Good Morning,
Thanks GeekyPete, but I think it’s a bit more than Kinda.
As our company and myself are highly featured in this thread, I thought I would answer in more detail and provide you with some supporting evidence.
It’s all about Data!
Organisations have a duty of care and legal responsibility to protect individuals personal data when it is in there custody.
This personal information is utilised, examined and disseminated on many many types of different medias whilst it is been used by that organisation. Keeping control of where that personal data is saved, copied and stored is an Information Security nightmare.
Personal information can end up on computers, laptops, servers, mobile phones, photocopiers, cameras. The list goes on and on.
When this information is being used by an organisation on live current equipment they will have spent considerable effort and money on protecting that data, with stringent security controls, physical and technical access controls, anti-theft and anti-hacking controls.
When the equipment this data is stored on comes to the end of its useful life and is retired, this is not only the time of greatest risk, but also the time when the security controls you have in place go out of the window. This is because you utilise a 3rd party company to take away your equipment and recycle it.
If any of this equipment that is being retired or its associated media has personal data held on it the company is acting as your data processor.
The reason you require a risk assessment and method statement for each data bearing device when it is going through the asset retirement stage is to ensure you have identified the potential risk should that device hold personal data and you lose control of that data and that you have methods of working and processes in place that ensure you mitigate these risks.
This works directly to the DPA 7th principle
The second part of your requirement and this comes directly to Stone_Charli’s statement of “you can only be in breach of the DPA should personal data for which you are responsible (as ‘The Data Controller’) be lost, stolen, compromised.
This is incorrect
A breach is where an organisation loses control of personal data that is in there custody as a data controller.
If you do not have a written signed contract with your 3rd party supplier who are acting as your data processor, that legally binds this company to process the data only as you have requested. They can do what they like with that data with no legal recourse. You are already in breach of the data protection act itself.
Don’t take my word for it Data Protection Act 1998 section 12 part (a)
Now let us move to some of the other things I have said in the interview and as a good example to reference on how things can go disastrously wrong let us use the penalty notice awarded to NHS Surrey http://breachwatch.com/wp-content/uploads/2013/07/nhs-surrey-monetary-penalty-notice.pdf
This is a specific breach that relates purely to Hard Disk Drives and no other data storage media, but the principle is the same, be that a mobile phone or a photocopier.
NHS Surrey appointed a company to dispose of equipment and where assured it would be done correctly. It didn’t.
The salient points of this £200,000 monetary penalty
The Commissioner is satisfied that there has been a serious contravention of section 4(4) of the Act. In particular, the data controller failed to choose a data processor which provided sufficient guarantees in respect of the organisational security measures governing the processing to be carried out, and to take reasonable steps to ensure compliance 6 with those measures. Further, the data controller did not have a written contract with the company under which the data processor was to act only on instructions from the data controller, and which required the company to comply with obligations equivalent to those imposed on a data controller by the Seventh Data Protection Principle.
In particular, the Commissioner would expect the data controller to have carried out a proper risk assessment and chosen a data processor providing sufficient guarantees in a written agreement.
The data controller should then have taken reasonable steps to ensure compliance with those measures such as effectively monitoring the destruction process and maintaining audit trails and inventory logs of hard drives destroyed by the company based on the serial numbers in the destruction certificates for each individual drive.
So let’s look at this further. I think my contract point is well covered as well as risk assessments and method statements. You need these so that your 3rd party disposal company knows what you want them to do with each storage device and a contract that legal binds them to do it.
The final part you need in ensuring security of personal data is evidence that the job has been completed to your requirements.
The Information Commissionaire stated in this monetary penalty award that the organisation should have “effectively monitoring the destruction process”
This is where in my interview I have stated that on the whole the industry is based on a promise with no proof provided.
An asset report listing make, model and serial number is not proof, nor is a waste transfer note. It’s a promise that the company that took your equipment has dealt with it as you expected.
For hard drives, an automated software generated report from programs such as Blanco, Killdisk Tabernus etc. Will provide details of the hard drive serial number, its size. The data it was wiped how many wipes it took and if it was successful or not.
If it was successful, that is proof. If it has failed what happens then? They say, oh we shred it, or crush it. Where is the proof?
What happens to data storage equipment that is not a hard drive? Or does not have a serial number? Where is your proof that the 3rd party company did the work you specified.
I hope anyone reading this can now see how easy it can be to end up like the unfortunate people at Surrey NHS
I am not here to bang on about my company or the services it provides. Just to clarify what legislation expects you to do.
For far too long the focus on IT Asset Disposal has been on complying with the WEEE Directive.
I agree with it and comply with it. But it’s not an organisation killer like breaching the DPA
Let me reiterate the average cost for a single data breach in the UK was £2,370,000.00 in most cases that is an organisation killer.
With new EU Data Directive Regulation 2015 being enacted the requirements for compliance and the costs of non-compliance will be significantly higher.
As I have eluded to all through this thread, most organisations will find it impossible to know if any of the equipment has personal data held within it.
Did some leave a sensitive CD in a machine?
Is a back-up tape still in the tape loader?
Is the SD card still in the phone or the camera?
You need to have rigorous controls and procedures in place so that even if a back-up tape is inadvertently left in a tape loader that’s been collected. The 3rd Party organisation have a procedure set down telling them what to do with it, that they are legally bound in a contract to deal with it that way and that they provide you with evidence that they did it.
Everything that could hold personal data on it, when given to a 3rd party should be treated as if has got personal data on it. The contract, controls and methods I have stated you should have in place will ensure you don’t breach the Data Protection Act.
Finally
Negligence Definition
“Conduct that falls below the standards of behaviour established by law for the protection of others against unreasonable risk of harm”
Make sure you don’t fall in to this category when disposing of redundant IT equipment.
Stone_Charli, if you are going to respond to this thread, before you do, make sure you speak to both Simon and Gary, before you type.