Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

EU Data Protection Directive – Let's see action?

by The Gurus
March 13, 2015
in Opinions & Analysis
Share on FacebookShare on Twitter

A few months ago we marked three years since the European Union Data Protection Directive was announced and in this writer’s opinion, it’s time for “A little less conversation a little more action”.
 
This week I attended a roundtable hosted by Fujitsu, whose information assurance consultant John Alcock said that despite it still being two years away, it was time to consider it and it is something that he sees that security people want to get a grip of.
 
Also in attendance was Neil Thacker, information security and strategy officer EMEA at Websense, who claimed that the delivery of the directive has created interest among businesses, particularly with the appointment of more chief privacy officers. “It is 20 years since the current directive was published, it is time to move onwards and upwards,” he said.
 
Also on the roundtable was Rik Turner, senior analyst at Ovum, who said that since the publication of the last directive, we have seen cloud, mobile and Big Data happen and the case now is that citizens do not know where data resides.
 
The general agreement on the roundtable was that “nothing is agreed until everything is agreed”, and this seems to be the case as to why it has been so slow in progressing. Thacker said that from the perspective of the CEO, they want to reduce the cost of the data breach, and in his experience the majority of organisations do not have great data security anyway.
 
“They may be focused on data security and compliance, and it is usually understand that collecting is one thing, but how you process it and how it flows is usually the bigger problem, as often it is not meant to leave the company but it does,” he said.
 
Thacker said that the role of the chief privacy officer is similar to that of the data protection officer, as in they will help with legal representatives and the principles of the current directive. Those of you with long memories will recall the plans to introduce a data protection officer in every business, and that prediction seems to have been realised.
 
A survey of 150 IT decision makers by Fujitsu found that 80 per cent believe that more stringent data protection laws are needed, and that 40 per cent do not believe that current regulation around data protection and privacy is adequate to protect an individual’s data.
 
Also perhaps that “chief” word in the title is one to show that the board is taking notice, as 80 per cent of IT decision makers want to see the regulation discussed at boardroom level. Thacker said that it should be an ongoing concern as what is coming has not been changed.
 
Asked by IT Security Guru why there has been such a hold up, Thacker said that there are many who want a clear answer, and there is the danger that we will end up with a watered down approach that adds more confusion.
 
There was a feeling that a delivery date of 2016 or 2017 was more realistic, but considering that it was announced in January 2012, I feel that a lack of communication on the state of the directive has been one of its key features and failings.

Tags: ComplianceData ProtectionLegalRegulation
ShareTweet
Previous Post

TeslaCrypt ransomware targets gamers

Next Post

Yahoo deploys end-to-end encryption for webmail

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol