' wasn't "sufficiently challenged" by Uckfield FM presenter, Ofcom rules ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rh5ZnnJRse4XJbX7NCDnLX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/93Dk7rL7LMgranZTDdyArn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Apr 2020 14:03:29 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[5g]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                    <category><![CDATA[Mobile Networks]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/93Dk7rL7LMgranZTDdyArn-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Radio equipment]]></media:description>                                                            <media:text><![CDATA[A pair of headphones resting on an audio mixer in a studio]]></media:text>
                                <media:title type="plain"><![CDATA[A pair of headphones resting on an audio mixer in a studio]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/93Dk7rL7LMgranZTDdyArn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Ofcom has imposed a sanction on a regional radio station after a guest claimed that the coronavirus outbreak was linked to China's rollout of <a href="https://www.itpro.com/mobile/28081/what-is-5g" data-original-url="https://www.itpro.com/mobile/28081/what-is-5g">5G</a> technology.</p><p>Uckfield Community Radio, in Sussex, was found to have breached broadcasting rules on 28 February when one of its presenters failed to "sufficiently challenge" claims made by an interviewee about <a href="https://www.itpro.com/cloud/354902/the-coronavirus-outbreak-is-the-clouds-chance-to-shine" data-original-url="https://www.itpro.com/cloud/354902/the-coronavirus-outbreak-is-the-clouds-chance-to-shine">COVID-19</a>.</p><p>As a result, the station must broadcast a summary of the regulator's findings to its listeners on a date to be confirmed. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/networking/26440/what-is-5g-ultimate-guide" data-original-url="/networking/26440/what-is-5g-ultimate-guide">What is 5g? Ultimate guide</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/354902/the-coronavirus-outbreak-is-the-clouds-chance-to-shine" data-original-url="/cloud/354902/the-coronavirus-outbreak-is-the-clouds-chance-to-shine">The coronavirus outbreak is the cloud's chance to shine</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/5g/354651/huawei-granted-limited-role-in-uks-5g-infrastructure" data-original-url="/mobile/5g/354651/huawei-granted-limited-role-in-uks-5g-infrastructure">Huawei granted "limited" role in UK's 5G infrastructure</a></p></div></div><p>The guest appeared on the Tony Williams morning show, introduced to listeners as a 'registered nurse', and made claims that the initial outbreak of the virus in Wuhan, China was linked to the rollout of <a href="https://www.itpro.com/infrastructure/network-internet/354845/scant-investment-and-fragmented-use-cases-could-stunt-5g" target="_blank" data-original-url="https://www.itpro.com/infrastructure/network-internet/354845/scant-investment-and-fragmented-use-cases-could-stunt-5g">5G</a> technology. The interviewee also made claims that people were being misled about the coronavirus – which Ofcom said "undermined trust" in the advice given out by relevant <a href="https://www.itpro.com/business/business-operations/354999/prime-minister-boris-johnson-calls-for-tech-to-support" target="_blank" data-original-url="https://www.itpro.com/business/business-operations/354999/prime-minister-boris-johnson-calls-for-tech-to-support">authorities</a>.</p><p>The interview began with a short disclaimer from the guest, which even referenced Ofcom: "Everything that I give today is information, it is not intended to replace any advice given by your medical practitioner if you are sick always seek advice from your GP".</p><p>Ofcom received a number of complaints about the broadcast and its resulting investigation concluded that the station failed to protect listeners. The regulator said it had breached 'rule 2.1' of the Ofcom Broadcasting Code and due to the seriousness of the breach, it has directed the station to broadcast a statement of the findings on a date which will be confirmed later.</p><p>"Uckfield FM broadcast a discussion which contained potentially harmful claims about the coronavirus virus, including unfounded claims that the virus outbreak in Wuhan, China was linked to the roll out of 5G technology," Ofcom said in its ruling.</p><p>Uckfield FM has since apologised for any "confusion and concern" resulting from the broadcast and the unfounded link between the coronavirus and 5G.</p><p>Last week, US President Donald Trump was challenged by reporters who suggested his wording of the outbreak was racist when he referred to it as the "Chinese virus".</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is the Data Protection Act 1998? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/data-protection/28085/what-is-the-data-protection-act-1998</link>
                                                                            <description>
                            <![CDATA[ Although data protection regulations have been updated, businesses may still find themselves sanctioned under the Data Protection Act 1998 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6Vfi3XsuHbbT9szsBF4mof</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tzFatVaPq6mrXtaezxRKtC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Jun 2019 10:57:00 +0000</pubDate>                                                                                                                                <updated>Mon, 12 Apr 2021 07:17:00 +0000</updated>
                                                                                                                                            <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tzFatVaPq6mrXtaezxRKtC-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A blue digital shield made from encrypted strings with a keyhole in the middle]]></media:description>                                                            <media:text><![CDATA[A blue digital shield made from encrypted strings with a keyhole in the middle]]></media:text>
                                <media:title type="plain"><![CDATA[A blue digital shield made from encrypted strings with a keyhole in the middle]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tzFatVaPq6mrXtaezxRKtC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European Union's General Data Protection Regulation (GDPR) has been the biggest shake-up of data protection laws the world has ever seen. Since its introduction in May 2018, the way businesses across Europe collect, store and use data has come under greater scrutiny. </p><p>However, its introduction also came amid the <a href="https://www.itpro.com/policy-legislation/31772/gdpr-and-brexit-how-will-one-affect-the-other" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/31772/gdpr-and-brexit-how-will-one-affect-the-other">UK's prolonged exit from the EU</a>. This led to uncertainty around the UK adopting the legislation as its main purpose was to harmonise data transfers throughout member states. However, <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a> has and will continue to exist in the UK in the form of the Data Protection Act (DPA) 2018, as will the Data Protection Act (DPA) 1998.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" data-original-url="/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">What is GDPR? Everything you need to know, from requirements to fines</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/28029/latest-gdpr-news-uk" data-original-url="/data-protection/28029/latest-gdpr-news-uk">GDPR news: GDPR turns six months old</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/30107/get-gdpr-ready" data-original-url="/general-data-protection-regulation-gdpr/30107/get-gdpr-ready">Seven steps to GDPR compliance</a></p></div></div><p>The DPA 2018 is often referred to as 'UK GDPR' but is actually an update to the DPA1998. It was changed to translate the majority of the GDPR's principles so that they fit into existing UK laws. </p><p>The 1998 law is still in use for cases of data misuse or theft that happened before 23 May 2018 (the implementation date of DPA 2018). Although this law has been in play for some time, it's important businesses understand how both work since they can still be found in breach of the older one for legacy incidents. </p><p>It's also important to understand that data laws have had to evolve, which may have changed some articles of the Data Protection Act 1998. Organisations must understand how much the law has changed and its current scope in terms of compliance, as well as how it can still make an impact on your business. </p><h2 id="what-does-the-data-protection-act-1998-mean">What does the Data Protection Act 1998 mean?</h2><p>The Data Protection Act 1998 was the law governing the processing of personal data by all organisations, be they public or private, including charities.</p><p>All data breaches in the UK are investigated by the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" target="_blank" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner's Office (ICO)</a> and the same was true then, although the act provided guidelines for the type of penalty that could be applied if someone was found to have been in contravention of the rules.</p><h3 class="article-body__section" id="section-data-protection-act-1998-summary"><span>Data Protection Act 1998: Summary</span></h3><p>The Data Protection Act 1998 regulated the use and protection of personal data, and outlined the responsibilities a business had to protect that data. It superseded the Data Protection Act 1984 and Access to Personal Files Act 1987.</p><p>It was amended in 2003 to give individuals more control over digital marketing communications they receive, meaning they must opt-in to receive emails, SMS text messages etc from an organisation if they've never had contact with it before.</p><h3 class="article-body__section" id="section-what-was-personal-data-defined-as"><span>What was personal data defined as?</span></h3><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="L8vUrzgp7mhwUJ5GEHSyyi" name="L8vUrzgp7mhwUJ5GEHSyyi.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/L8vUrzgp7mhwUJ5GEHSyyi.png" mos="https://cdn.mos.cms.futurecdn.net/L8vUrzgp7mhwUJ5GEHSyyi.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Managing security risk and compliance in a challenging landscape</strong></p><p class="fancy-box__body-text">How key technology partners grow with your organisation</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/digital-transformation/354266/managing-security-risk-and-compliance-in-a" data-original-url="/business-strategy/digital-transformation/354266/managing-security-risk-and-compliance-in-a">FREE DOWNLOAD</a></p></div></div><p>According to <a href="https://www.itpro.com/data-protection/28020/data-protection-principles" target="_blank" data-original-url="https://www.itpro.com/data-protection/28020/data-protection-principles">data protection principles</a>, and previous regulations, personal data is defined as information related to an individual that can be used either in isolation or in tandem with other data sources, to reveal that individual's identity. If there is such pre-existing data held by a data controller, then personal data also encompasses information that may come under this entity's possession.