<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DiskShred Blog &#187; Data Retention</title>
	<atom:link href="http://blog.diskshred.co.uk/category/data-retention/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.diskshred.co.uk</link>
	<description>Debate and advice on data security</description>
	<lastBuildDate>Mon, 09 Aug 2010 11:34:03 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Smartphones…not so smart now</title>
		<link>http://blog.diskshred.co.uk/2010/06/28/smartphones%e2%80%a6not-so-smart-now/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=smartphones%25e2%2580%25a6not-so-smart-now</link>
		<comments>http://blog.diskshred.co.uk/2010/06/28/smartphones%e2%80%a6not-so-smart-now/#comments</comments>
		<pubDate>Mon, 28 Jun 2010 09:40:10 +0000</pubDate>
		<dc:creator>Keith Pryde</dc:creator>
				<category><![CDATA[Data Disposal]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Data Retention]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://blog.diskshred.co.uk/?p=137</guid>
		<description><![CDATA[It’s the age of the Smartphone.  The market is saturated with them whether it’s the iPhone, Blackberry, Palm Pre, Samsung…the list goes on.  And if you don’t have one you’re probably planning on getting one.
The beauty of these models is you can do everything on the go – check emails, send texts, make calls, surf [...]]]></description>
			<content:encoded><![CDATA[<p>It’s the age of the Smartphone.  The market is saturated with them whether it’s the iPhone, Blackberry, Palm Pre, Samsung…the list goes on.  And if you don’t have one you’re probably planning on getting one.</p>
<p>The beauty of these models is you can do everything on the go – check emails, send texts, make calls, surf the net and even arrange your schedule.  It’s like carrying a mini laptop in your pocket.</p>
<p>But the problem with having so much information stored on your phone is that you have so much information stored on your phone.</p>
<p>Take a minute and think about how much personally identifiable information is on your phone.  Portable devices carry personal data relating to recent calls made, photos, emails, route from home to work, stored texts which are all potentially comprising data.</p>
<p>Now imagine your phone is lost or stolen.</p>
<p>Scary thought isn’t it.  Especially if you use the phone for business.</p>
<p>But it’s not just theft and loss that are dangerous.  Even the simply upgrading your phone can be hazardous.  Has your phone been completely wiped of all data?  That’s the risk you take when you hand in your old phone over for a shiny new replacement.</p>
<p>It is important, especially for those who store both personal and work related information on their smartphones, to ensure the data is secure.  It’s not enough to shred the storage devices from servers, laptops and PC’s, these handheld devices also need to be physically destroyed if they are no longer used.</p>
<p>It is vital that all categories of personally identifiable information are securely disposed of.</p>
<p><a title="Pwc Report" href="http://www.pwc.co.uk/pdf/protecting_your_business_security_awareness.pdf " target="_blank">A new report from consultancy PwC </a>this week found that a company&#8217;s employees are its best defence against security threats, and should be empowered and educated about technology risk including mobile phones.</p>
<p>So let’s all start by taking much more ‘personal accountability’ by looking after portable business data as carefully as you would your own personal filing cabinet.  You wouldn’t leave your last itemised phone bill, bank details, personal address book or photos lying around would you?</p>
<p>And beware of the honey trap.  Just ask <a title="Gordon Brown's aide's Blackberry stolen" href="http://www.theregister.co.uk/2010/06/15/gchq_iphone/ " target="_blank">Gordon Brown’s aide </a>about securing his BlackBerry.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.diskshred.co.uk/2010/06/28/smartphones%e2%80%a6not-so-smart-now/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Conference launched to prepare NI organisations for ICO new powers</title>
		<link>http://blog.diskshred.co.uk/2010/05/14/conference-launched-to-prepare-ni-organisations-for-ico-new-powers/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=conference-launched-to-prepare-ni-organisations-for-ico-new-powers</link>
		<comments>http://blog.diskshred.co.uk/2010/05/14/conference-launched-to-prepare-ni-organisations-for-ico-new-powers/#comments</comments>
		<pubDate>Fri, 14 May 2010 08:30:23 +0000</pubDate>
		<dc:creator>Keith Pryde</dc:creator>
				<category><![CDATA[Data Disposal]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Data Retention]]></category>
		<category><![CDATA[DiskShred]]></category>
		<category><![CDATA[Legislation]]></category>

		<guid isPermaLink="false">http://blog.diskshred.co.uk/?p=124</guid>
		<description><![CDATA[AS we all know, the Information Commissioner’s Office now has the power to fine organisations up to £500,000 for deliberate or negligent data breaches and after Deputy Commissioner David Smith’s speech at InfoSecurity Europe, the tiger is no longer toothless.
