+ Reply to Thread
Results 1 to 3 of 3

Thread: Data Protection Act

  1. #1
    JamesA is offline Coder JamesA will become famous soon enough
    Join Date
    Dec 2006
    Posts
    30

    Default Data Protection Act

    I admin an online community and we may at sometime be collecting information such as names, addresses and phone numbers as the community turns into an official organization. All of the membership management could be handled on the website where members submit this information. Any access to this information would be through a password protected admin panell

    A point was raised during discussion in respect to being in complyance with the Data Protection Acts. Information on the Data Protection Comissioners website seems to pertin to storage and inputing of information on a local server and not a remote server where a website is hosted.
    A Guide for Data Contollers - Data Protection Commissioner - Ireland
    A minimum standard of security would include the following:
    • access to central IT servers to be restricted in a secure location to a limited number of staff with appropriate procedures for the accompaniment of any non-authorised staff or contractors;
    • access to any personal data within an organisation to be restricted to authorised staff on a ‘need-to-know’ basis in accordance with a defined policy;
    • access to computer systems should be password protected with other factors of authentication as appropriate to the sensitivity of the information;
    • information on computer screens and manual files to be kept hidden from callers to your offices;
    • back-up procedure in operation for computer held data, including off-site back-up;
    • all reasonable measures to be taken to ensure that staff are made aware of the organisation’s security measures, and comply with them;
    • all waste papers, printouts, etc. to be disposed of carefully;
    • a designated person should be responsible for security and for periodic reviews of the measures and practices in place.
    They also say that appropriate security measures must be taken depending on the sensitivity of the information being collected. We wont be collecting anything like credit card numbers so can anyone comment on whether what I'm describing (password protected folders on a remote server) might be compliant?

  2. #2
    blacknight's Avatar
    blacknight is offline Web Slave blacknight is a splendid one to behold blacknight is a splendid one to behold blacknight is a splendid one to behold blacknight is a splendid one to behold blacknight is a splendid one to behold blacknight is a splendid one to behold blacknight is a splendid one to behold blacknight is a splendid one to behold
    Join Date
    Jan 2006
    Location
    Ireland
    Posts
    7,890

    Default

    The simplest thing to do is ring them and ask. They're very helpful and if you need to register with them they'll walk you through the entire process

  3. #3
    nevf's Avatar
    nevf is offline You can talk to the Face. nevf has a spectacular aura about nevf has a spectacular aura about
    Join Date
    Aug 2006
    Location
    Ireland, Mayo
    Posts
    458

    Default

    Once your site collects the minimum information required to function, and doesn't request more information than actually required. And that only a limited number, preferably one person can access such information, you should be grand.

    The one problem I recall is that one site was requested, to remove personal information of people from the public's view.

    Also, by the term 'off-site'. That also includes your own personal computer. So just download the odd backup and password protect on your PC, that is seen as okay.

    I had to contact them before in relation to a different matter, sound people to talk to.

+ Reply to Thread

Similar Threads

  1. MAPS spam protection - Plesk/VPS
    By Spiralli in forum Server / Technical Administration Tips and Queries
    Replies: 1
    Last Post: 07-07-2008, 04:22 PM
  2. pay per click data
    By koconnor in forum Pay Per Click Advertising (PPC)
    Replies: 12
    Last Post: 11-02-2008, 05:10 PM
  3. Data retention
    By ConorP in forum Hosting
    Replies: 12
    Last Post: 08-11-2007, 10:08 PM

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts

Search Engine Optimization by vBSEO

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64