</p><p>This also included expressions of opinion about that person and any intention the data controller or another individual may have in regards to them.</p><p>The DPA 1998 also provided protection for sensitive personal data, which was defined as information relating to a person's racial or ethnic origin, political and religious or similar beliefs, membership of a trade union, physical and mental health, sex life, any criminal charges or allegations against them, and any proceedings against them (such as a court case or a prison sentence).</p><h3 class="article-body__section" id="section-what-data-formats-were-covered"><span>What data formats were covered?</span></h3><p>The DPA defined possession of data as that which resided in a machine or on paper in a readable, accessible way. Regarding paper forms of information, the ICO classified paper filing systems as individuals' records being held in a "systematic, structured way" that provided easy access to those individuals' information.</p><p>Data was also classified as "accessible records" covering health or education. While this information wasn't necessarily held in a structured, easily accessible way, it was important enough that the DPA stipulated it should still be protected.</p><p>Data controllers' "data processing" activities were also subject to the DPA's rules. Processing was a very broad term covering plenty of things, but was thought of as relating to every interaction had with personal data. As the ICO noted, almost any activity concerning data would constitute processing.</p><h3 class="article-body__section" id="section-what-were-the-penalties-for-a-data-breach"><span>What were the penalties for a data breach?</span></h3><p>There were a number of penalties and processes available to the ICO when it came to taking action on data protection.</p><p>The most material impact was perhaps the possibility of a fine. As of April 2010, the ICO was able to issue penalties of up to £500,000 for offences taking place on or after that date, although the maximum fine was only ever imposed once (against Facebook during the <a href="https://www.itpro.com/data-protection/30792/cambridge-analytica-facebook-scandal" target="_blank" data-original-url="https://www.itpro.com/data-protection/30792/cambridge-analytica-facebook-scandal">2018 Cambridge Analytica scandal</a>).</p><p>It was also able to lay out processes an organisation should have undertaken in order to improve its data protection posture, and was able to conduct audits to ensure compliance (these could have been consensual or, if necessary, compulsory).</p><p>If a breach occurred, in addition to the possibility of a £500,000 fine, the ICO was able to prosecute anyone it believed had committed a criminal offence under the act.</p><h2 id="what-is-the-data-protection-act-2018">What is the Data Protection Act 2018?</h2><p>After 20 years, UK data protection regulations received an overhaul following Royal Assent on 23 May. The <a href="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018" target="_blank" data-original-url="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018">Data Protection Act 2018</a> updates the UK's data protection legislation to make it more relevant to the way technology is used today and harmonises laws with that of GDPR.</p><p>The act mirrors GDPR in many aspects, including <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/31025/gdpr-fines-how-high-are-they-and-how-can-you-avoid" target="_blank" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/31025/gdpr-fines-how-high-are-they-and-how-can-you-avoid">tougher sanctions for data breaches</a> (up to £17 million or 4% of global turnover).</p><p>The new Data Protection Act 2018 modernises the UK's data protection framework to account for the value of people's personal data today, offering people stronger rights over what others can do with their data, and requiring companies to gain people's consent to use their information.</p><p>Generally, most provisions under the 1998 act have been strengthened, requiring far more from organisations when it comes to seeking consent and holding data for longer than necessary.</p><p>When it comes to processing data, companies are now required to make efforts to be transparent, which was not necessarily required under the 1998 act. It's also far more difficult to collect data under the 2018 act, as it needs to have an explicit purpose.</p><p>What specific data could be collected was also up for interpretation under the 1998 act, as organisations could use it provided it wasn't deemed "excessive" compared to its original purpose. Under the 2018 act, the processing is limited to only that data considered relevant.</p><p>For more information on the new Data Protection Act 2018, and how it works alongside GDPR, <a href="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018" target="_blank" data-original-url="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018">head here</a>.</p><h2 id="data-protection-act-1998-important-terms-and-further-reading">Data Protection Act 1998: Important terms and further reading</h2><p><strong>Data subject:</strong> Data subject is a term used in both the GDPR and DPA. It refers to an individual who is the subject of personal data.</p><p><strong>Data controller:</strong> As with data subject, data controller is used in the GDPR and DPA. It means a person who individually or with a group of other people decides how and why any personal data is or will be processed.</p><p>For more information on the DPA, you can visit the ICO's <a href="https://ico.org.uk/for-organisations/guide-to-data-protection">guide to data protection</a>, and <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">click here for more information on the GDPR</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Information governance in a world of increased data regulation ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/information-governance/354169/information-governance-in-a-world-of-increased</link>
                                                                            <description>
                            <![CDATA[ Companies have to manage the dual challenges of data growth and increased regulation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eYpNAPPyHFxDsrtGzXEGLq</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/CbnLGmWL6tkYnVAnuubWVF-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 31 May 2019 16:39:41 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/CbnLGmWL6tkYnVAnuubWVF-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/CbnLGmWL6tkYnVAnuubWVF-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The business environment is growing increasingly complex, with companies asked to manage the dual challenge of exponential growth of data and increased regulation, or face fines and long-term damage to their brands.</p><p>This whitepaper explores how companies can implement an information governance program: a set of controls, processes and technologies to maximise the value of information assets while minimising risks of non-compliance with data privacy requirements.</p><p>Download it now to learn how to develop a policy framework and establish an information governance team.</p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="high" data-lazy-src="https://dennis.cvtr.io/forms/hitachi-form?locale=1&p=false&wp=2978"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Defra's no-deal Brexit IT systems may not be ready for 29 March ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/32369/defras-no-deal-brexit-it-systems-may-not-be-ready-for-29-march</link>
                                                                            <description>
                            <![CDATA[ MPs are concerned the department will resort to "manual fallbacks" that are slower and more error-prone ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">o8ENiXkmm9VRfnJ9dnsfPT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eWKEiuZGBpFP4uQbpEQUPn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 13 Mar 2019 12:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eWKEiuZGBpFP4uQbpEQUPn-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An old laptop turned off resting on a rock by a stream]]></media:description>                                                            <media:text><![CDATA[An old laptop turned off resting on a rock by a stream]]></media:text>
                                <media:title type="plain"><![CDATA[An old laptop turned off resting on a rock by a stream]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eWKEiuZGBpFP4uQbpEQUPn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Work on four of the six IT systems central to standards, environmental control and border control in the event of a no-deal Brexit has not yet been completed, less than two weeks until Brexit.</p><p>Despite the UK currently scheduled to leave the European Union (EU) without a deal on 29 March, the Department for Environment, Food and Rural Affairs (Defra) has yet to fully prepare for a no-deal outcome.</p><p><a href="https://www.parliament.uk/business/committees/committees-a-z/commons-select/public-accounts-committee/news-parliament-2017/report-published-brexit-uk-border-further-progress-review-17-19" target="_blank">MPs with the Public Accounts Committee (PAC)</a> expressed concern in its latest report that both Defra and the Department for Transport's current plans are not solid enough to address the scale of the challenge that a no-deal Brexit presents.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/bugs/32143/the-facts-of-the-y2k-bug-and-why-it-was-nothing-like-brexit" data-original-url="/bugs/32143/the-facts-of-the-y2k-bug-and-why-it-was-nothing-like-brexit">The facts of the Y2K bug and why it was nothing like Brexit</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/31939/government-systems-unprepared-for-no-deal-brexit" data-original-url="/policy-legislation/31939/government-systems-unprepared-for-no-deal-brexit">Government systems 'unprepared' for no-deal Brexit</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/31209/eu-sinks-uk-hopes-for-post-brexit-role-for-uk-in-developing-data-protection" data-original-url="/policy-legislation/31209/eu-sinks-uk-hopes-for-post-brexit-role-for-uk-in-developing-data-protection">EU sinks UK hopes for post-Brexit role for UK in developing data protection laws</a></p></div></div><p>Two of Defra's IT systems have gone live, and four are in the process of being tested, according to the committee's latest report. This follows previous concerns, raised in November, that none of the six systems had yet undergone sufficient testing.</p><p>The biggest risk to delivering the four incomplete IT systems is that a number of them depend on a "common registration module" that itself is not yet complete. Work is in progress to make this more user-friendly.