Jump to content

Recommended Posts

Posted

Hi

 

In the past we have used ecosystems to recycle hardware (old desktops, printers etc) after we saw other edugeek users had used them. We went to book another free recycling collection with them and they now charge an annual fee, which i only found out by reading their contract. No mention was made of this when booking the collection!

 

Also according to them the whole hardware recycling industry is in breach of Data protection Act 1998 as they do not use contracts, risk assessments and method statements. So even our past collections with them they are saying breached DPA. This seemed quite a claim for them to make.

 

http://www.ecosystems-group.co.uk/interview.mp4

 

Do you have risk assessments, method statements and contracts with your hardware recycling companies?

 

I wanted to see who else people use and if they provide the service for free and abide by DPA and WEEE.

 

Cheers

Posted

He's right, Kinda...

 

https://ico.org.uk/media/for-organisations/documents/1570/it_asset_disposal_for_organisations.pdf

 

See this at the bottom of page 2. However, it's good to remember that this is only the case if you are passing on devices which hold Personal Data. So, for example the computers I dispose of hold no user data at all. Just the OS so this is OK and not covered by the DPA. Also you can get round all that by destroying the data yourself before arranging collection. Again, contract method statements etc are not required. I usually insist on a certificate of data destruction anyway.

Posted (edited)

Hi @tj2419,

 

Was interested to see your post - as we offer IT recycling - so went to our Compliance Manager and asked him for his thoughts:

 

The statement claiming that the whole Recycling industry is in breach of the DPA because they don’t use contracts, conduct risk assessment or issue method statements is misleading/inaccurate.

 

Firstly - you can only be in breach of the DPA should personal data for which you are responsible (as ‘The Data Controller’) be lost, stolen, compromised etc, for which you would be responsible even if the breach occurs when the data is held by your recycling partner.

 

Secondly – ICO guidance for Data Controllers on the disposal of data bearing media does recommend such steps as Contracts, Risk Assessment & method statements (amongst lots of other controls) so that you as the controller can demonstrate proper due care & diligence for the handling of the data you are responsible for, but it isn't a legal requirement.

 

It is therefore very important that you ensure you use a Recycling partner who is able to demonstrate that it meets high levels of data security through the implementation of recognised national/international standards. (Eg. ISO27001/ADISA). Selecting such Recycling partners, as the guidance details, will enable you to show (in the event of a data breach) appropriate due diligence was followed. So ideally this should be a formal policy of your organisation, to ensure that Recycling partners are chosen on the basis of their data security and not just on costs alone.

 

Our recycling services are certified by ADISA at the highest level (Distinction with Honours) and ISO27001; and we provide a free of charge recycling service providing effective levels of data protection. The Stone Recycling facility holds an Environmental Permit issued by the Environment Agency and is regulated by them for conformance against the requirements of the WEEE Regulations.

 

Hope this helps - and if you would like some more advice/help with your IT recycling, please feel to drop me a PM :)

 

Thanks,

 

Charli

Edited by Stone_Charli
  • Thanks 3
  • 3 weeks later...
Posted (edited)

Good Morning,

 

Thanks GeekyPete, but I think it’s a bit more than Kinda.

 

As our company and myself are highly featured in this thread, I thought I would answer in more detail and provide you with some supporting evidence.

 

It’s all about Data!

 

Organisations have a duty of care and legal responsibility to protect individuals personal data when it is in there custody.

 

This personal information is utilised, examined and disseminated on many many types of different medias whilst it is been used by that organisation. Keeping control of where that personal data is saved, copied and stored is an Information Security nightmare.

 

Personal information can end up on computers, laptops, servers, mobile phones, photocopiers, cameras. The list goes on and on.

 

When this information is being used by an organisation on live current equipment they will have spent considerable effort and money on protecting that data, with stringent security controls, physical and technical access controls, anti-theft and anti-hacking controls.

 

When the equipment this data is stored on comes to the end of its useful life and is retired, this is not only the time of greatest risk, but also the time when the security controls you have in place go out of the window. This is because you utilise a 3rd party company to take away your equipment and recycle it.

 

If any of this equipment that is being retired or its associated media has personal data held on it the company is acting as your data processor.

 

The reason you require a risk assessment and method statement for each data bearing device when it is going through the asset retirement stage is to ensure you have identified the potential risk should that device hold personal data and you lose control of that data and that you have methods of working and processes in place that ensure you mitigate these risks.

 

This works directly to the DPA 7th principle

 

The second part of your requirement and this comes directly to Stone_Charli’s statement of “you can only be in breach of the DPA should personal data for which you are responsible (as ‘The Data Controller’) be lost, stolen, compromised.

