Close on the footsteps of its neighbouring countries, Ireland is also looking at the data protection rules with more details. According to these rules an organization should report a data breach incident to the authorities incase of any incidents involving loss of personal data of more than 100 people.
According to William Malcolm, a privacy lawyer with the law firm Pinsent Masons Ireland has had its share of high-profile data breaches which has spurred the creation of the code of practice.
As per the proposal by Ireland’s privacy regulator data losses will now be declared to Ireland’s Data Protection Commissioner in line the draft code of practice published by the Commissioner.
Can the organizations avoid reporting?
Yes, they can certainly avoid the report of data breach if their data is encrypted and protected by a strong password. In addition, they can also escape reporting if their devices are using a remote memory-wipe feature which is activated on the lost device.
Some experts foresee the masking of critical incidents as the problem with data breach notification guidelines. They believe that due to these rules there is a possibility that major incidents could get hidden and lesser known events exposed.
A couple of years ago, the government of Ireland had recommended the creation of an official guidance which would highlight the the time to report the incidents. The office of the data protection commissioner has published the proposed draftcode of practice on its Web site and starting June 18 it would be available for public comment.
According to Irish Data Protection Commissioner Billy Hawkes, “I have sought to bring forward a draft Code as quickly as possible after the Review Group report to respond to public concern in relation to organisations losing personal data under their control while at the same time not imposing an undue burden on those organisations”.
What if data loss involves less than 100 people?
If the loss incident involving less than 100 people includes sensitive personal data or financial information then that must be reported as well.
What would the report constitute?
The report would include the following:
- Type of the data compromised
- What action has been taken
- How people have been informed or the reason for not informing people
- What kind of actions have been taken to limit the problems for affected people.
Data Security with Alertsec Xpress
Why do data breach incidents happen in the first place? Perhaps your organization didn’t take the requisite steps or there was some level of negligence with the handling of data.
If you use a data security software a theft would simply be reduced to an insurance matter and cost of the hardware plus time to rebuild the laptop. That is certainly a small price to pay compared to what can happen if you lose confidential or senstive data. Alertsec Xpress offers a very good and easy-to-use laptop security service that includes more than the traditional software licensing model. Feel free to subscribe for your personal 30-day free trial.
Related articles by Zemanta
- Ireland publishes proposed data breach notification rules (go.theregister.com)
- ICO will not compel companies to report data losses (v3.co.uk)



![Reblog this post [with Zemanta]](http://img.zemanta.com/reblog_e.png?x-id=632f7850-4a96-40ff-95d7-f815879f95af)

![Reblog this post [with Zemanta]](http://img.zemanta.com/reblog_e.png?x-id=1204309d-513a-47f3-b997-53d587bc51fb)