</p><p>In the event the IT systems have not been completed by 29 March, Defra told the PAC that it has a set of "manual fall-backs". But these manual processes would be slower, have a higher error rate, and be more burdensome for users. The departments will also lose elements of the system integration.</p><p>Both departments are also considering staffing needs for the issues that will result from a no-deal Brexit, including forming 24-hour emergency centres.</p><p><strong>15/11/18: Defra blasted for "alarming" lack of critical IT tests ahead of Brexit</strong></p><p>The Department for Environment, Food and Rural Affairs (Defra) has been lambasted for failing to test critical IT systems ahead of the UK's withdrawal from the European Union.</p><p>Six systems, including a food import notification system and another that will replace the EU's platform for monitoring chemicals, are being developed but have yet to be fully tested, causing MPs to raise concerns about the department's complacency and ability to function post-Brexit.</p><p>The most complex of Defra's systems, a food notification system, won't be tested until "January or February", according to Parliament's Public Accounts Committee (PAC), falling worryingly close to the March 2019 deadline.</p><p>Defra Ministers have admitted there is a risk with not sufficiently testing these systems, the PAC said, due to the scale and complexity of the task at hand, and conceded issues are bound to arise. However, they reassured the committee while giving evidence that the six systems will be available in time in the event of a no-deal scenario.</p><p>"Brexit looms but the Department for Environment, Food & Rural Affairs is a long way from being ready," said PAC chair Meg Hillier MP. "Anyone working in the dark is prone to stumble but in Defra's case I am concerned that the Department has lost sight of its priorities."</p><p>In light of great risks associated with a no-deal Brexit, Hiller added that it is "alarming" how little information Defra has provided publicly to allow businesses and organisations to prepare. The Department is too complacent, moreover, about the levels of disruption to trade.</p><p>"Brexit border planning is not sufficiently developed," she added. "Six critical IT systems are still to be tested and there is a risk that in the Department's rush to prepare necessary legislation, the quality of that legislation will suffer."</p><p>The PAC highlighted several issues in its report including a very limited engagement with SMBs, as well a plan that involves testing all the IT systems at once from January. This, the committee says, will inevitably throw up new issues, and put increasing strain on the chances of the new systems working in time.</p><p>Defra says it does not accept the PAC's conclusions, and have accused the committee of inaccurately reflecting its level of preparation.</p><p>"The PAC have ignored key findings from the National Audit Office (NAO), which found that 'Defra has achieved a great deal and to a very demanding timescale'," a Defra spokesperson told <em>IT Pro</em>.</p><p>"In producing this one-sided report, the PAC have failed to acknowledge the substantial progress we have made in replacing EU functions, hiring key staff and building new IT systems."</p><p>The spokesperson added Defra has met several targets on additional staff hiring and reducing IT workload inefficiencies, and quoted praise from <a href="https://www.nao.org.uk/wp-content/uploads/2018/09/Defra-Progress-Implementing-EU-Exit.pdf" target="_blank">the separate NAO report</a> that said the department "has achieved a great deal in difficult circumstances".</p><p>The NAO report, incidentally, also levelled criticism mirroring the PAC's findings on implementing the new IT systems, saying: "because it has not fully defined its future service requirements, Defra has not yet ensured that the new IT systems it is developing can meet future operational capability".</p><p>In the event the new food import notification system is not ready by March 2019, the spokesperson continued, there are contingencies in place to ensure the import for live animals, animal products, and high-risk food continues with minimal disruption.</p><p>The additional IT systems Defra is developing include platforms to support export health certificates, fish catch certificates, fluorinated gases and ozone-depleting substances, and veterinary medicines authorisation.</p><p>The PAC has issued a number of recommendations and demanded that Defra provide them with a further update by the end of December on whether the key IT projects are on track for testing in the new year. MPs have also demanded a further update later in January on the results of the testing.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Government to hold talks with Facebook's Mark Zuckerberg over regulating tech giants ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/33051/government-to-hold-talks-with-facebooks-mark-zuckerberg-over-regulating</link>
                                                                            <description>
                            <![CDATA[ Culture secretary will use the 30-minute meeting to explore ways to remove harmful content from social media ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nbUMhEd8LKDBvdWzN2sPES</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ymWtjRGydz7E6qkDit4EpK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 21 Feb 2019 11:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ymWtjRGydz7E6qkDit4EpK-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Zuckerberg looking worried]]></media:description>                                                            <media:text><![CDATA[Zuckerberg looking worried]]></media:text>
                                <media:title type="plain"><![CDATA[Zuckerberg looking worried]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ymWtjRGydz7E6qkDit4EpK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The culture secretary will hold talks with Mark Zuckerberg today in an attempt to engage the Facebook CEO just weeks before the government releases proposals to regulate big tech companies.</p><p>Secretary of state for digital, culture, media and sport (DCMS) Jeremy Wright will be granted 30 minutes of Zuckerberg's time, according to the <a href="https://www.bbc.co.uk/news/technology-47315608"><em>BBC</em></a>, at the company's Californian headquarters today.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/31947/has-the-government-finally-lost-its-patience-with-silicon-valley" data-original-url="/policy-legislation/31947/has-the-government-finally-lost-its-patience-with-silicon-valley">Has the government finally lost its patience with Silicon Valley?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/32885/make-social-media-firms-liable-for-harm-to-children-mps-say" data-original-url="/policy-legislation/32885/make-social-media-firms-liable-for-harm-to-children-mps-say">Make social media firms liable for harm to children, MPs say</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/32931/european-commission-says-tech-giants-are-more-effectively-examining-illegal" data-original-url="/policy-legislation/32931/european-commission-says-tech-giants-are-more-effectively-examining-illegal">European Commission says tech giants are more effectively examining illegal hate speech</a></p></div></div><p>The meeting has been scheduled in the wake of growing pressure on the role social media giants are playing in exacerbating mental health conditions in young people, with repeated suggestions from the government they are ready to legislate.</p><p>Facebook has also this week been <a href="https://www.itpro.com/policy-legislation/33021/facebook-behaves-like-digital-gangsters-with-customer-data-mps-warn" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/33021/facebook-behaves-like-digital-gangsters-with-customer-data-mps-warn">lambasted by the DCMS select committee in the findings</a> of its 18-month investigation into fake news and disinformation, with the influential group of MPs accusing the tech giant of behaving like "digital gangsters".</p><p>Zuckerberg had refused to meet with or give evidence to the committee during its investigation, much to the ire of its chair Damian Collins MP, who has made countless attempts to engage the Facebook founder.</p><p>But the culture secretary, leading a UK delegation that includes digital minister Margot James, will speak with Zuckerberg about ways to prevent online harm, in an attempt to gauge his views ahead of publishing a legislative white paper. The Californian trip will also include meetings with Apple, Google, and Twitter among other firms.</p><p>Due in the next few weeks, the white paper will outline the government's thinking on how to regulate tech giants for the first time, with mounting speculation that any new proposals will include setting up an industry watchdog.</p><p>An independent regulator, akin to Ofcom for telecoms firms, are among the range of measures proposed in the DCMS committee's report, as well as its demand for a compulsory code of conduct.</p><p>The 108-page report particularly focused on how Facebook failed to prevent the spread of fake news and disinformation on its platform during political campaigns, as well as failed to deal with known sources of harmful content.</p><p>The committee also accused the social media firm of deliberately disregarding data privacy principles and willfully breaking data laws in the interests of "profit over data security".</p><p>"We believe that in its evidence to the Committee Facebook has often deliberately sought to frustrate our work, by giving incomplete, disingenuous and at times misleading answers to our questions," Collins said after the publication of his report.</p><p>"Even if Mark Zuckerberg doesn't believe he is accountable to the UK Parliament, he is to the billions of Facebook users across the world. Evidence uncovered by my Committee shows he still has questions to answer yet he's continued to duck them, refusing to respond to our invitations directly or sending representatives who don't have the right information."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The ICO wants a wider remit where data is used ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/33013/the-ico-wants-a-wider-remit-where-data-is-used</link>
                                                                            <description>
                            <![CDATA[ Personal data and its regulation are "indivisible" from conversations about AI, Brexit and fake news, says Elizabeth Denham ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nW5BdNcYPTTBBw1rmqVefk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LCexciyQGZSc7LQ6JYu2fP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 15 Feb 2019 12:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LCexciyQGZSc7LQ6JYu2fP-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Information commissioner Elizabeth Denham]]></media:description>                                                            <media:text><![CDATA[Information commissioner Elizabeth Denham]]></media:text>