Poised to attack, the ICO is ready to dish out hefty fines to those who are [...]]]></description>
			<content:encoded><![CDATA[<p>AS we all know, the Information Commissioner’s Office now has the power to fine organisations up to £500,000 for deliberate or negligent data breaches and after Deputy Commissioner David Smith’s speech at InfoSecurity Europe, the tiger is no longer toothless.</p>
<p>Poised to attack, the ICO is ready to dish out hefty fines to those who are careless with their data security.  But recent market research showed smaller SMEs were unaware of the ICO’s new powers.</p>
<p>For Northern Ireland companies unsure about the changes in the law there is a conference next month that can help. </p>
<p>The Legal-Island Data Protection &amp; Compliance Update Conference takes place on Thursday 3<sup>rd</sup>June at Dunsilly Hotel, Junction One in Antrim.  The full day event aims to arm organisations with all the very latest information on how to comply with the new measures and avoid the substantial monetary penalties now in force.</p>
<p>The conference will break down the responsibilities of organisations when processing employee or customer data, explain the new penalties and advise on data storage or disposal.  The afternoon session is broken into three streams – Customer Data, Marketing Both Online and Offline and Human Resources.  Delegates can choose which stream will benefit them the most.</p>
<p>Conferences like this are very beneficial for organisations particularly management staff and those in charge of sensitive information.  As I have said many times it is vital to educate staff on data protection and it is the responsibility of management to initiate and then enforce security protocols in the workplace.</p>
<p>If that hasn’t sold you perhaps one of the speakers will.  Catherine Vint, a senior investigator in the Information Commissioner’s Office Northern Ireland will be addressing the conference.  Where better to get advice on how to avoid the £500k fine than from the ICO itself?</p>
<p>And if that still hasn’t sold you – we’ll be there!  DiskShred are one of the sponsors and we’ll be exhibiting at the conference.  If you have any questions about secure data destruction feel free to drop by and say hello. </p>
<p>Full conference details and prices can be found <a title="Legal-Island Data Protection &amp; Compliance Conference" href="http://www.legal-island.com/events/all-events/218/data-protection-and-compliance-update-conference/" target="_blank">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.diskshred.co.uk/2010/05/14/conference-launched-to-prepare-ni-organisations-for-ico-new-powers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The ICO shows its teeth at InfoSecurity Europe</title>
		<link>http://blog.diskshred.co.uk/2010/05/11/the-ico-shows-its-teeth-at-infosecurity-europe/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=the-ico-shows-its-teeth-at-infosecurity-europe</link>
		<comments>http://blog.diskshred.co.uk/2010/05/11/the-ico-shows-its-teeth-at-infosecurity-europe/#comments</comments>
		<pubDate>Tue, 11 May 2010 07:59:54 +0000</pubDate>
		<dc:creator>Keith Pryde</dc:creator>
				<category><![CDATA[Data Disposal]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Data Retention]]></category>
		<category><![CDATA[DiskShred]]></category>

		<guid isPermaLink="false">http://blog.diskshred.co.uk/?p=98</guid>
		<description><![CDATA[WELL InfoSecurity Europe is over for another year…and what an event it was.
