Home
Security assessments and audit
Security design and review
Policies, standards and procedures
Approach
Case studies
Check lists
Top 10s
Company information
Principal staff
Website map
Terms of use
Privacy notice
Legislation
Standards and codes of practice
Organisations
Publications
Addresses
Enquiry form
Business case for investing in proactive privacy protection
business case for investing in pro-active privacy protection
Watson Hall Ltd and John Leach Information Security Ltd jointly undertook a project for the United Kingdom Information Commissioner's Office (ICO) to research and develop an easily understandable and compelling business case that will help organisations to justify and implement privacy protection within their business processes and systems. On 7th August 2009 the ICO announced the appointment and forthcoming discussion document. The final report was announced at the at the Data Protection Officer Conference in Manchester on 3rd March 2010.
Final report
The report The Privacy Dividend was published by the ICO on Wednesday 3rd March 2010 (2.4 MB PDF, 93 pages A4).
Press coverage and discussion elsewhere about the project.
Background
The Privacy by Design report, commissioned by the ICO in 2008, identified the absence of a soundly argued business case for investing in privacy friendly systems and business processes as one of the barriers to more proactive privacy protection.
In order to address this aspect, the ICO commissioned to develop a document setting out the business case for investing in proactive privacy protection in existing or new business processes. This involved understanding the organisational processes involved in procuring, implementing and changing information systems and business processes across the public, private and professional services sectors, researching the value of personal information as an asset and quantifying the risk to personal information.
As part of this work, we undertook research on the organisational methods involved in implementing business processes and procuring information systems. We researched and detailed the role and value of personal information for data handlers, covering organisations in the public, private and professional service sectors. We also quantified the potential risks faced by personal information whilst in the hands of data handlers.
Discussion document
We would like to thank all the people and organisations that have contributed to our research.
To support this research and to bring together a wide range of views, we conducted a number of interviews and published a discussion document. The discussion document described and expanded upon a number of central issues relevant to this work and was the primary means by which we solicited input from a wide range of knowledgeable contributors. Input from all types of organisations that collect and process personal information, other interested organisations, and individuals was welcomed.
Download
The discussion document version 1.2 was published on Tuesday 25th August 2009 (236 kB PDF, 24 pages A4). This file is also linked from the right hand margin of the page.
Contributions
Contributions provided will remain confidential to us and will not be shared with the ICO or any other party. However, we may wish to refer to or quote from contributions though we would ensure that the source of the contribution (either individual or organisation) was not and could not be identified unless the source provided their express consent. Please also read our privacy notice.
Contacts
Please contact the ICO for further information about the report. For other information, please use either of the following.
|
|
|
John Leach Information Security LtdDr John Leach |
Watson Hall LtdMr Colin Watson |
These pages contain general information only. Nothing in these pages constitutes professional advice. Please read the website's terms of use, and consult a suitably qualified information security professional on any specific problem or matter.