                                <media:title type="plain"><![CDATA[Information commissioner Elizabeth Denham]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LCexciyQGZSc7LQ6JYu2fP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Information Commissioner, Elizabeth Denham, has said that future regulation on technologies and policies that are underpinned by data must include her office.</p><p>Speaking at the Institute for Government, Denham said that personal data and it's regulation were "indivisible" from conversations about AI, Brexit and the spread of misinformation.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/7BTOszBNfo0" allowfullscreen></iframe></div></div><p>Her comments come after a year of high-profile action against Facebook, which the ICO fined over the <a href="https://www.itpro.com/data-protection/32417/facebook-appeals-ico-fine" target="_blank" data-original-url="https://www.itpro.com/data-protection/32417/facebook-appeals-ico-fine">Cambridge Analytic scandal</a>. However, on Thursday Denham wanted to discuss the further implications of data rather than just its protection.</p><p>"I've given evidence to Parliament, over a dozen times, and not just talking about issues of data protection, but on wider issues that have data at their heart," she said. "Data ethics, the deployment of AI in the UK, the security implications of Brexit, algorithmic decision making, fake news and disinformation.</p><p>"You can't discuss these issues, or have an informed policy direction without taking data protection into account. So personal data and its regulation are indivisible from these conversations."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" data-original-url="/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">What is the Information Commissioner’s Office (ICO)?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/32417/facebook-appeals-ico-fine" data-original-url="/data-protection/32417/facebook-appeals-ico-fine">Facebook agrees to pay £500,000 ICO fine</a></p></div></div><p>Denham, who came to the UK in 2016, said that she had been looking around other regulatory bodies and found that none had quite the "breadth of the remit of the ICO" but her comments suggest that even that is not enough.</p><p>"It used to be a relatively sleepy area of law - freedom of information and data protection - but now information rights are an essential plank of modern democracies," she said.</p><p>"It's all about trust and confidence that people have in government institutions. Simply put, freedom of information and data protection support the legitimacy of public administration."</p><p>Denham went on to say that the ICO "will take action, whenever and wherever, data obligations are disregarded" but added that the challenge it presents keeps her up at night: "That is a really big challenge for us and a really big challenge for my office because public expectations are so high and we've got to keep our eye on many developing policy debates and conversations where data use arises."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ No-deal Brexit will block critical data transfers from EU, warns ICO ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/32576/no-deal-brexit-will-block-critical-data-transfers-from-eu-warns-ico</link>
                                                                            <description>
                            <![CDATA[ With no time to reach a data adequacy agreement, the ICO has published guidance for businesses to avoid disruption ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fHZqW295VNdrw1dk4x84g8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2B95cpsCBxVbuTGjPty6JK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Dec 2018 10:48:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2B95cpsCBxVbuTGjPty6JK-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Europe and middle east map at night lit up with data lines]]></media:description>                                                            <media:text><![CDATA[Europe and middle east map at night lit up with data lines]]></media:text>
                                <media:title type="plain"><![CDATA[Europe and middle east map at night lit up with data lines]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2B95cpsCBxVbuTGjPty6JK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" target="_blank" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner's Office (ICO)</a> has issued guidance for UK organisations on how to cope with data transfers being blocked in the event Britain crashes out of the European Union (EU) without a deal.</p><p>Despite bringing the <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">General Data Protection Regulation (GDPR)</a> into UK law in the form of the Data Protection Act 2018, leaving the EU without a deal in place means Britain will be, for a time, classed as a third country' until an adequacy agreement can be implemented.</p><p>This means that while some data can be transferred from the UK to European Economic Area (EEA) countries, something supported by the UK government, there will be a stop to all flow of personal information in the opposite direction until a data adequacy agreement comes into force, according to the ICO.</p><p>Personal information has been able to flow freely between the UK and EU countries to date because all nations have adhered to the same standards. The EU also allows the free-flow of data between member states and non-EU countries through data adequacy decisions.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/31772/gdpr-and-brexit-how-will-one-affect-the-other" data-original-url="/policy-legislation/31772/gdpr-and-brexit-how-will-one-affect-the-other">GDPR and Brexit: How will one affect the other?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/32534/should-we-have-left-the-brexit-decision-to-ai" data-original-url="/business-strategy/32534/should-we-have-left-the-brexit-decision-to-ai">Should we have left the Brexit decision to AI?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/31503/uk-government-wants-eu-to-acquiesce-with-its-data-safeguards-even-as-brexit" data-original-url="/policy-legislation/31503/uk-government-wants-eu-to-acquiesce-with-its-data-safeguards-even-as-brexit">UK government wants EU to acquiesce with its data safeguards even as Brexit looms</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-security/31831/experts-warn-of-brain-drain-if-intelligence-sharing-is-absent-from-brexit-deal" data-original-url="/cyber-security/31831/experts-warn-of-brain-drain-if-intelligence-sharing-is-absent-from-brexit-deal">Experts warn of 'brain drain' if intelligence sharing is absent from Brexit deal</a></p></div></div><p>But any such arrangements will take time to conclude and cannot logistically be in place by March 2019, the legislative date of withdrawal, unless Article 50 is extended or suspended. This means businesses will need to consider their circumstances and adapt their operations accordingly.</p><p>It could also severely hamper the delivery of public services, including many NHS Trusts and their suppliers, which <a href="https://www.cloudpro.co.uk/cloud-essentials/private-cloud/7819/nhs-patient-records-to-be-stored-in-aws-cloud-platform" target="_blank">store data on often-EEA-based AWS servers</a>.</p><p>"The <a href="https://ico.org.uk/for-organisations/data-protection-and-brexit/data-protection-if-there-s-no-brexit-deal/the-gdpr/international-data-transfers" target="_self">guidance we have produced</a> will help organisations plan ahead and ensure that personal data continues to flow," said Information Commissioner Elizabeth Denham.</p><p>"We will be providing further information to the small number of organisations in the UK that rely on approved Binding Corporate Rules for their transfers to explain how they may be affected.</p><p>"We will continue to help all organisations understand how any future changes in data protection regulation will affect you and the measures you need to put in place."</p><h3 class="article-body__section" id="section-minimising-disruption-post-brexit"><span>Minimising disruption post-Brexit</span></h3><p>The broader guidance includes a set of <a href="https://ico.org.uk/for-organisations/data-protection-and-brexit/data-protection-if-there-s-no-brexit-deal/the-gdpr/international-data-transfers" target="_blank">frequently asked questions (FAQs)</a> regarding the various information and data regulations with which businesses have had to comply, as well as a <a href="https://ico.org.uk/media/2553958/leaving-the-eu-six-steps-to-take.pdf" target="_blank">six-step checklist</a> for organisations to follow.</p><p>The FAQs highlight such queries as what will the UK data protection law be if we leave without a deal?', and Will the GDPR still apply if we leave the EU without a deal?'</p><p>The ICO's six-step checklist, meanwhile, highlights a range of measures organisations will need to implement to ensure minimal disruption beyond March.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="aJgu3xQuRojk3G4kB4zgC4" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/aJgu3xQuRojk3G4kB4zgC4.png" mos="https://cdn.mos.cms.futurecdn.net/aJgu3xQuRojk3G4kB4zgC4.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>These include continual GDPR compliance, assessing transfers to and fro the UK, reviewing the organisational structure if operating across Europe, reviewing privacy information and documentation, as well as raising the level of awareness among senior staff.</p><p>One key measure that businesses can implement are Standard Contractual Clauses between themselves and EU-based organisations. The ICO has also produced an <a href="https://ico.org.uk/for-organisations/data-protection-and-brexit/standard-contractual-clauses-for-transfers-from-the-eea-to-the-uk-interactive-tool" target="_blank">interactive walkthrough mainly targeting SMBs</a> to determine whether this is a suitable measure for them to implement.</p><p>The walkthrough includes help with completing the essential clauses of these contracts and also minimises the costs of putting these into place. The ICO is also aiming to incorporate an online tool that can automatically generate these contracts.</p><h3 class="article-body__section" id="section-prospects-of-39-no-deal-39-are-rising"><span>Prospects of 'no deal' are rising</span></h3><p>The guidance has been issued amid political uncertainty surrounding the draft Withdrawal Agreement, with a host of voices both domestically and in Europe warning the prospects of no deal' are rising.</p><p>The likelihood of the Theresa May's agreement securing enough support by MPs is low, with the Prime Minister repeatedly claiming the only other two options on the table if her deal is rejected are no deal' and no Brexit'.</p><p>The guidance sets out a number of key examples of organisations that may be affected by the change in circumstance.</p><p>No-deal withdrawal wouldn't impact, for instance, a hotel in Cornwall that takes bookings from individuals across Europe that provide their personal details including names, and contact details, and sends personal data back to them.</p><p>The international transfers' aspect of no-deal withdrawal could affect the business if it uses a cloud IT service which stores or processes the data anywhere outside of the UK; for example an AWS server in the Netherlands.</p><p>Restricted transfers can, however, continue if this is covered by an adequacy decision made by the UK government.</p><p>The UK government also intends to recognise previous EU adequacy decision made by the European Commission prior to the exit date. These will allow restricted transfers to continue for those organisations whose data activities have already been covered by an adequacy decision.</p><p>The only exception, the ICO says, regards the <a href="https://www.itpro.com/privacy/31461/eu-parliament-sets-two-month-deadline-for-privacy-shield-suspension" target="_blank" data-original-url="https://www.itpro.com/privacy/31461/eu-parliament-sets-two-month-deadline-for-privacy-shield-suspension">EU/US Privacy Shield</a>, which the UK will not be a part of without a deal, as it is a specific EU/US arrangement.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ China erases citizens’ social media accounts in widespread censorship campaign ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/32353/china-erases-citizens-social-media-accounts-in-widespread-censorship</link>
