Posts Tagged ‘Euro’

Data loss compensation in Europe

Thursday, August 28th, 2008

Data loss is something you may read about frequently. You may have had your own details breached or likely know someone who was affected. It is far less likely that you know someone you was compensated due to data loss. When was the last time you heard of data loss compensation? It is quite possible that data about you has been lost and you were not informed. It is much less likely that you will ever be compensated for any data loss incident.

With all the coverage data loss stories get in the newspaper, television, radio and  indeed blogs is remarkable that most people will never have heard of a data loss compensation case let alone know someone who was compensated. This is not specific to Europe but given the existence of a Euro comissioner and data comissioners in every member state, Europe is a good place to start.

Data loss is on an upward climb. Data loss awareness has certainly not been left behind. The medias continued coverage of data loss stories is a good indication not necessarily of the dangers presented by data loss (which are very real) but more so of the keen interest the public have in data loss news stories.

Some may believe that a data loss news story about a bank or corporation is near punishment enough for that institution. This may have been the case some time ago when the number of data loss news stories was minimal compared to now. Today however, a single data loss story will struggle to stand out.

Large businesses appear to continue without great difficulty after a data breach. The situation has become so common that some people may consider the occasional data loss event as normal! How come?

Here are some of the reasons.

Sanction.

Some of the possible sanctions which exist for data loss may appear quite serious to the individual or the small business but given that sanctions are on a per incident basis and not on a per person affected basis they dont actually have much effect on the bottom line and therefore planning of a bank or large corporation. What effect will a fine of one or two million Euros have on a major financial institution?

Breach procedure.

The existence of data protection legislation and data commissioners is intended to provide a level of protection for the public. The number of cases has now got to such a level that an organisation can take the procedures adopted and outcomes of prior cases as a learning curve in how do deal with a breach from the organisations viewpoint. A basic example is that simply reporting an incident on time (no matter how serious the incident is) removes that incident from the worst case scenario list. Organisations will use this and spokespersons will repeatedly say things like “The incident was reported within an appropriate time frame”, giving credence to an organisation which has compromised individuals due to its own failure to implement safeguards.

Compensation.

Data loss compensation is the most important issue here. You are not entitled to compensation because an organisation lost your data. If you need to read that last line again, go ahead. This applies even if the company lost your name, address and bank account number. The data loss has to result in a specific problem such as a crime against you and you need to be able to clearly demonstrate the link. This is rare and unusual compared to the amount of people about whom data is lost.

Number of events.

The number of data loss events reduces the significance of any one story and therefore the impact on the organisation involved. The apparent across the board inability of large numbers of organisations to protect data is actually to a degree legitimising their inaction.

Compensation requirement.

Large fines for corporation are not working. Prosecution at CEO level is always difficult and could be unfair. It’s all too easy to say a CEO is responsible for the business but most moderate people would agree that a line must be drawn somewhere.

A small standardised data loss compensation amount per individual could change everything. This would result in large corporations increasing protection as one mass data loss could hurt. It would also provide recognition that to loose someones data in a manner which puts it in the wild is wrong and is a wrong against that person.

By all means if people were significantly affected by a data loss the door would be open for greater compensation at individual case level but one thing (of many) that is needed to greatly increase protection and data respect is a small per person per case standard amount.

This would not be difficult to implement in Europe (if the will is there) as we have a broadly common framework and this area is in its infancy (one hopes given the apparent lack of control) and clearly needs broad, common action.

The specifics of the amount are not important if it is small enough to be accepted by industry and large enough to make data loss prevention a serious issue.

If you liked that post, then try these...

Search storage 7 key Questions about disk based backup. They missed at least one. on October 9th, 2008
I got an email this morning from searchstorage.

Interview with David Whitelegg of itsecurityexpert.co.uk on September 23rd, 2008
Interview with David Whitlegg of itsecurityexpert.

Mobile phone content backup and some iPhone plans

Tuesday, July 29th, 2008

There have been a number of tacky products about for a while which allow users to backup up their phone. The most common is USB (Yuk) which involves many manual processes. (even if you then sent it to online backup)

More recently however we have had online phone backup enter the market with third party companies programming symbian. There would appear to be significant complications with this at present. It is a better method and when it matures it should be the standard way to backup phones.

Add to the above the possibilities if mobile phone companies entered the online phone market (just a matter of time) in a real sense. What could they do differently?  Well in a addition to the obvious of a central billing point, they could run continuous backup of your phone and make the data available anywhere and anytime. Nice. It’s coming soon, real soon and you want it. If you don’t want you need it.

And now off the track for some iPhone indulgence.

Let’s face it, we all want an iPhone. Not because of technology. Certainly not because of price. It is just so well designed. Many of us will wait for value. Some just can’t. I checked the Irish market (in passing) recently. O2 appear to have that market sown up so I decided not to surrender to them ’till they have taken their premium from the rich and actually decide to sell the iPhone in serious volume. After that I couldn’t help seeing iPhone info everywhere.

I noted that Vodafone have iPhone monthly plans at Euro 29.90 in Portugal and the same company Vodafone, using the same phone, iPhone have plans at Euros 59 in Italy.

There are only two possibilities here.

The first is that the two entry level packs offer the exact same deal. If this is the case, surely it is a very obvious example of price discrimination. Is it allowed?

The second is that the deals are different. If this is the case, Vodafone have forgotten that both countries are not just in the same region but in the Euro zone which is a market and more specifically a common market. On what basis can they decide the Italians need more talk time or that talk should be cheap in Portugal.

If only O2 hadn’t got the iPhone all sown up here, we would see what Vodafone think of the Irish. Maybe we are better off not knowing.

If you liked that post, then try these...

Bill Gates departs Microsoft for greater challenges. on June 30th, 2008
Unless you have been on an vacation in a different Galaxy, you will be aware that Bill Gates is leaving Microsoft.

Eurozone Mobile phone content probe and cleanup on July 17th, 2008
Euro action to clean up mobile phone services and content industry.