Categories
Best practice ePrivacy Regulation Europe Legal & Compliance Strategy and Management UK

Will new EU ePrivacy law be the cause of more regulation frustration?

Despite timely advice, recent research shows that 32% of UK organisations are as yet unprepared for next year’s changes to data protection regulations (GDPR). But will this potentially costly failure to prepare be further compounded by a complementary and co-inciding law change – the EU ePrivacy law? The implications for the data driven marketing industry are far-reaching, in terms of how businesses can approach customers, collect and process data.

This content is for Free membership members only.
Register
Already a member? Log in here
Categories
Best practice Data Protection Europe GDPR Legal & Compliance Strategy and Management UK

Get your house in order ready for incoming data protection rule

Shape up or ship out: that’s the warning for those who fail to prepare for the imminent data protection rule. The European Commission’s plan for the first overhaul in data protection legislation in more than 20 years is unrelenting – and fast approaching. Are you ready?

This content is for Free membership members only.
Register
Already a member? Log in here
Categories
Global Insight Legal & Compliance Strategy and Management

Web analytics and safeguarding your site in the ‘age of impersonator bots’

The online experience can be affected by spammers attempting to boost interest in trending topics and attack bots trying to impersonate human users. Generally, these impersonator bots are up to no good; what can be done about them?

This content is for Free membership members only.
Register
Already a member? Log in here
Categories
Best practice Europe Legal & Compliance Strategy and Management UK

Why an ethical approach is the only way for charities to succeed in data driven fundraising

Adam Williams says responsible companies should operate a code of ethics that is sensitive to the person being targeted.

This content is for Free membership members only.
Register
Already a member? Log in here
Categories
Asia-Pacific Case Studies Eastern Europe Europe Global Legal & Compliance Strategy and Management

Tackling counterfeiting, protecting brands: case study

The growth of the internet has brought about many advantages for consumers, particularly when it comes to shopping. However, the internet also presents significant opportunities for counterfeiters and it is becoming easier to reach consumers in the online space with fake products.

This content is for Free membership members only.
Register
Already a member? Log in here
Categories
Best practice Legal & Compliance Strategy and Management UK

How businesses can protect their brands from online fraud

There are a number of steps which can be taken by brands to mediate the risk of online fraud.

This content is for Free membership members only.
Register
Already a member? Log in here
Categories
Europe In the News Legal & Compliance Strategy and Management USA

Data privacy fears threaten $250bn transatlantic trade

us-eu-flags-2The uncertainty is being fuelled by a double whammy of scepticism about how robust Privacy Shield is and fears that the alternative method, used by 80% of companies – the so-called standard contractual clauses (SCCs) – could be soon be rendered illegal.

According to a survey of 600 data professionals in the US and EU, only 40 US firms have so far adopted Privacy Shield, with just 34% intending to use the new data privacy framework, compared with 50% which used its Safe Harbour forerunner.

The situation is not being helped by EU data regulators sitting on the Article 29 Working Party (WP29). Although they approved the framework in late July, they have set off alarm bells by pledging to keep a close eye on how Privacy Shield develops.

Data privacy Shield assessment

At the time, they released a statement which said: “The first joint annual review will be a key moment for the robustness and efficiency of the Privacy Shield mechanism to be further assessed.”

US think tank the Brookings Institution has estimated that “digitally delivered services” between the EU and the US – including customer data storage – were worth nearly $250bn (£188bn) in 2015.

IAPP president and chief executive Trevor Hughes commented: “The legal uncertainty of standard contractual clauses and the scepticism about Privacy Shield may be a hangover effect from the Max Schrems case that invalidated Safe Harbour in the European courts. Clearly, organisations face an extremely complex regulatory landscape as they look to build their businesses for the digital future.

“It will be vital for them to employ privacy professionals at the highest levels of management to help navigate that landscape and capitalise on opportunity.”

Categories
Europe In the News Legal & Compliance Strategy and Management UK

Data breach has affected nearly a quarter of UK consumers

In a world where an ever-increasing number of transactions are carried out online – requiring consumers to share personal information – the threat of a data breach is never far away. In the last month alone, Netflix and Facebook have both been hacked and in June 2016, a breach at South Yorkshire Police Force’s website potentially put confidential data at risk.