                                                                            <description>
                            <![CDATA[ Following the country's restriction on media outlets, China have exercised their censorship laws eliminating 9,800 social media accounts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5MFR3zJ3YDMvWy4HcrzhYG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QTdNJdBeaYkmGH2MZTNPim-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 13 Nov 2018 13:50:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QTdNJdBeaYkmGH2MZTNPim-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[china]]></media:description>                                                            <media:text><![CDATA[china]]></media:text>
                                <media:title type="plain"><![CDATA[china]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QTdNJdBeaYkmGH2MZTNPim-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In the early hours of the morning, it was reported that China's primary security authority has deleted 9,800 social media accounts due to inappropriate content, reported <a href="https://uk.reuters.com/article/uk-china-censorship/china-scours-social-media-erases-thousands-of-accounts-idUKKCN1NI0CG" target="_blank"><em>Reuters</em></a>.</p><p>The Cyberspace Administration of China (CAC) made a statement in relation to its campaign launched on 20 October 2018, saying it had erased a massive amount of the increasingly prevalent 'self-media' accounts that emerged in recent months.</p><p>The accounts were erased for "spreading politically harmful information, maliciously falsifying (Chinese Communist) party history, slandering heroes and defaming the nation's image".</p><p>The wiped accounts had appeared on two of China's premier social media platforms, WeChat and Weibo. Tencent and Sina, the two companies who own and operate the platforms were also summoned by the CAC and admonished for failing to prevent "uncivilized growth" and causing "all kinds of chaos".</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/privacy/30981/google-gets-caught-up-in-russian-internet-censorship-battle" data-original-url="/privacy/30981/google-gets-caught-up-in-russian-internet-censorship-battle">Google gets caught up in Russian internet censorship battle</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/611005/internet-censorship-who-decides" data-original-url="/611005/internet-censorship-who-decides">Internet censorship: Who decides?</a></p></div></div><p>The term 'self-media' is used to refer to social media channels, much like ones found on Snapchat's stories, posing as genuine media outlets. The channels produce original content which spans a breadth of topics but aren't officially registered with authorities.</p><p>The prevalence and popularity of these accounts have been largely attributed to the interesting and sometimes sensational content that they churn out, which comes as a breath of fresh air from the state-regulated official sources which like to keep content produced in Chinese cyberspace in-line with communist party ideals.</p><p>Despite freedom of expression being codified in China's constitution, the one-party state does allow some leniency but keeps a strict limit on the extent to which the party can be criticised.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FCC admits net neutrality DDoS attack was work of fiction ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/it-regulation/31645/fcc-admits-net-neutrality-ddos-attack-was-work-of-fiction</link>
                                                                            <description>
                            <![CDATA[ FCC chairman Ajit Pai pins error on former CIO providing "inaccurate information" ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2YDTi2g53fudUdo7qFTL95</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7QKp7oZuufEDLQLhje6AVH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Aug 2018 11:21:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7QKp7oZuufEDLQLhje6AVH-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7QKp7oZuufEDLQLhje6AVH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US Federal Communications Commission has admitted that the alleged hack which blocked pro-net neutrality comments never happened, sparking outrage amongst activists.</p><p>FCC Chairman Ajit Pai released <a href="https://docs.fcc.gov/public/attachments/DOC-353298A1.pdf" target="_blank">a statement</a> yesterday confirming that the outage that prevented many people from leaving comments on the FCC's net neutrality proposal last May was not caused by "external" actors as previously suggested, but instead by inadequate IT systems, implying that it was overwhelmed by the sheer volume of commenters.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/31143/us-senate-saves-net-neutrality-for-now" data-original-url="/policy-legislation/31143/us-senate-saves-net-neutrality-for-now">US Senate saves net neutrality – for now</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/networking/28043/what-is-net-neutrality" data-original-url="/networking/28043/what-is-net-neutrality">What is net neutrality?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/31103/net-neutrality-laws-are-now-officially-dead" data-original-url="/network-internet/31103/net-neutrality-laws-are-now-officially-dead">Net neutrality laws are now officially dead</a></p></div></div><p>The statement follows the conclusion of an investigation by the FCC's Inspector General into the agency's claims that it fell victim to a DDoS attack. Pai has primarily blamed ex-CIO David Bray for spreading the DDoS story, as well as implying that the technical failings were the result of mismanagement by the Obama-era FCC leadership.</p><p>"I am deeply disappointed that the FCC's former Chief Information Officer (CIO), who was hired by the prior Administration and is no longer with the Commission, provided inaccurate information about this incident to me, my office, Congress, and the American people," Pai said in a statement.</p><p>"It has become clear that in addition to a flawed comment system, we inherited from the prior Administration a culture in which many members of the Commission's career IT staff were hesitant to express disagreement with the Commission's former CIO in front of FCC management."</p><p>He also stated that the organisation's Electronic Comment Filing System (ECFS) was deeply in need of updating, and the FCC has pledged to improve it with the help of a congressional grant.</p><p>Many campaigners, however, are now calling for Congress to reinstate the net neutrality rules rolled back by the FCC, with Fight for the Future's deputy director Evan Greer arguing that the FCC's actions have rendered the pretext for the repeal "illegitimate".</p><p>"Under Ajit Pai's leadership, the FCC sabotaged its own public comment process," she said in <a href="http://tumblr.fightforthefuture.org/post/176708614273/breaking-fcc-finally-admits-that-alleged-ddos" target="_blank">a statement</a>. "From ignoring millions of fraudulent comments using stolen names and addresses to outright lies about DDoS attacks that never happened, the agency recklessly abdicated its responsibility to maintain a functional way for the public to be heard."</p><p>"Pai attempts to blame his staff, but this happened on his watch, and he repeatedly obstructed attempts by lawmakers and the press to get answers. The repeal of net neutrality was not only unpopular, it was illegitimate. Congress must act now to pass the CRA resolution to reverse this decision and restore basic protections for Internet freedom."</p><p>The outage that the FCC initially blamed on a DDoS attack occurred last year, while the regulator was still in the process of gathering feedback and comments on whether or not to keep net neutrality rules in place. Powerful telco lobbies were in favour of repealing the rules, but polls showed that most ordinary people supported them, and the FCC's request for comment represented one of the only opportunities for them to make their opinions heard.</p><p>This was fuelled particularly by comedian John Oliver, after a segment on net neutrality from his HBO show <em>Last Week Tonight</em> went viral. The segment included simple instructions on how to leave a comment in support of net neutrality, and the FCC was promptly flooded with over 1.6 million responses. Shortly afterwards, the ECFS experienced a major outage, leaving people unable to post any further comments.</p><p>Although it's impossible to say for certain that the influx of feedback was a direct result of Oliver's segment, it's highly likely - particularly as the same thing happened in 2014. In a separate episode three years earlier, Oliver also issued a similar plea to users asking them to get in touch with the FCC to support net neutrality rules, after which the regulator received another deluge of comments.</p><p>The FCC's comments system went down in this instance too but, at the time, the watchdog (then led by Democrat Tom Wheeler) blamed the outage on the unexpected spike in traffic, coupled with old and ailing software.</p><p>While logic (and Pai's statement) would suggest that the same thing happened last year, the FCC instead insisted that the recent outage was the result of a DDoS attack. FCC officials also told <a href="https://gizmodo.com/fcc-emails-show-agency-spread-lies-to-bolster-dubious-d-1826535344">reporters that the 2014 outage was also caused by a DDoS and that Wheeler was covering it up, according to a <em>Gizmodo</em> report</a>. </p><p>Multiple sources have disputed these accounts, citing the FCC's refusal to produce any evidence in support of its claims. In fact, the Government Accountability Office is still in the midst of an independent investigation into the FCC's claims. This investigation is separate from the Inspector General's report, which has not yet been made public.</p><p>"The Inspector General Report tells us what we knew all along," said Jessica Rosenworcel, a Democrat member of the FCC and staunch defender of net neutrality; "The FCC's claim that it was the victim of a DDoS attack during the net neutrality proceeding is bogus."</p><p><em>Image: Shutterstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ People are more aware of their data rights than ever before, says ICO ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/information-commissioner/31565/people-are-more-aware-of-their-data-rights-than-ever-before-says-ico</link>
