house of lords

Lords renew calls for security action

The Upper House is refusing to lie down in its fight to protect personal data

Written by Phil Muncaster

The House of Lords Science and Technology Committee released its long-awaited follow-up report to its 2007 document on personal internet security earlier this month. But although government attitudes to some of the issues have softened, there appears to still be a long way to go before any of the recommendations are acted on.

“We acknowledge that, following the government’s disappointing response to our report, they have reflected further and, with regard to some of the issues we raised, there has been some progress towards meeting our concerns,” the report concluded. “What progress there is, however, appears to be slow.”

The main recommendations in the follow-up report are:

  • The introduction of a data breach notification law.
  • A return to old fraud reporting laws whereby the first point of contact is the police, not the banks.
  • New laws to place liability for losses through online fraud on the banks.

The Lords maintained that current Banking Code rules are not sufficient as they allow the banks to claim that customers have been negligent in fraud cases.

“We have significant concerns about the way in which complaints of online banking fraud are currently handled and, in particular, the basis on which the banks determine that an alleged fraud is to be attributed to the customer, whether by fraudulent or negligent activity,” said the report.

The committee was given evidence suggesting between 1,000 and 10,000 individuals have been denied compensation.

On the issue of fraud reporting, the report is critical of the government for doing little to address concerns about the current system, whereby fraud victims must report to their banks in the first instance, rather than the police. “We were concerned about reporting fraud in this sequence on the grounds that the decision of the banks to pass a report to the police might be influenced by commercial factors,” said the report.

Committee member Lord Broers argued that it was “encouraging that the government has come round slightly in this issue” by saying it will look at the problem again.

But others argued that police are currently ill-equipped to deal with handling fraud cases. Simon Heron, managing director of network security vendor Network Box, said that law enforcement suffers from a lack of funding and is not interested in small incidents of online fraud.

“If they come across a multimillion pound internet fraud case then they can push it up to the Serious Organised Crime Agency, but my impression is that the small and damaging incidents are not under control,” he said. “Internet crime is just not taken seriously, ­ the people making the decisions are not aware of the commercial ramifications a lack of confidence in the internet could cause.”

The Lords also renewed calls for US-style data breach notification legislation to
be enacted in the UK.

Richard Turner, chief executive of content security vendor Clearswift, said that firms that clearly communicate to their customers what information they gather and store, and what will happen in the event of a breach, could use that as a competitive differentiator.

“Without this legislation there won’t be the constant driver for the responsible and safe management and collection of information,” he added. “As a custodian of someone’s information, you have an absolute obligation to tell that person as soon as you find out.”

Tags:

reader comments

related articles

information commissioner

Data watchdog serves notice on government departments

HMRC & MoD slapped with enforcement notices 15 Jul 2008

 

Lords renew calls for security laws

Follow-up to Personal Internet Security report is launched today 08 Jul 2008

Commissioner urges data protection reform

UK Information Commissioner says European data laws are outdated 07 Jul 2008

NHS falls victim to another data breach

Another public sector organisation loses personal details 01 Jul 2008

Government plans to store comms data

Proposed database could mean logs of all phone calls, emails and internet usage are centrally stored 20 May 2008

Information Commissioner gets stronger powers

The Information Commissioner has finally got his wish, increased powers to tackle data breaches 09 May 2008

Lords renew calls for security laws

Follow-up to Personal Internet Security report is launched today 08 Jul 2008

Banks should be liable for e-fraud

House of Lords committee describes current system as 'wholly unsatisfactory' 11 Jul 2008

Lords to launch follow-up security report

Science and Technology Committee disappointed with government response to its 2007 report 21 Feb 2008

related whitepapers

today's top stories

Body Shop rolls out PCI system

Retailer hopes to benefit from improved customer data analysis 07 Oct 2008

Where to offshore (and why not here?)

Tholons, the research firm founded by well-known offshoring guru Avinash Vashistha , has just published some new research in Global Services magazine... 07 Oct 2008

The future of Ethernet

Where is Ethernet going? We look at the future of the widely-used networking technology. 07 Oct 2008

The pIT stop Q&A: How can I measure the business success of IT applications?

Ou expert panel answers readers' real-life IT questions 07 Oct 2008

National Identity Fraud Prevention Week

Every Monday seems to mark the beginning of a new awareness drive and this week’s theme has particular importance to small businesses... 06 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you apply for a job that was advertised on Facebook or a similar social networking site?

Would you apply for a job that was advertised on Facebook or a similar social networking site?

The government is using Facebook to recruit IT staff - would you apply to such an ad?

Previous poll results

Latest audio and video articles

Ethernet cableVideo

The future of Ethernet

Where is Ethernet going? We look at the future of the widely-used networking technology. 07 Oct 2008

Podcast imageAudio

Computing podcast - Next-generation broadband Britain; and we report from Gartner's IT security summit

In our latest podcast, we discuss the hurdles that a national fibre-optic network must overcome, and look at the issues discussed at the recent IT security conference 02 Oct 2008

Latest in-depth articles

Features

How to ensure progress in programming

Best practice advice from Forrester Research 02 Oct 2008

BT workersAnalysis

Wanted: a viable model for fibre

While other European countries are pressing ahead with fibre rollouts, progress in the UK is being held back as the debate over who will foot the bill drags on, writes Dave Bailey 02 Oct 2008

Advertisement

Primary Navigation