HMRC building
The KTN hope the guidelines will prevent information loses on the scale of HMRC

Cyber Security KTN issues privacy guidelines

Businesses should examine privacy implications at all stages of a project lifecycle

Written by Tom Young

Businesses must meet privacy requirements at four stages of any project lifecycle that may involve personal information, according to a report from the Cyber Security Knowledge Transfer Network (KTN).

In order to protect customer and employee details, privacy must examined at the initiation, planning, execution and closure of a generic project lifecycle.

This will ensure organisations comply with any future guidelines as well as current ones, according to Nigel Jones, head of KTN.

"Trying to engineer privacy as an afterthought never works," he said. "This is the only way organisations can be sure they are doing the right thing."

The paper recommends that:

- At the project initiation stage high level privacy objectives need to be set - project owners need to be aware of applicable privacy laws and regulations, such as the EU Data Protection Directive and the US Safe Harbour agreement.

- Technology envisaged for use by the project should also be subject to a high level review to ensure that appropriate privacy controls can be implemented.

- At The project-planning stage technologies such as encryption should be considered to protect consumer and client data on storage media, and Privacy Imapct Assessments should be carried out.

- Audits and change control procedures should continue after the closure of a project to ensure privacy requirements are continually addressed.

- Organisations should ensure that a senior role is established with overall responsibility for privacy, and ensure that responsibility is not delegated, as in the case of the HM Revenue and Customs lost discs fiasco.

- When a project is decommissioned all relevant information needs to be carefully destroyed.

- Customers should also as far as possible be given the choice of opting out of services that require the collection of additional personal information.

- Systems should have strong access controls, to ensure that personal information is only accessed by those who are authorised to do so. Access should be logged, and logs regularly audited.

- Where possible, personal information should be stored together with metadata that describes it and its intended use.

- Organisations should implement transparent procedures for remediation of errors in personal information, or privacy breaches.

The Cyber Security KTN is run by QinetiQ on behalf of the government’s Technology Strategy Board.

reader comments

related articles

Richard Thomas

Privacy watchdog to get new powers

Office will be given ability to spot check central government 22 Apr 2008

 

Phorm must be opt in

Controversial system must be opt in and keep information anonymous, says ICO 10 Apr 2008

Data watchdog to keep an eye on BT's Phorm trial

Information Commissioner's Office wants experts to scrutinise the technology 07 Apr 2008

Gateway reviews must look at privacy, says Information Commissioner

But Office of Government Commerce rejects use of assessments as standard 06 Mar 2008

M&S breached Data Protection Act

Watchdog rules loss of 26,000 employees' details on unencrypted laptop breaks the law 25 Jan 2008

Security research challenge gets £250,000 funding

Vendor backed network to provide rewards for tackling particular security issues 08 Apr 2008

Information Commissioner says database threatens way of life

Calls for public debate about Government plans 16 Jul 2008

Watchdog slams Skipton over data loss

Loss of 14,000 customer records breached Data Protection Act 21 Feb 2008

related whitepapers

today's top stories

Review 2008: Top 10 most-read stories of the year

We reveal the 10 articles from 2008 that you read more than any others on Computing.co.uk during the year 02 Jan 2009

A year of lost data, lost jobs and a "dead' Jobs

Our month-by-month review of a year that witnessed a flood of redundancies, data blunders and economic turmoil ­- but at least Steve Jobs still has his health 18 Dec 2008

Review 2008: Top 10 IT innovations

Our latest look back at the year highlights the top technology innovations of 2008 22 Dec 2008

Review 2008: Top 10 IT leader interviews

We look back on the best of Computing's exclusive interviews with the most influential leaders in UK IT 22 Dec 2008

Review 2008: Top 10 financial services IT stories

Computing this year followed the turmoil in financial services and its consequences for IT. We look at the highlights of 2008 on how the sector is weathering the recession 22 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Should the government cut costs by scrapping major IT projects?

Should the government cut costs by scrapping major IT projects?

Tell us what you think

Previous poll results

Latest audio and video articles

Podcast imageAudio

Computing podcast - the highlights of 2008

The Computing team pick their personal favourites of the year 18 Dec 2008

Xperia X1Video

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1 12 Dec 2008

Latest in-depth articles

Eugene KasperskyAnalysis

Q&A: Kaspersky Lab's Eugene Kaspersky

Kaspersky Lab founder Eugene Kaspersky tells vnunet.com why the software industry could be losing its brightest stars to the world of online crime 30 Dec 2008

Mark LewisAnalysis

Q&A: EMC's Mark Lewis

Mark Lewis, president of EMC's content management and archiving division, discusses the firm's content management strategy with vnunet.com 31 Dec 2008

Advertisement

Primary Navigation