                                                                            <description>
                            <![CDATA[ Watchdog issued a record £5 million in fines to organisations in 2017/18 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gRRi1q1Pxs1s9L9jLSPzmw</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UNFKPhh6QzWV4ekNzN5YLA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 24 Jul 2018 10:28:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UNFKPhh6QzWV4ekNzN5YLA-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UNFKPhh6QzWV4ekNzN5YLA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The public has growing increasingly aware of its privacy rights over the last 12 months, according to the Information Commissioner's Office (ICO), which regulates data protection in the UK.</p><p>The data watchdog highlighted an increase in complaints and self-reported breaches, as well as a significant rise in calls from the public and organisations, as evidence that privacy and data protection matters have become more important to people.</p><p>Data protection complaints rose by 14.5% in 2017/18, according to the ICO's <a href="https://ico.org.uk/media/about-the-ico/documents/2259463/annual-report-201718.pdf" target="_blank">annual report</a>, released this week, and it recorded a 29% rise in self-reported data breaches from organisations, from 2,447 to 3,156. Self-reporting is now mandatory under GDPR, so the number is expected to rise yet further over the course of 2018/19.</p><p>Moreover, the data regulator received almost 46,000 more calls than the previous year - an increase of 24.1% - while the number of live chats requested rose by 61.5%. Approximately two-thirds, 68%, of enquiries were from members of the public while the remainder were from organisations - with the vast majority of enquiries, 85%, concerning the DPA.</p><p>"This is an important time for privacy rights, with a new legal framework and increased public interest," said information commissioner Elizabeth Denham.</p><p>"Transparency and accountability must be paramount, otherwise it will be impossible to build trust in the way that personal information is obtained, used and shared online."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/31348/bt-walloped-with-70k-ico-fine-for-5-million-spam-emails" data-original-url="/marketing-comms/31348/bt-walloped-with-70k-ico-fine-for-5-million-spam-emails">BT walloped with £70K ICO fine for 5 million spam emails</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/31193/ico-inundated-with-smb-calls-asking-for-gdpr-guidance" data-original-url="/general-data-protection-regulation-gdpr/31193/ico-inundated-with-smb-calls-asking-for-gdpr-guidance">ICO 'inundated' with SMB calls asking for GDPR guidance</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/31483/facebook-fined-500000-by-the-ico-following-cambridge-analytica-data-scandal" data-original-url="/policy-legislation/31483/facebook-fined-500000-by-the-ico-following-cambridge-analytica-data-scandal">Facebook fined £500,000 by the ICO following Cambridge Analytica data scandal</a></p></div></div><p>The ICO issued 1.29 million in fines for serious failures under <a href="https://www.itpro.com/data-protection/28085/what-is-the-data-protection-act-1998" target="_blank" data-original-url="https://www.itpro.com/data-protection/28085/what-is-the-data-protection-act-1998">the old Data Protection Act 1998 (DPA)</a>. These were issued alongside 138,000 in fines to charities for unlawfully processing personal data, and a further 80,000 penalty issued to a data broking organisation.</p><p>Breaches of the Privacy and Electronic Communications Regulations (PECR), meanwhile, saw 26 organisations fined a collective 3.28 million for nuisance calls and spam texts, altogether amounting to the greatest number, and amount, of penalties the ICO has issued in its history.</p><p>The watchdog launched 19 prosecutions in 2017/18 resulting in 18 convictions under the DPA, and issued a further six cautions. One highlight mentioned in the report was the ICO's ongoing investigation into 30 organisations, including Facebook and Cambridge Analytica, into the misuse of personal data in political campaigning.</p><p>As part of these investigations, the regulator <a href="https://www.itpro.com/policy-legislation/31483/facebook-fined-500000-by-the-ico-following-cambridge-analytica-data-scandal" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/31483/facebook-fined-500000-by-the-ico-following-cambridge-analytica-data-scandal">levied a 500,000 fine against Facebook earlier in July</a> - the maximum possible fine under the old DPA - for two breaches of the 1998 act.</p><p>Because the offences had been committed prior to 25 May, they were not adjudicated under GDPR - which carries with it a maximum fine of 20 million, or 4% of an organisation's global annual turnover (whichever is higher), for the most serious breaches.</p><p>In the lead up to the European Union's (EU's) tough new set of data laws coming into force, the ICO also offered guidance and advice to organisations racing to comply - including the set-up of a small business helpline, and the launch of a UK-wide 'Your Data Matters' awareness campaign.</p><p>"At the time of my previous annual report the office was heavily involved in preparations for the upcoming General Data Protection Regulation (GDPR), working on guidance with our EU counterparts and identifying how our own processes needed to change to take account of the GDPR," Denham continued.</p><p>"In 2017/18 this activity has upped a few gears and involved many more staff. We have produced well received guidance on the new law for organisations, and have also continued a successful change management process to ensure our internal processes and workflows are up to the demands placed upon us by GDPR."</p><p><em>Picture: Information commissioner Elizabeth Denham</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Facebook: We won't remove fake news ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/31511/facebook-we-wont-remove-fake-news</link>
                                                                            <description>
                            <![CDATA[ Revelation follows Ofcom's threat to regulate social media platforms in a bid to curb misinformation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vyso8hGaqqVRzQo6V3WJER</guid>
                                                                                                                            <pubDate>Mon, 16 Jul 2018 09:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                                        <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Facebook doesn't plan to remove fake news from its platform, believing false information doesn't violate its terms and conditions, despite the threat of regulation looming for social media firms that don't improve their accountability.</p><p>In a media presentation at its Manhattan offices last week, the social network said that removing fabricated posts would be "contrary to the basic principles of free speech" as publishers had very different points of view, instead saying it would demote posts in the news feed that it deems to be fake.</p><p><em>CNN</em> reporter Oliver Darcy <a href="https://money.cnn.com/2018/07/11/media/facebook-infowars/index.html" target="_blank">asked the company</a> how it could claim to be tackling the spread of fake news while it allowed infamous theory conspiracy website InfoWars to remain on the platform.</p><p>InfoWars produces online talk shows and boasts 900,000 followers on Facebook, but the site has been known to publish false information and conspiracy theories, claiming that the Sandy Hook school shooting was faked by the US government.</p><p>In response to <em>CNN</em>, the head of Facebook's news feed, John Hegeman, said: "We created Facebook to be a place where different people can have a voice. Just for being false that doesn't violate the community standards."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/facebook-at-work/30501/facebook-to-test-the-down-vote-to-tackle-fake-news-and-abusive-comments" data-original-url="/facebook-at-work/30501/facebook-to-test-the-down-vote-to-tackle-fake-news-and-abusive-comments">Facebook to test the ‘down vote’ to tackle fake news and abusive comments</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/28446/google-and-facebook-reveal-tools-to-battle-fake-news" data-original-url="/strategy/28446/google-and-facebook-reveal-tools-to-battle-fake-news">Google and Facebook reveal tools to battle fake news</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/31428/facebooks-750-page-response-to-congress-repeats-itself-437-times" data-original-url="/policy-legislation/31428/facebooks-750-page-response-to-congress-repeats-itself-437-times">Facebook's 750-page response to Congress repeats itself 437 times</a></p></div></div><p>"We see pages on both the left and the right pumping out what they consider opinion or analysis but others call fake news," Facebook said in a follow-up tweet. "We believe banning these Pages would be contrary to the basic principles of free speech."</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1017477222083411968"></a></p></blockquote><div class="see-more__filter"></div></div><p>In a second tweet, Facebook said it would "demote" individual posts that are reported as being fake news, and any pages or domains that repeatedly share it.</p><p>In February the social network trialled a <a href="https://www.itpro.com/facebook-at-work/30501/facebook-to-test-the-down-vote-to-tackle-fake-news-and-abusive-comments" data-original-url="https://www.itpro.com/facebook-at-work/30501/facebook-to-test-the-down-vote-to-tackle-fake-news-and-abusive-comments">'downvote'</a> feature to combat offensive and misleading content, but regulators are cracking down on social media around the spread of misinformation.</p><p>Writing in <a href="https://www.thetimes.co.uk/edition/comment/it-s-time-to-regulate-social-media-sites-that-publish-news-pxsg9t3fv" target="_blank"><em>The Times</em></a> on Friday, Ofcom chief executive Sharon White said that social media platforms need to be "more accountable" in how they police content.</p><p>"The argument for independent regulatory oversight of large online players has never been stronger," she said.</p><p>"In practice, this would place much greater scrutiny on how effectively the online platforms respond to harmful content to protect consumers, with powers for a regulator to enforce standards and act if these are not met."</p><p>White also highlighted Ofcom research that suggested users have little trust in social media content, with only 39% considering it to be a trustworthy news source, compared to 63% for newspapers and 70% for TV.</p><p><em>Picture: Shutterstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Electoral regulator calls for changes to voting law to save democracy  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/31377/electoral-regulator-calls-for-changes-to-voting-law-to-save-democracy</link>
