Nexus of Forces erodes corporate privacy measures

happygeek 0 Tallied Votes 375 Views Share

Gartner defines the 'Nexus of Forces' as being "the convergence and mutual reinforcement of social, mobility, cloud and information patterns that drive new business scenarios". The global IT analyst outfit has also just released details of research which suggests that the perceived level of maturity when it comes to the privacy activity of organisations has gone down since 2011, with many admitting their own existing privacy efforts are inadequate. Gartner insists that these companies need to refocus their efforts in order to deal with the impact of the Nexus of Forces.

According to Carsten Casper, research vice president at Gartner, more than a third of organisations still "consider privacy aspects in an ad hoc fashion" and admits surprise at so many saying they are not conducting privacy impact assessments before major projects. "62 per cent do not scan websites and applications, or conduct an organisation-wide privacy audit every year" Casper says "organisations must put these activities on their to-do list for 2014."

According to the research, 43 per cent of organisations have a comprehensive privacy management programme in place, which is good but puts them firmly in the minority. Some seven per cent admitted that they only do "the bare minimum" when it comes to privacy laws.

"Organisations continue to invest more in privacy due to ongoing public attention and a number of new or anticipated legal requirements" Casper admits "they also show that previous investments have not always paid off and that organisations need to refocus their privacy efforts if they want to raise the maturity level of their privacy programmes back to that of 2011."

The research also revealed that 90 per cent of organisations have one person or more responsible for privacy issues, which is encouraging news as Gartner insists it has consistently seen that privacy programmes only succeed if someone is actually driving them. Less encouraging is the observation that privacy programmes 'owned' by this designated individual is far from being the norm. Apparently only 66 per cent of survey respondents globally said that they have a defined privacy officer role, in Germany the number was 85 per cent however. Unsurprisingly this is because such a role is a legal requirement...

Other key statistics from the Gartner research includes:

Across the board, 32 per cent of survey respondents said that their organisations have increased privacy-related staff from last year to this, representing the most significant increase since Gartner started privacy surveys back in 2008.

38 per cent of organisations transform personal data before transmitting it abroad (with masking, encryption or similar), thus keeping sensitive data local, while allowing some functionality abroad. Domestic storage accounts for 29 per cent and remote storage with only local access is 27 per cent.

Analysts will further examine the outlook of privacy in Europe at the Gartner Symposium/ITxpo 2013, in Barcelona, Spain between the 10th and 14th of November.

Dani AI

Generated

This thread is really about two different problems at once: organisational data governance versus visible workplace surveillance. correctly steered the discussion toward data-handling practices, while 's anecdote about account records surviving corporate takeovers is a useful real-world example of legacy-data risk.

Since 2013 the compliance landscape has hardened. European rules require formal impact assessments for likely high‑risk processing and set out when a Data Protection Officer is required, and U.S. state law (notably California) now gives consumers stronger, enforceable rights backed by a dedicated regulator. These legal hooks are why privacy programmes must move from ad‑hoc to governed. (ico.org.uk)

Mergers and acquisitions are a recurring source of problems: data often moves with business assets, and old systems or weak due diligence create exposure. Practical protections used by counsel and regulators include narrow, need‑to‑know disclosure during due diligence; thorough data mapping and records of processing; contractual reps, warranties and indemnities for security; and a clear post‑closing remediation plan. Regulators have taken enforcement action where diligence was insufficient. (debevoise.com)

Short, practical checklist that raises maturity quickly:

  • assign a single accountable privacy owner and publish contact details;
  • build and maintain a data inventory and flow map (ROPA);
  • run DPIAs before any new high‑risk project and document mitigation;
  • adopt retention and secure deletion rules for legacy records;
  • pseudonymize/encrypt personal data before cross‑border or third‑party transfers;
  • scan websites/apps for trackers and perform yearly privacy audits;
  • include privacy/security reps and post‑close remediation in M&A contracts.
    Operational frameworks such as the NIST Privacy Framework provide an implementation path from policy to controls. (nist.gov)

These points address the gap between awareness and operational control that the thread highlights: governance, documented risk assessment, minimal disclosure in deals, and measurable remediation are what lift a privacy programme out of "ad hoc" into defensible practice.

Member Avatar for Member #949455
Member #949455

According to the research, 43 per cent of organisations have a comprehensive privacy management programme in place, which is good but puts them firmly in the minority. Some seven percent admitted that they only do "the bare minimum" when it comes to privacy laws.

There's no privacy at workplace because it is own by the company. It's bit hard for any lawmaker to do anything about it, each company has it own code of ethics. Everywhere you go there is a camera recording things. Big brother watching little brother.

But I hope things will improve regarding about privacy but that won't happend anything soon.

happygeek 2,411 Most Valuable Poster Team Colleague Featured Poster

You have firmly grasped the wrong end of the stick. This is about the privacy of the data being handled by the organisation...

Member Avatar for Member #949455
Member #949455

You have firmly grasped the wrong end of the stick. This is about the privacy of the data being handled by the organisation...

HG

It's bit hard to explain this. For example I open an with Ameritrade 14 years ago. I invested money on stocks and etc. I close my account 3 years later and 11 years later it's called TD Ameritrade, Ameritrade brought TD Waterhouse.

They still have my information after all these years. Companies taking over companies is normal but transfering sensative data is very sensative issue and topic base on the acquisition.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.