Security threats Toolkit
Story: Watchdog aims to compel data-breach confessions
CMA
Fine in theory, but we hope the NCC has thought it through. Any new legislation must be careful to define what constitutes a breach. For example:
• Is a data loss necessarily a data breach?;
• Does a data breach occur even where no harm has been caused?
• Is the loss of encrypted data always harmless? Or must the strength of the crypto algorithm be taken into account when making a judgement?
• If it can be shown that the data was lost in some remote part of the business chain (eg: by an ISP, by a data warehouse, a call centre, or outsourcer) and not by the data user, how will blame be apportioned?
Full Talkback thread