                                                                            <description>
                            <![CDATA[ The Electoral Commission says urgent improvements needed to ensure transparency for voters in the digital age ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">awaJ1RfW2T6xduYSPnzECV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bqxosWB4jkNC5uBgLjvQnX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 26 Jun 2018 09:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bqxosWB4jkNC5uBgLjvQnX-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bqxosWB4jkNC5uBgLjvQnX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Electoral Commission has called for urgent reforms to the electoral law saying that British democracy "may be under threat" following a series of online political scandals.</p><p>In a report called "Digital campaigning: increasing transparency for voters" the elections regulator is calling on Westminster and the UK's devolved governments to combat the largely unregulated world of online political campaigning.</p><p>The Commission wants the government and social media companies to improve transparency around the targeting of voters online and combat misinformation, the misuse of personal data and overseas interference in elections.</p><p>"The last decade has seen an explosion in the use of digital tools in political campaigning," the report states. "Perceptions have also changed in that time.</p><p>"The use of social media was first heralded as a positive revolution in the mass engagement of voters. More recently we have seen serious allegations of misinformation, misuse of personal data, and overseas interference. Concerns that our democracy may be under threat have emerged."</p><p>To combat this threat, the Electoral Commission has called for a change in the law to require all digital political campaign material to state who paid for it and for a new legislation to make it clear that spending in UK elections and referendums by foreign organisations and individuals is not allowed.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/30795/cambridge-analytica-and-facebook-what-happened-and-has-it-impacted-any-votes" data-original-url="/data-insights/30795/cambridge-analytica-and-facebook-what-happened-and-has-it-impacted-any-votes">Cambridge Analytica and Facebook: What happened and has it impacted any votes?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/30792/cambridge-analytica-facebook-scandal" data-original-url="/data-protection/30792/cambridge-analytica-facebook-scandal">Cambridge Analytica: US Congress probes data firm set up by ex-Cambridge Analytica employee</a></p></div></div><p>It also calls for political campaigns to declare their spending soon after or during a campaign and more detailed paperwork on how they spend money online. It would also like to increase the maximum fine it can impose on organisations and individuals who break the rules. The current limit is 20,000 per offence.</p><p>"Urgent action must be taken by the UK's governments to ensure that the tools used to regulate political campaigning online continue to be fit for purpose in a digital age," said Sir John Holmes, chair of the Electoral Commission.</p><p>"Implementing our package of recommendations will significantly increase transparency about who is seeking to influence voters online, and the money spent on this at UK elections and referendums."</p><p>The interventions come in the aftermath of the 2016 EU referendum. The regulator has a pending report due next month into Vote Leave spending and <a href="https://www.bbc.co.uk/news/uk-politics-44567588" target="_blank">according to a leaked copy of the investigation obtained by the BBC</a>, it is likely to find the Brexit campaign broke spending rules.</p><p>The Commission has also welcomed social media companies' commitments to political campaigning transparency and called on them to deliver their proposals for online databases of political adverts in time for UK elections in 2019 and 2020.</p><p>Following the <a href="https://www.itpro.com/data-insights/30795/cambridge-analytica-and-facebook-what-happened-and-has-it-impacted-any-votes" data-original-url="https://www.itpro.com/data-insights/30795/cambridge-analytica-and-facebook-what-happened-and-has-it-impacted-any-votes">Cambridge Analytica scandal</a> that saw online voters influenced during Donald Trump's presidential campaign, the Commission also called on social media companies to put in place new controls to check that people or organisations who want to pay to place political adverts about elections and referendums in the UK are legally permitted to do so.</p><p><em>Picture: Shutterstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is information governance? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/strategy/29842/what-is-information-governance</link>
                                                                            <description>
                            <![CDATA[ What structures, policies, procedures, processes and controls are needed to manage information in the enterprise? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oEstyHZCgbzoVSE5hdbAzq</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PJN5BvWNyEsCLAhi3zctEA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 01 Jun 2018 07:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PJN5BvWNyEsCLAhi3zctEA-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[information]]></media:description>                                                            <media:text><![CDATA[information]]></media:text>
                                <media:title type="plain"><![CDATA[information]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PJN5BvWNyEsCLAhi3zctEA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Businesses are constantly seeking to ensure they are fully compliant with regulatory demands over data sharing and information governance - especially in light of <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a>, which came into force on 25 May 2018. But beyond this, large organisations are always seeking to improve their data and information governance skills more generally.</p><p>Information governance, according to the <a href="http://www.datagovernance.com/adg_data_governance_definition" target="_blank">Data Governance Institute</a>, is a system of decision rights and accountabilities for information-related purposes. The institute says these are "executed according to agreed-upon models, which describe who can take what actions with what information, and when, under what circumstances, using what methods".</p><p>This may also offer employees a reliable avenue for dealing with the host of different regulatory and legal hurdles that apply to handling customer or user data. With various pieces of legislation in force simultaneously this could be confusing.</p><p>These include <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">The Computer Misuse Act 1990</a>; <a href="https://www.itpro.com/data-protection/28085/what-is-the-data-protection-act-1998" target="_blank" data-original-url="https://www.itpro.com/data-protection/28085/what-is-the-data-protection-act-1998">The Data Protection Act 1998</a>; The Human Rights Act 1998; The Freedom of Information Act 2000; and The Privacy and Electronic Communication Regulations 2003, as well as the GDPR-inspired Data Protection Act 2018.</p><h3 class="article-body__section" id="section-important-targets"><span>Important targets</span></h3><p>Information governance offers a framework to bring together aspects of data handling into one single, over-arching policy, ensuring it complies with all relevant data laws. This not only makes it easier for employees to access the information they need to run their day-to-day tasks, but it also means the entire organisation is more likely to be compliant.</p><p>Information Governance can also help cut costs associated with the collection, management and storage of data, allowing firms to take advantage of low-cost cloud services they perhaps would not have been able to use in the past, because of the sensitivity of the data they hold, for example.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/30107/get-gdpr-ready" data-original-url="/general-data-protection-regulation-gdpr/30107/get-gdpr-ready">Seven steps to GDPR compliance</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/607521/survey-firms-lack-information-governance" data-original-url="/607521/survey-firms-lack-information-governance">Survey: Firms lack information governance</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/29477/uk-moves-to-mirror-gdpr-with-data-protection-bill" data-original-url="/data-protection/29477/uk-moves-to-mirror-gdpr-with-data-protection-bill">UK moves to mirror GDPR with Data Protection Bill</a></p></div></div><p>Because the data is already compliant before employees access it, workers are able to use it freely to make better business decisions, ultimately resulting in higher levels of productivity across the entire organisation.</p><p>As part of information governance, the company will also need to outline and adhere to their individual data strategies, policies and standards, ensuring everyone in the organisation understands them and is using them as a unified entity. There's no point having policies and strategies if not everyone is using or sticking to them, including management and the board.</p><p>Information governance should be the centre of IT strategy and it should be used to dictate how data management projects and services are developed and implemented.</p><h3 class="article-body__section" id="section-measuring-success"><span>Measuring success</span></h3><p>Organisations can measure the success of their information governance efforts against the following:</p><ul><li>Has the application of information governance practices fixed any outstanding problems that led to its original deployment?</li><li>Are data standards well-defined and comprehended by users who need to be mindful of them?</li><li>Is data and information of a superior quality or of better use as a consequence of the modifications made?</li><li>Do users within an organisation recognise the main parts they play in information governance within their department?</li></ul><h3 class="article-body__section" id="section-best-practices"><span>Best practices</span></h3><p>When implementing an effective information governance strategy, it is crucial to follow best practices.</p><p><strong>Have executive sponsorship</strong> the success of information governance within an organisation often;rides on executive sponsorship of the initiative in order for it to remain a priority.</p><p><strong>Know your starting point</strong> Before you can figure out where your information governance initiative takes you, you need to assess your starting point and incorporate this into your initial governance strategy.</p><p><strong>Be realistic</strong> Always make sure that your organisation's information governance project has a realistic and achievable starting point. Start small, build up and develop successes to promote information governance to the wider user base.</p><p><strong>Have checkpoints</strong> with specific milestones, an organisation can check what is and isn't working in order to make changes and ensure the long-term viability and sustainability of the project.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google gets caught up in Russian internet censorship battle ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/privacy/30981/google-gets-caught-up-in-russian-internet-censorship-battle</link>
