Lee & White

Dedicated to Excellence

  • Home
  • About Us
  • Services
  • Blog
  • Press
  • Publications
  • News
Home > Blog

Go Back

Toothless lion grows teeth

Posted by: Lee & White

Thursday, October 24, 2013

Sleeping LionIt has finally happened.

The Belgian Privacy Commission was once regarded as a toothless lion where its role was mainly passive in nature - giving advice and recommendations. Although it had the power to send warnings and denounce violations to the public prosecutor (only if a complaint first reaches the Commission), it was unable to sanction or do much else. This has resulted in violations of the Data Protection Law nationwide where companies and organisations fearlessly processed personal data according to their whims and fancies. The Privacy Commission has finally realised its inability to bite and is doing something about it.

On October 21, 2013, the Belgian Privacy Commission announced in De Standaard, its intention to set up a special investigation team which would actively seek out breaches of privacy. The Commission wants to play a more active role in checking whether companies or organisations are breaching privacy. By policing, it would be able to better protect the privacy of the individual and maintain law and order.

The initiative is said to have stemmed from recent data breaches:
  • The National Railway Company of Belgium (NMBS/SNCB) stored personal data of 1.46 million customers  on a non-secure server which resulted in the leak of these data (which included first and last names, gender, date of birth, email addresses, phone numbers, and in some cases home addresses) whereby there was possible access by a mere online search engine query.
  • Belgacom's (Belgium's largest telecoms company) internal IT systems had been breached and compromised with malware by a third party which enabled hackers to access telephone and online information.
Although this realisation has come in much later than preferred in comparison with the ICO, its UK counterpart, it is a move that must be applauded.

The gravity of the current situation where the protection of personal data is currently in shambles has reached its limit, and more than ever, the Privacy Commission needs stronger powers to tackle these breaches and safeguard the privacy of the individual. The Commission stated that the investigation team will in the first instance, look into companies and organisations which handle sensitive personal data such as insurance companies and hospitals and focus on a particular sector each year.

The Commission is also seeking to obtain the power to sanction non-compliant companies and organisations as the current situation is such that the Commission can refer violations to the courts, but this is regarded as an overkill. With such a power, the Commission would be able to make decisions such as to no longer allow an offender access to a particular database to render their operations and business more difficult or to revoke permission to build a database.

With this development, companies and organisations which are still relaxed in their attitude towards the protection of personal data and regard such protection as non-profitable, should re-think the business case of protecting personal data and have it as priority in their next budget before it is too late.

Category:

Tags Data Breach Personal Data Government Organisations

Archive

  • 2014
    • March 2014
  • 2013
    • October 2013
    • July 2013
    • May 2013
  • 2012
    • March 2012
    • February 2012
    • January 2012
  • 2011
    • December 2011
    • July 2011
    • June 2011
    • May 2011
    • April 2011
    • February 2011
  • 2010
    • December 2010
    • September 2010
    • June 2010
    • May 2010
    • April 2010
    • February 2010
  • 2009
    • October 2009
    • August 2009
    • June 2009
    • April 2009
  • 2008
    • November 2008
    • October 2008
    • August 2008
    • July 2008
    • June 2008
    • May 2008
    • April 2008
    • March 2008
    • February 2008
    • January 2008
  • 2007
    • December 2007
    • November 2007



Tags

  • Best Practices (11)
  • Business Incentive (1)
  • Data Breach (8)
  • Data Handling Manual (5)
  • Data Protection Officer (1)
  • EU (4)
  • FSA (1)
  • Government (13)
  • Human Rights (6)
  • Internet (21)
  • IT (21)
  • Organisations (40)
  • Personal Data (48)
  • Private Persons (30)
  • Spam (4)

 

Copyright © 2003-2025 Lee & White®. All rights reserved.

Legal Notice  -  Privacy Policy  -  Contact