According to new YouGov research commissioned by credit information provider, Equifax (YouGov online survey. Total sample size was 2,037 adults. Fieldwork undertaken between June 17-20 2016. Figures from YouGov Plc), nearly a quarter (23%) of UK consumers say that a company holding their personal information has experienced a data breach, with those in the South East being the most affected at 30% and residents in the North East being the least affected at 19%. When it comes to the generations, the 25-34-year-olds seem the most affected at 31%; the figure falling to just 18% for the over-55s.

Financial compensation after data breach expected

It seems that with the increased risk of a data breach, consumers’ expectations of how they are informed and assisted by any company holding their data are unsurprisingly high. Almost three-quarters (73%) of UK adults surveyed by YouGov on behalf of Equifax think companies should tell them that they have experienced a data breach at some point, with 63% expecting to be told within a few hours of the breach being discovered by the company. 61% would expect financial compensation if their personal data was misused as a result of the breach and 57% would expect to have a free monitoring service set up to alert them if their financial information is misused.

Not only do consumers expect fast action and compensation if their data is breached, companies also need to adhere to the Data Protection Act enforced by the ICO. Companies may receive a fine if they suffer a breach of customer data, and also may face legal action. Future regulation may also require organisations to notify all individuals if they suffer a breach.data breach equifax image1

Lisa Hardstaff, credit information expert at Equifax, explained: “A data breach isn’t just a huge logistical challenge for any organisation. It also can do serious damage to brand reputation, as our recent research revealed. 61% of consumers said they would be unlikely to purchase goods or services from a company if it had experienced a data breach in the past.

“It’s clear that consumers quite rightly expect companies to look after their data. But individuals have a part to play, too, in keeping their own details safe. It’s worth remembering that social media accounts hold a lot of personal information, giving fraudsters more than enough data to help them steal someone’s identity and rack up debt in their name. However, our latest research revealed that consumers are most worried about their bank account and credit card details being stolen (84%), while only 7% are worried about hackers gaining access to social media account login details, in the event of a breach.

“Fraudsters are continually evolving their methods and, while organisations tracking and stopping them do have high success rates, the financial incentive for fraudsters to invent new techniques means they stay one step ahead of those out to stop them. Consumer vigilance is therefore key and while the onus is on a business to take action to protect the personal information that has been hacked, there are steps consumers can take, too, including changing passwords.”

Categories
Asia-Pacific Australia Best practice Global Legal & Compliance Strategy and Management

Why action and transparency matter during a security breach

Data Theft 101: Renée Frappier discusses why improperly handling a security breach hurts businesses – and what your organisation should do instead.

This content is for Free membership members only.
Register
Already a member? Log in here
Categories
Europe In the News Legal & Compliance Strategy and Management UK

Charities face huge fines for ignoring opt-out service

charity fundraisingCharities that ignore the Fundraising Preference Service would still be in breach of the law – and liable for fines of up to £500,000 – despite the fact that it is not a statutory requirement, the UK Information Commissioner’s Office has confirmed.

Speaking at a recent conference in London, the ICO senior policy officer Richard Marbrow said the FPS would have legal status because the regulator would view consumer sign-ups as a withdrawal of consent to receive marketing communications.

Marbrow said some professionals had suggested charities would be able to ignore the service because it was non-statutory, but the ICO could pursue them for breaching the consent requirements of the Data Protection Act. DPA breaches carry a maximum fine of £500,000.

Charities opt-out service: FPS criticised

Although former Information Commissioner Christopher Graham initially criticised the FPS for being confusing, the regulator now wants the service to apply to all marketing communications, bringing it under the Privacy & Electronic Communications Regulations. Breaches of PECR carry a maximum fine of £250,000.

One study estimated that up to 30 million people could sign up to the FPS.

The move came as Graham’s successor Elizabeth Denham (pictured) took up the role from July 18. Ms Denham said: “I am delighted to have taken up this position and am excited about the challenges ahead. I look forward to working with staff and stakeholders to promote openness by public bodies and data privacy for individuals.”Information Commissioner UK

Denham, who will serve a five-year term as Information Commissioner, has held senior positions in privacy regulation in Canada over the last 12 years. Since 2010, she has been the Commissioner at the Office of the Information & Privacy Commissioner for British Columbia, Canada.