                                                                            <description>
                            <![CDATA[ US search giant accused of helping Telegram chat service evade Russian ban ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">myUxXoEr8CzQLNRDQFakK1</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mknbZyZwToY6qUbwayj3KC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Apr 2018 10:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mknbZyZwToY6qUbwayj3KC-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mknbZyZwToY6qUbwayj3KC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Gmail and Google Search have been partially blocked in Russia after the state's communication watchdog accused the US search engine of helping people continuing to use the banned chat service Telegram in the country.</p><p>Russia blocked certain Google IP addresses in Moscow, St. Petersburg, Kazan, Krasnoyarsk and other cities yesterday after they were added to Roskomnadozor's list of banned sites.</p><p>"Google hasn't complied with Roskomnadzor requests and, despite a court ruling, keeps allowing Telegram Messenger to use its IP addresses to operate in Russia," the watchdog said on its official page on the VK.com social network. "Therefore, Roskomnadzor included some Google IP addresses into a register of banned internet resources."</p><p>Gmail, Google Search and some Android app push notifications are affected, according to <a href="https://techcrunch.com/2018/04/22/google-confirms-some-of-its-own-services-are-now-getting-blocked-in-russia-over-the-telegram-ban" target="_blank"><em>TechCrunch</em></a>. </p><p>This is the latest development in Russia's war on Pavel Durov's encrypted Telegram messenger service, which Russian authorities had started blocking on 16 April after Durov failed to comply with legislation requiring the company to give the federal security services access to users' encrypted messages.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/networking/27555/russia-has-officially-banned-linkedin" data-original-url="/networking/27555/russia-has-officially-banned-linkedin">Russia has officially banned LinkedIn</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-attacks/30946/security-agencies-warn-of-russian-cyber-campaign-against-company-networks" data-original-url="/cyber-attacks/30946/security-agencies-warn-of-russian-cyber-campaign-against-company-networks">Security agencies warn of Russian cyber campaign against company networks</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/national-cyber-security-centre-ncsc/30355/russian-cyber-attack-would-cripple-uk-infrastructure-warns" data-original-url="/national-cyber-security-centre-ncsc/30355/russian-cyber-attack-would-cripple-uk-infrastructure-warns">Russian cyber attack would cripple UK infrastructure, warns defence secretary</a></p></div></div><p>Despite the ban, Telegram users were able to continue accessing the service by using VPNs and hopping from various IP addresses on sites like Google to bypass the block.</p><p>The decision to block Telegram has also forced Kremlin officials to switch to Mail.ru's ICQ chat service.</p><p>In a post on his own Telegram channel, Durov warned that Russia is heading into an era of "full-scaled internet censorship", and that this was its strongest crackdown on internet freedom so far.</p><p>"For seven days Russia has been trying to ban Telegram on its territory - with no luck so far. I'm thrilled we were able to survive under the most aggressive attempt of internet censorship in Russian history with almost 18 million IP addresses blocked.</p><p>"My thanks to all the members of the #DigitalResistance movement. Keep up your great work setting up socks5-proxies and VPNs and spreading them among your Russian friends and relatives. They will be needed as the country descends into an era of full-scale internet censorship."</p><p>A Google spokesperson told <em>TechCrunch</em>: "We are aware of reports that some users in Russia are unable to access some Google products, and are investigating those reports."</p><p><em>Picture: Shutterstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 3 reasons why Nadine Dorries is totally wrong about password sharing ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/30089/3-reasons-why-nadine-dorries-is-totally-wrong-about-password-sharing</link>
                                                                            <description>
                            <![CDATA[ Frustration abounds as MPs expose their backwards security practises ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uiCsMdYaUAaaM2z13NyyhB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/T5otn7g3g38REfj2ZVHKvY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 04 Dec 2017 17:33:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/T5otn7g3g38REfj2ZVHKvY-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[facepalm sad social media]]></media:description>                                                            <media:text><![CDATA[facepalm sad social media]]></media:text>
                                <media:title type="plain"><![CDATA[facepalm sad social media]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/T5otn7g3g38REfj2ZVHKvY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Shh - what's that? If you listen very, very carefully, you'll hear it; it's the sound of countless security experts smashing their heads against their keyboards in frustration. The cause, <a href="https://www.itpro.com/security/28380/deeply-misguided-tech-industry-rejects-rudd-s-attack-on-encryption" target="_blank" data-original-url="https://www.itpro.com/security/28380/deeply-misguided-tech-industry-rejects-rudd-s-attack-on-encryption">as so often before</a>, is the government's laughable attitude to data privacy and cyber security.</p><p>Where to begin with this latest shambles? You may recall that First Secretary of State Damian Green was allegedly found to have rude and naughty pictures of the pornographic variety on his government-issued computer, which Green denies.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29705/what-are-biometrics" data-original-url="/security/29705/what-are-biometrics">What are biometrics?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28576/dreaming-of-a-world-without-passwords" data-original-url="/security/28576/dreaming-of-a-world-without-passwords">Dreaming of a world without passwords</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="/security/29093/what-is-phishing">What is phishing?</a></p></div></div><p>Nadine Dorries, Conservative MP for Mid Beds, leapt to Green's defence over the weekend, pointing out that if porn was found on Green's computer, it may not have been him who was downloading and/or viewing it on taxpayer time. After all, she said, her staff use her login to access her official computer all the time. Even interns on exchange programmes!</p><p>Er, sorry... What?</p><p>Yes folks, you read that correctly - Dorries is so free and easy with her access credentials that she even hands them out to visiting exchange students. To make matters worse, several of her fellow MPs admitted they also share their login details with staff, including Nick Boles, Will Quince and Robert Syms.</p><p>Of course, Dorries was quick to downplay the seriousness of her actions, stating that all she has on her computer is a shared email account, with no access to government documents. Boles, similarly, said that only the four people he employs to deal with correspondence from constituents have access to the passwords, which are regularly changed.</p><p>For the avoidance of doubt, let's be crystal clear: this is a dangerous, insecure and irresponsible practice. Under no circumstances should anyone be sharing one login between multiple staff members. There are numerous ways to ensure staff members can access a shared computer, mailbox or file storage system without having one login that simply gets passed around, and the fact that government MPs are apparently not using any of them is extremely alarming.</p><p>Dorries and co claim that sharing their login with staff isn't an issue, but let's take the time to unpick some of the many, many problems with these arguments.</p><p>Firstly, there's the issue of lateral movement. Dorries says that the only thing on the computer is a shared email account. Even if that's true, the computer itself is 'Westminster-based', and is likely to be connected to some kind of internal network. This opens up the possibility for lateral movement, using Dorries' machine as a way to gain access to a more important target within the network.</p><p>Then there's the issue of data protection. The shared mailbox used by the staff of Dorries and Boles presumably contains at least a partial list of constituents' names and email addresses, along with who knows what additional information shared as part of their correspondence. Behaviour like this puts all of that information at risk.</p><p>Last but not least, accountability is the biggest problem with using a shared login - and one that is best illustrated, ironically, by the very issue that prompted Dorries' admission in the first place. She is quite right in stating that if Green's access credentials were shared by his staff, there's no way of proving that it was him that was allegedly looking at porn, but that's a huge problem.</p><p>Let's imagine that, instead of perusing some nudes, the First Secretary of State was instead accused of using his computer to <a href="https://www.itpro.com/antivirus/30085/kaspersky-offers-hackers-100000-for-spotting-bugs" target="_blank" data-original-url="https://www.itpro.com/antivirus/30085/kaspersky-offers-hackers-100000-for-spotting-bugs">leak classified intelligence data to Russian agents</a>. With a single shared login, it's virtually impossible to trace the source of the leak back to the mole. If everyone has their own credentials, it's instantly obvious.</p><p>The concept of not sharing your username and password with anyone is a basic, fundamental tenet of cyber security best practice, and the tools to ensure that you shouldn't need to share your credentials have existed for years. Considering that the Tories are supposed to be the party of business, its own staff seem to be <a href="https://www.itpro.com/public-sector/29288/whatsapp-amber-not-getting-the-message" target="_blank" data-original-url="https://www.itpro.com/public-sector/29288/whatsapp-amber-not-getting-the-message">trailing laughably far behind the curve</a> when it comes to keeping up with industry security standards - which would be funny if it wasn't so alarming.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>