The big story of the three-day exhibition was the ICO Deputy Commissioner David Smith’s opening address to delegates.  Not only did he name and shame the NHS as the worst culprit for data breaches but he warned plans to make some data breach [...]]]></description>
			<content:encoded><![CDATA[<p>WELL InfoSecurity Europe is over for another year…and what an event it was.</p>
<p>The big story of the three-day exhibition was the ICO Deputy Commissioner David Smith’s opening address to delegates.  Not only did he name and shame the NHS as the worst culprit for data breaches but he warned plans to make some data breach notifications mandatory in the UK as part of a wider European directive are afoot.</p>
<div id="attachment_102" class="wp-caption alignleft" style="width: 116px"><a href="http://blog.diskshred.co.uk/wp-content/uploads/2010/05/david_smith.jpg"><img class="size-full wp-image-102 " title="David Smith" src="http://blog.diskshred.co.uk/wp-content/uploads/2010/05/david_smith.jpg" alt="" width="106" height="106" /></a><p class="wp-caption-text">The ICO Deputy Commissioner David Smith</p></div>
<p>He said the European Commission review of data laws will mean huge changes for organisations whose data security has been breached.</p>
<p>“Breach notification is on the agenda”, said Mr Smith.  “It&#8217;s coming for telecommunications companies, and there&#8217;s no logical reason to confine it to them.&#8221;</p>
<p>The UK will have data breach notification laws for the telecommunications sector within 18 months and the ICO expects this to roll out to other business organisations.</p>
<p>But perhaps the most surprising part of Mr Smith’s speech was his remarks regarding the ICO’s new penalty powers.</p>
<p>He said: “We have got some more powers now and are no longer the toothless tiger or bulldog we have been described as”.</p>
<p>He told the audience of exhibitors and delegates that the ICO were ready and willing to hand out fines to organisations who deliberately breach the Data Protection Act.</p>
<p>In fact Mr Smith even called for prison sentences for professional data thieves, including private investigators and employees who sell valuable information.</p>
<p>I took some time out from our stand to sit in on the address and when Mr Smith asked for questions from the floor I took the opportunity to pose the final question.</p>
<p>In light of recent market research, which showed smaller SMEs were unaware of the ICO’s new powers, I asked Mr Smith if he was concerned about these findings and if they planned to target a couple of offending organisations soon to help publicise their new &#8217;super powers&#8217;.</p>
<p>He replied that while they recognised the need to highlight the new powers to fine small businesses, they would not set out to target any one particular organisation.  However his earlier comments on the NHS might suggest otherwise.</p>
<p>No one knows when the ICO will strike but one thing is for sure, it will happen organisations will be fined, despite all the warnings from InfoSec exhibitors.</p>
<p>Over 12,000 people attended the three day event and our stand was busy throughout.  We got more than 500 entries to our iPad giveaway, which was won by Rob Howell-Jones.</p>
<p style="text-align: center;">
<div id="attachment_100" class="wp-caption aligncenter" style="width: 310px"><a href="http://blog.diskshred.co.uk/wp-content/uploads/2010/05/STAND-4.jpg"><img class="size-medium wp-image-100 " title="DISK SHRED STAND" src="http://blog.diskshred.co.uk/wp-content/uploads/2010/05/STAND-4-300x225.jpg" alt="" width="300" height="225" /></a><p class="wp-caption-text">The busy DiskShred stand at InfoSec Europe 2010</p></div>
<div class="mceTemp mceIEcenter" style="text-align: center;">
<dl id="attachment_107" class="wp-caption   aligncenter" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://blog.diskshred.co.uk/wp-content/uploads/2010/05/STAND-3.jpg"><img class="size-medium wp-image-107 " title="DiskShred Stand 2" src="http://blog.diskshred.co.uk/wp-content/uploads/2010/05/STAND-3-300x225.jpg" alt="" width="300" height="225" /></a></dt>
<dd class="wp-caption-dd">Waiting for the doors of InfoSec Europe 2010 to open.</dd>
</dl>
</div>
<p style="text-align: left;">Information Security expert and well known blogger /author Brian Honan of BH Consulting dropped by the DiskShred stand.  He attended the InfoSec exhibition to sign copies of his new book <em>Implementing ISO27001 in a Windows 7 Environment</em> on the IT Governance stand – his book is a must for every information security practitioner’s technical library.</p>
