Security15.09.2013

Beware how you handle personal information

Data Security

Thousands of laptops and related hardware travel between workplaces and homes on a daily basis.

And while taking documents home is nothing new, all private and public entities processing personal information could soon face fines running into millions of rands, if the personal information of their clients, employees or others are breached.

The Protection of Personal Information Bill (PoPI) was passed by Parliament last month. The bill now needs to be signed by the President before it gets enacted. From the date of introduction of the legislation, companies will have one year to comply.

The legislation is based on the privacy guidelines of the European Union. Its introduction is essentially an effort to ensure that South Africa’s privacy laws are in line with those of its trading partners, so data can be exchanged without concerns.

While breaches in personal information are not uncommon, up until the legislation takes effect, there has been no law governing the disclosure of such breaches to those affected. In future, all such infringements would have to be reported to a still-to-be-appointed Regulator and made public.

Non-compliance could lead to fines of up to R10m per privacy infringement being imposed.

Daniella Kafouris, legal privacy leader at Deloitte, says one of the most common types of data breaches that occur within organisations is as a result of hacking – where someone exploit vulnerabilities in the information system to gain access to personal information of clients, employees or others.

Another area of concern is with regards to disgruntled employees.

Kafouris says it is quite easy for an employee to walk out of an organisation with a flash drive full of client details and to give it to a competitor. This would be an example of a data leakage, and it would have to be reported to the Regulator.

“It is quite easy for information to get lost, whether it is hard copy or soft copy. What we always advise towards, is preparing a solid incident management process where it doesn’t matter what incident occurs – you know exactly how to cope with it within your business. So your incident response as an organisation is an absolutely critical element of PoPI compliance,” she says.

In some cases it would be advisable to compel employees to lock their laptops at work or not to use flash drives at all.

However, this is not always an option and in some cases other measures would need to be taken – for example encrypting flash drives so that if it does get into the wrong hands, a password is needed to access the information. Having sufficient policies that govern employee behavior around this is also pertinent.

One of the weakest links is often a lack of communication between departments after an employee leaves an organisation, Kafouris says.

The link between the human resources (HR) department, the information technology (IT) department and facilities management is often inadequate. In many cases, HR does not tell the facilities department that an employee should no longer have access to the building or the IT department does not collect the laptop from the employee, she says.

The cost of compliance

Despite the far-reaching implications of the pending legislation, less than half of companies that participated in a recent Deloitte survey have started the road to compliance.

Kafouris says some companies are applying a wait and see approach. There also seems to be a lot of uncertainty about which department would be best suited to be tasked with compliance.

The low level of compliance is concerning. Kafouris says organisations that haven’t started the journey to compliance would probably need between two and four years to get ready.

“So the one-year compliance period isn’t nearly enough.”

In medium to heavy-regulated industries such as financial services and healthcare, the cost of compliance could be anything between R10m and R50m, she says.

If an organisation does not process a lot of personal information, the numbers would be substantially smaller.

However, the reputational damage that a company could suffer as a result of the public reporting of a security breach is probably one of the biggest compliance issues.

Internationally numerous companies have bore the brunt of a public outcry after private information was leaked.

Source: Moneyweb

More on security and privacy

Killing spam softly: POPI in South Africa

Beware attacks from possible no-spam list leak

Massive security flaw exposes Joburg residents’ private info

Show comments

Latest news

More news

Trending news

Poll

If you could only have one video streaming service, what would you choose?

View Results

Loading ... Loading ...
Sign up to the MyBroadband newsletter