Lee & White

Dedicated to Excellence

  • Home
  • About Us
  • Services
  • Blog
  • Press
  • Publications
  • News
Home > Blog

Go Back

The Early Bird

Posted by: Lee & White

Tuesday, August 19, 2008

We manage IT projects on a daily basis, and in every project there is the returning constant of processing personal data.

I must say that most clients we have worked with show the goodwill to properly handle personal data, but sometimes other priorities, like financial limitations or time constraints, make it such that proper processing is seen to be a lower, if not the lowest priority.

Sometimes we get called in to audit a company to check existing processes and applications for compliance to data processing laws. We then need to inventorise what kind of data is kept and where, how it is handled, and what the procedures and communications are. Basically, a thorough in-depth audit that involves and affects all levels of the business.

When we are involved from the very start, we can, even already on a requirements or functional level, pinpoint where issues would arise, and through small changes in the design and implementation process, ensure that applicable laws and good practices are met.

It is the same for all problems; if you can catch and fix it at an early stage, the cost is a factor lower than if you have to fix it at a later stage. If, of course, even at that stage you do not fix it, then the cost of being caught after go-live is enormous. This can not only have financial implications, but also cause damage to reputation and brand, as well as have criminal consequences.

A data protection officer should be involved at every stage of a new project. He should validate business requirements, check functional analyses, approve technical designs and audit proper handling after go-live. If properly executed, the amount of time (and budget) spent on this role would be minimal, and as such only big corporations need a full FTEto perform this role. Most companies can hire external consultants to do this on a part time or time and material basis.

Some companies make the mistake of asking their in-house legal department or company lawyer to advise on data protection issues. Unfortunately, these individuals are not specialized to give this kind of advice and are usually fully booked to solve other company related legal issues. Also, they might be too deeply involved in the business to give impartial advice.

Specialized legal consultants have the experience and know-how through different projects to handle these kind of problems on a daily basis. They can also deliver impartial advice without risk of conflict of interest.

So, in conclusion
  1. Hire a professional to get a professional job done.
  2. Fix problems before they arise.
  3. Do not ignore laws and best practices.

    Category:

    Tags Personal Data Organisations IT

    Archive

    • 2014
      • March 2014
    • 2013
      • October 2013
      • July 2013
      • May 2013
    • 2012
      • March 2012
      • February 2012
      • January 2012
    • 2011
      • December 2011
      • July 2011
      • June 2011
      • May 2011
      • April 2011
      • February 2011
    • 2010
      • December 2010
      • September 2010
      • June 2010
      • May 2010
      • April 2010
      • February 2010
    • 2009
      • October 2009
      • August 2009
      • June 2009
      • April 2009
    • 2008
      • November 2008
      • October 2008
      • August 2008
      • July 2008
      • June 2008
      • May 2008
      • April 2008
      • March 2008
      • February 2008
      • January 2008
    • 2007
      • December 2007
      • November 2007



    Tags

    • Best Practices (11)
    • Business Incentive (1)
    • Data Breach (8)
    • Data Handling Manual (5)
    • Data Protection Officer (1)
    • EU (4)
    • FSA (1)
    • Government (13)
    • Human Rights (6)
    • Internet (21)
    • IT (21)
    • Organisations (40)
    • Personal Data (48)
    • Private Persons (30)
    • Spam (4)

     

    Copyright © 2003-2025 Lee & White®. All rights reserved.

    Legal Notice  -  Privacy Policy  -  Contact