<p style="text-align: left;">Also Peter Hayes from the CCTM Secretariat (Claims Tested Mark awarding body on behalf of UK Government CESG) visited our stand to congratulate us on prominently promoting the CESG Claims Tested logo on the stand header.</p>
<p style="text-align: left;">InfoSec gave us time to network and meet fellow information security Tweeters and bloggers.  We met Tim Schraider and Maritz Cloete, two directors of CS Risk Management &amp; Compliance in London, who are avid followers of DiskShred’s comments on Twitter.  It was great to put a face to the profile!</p>
<p style="text-align: left;">All in all it was a worthwhile experience for the DiskShred team.  I can only hope events like InfoSec Europe succeed in educating staff from all sectors and business organisations about the importance of information security and data protection.</p>
<p style="text-align: left;"><a href="http://blog.diskshred.co.uk/wp-content/uploads/2010/05/INFOSEC-8.jpg"><img class="alignleft size-medium wp-image-115" title="DiskShred Stand 3" src="http://blog.diskshred.co.uk/wp-content/uploads/2010/05/INFOSEC-8-300x225.jpg" alt="" width="300" height="225" /></a></p>
<p style="text-align: center;">
<p style="text-align: left;">Check out pics of the event on the <a title="InfoSec 2010 Group" href="http://www.flickr.com/groups/1422217@N23/" target="_blank">InfoSec 2010 Flickr group</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.diskshred.co.uk/2010/05/11/the-ico-shows-its-teeth-at-infosecurity-europe/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Security experts take over London</title>
		<link>http://blog.diskshred.co.uk/2010/04/23/security-experts-take-over-london/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=security-experts-take-over-london</link>
		<comments>http://blog.diskshred.co.uk/2010/04/23/security-experts-take-over-london/#comments</comments>
		<pubDate>Fri, 23 Apr 2010 07:30:31 +0000</pubDate>
		<dc:creator>Keith Pryde</dc:creator>
				<category><![CDATA[Data Disposal]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Data Retention]]></category>
		<category><![CDATA[DiskShred]]></category>

		<guid isPermaLink="false">http://blog.diskshred.co.uk/?p=92</guid>
		<description><![CDATA[THE UK and Europe’s top security experts are travelling to London next week for InfoSecurity Europe at Earl’s Court.
Celebrating 15 years in the industry, this event is by far the biggest in the information security calendar with exhibitors from all over the world displaying their products.
But that’s not all InfoSec has to offer.
Unlike other industry events, [...]]]></description>
			<content:encoded><![CDATA[<p>THE UK and Europe’s top security experts are travelling to London next week for <a title="InfoSecurity Europe" href="http://www.infosec.co.uk/" target="_blank">InfoSecurity Europe </a>at Earl’s Court.</p>
<p>Celebrating 15 years in the industry, this event is by far the biggest in the information security calendar with exhibitors from all over the world displaying their products.</p>
<p>But that’s not all InfoSec has to offer.</p>
<p>Unlike other industry events, InfoSec offers a free Education Programme.  This includes seminars, workshops and round table discussions featuring talks from some of the most influential security experts in the world.</p>
<p>New to this year’s line-up are the Discussion Den and Security Workshops.  The Discussion Den involves an interactive panel session debating various topics including cybercrime and mobile security.  No doubt the Caretower IT Specialists talk on Tried &amp; Tested Methods Of Securing Funding For Your Security Projects will be popular.</p>
<p>The eagerly anticipated Security Workshops are proving very popular with organisers asking people to pre-register to attend.  The four themes are Data Leakage Prevention, Global Corporate Challenges, Online Security and Threats &amp; Mitigation. </p>
<p>I hope to get the opportunity to hear the keynote address by Deputy Information Commissioner David Smith, where he’ll discuss the ‘ins and outs’ of the new £500k data loss fines.</p>
<p>I am well aware that I may be preaching to the converted but I can’t help stressing the importance of events like InfoSec.  The exhibition is designed to educate businesses on data protection in the hope that they will return to their offices armed with the information and contacts they need to implement a security structure.</p>