 

This is incorrect

 

A breach is where an organisation loses control of personal data that is in there custody as a data controller.

 

If you do not have a written signed contract with your 3rd party supplier who are acting as your data processor, that legally binds this company to process the data only as you have requested. They can do what they like with that data with no legal recourse. You are already in breach of the data protection act itself.

 

Don’t take my word for it Data Protection Act 1998 section 12 part (a)

 

Now let us move to some of the other things I have said in the interview and as a good example to reference on how things can go disastrously wrong let us use the penalty notice awarded to NHS Surrey http://breachwatch.com/wp-content/uploads/2013/07/nhs-surrey-monetary-penalty-notice.pdf

 

This is a specific breach that relates purely to Hard Disk Drives and no other data storage media, but the principle is the same, be that a mobile phone or a photocopier.

NHS Surrey appointed a company to dispose of equipment and where assured it would be done correctly. It didn’t.

 

The salient points of this £200,000 monetary penalty

 

The Commissioner is satisfied that there has been a serious contravention of section 4(4) of the Act. In particular, the data controller failed to choose a data processor which provided sufficient guarantees in respect of the organisational security measures governing the processing to be carried out, and to take reasonable steps to ensure compliance 6 with those measures. Further, the data controller did not have a written contract with the company under which the data processor was to act only on instructions from the data controller, and which required the company to comply with obligations equivalent to those imposed on a data controller by the Seventh Data Protection Principle.

 

In particular, the Commissioner would expect the data controller to have carried out a proper risk assessment and chosen a data processor providing sufficient guarantees in a written agreement.

 

The data controller should then have taken reasonable steps to ensure compliance with those measures such as effectively monitoring the destruction process and maintaining audit trails and inventory logs of hard drives destroyed by the company based on the serial numbers in the destruction certificates for each individual drive.

 

So let’s look at this further. I think my contract point is well covered as well as risk assessments and method statements. You need these so that your 3rd party disposal company knows what you want them to do with each storage device and a contract that legal binds them to do it.

 

The final part you need in ensuring security of personal data is evidence that the job has been completed to your requirements.

 

The Information Commissionaire stated in this monetary penalty award that the organisation should have “effectively monitoring the destruction process”

 

This is where in my interview I have stated that on the whole the industry is based on a promise with no proof provided.

 

An asset report listing make, model and serial number is not proof, nor is a waste transfer note. It’s a promise that the company that took your equipment has dealt with it as you expected.

 

For hard drives, an automated software generated report from programs such as Blanco, Killdisk Tabernus etc. Will provide details of the hard drive serial number, its size. The data it was wiped how many wipes it took and if it was successful or not.

 

If it was successful, that is proof. If it has failed what happens then? They say, oh we shred it, or crush it. Where is the proof?

What happens to data storage equipment that is not a hard drive? Or does not have a serial number? Where is your proof that the 3rd party company did the work you specified.

 

I hope anyone reading this can now see how easy it can be to end up like the unfortunate people at Surrey NHS

 

I am not here to bang on about my company or the services it provides. Just to clarify what legislation expects you to do.

 

For far too long the focus on IT Asset Disposal has been on complying with the WEEE Directive.

 

I agree with it and comply with it. But it’s not an organisation killer like breaching the DPA

 

Let me reiterate the average cost for a single data breach in the UK was £2,370,000.00 in most cases that is an organisation killer.

 

With new EU Data Directive Regulation 2015 being enacted the requirements for compliance and the costs of non-compliance will be significantly higher.

 

As I have eluded to all through this thread, most organisations will find it impossible to know if any of the equipment has personal data held within it.

 

Did some leave a sensitive CD in a machine?

 

Is a back-up tape still in the tape loader?

 

Is the SD card still in the phone or the camera?

 

You need to have rigorous controls and procedures in place so that even if a back-up tape is inadvertently left in a tape loader that’s been collected. The 3rd Party organisation have a procedure set down telling them what to do with it, that they are legally bound in a contract to deal with it that way and that they provide you with evidence that they did it.

 

Everything that could hold personal data on it, when given to a 3rd party should be treated as if has got personal data on it. The contract, controls and methods I have stated you should have in place will ensure you don’t breach the Data Protection Act.

 

Finally

 

Negligence Definition

 

“Conduct that falls below the standards of behaviour established by law for the protection of others against unreasonable risk of harm”

Make sure you don’t fall in to this category when disposing of redundant IT equipment.

 

 

 

Stone_Charli, if you are going to respond to this thread, before you do, make sure you speak to both Simon and Gary, before you type.

Edited by Chris-Littlewood

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...