Showing posts with label AIIM. Show all posts
Showing posts with label AIIM. Show all posts

Monday, 21 December 2015

Seasons greetings from this unseasonably warm UK

Just a short post to both thank my clients during the last year, and for those who have noticed a lack of recent postings to assure you I am still alive.
First the thanks. After two and a half years it is good to know that there is demand for an independent analyst. As the majority of my engagements have been under very restrictive NDAs, I must be careful who I name, but you know who you are and I thank you for your business. Two I can name are Capita and AIIM both of whom have indulged my passion for Data Protection and the forthcoming EU General Data Protection Regulation in particular.
Second my focus for research and consultancy in 2016. GDPR will I believe stay top of my list, as part of the Information Management stream. In addition, despite the UK appearing to give up on renewable energy from photo-voltaic sources (solar panels), I will still be doing a lot of work on market sizing, pricing and sustainable business models, both for the UK and across Europe.
So seasons greetings to all, and all the best for 2016.
Mike

Tuesday, 29 September 2015

#gdpr - still keeping me busy

Following last week's AIIM webinar, I am currently early preparation for a 19 November Capita event . Bit scary as representatives of the UK Information Commissioner's Office (ICO), the EU and the UK Ministry of Justice will be speaking as well. Despite delays in getting the Regulation through it is now very high on the agenda.

UK-related examples, poppy sellers being hounded for charity donations, Lloyds bank customers having their data lost by RSA, and of course all those who submitted their details to Ashley-Madison.
However, lots of challenges still out there to be addressed. Should be an informative day for speakers as well as attendees.

Friday, 4 September 2015

AIIM webinar on EU Data Protection 24 September

Just putting final touches to my presentation. Despite the migrant crisis, there is a lot going on at the moment across Europe on #gdpr. Somewhat ironically having GDPR in place by now, may have helped address the information flow issues which could support a 'whole Europe' policy for migrants/refugees.

Tuesday, 21 April 2015

Channelnomics Webcast

                                                      
Took part in an interesting debate representing AIIM on new security challenges including EUGDPR alongside Mark Oakton, Chief Executive, Infosec Partners; Alan Ryan, Security Practice Director, MTI Technology;Omer Wilson, EMEA Marketing Director, Digital Realty and Tom Owen, Security Manager, Memset. 
Was a bit hot under the lights (I didn't need that tee-shirt).

Link to the download: http://bit.ly/1J68nSG
Link to the player:      http://bit.ly/1HQhcP7

Tuesday, 30 September 2014

EU General Data Protection Regulation is coming!

I have had three press calls in the last month about the issue. I have been invited to speak at AIIM's Trade Meeting in London on 10 October on the matter, and Oracle yesterday announced it is opening not one, but TWO, data centres in Germany (#oow14) to add to the three it already has in Europe.
The 'growing demand' in Oracle's press release is not just about capacity, but also a recognition that from the implementation of the Regulation, data storage in the cloud, about EU citizens, outside the EU's boundaries, will be both a business risk and potentially a competitive disadvantage.
Businesses and organisations need to start taking action now. The recent AIIM report is a good 'primer'.

Thursday, 31 July 2014

EU GDPR , not hard to address - just think differently

When I am discussing with clients the potential impact on their business processes of the forthcoming EU General Data Protection Regulation (GDPR), I am invariably asked for an example and I always endeavour to identify one appropriate for their business environment.
Imagine therefore, my delight when one, which is applicable to more than half the UK population, landed literally on my mat this morning.
The example in question was a letter from our local Electoral Registration Officer (ERO -the council chief executive) explaining that there are now two versions of the electoral register: the existing ‘electoral register’ and the new ‘open register’, but I didn’t need to do anything as I had automatically been put on both.
In the UK, the electoral register lists the names and addresses of everyone who is registered to vote in public elections, it is also used for detecting crime, calling people for jury service and checking credit applications. The new open register is an extract from the electoral register which can be sold to any person, company or organisation, in most cases for marketing by the person buying and to raise income for the ERO selling.
One of the central requirements of the forthcoming  GDPR is that there is ‘explicit consent’ for the use of personal information, with a few exceptions for national security and public health. Therefore under the Regulation, rather than the wording of my letter being ‘Your name and address will be included in the open register unless you ask for them to be removed’. The wording needs to state ‘Please confirm you are willing for your information to go on the open register’.
This may make my ERO balk, because rather than a few members of the electorate ringing up his team to be taken off the open register i.e. ‘opt-out’, his team would potentially have to deal with a much higher number of requests to ‘opt-in’.
However, if the ERO looks again at the process; each year he sends a letter to the ‘head of the household’ requiring them to list the names and dates of birth all residents who will be 18 before the next election. It would be a simple change to require there to be a signature against each name confirming that that person wishes either to ‘opt-in’ or ‘opt-out’ of the open register. This should be compliant with the GDPR and as a bonus it could reduce the current opportunity for electoral fraud.
As I said in a recent AIIM webinar organisations need to see the GDPR as an opportunity, not an overhead, those that don’t will be caught by the regulator and it will cost, both in reputation and fines (up to €1 million or 2% of annual global sales). My suggested change to process will not cost the ERO any more than now, and may even save him the costs of some of his team answering calls from the worried electorate.