<p>However in some cases, the very people who should be attending to learn more about protecting their reputation and their clients’ privacy are the ones who are probably careless about personal identifiable information and are likely to get hit with the wrath of the ICO.</p>
<p>So if you want to avoid a nasty fine, speak to the experts at InfoSec Europe&#8230;</p>
<p>And if you want to <a title="DiskShred iPad Competition" href="http://www.diskshred.co.uk/diskshredComp.html" target="_blank">win a brand new Apple iPad visit us at stand E64!</a></p>
<p>Hope to see you there.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.diskshred.co.uk/2010/04/23/security-experts-take-over-london/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Avoiding the Volcano – Top 10 Guide to Information Data Security</title>
		<link>http://blog.diskshred.co.uk/2010/04/20/avoiding-the-volcano-%e2%80%93-top-10-guide-to-information-data-security/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=avoiding-the-volcano-%25e2%2580%2593-top-10-guide-to-information-data-security</link>
		<comments>http://blog.diskshred.co.uk/2010/04/20/avoiding-the-volcano-%e2%80%93-top-10-guide-to-information-data-security/#comments</comments>
		<pubDate>Tue, 20 Apr 2010 15:28:14 +0000</pubDate>
		<dc:creator>Keith Pryde</dc:creator>
				<category><![CDATA[Data Disposal]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Data Retention]]></category>
		<category><![CDATA[DiskShred]]></category>

		<guid isPermaLink="false">http://blog.diskshred.co.uk/?p=83</guid>
		<description><![CDATA[IT’S now mid-April, the Information Commissioner’s Office powers to fine organisations up to £500,000 for a ‘deliberate or negligent’ data breach are officially in force.  But word on the web is that businesses still aren’t taking heed of security warnings.
It’s time to wake up and smell the coffee – the ICO is ready, willing and [...]]]></description>
			<content:encoded><![CDATA[<p>IT’S now mid-April, the Information Commissioner’s Office powers to fine organisations up to £500,000 for a ‘deliberate or negligent’ data breach are officially in force.  But word on the web is that businesses still aren’t taking heed of security warnings.</p>
<p>It’s time to wake up and smell the coffee – the ICO is ready, willing and able to impose these fines.  Do you want to incur the wrath of the ICO?  I didn’t think so. </p>
<p>We are a leading on-site data disposal service with over nine years experience of secure data destruction so we know a little something about information security.  We have put together a guide to help businesses get their house in order and avoid a hefty fine.</p>
<ol>
<li>First things first organisations need to be aware of the importance of data.  Whether it is trade secrets or personal customer information, a data breach can cause serious damage to a business – and not just financially.  When trust is lost it can be extremely difficult for a company to repair its reputation and this affects future business prospects.  Losing information is very serious, be aware of that.</li>
<li>There are some people out there who think the ICO won’t enforce the new powers but don’t be misled.  The new Information Commissioner Christopher Graham is poised to pounce.  He said: “Getting data protection right has never been more important than it is today&#8230;I will not hesitate to use these tough new sanctions for the most serious cases where organisations disregard the law.”</li>
<li>As I have talked about before, all staff must be educated on the importance of data protection.  Careless staff can cost a business dearly, security protocols must be in place to ensure the protection of information.  Just last month the <a title="Barnet Council Security Breach" href="http://www.infosecurity-magazine.com/view/8472/barnet-council-discovers-9000-reasons-to-encrypt-data/" target="_blank">personal details of 9000 school children </a>were compromised after unencrypted CDs and USB sticks were stolen from a council employee’s home.  Fortunately for the council the incident occurred before the ICO powers came into force and they avoided a substantial penalty.</li>
<li>And that goes for the big wigs too.  There has to be corporate compliance to ensure a data loss does not occur.  The top dogs in any company must also take these measures seriously.  However as the recent <a title="Ponemon Study" href="http://www.absolute.com/resource_center/whitepapers/ponemon-human-factor" target="_blank">Ponemon study </a>revealed, that is not always the case.  The survey found that 53 per cent of British business managers have disengaged the encryption on their laptops.  This is hardly a good leadership example to set for their own staff.</li>
