Staff ignore Data Protection Act to get job done

Information management policies are poorly executed and cast aside, survey finds

Staff are not being trained in how to handle personal data by their employers, despite a legal obligation to do so under the Data Protection Act according to a survey.

IT Governance has found that in a survey of 130 technology and compliance professionals, including CIOs, that 96 per cent of the organisations held customer or patient information and that 56 per cent held financial information, 39 per cent held sensitive personal information – i.e. ethnic or political affiliation – and 36 per cent held medical information. But only 55 per cent of the employees at these organisations had been trained on the legal responsibilities they had in their handling of that information.

“Under the Data Protection Act it is a legal requirement for organisations to safeguard personal information, but this can only be achieved with the support of employees,” said Alan Calder the IT Governance chief executive.

Carrying out its research IT Governance found that employees regularly side-stepped policies and procedures purely to do their jobs. IT Governance said this was because information management policies were either too obtrusive in design or implementation.

Organisations are aware of their responsibilities under the Data Protection Act, with over 80 per cent tasking an individual for data control and maintaining privacy. Documented procedures existed in 68 per cent of organisations polled; policies for protecting personal data existed in 82 per cent of organisations.

Earlier this year IT specialists Capgemini called for CIOs to put information management and policy back into their job role. In a study Capgemini found that the information culture in many organisations is broken, which in turn led to information management debacles like HMRC data loss.



Email Updates

CIO Newsletters: Expert insight, advice and tools for technology, business, leadership and the CIO career.


Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.


CIO White Papers

Legal risks of uncontrolled email and web use

Exploring the challenges facing IT Mangers today and vital steps to ensure safe internet an email use by employees.

The challenge of strategic alignment

Recent research also shows that many organisations give too much prominence to internally generated KPIs – controlling the controllable – rather than looking outwards at threats and opportunities on the horizon which can ultimately be far more influential on performance.

Six essential steps to successful IT centralisation

This report, based on the real experience of a recent centralisation project, is aimed at those involved in IT strategy within their organisation. It provides some practical insights for CIOs, CTOs, Heads of IT, IT Directors and those involved more closely with the service management function.

Managing email: Exploring common email management challenges (and how to overcome them)

We surveyed 157 IT professionals to understand the difficulties and opportunities faced by email managers. From this we were able to highlight some easy-to-manange solutions to their most pressing problems.


CIO UK - Business - Technology - Leadership

Differentiate your company with complete CRM

Focused on productivity and empowerment and leveraging the natural rhythms people work
What defines Complete CRM? How businesses can better engage customers and users, manage customer transactions, and analyse results to adapt and take advantage of changing business and economic circumstances.

DOWNLOAD

Oracle White Paper

IT Misuse Survey

Complete this survey and you could win a Nexus One.

CIO are running a short survey to discover how UK businesses are managing internet and email misuse in the Enterprise.

COMPLETE SURVEY

Virtualisation - The 'black hole' of security?

Covering the set of issues, ideas and perceptions discussed during a recently held debate about the effect of virtualisation techniques on organisational security. This paper provides a comprehensive account of all the subject matters debated and concludes with key takeaways and IDC recommended actions.

DOWNLOAD

Trend Micro



* *