Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« EU Data Protection Directive 95/46/EC: Member Countries | Main | Thank Goodness For Backup Planning! »

EU Data Protection Audits Active and Anticipated

As a follow-up to my blog posting yesterday, I wanted to point out that the European Union (EU) Data Protection Authorities (DPAs) have been very active in pursuing data protection law compliance.

While the DPAs do investigate organizations according to complaints received, as is the practice in most countries, especially in the U.S., the EU DPAs are also actively auditing organizations for compliance based upon industry. Earlier this year they worked together to audit businesses within the health insurance industry.

This was not just two or three country DPAs working together; the health insurance company audits were carried out by the DPAs of: Austria, Belgium, Cyprus, the Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Slovenia, the Slovak Republic, Spain, Sweden, and the United Kingdom.

This is the first time that the EU DPAs have joined forces for data protection law compliance audits. It will not be their last. They indicate they will use six criteria to determine these collaborative compliance audits for more industries.

The report points out the need for information security measures to be in place, along with data retention requirements to be in compliance with data protection (privacy) laws.

Interestingly, they also indicated,

"In a similar vein, we should also consider the possibility of future collaboration between WP29 and other international entities or organisations with privacy enforcement abilities and the ability to cooperate internationally (FTC, OECD, APEC, etc.) and in this way, contribute to a global improvement in data protection."

So there clearly is a trend to try and have global compliance efforts pursued through cooperation with each country's oversight authorities.

One more incentive for multinational companies to know and understand all their data protection and privacy requirements wherever they have offices, employees and customers, and then act to be in compliance with the requirements.

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/496

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.