<li>The best way to know if your data protection policies are up to scratch is to test them.  Give your procedures a complete overhaul to ensure your data security and breach policies are running smoothly.  This includes website privacy, internal data, data retention, data disposal, portable information and the use of third parties.</li>
<li>When outsourcing services to a third party, whether it’s for hard drive shredding or encryptions, make sure all contracts meet your data security policies.  Ask the contractors for proof of pre-employment screening and 5-year security background checks (in compliance with BS7856:2006).  Also ask for proof that the chosen data destruction company is accredited to BSEN15713:2009 for Secure Destruction of Confidential Media or holds a CESG CCTM accreditation from the UK Government.</li>
<li>These days data can be stored on the smallest of devices.  CDs, USBs, PDAs and even Smartphones store an enormous amount of information but they are easily misplaced and could fall into the wrong hands.  It is important for businesses to enforce ‘don’t take home’ policies with staff to avoid loss or theft, and when these devices are deemed redundant dispose of them correctly, guaranteeing all data has been destroyed.</li>
<li>Greening your office is good for the environment but before donating old computer equipment make sure it has been professionally wiped and overwritten using software that meets an accredited standard, such as the CESG InfoSec IA Standard 5, otherwise significant data could end up in the wrong hands.  This point has been championed by <a title="EDPS press release" href="http://europa.eu/rapid/pressReleasesAction.do?reference=EDPS/10/7&amp;format=HTML&amp;aged=0&amp;language=EN&amp;guiLanguage=en" target="_blank">European Data Protection Supervisor Peter Hustinx</a>, who warned the EU’s proposal to recast the old WEEE (Waste Electrical and Electronic Equipment) Directive focuses too heavily on the environmental issues. He said: “It is important to take into account the potentially damaging effects of WEEE disposal on the protection of personal data stored in used equipment. Respect for security measures and a ‘privacy by design’ approach should be seen as essential pre-conditions in order to effectively guarantee the right to the protection of personal data.”</li>
<li>Trusting an outsider to dispose of data storage devices can be difficult for some companies.  Take control of your data disposal and insist on witnessing the destruction.  That way you know the job has been done.</li>
<li>Finally, information security is an ongoing process.  This isn’t a Spring clean quick fix.  Businesses need a long-term strategy to keep them and their customers secure.  I know it might sound like a broken record but it’s better to be safe than sorry, particularly when potentially up to £500k is at stake.</li>
</ol>
<p>To discuss this further, we’ll be taking a stand at InfoSecurity Europe at Earl’s Court in London from 27<sup>th</sup> – 29<sup>th</sup> April.  Visit us at stand E64.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.diskshred.co.uk/2010/04/20/avoiding-the-volcano-%e2%80%93-top-10-guide-to-information-data-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>At last&#8230;the business case for investment in data protection has arrived!</title>
		<link>http://blog.diskshred.co.uk/2010/03/29/at-last-the-business-case-for-investment-in-data-protection-has-arrived/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=at-last-the-business-case-for-investment-in-data-protection-has-arrived</link>
		<comments>http://blog.diskshred.co.uk/2010/03/29/at-last-the-business-case-for-investment-in-data-protection-has-arrived/#comments</comments>
		<pubDate>Mon, 29 Mar 2010 08:00:56 +0000</pubDate>
		<dc:creator>Keith Pryde</dc:creator>
				<category><![CDATA[Data Disposal]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Data Retention]]></category>

		<guid isPermaLink="false">http://blog.diskshred.co.uk/?p=63</guid>
		<description><![CDATA[WE are definitely a trusting nation.  Think about it.  On any given day we are willing to part with our private information, trusting the organisation to protect it with all their might. 
And we don’t think for a second that these sacred facts will be left on a train or posted to someone else’s address.
Are we [...]]]></description>
			<content:encoded><![CDATA[<p>WE are definitely a trusting nation.  Think about it.  On any given day we are willing to part with our private information, trusting the organisation to protect it with all their might. </p>
<p>And we don’t think for a second that these sacred facts will be left on a train or posted to someone else’s address.</p>
<p>Are we to blame for being naive?  No we aren’t.  We take businesses into our confidence when we share this information and they are supposed to value this as much as we do.</p>
<p>Organisations aren’t putting enough effort and funds into the protection of personal information.  In the last few months alone details have emerged of new data leaks from city councils, hospital trusts, banks, lawyers, the Student Loans Company and even MI5.</p>
<p>From laptop theft through to careless disposal policies, it is clear many companies are leaving the protection of data to chance.</p>
<p>In response to this, the Information Commissioner’s Office issued <a title="The Privacy Dividend Report" href="http://www.ico.gov.uk/upload/documents/library/data_protection/detailed_specialist_guides/privacy_dividend.pdf" target="_blank">The Privacy Dividend report</a>, urging businesses to be proactive and invest in data protection protocols.</p>
<p>This is a complete turnaround.  At last there is a business case justification for proper investment in privacy protection rather than reactionary spending after the fact.</p>
<p>The report details a plan for businesses to assess and implement a protection plan for their data, whether it’s the calculation of the value of personal information to the benefits of privacy protection.</p>
<p>But these protections must be built into the company’s core business.  There are no halfway measures when it comes to protecting private information.</p>
<p>Having preventative measures in place will not only improve your compliance with the law but will also promote loyalty and reduce potential financial risks.</p>
<p>Trust is a tricky business – when you have it it’s invaluable but when you lose it, it’s nearly impossible to get back.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.diskshred.co.uk/2010/03/29/at-last-the-business-case-for-investment-in-data-protection-has-arrived/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Quit stockpiling and spring clean those records</title>
		<link>http://blog.diskshred.co.uk/2010/03/22/quit-stockpiling-and-spring-clean-those-records/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=quit-stockpiling-and-spring-clean-those-records</link>
		<comments>http://blog.diskshred.co.uk/2010/03/22/quit-stockpiling-and-spring-clean-those-records/#comments</comments>
		<pubDate>Mon, 22 Mar 2010 09:04:21 +0000</pubDate>
		<dc:creator>Keith Pryde</dc:creator>
				<category><![CDATA[Data Disposal]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Data Retention]]></category>

		<guid isPermaLink="false">http://blog.diskshred.co.uk/?p=53</guid>
		<description><![CDATA[HOW long should we keep our company records?  Well how long is a piece of string?
Many businesses find themselves with an abundance of documents, both hard copies and electronically stored, with no idea when they should get rid of them.
Offices become cluttered with paper, files, computers and CDs with no end in sight.
But there is [...]]]></description>
			<content:encoded><![CDATA[<p>HOW long should we keep our company records?  Well how long is a piece of string?</p>
<p>Many businesses find themselves with an abundance of documents, both hard copies and electronically stored, with no idea when they should get rid of them.</p>
<p>Offices become cluttered with paper, files, computers and CDs with no end in sight.</p>
<p>But there is light at the end of the chaotic tunnel.</p>
<p>The <a title="BSIA Guidelines for Data Retention" href="http://www.bsia.co.uk/web_images/publications/form_233.pdf" target="_blank">British Security Industry Association </a>(BSIA) guidelines suggest businesses should put in place a records management system to dispose of data without risk of loss.</p>
<p>Some documents, like company registers need to be kept for the lifetime of the organisation, whereas VAT personnel records should be properly disposed of seven years after termination of employment.</p>
<p>This is why it is important to take the time to make staff aware what can be retained and for how long.  Educating employees on data loss prevention will go a long way in saving the organization money and time.</p>
<p>The BSIA recommend putting a policy in place for secure shredding and recycling for company records, and obtaining an approved service provider.</p>
<p>There are no more excuses for stockpiling those old PC’s.  It’s time to quit hoarding and spring clean your records.  Just remember, get them all professionally shredded, safely file the Certificate of Destruction and win back all that space.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.diskshred.co.uk/2010/03/22/quit-stockpiling-and-spring-clean-those-records/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

