Irish SEO,  Marketing & Webmaster Discussion

 

Data Protection Act

This is a discussion on Data Protection Act within the Webmaster Discussion forums, part of the Webmaster Help category; I admin an online community and we may at sometime be collecting information such as names, addresses and phone numbers ...


Go Back   Irish SEO, Marketing & Webmaster Discussion > Webmaster Help > Webmaster Discussion

Register Forum Rules FAQDonate Calendar Search Today's Posts Mark Forums Read

  #1 (permalink)  
Old 18-11-2008, 07:47 PM
Frontpage User
 
Join Date: Dec 2006
Posts: 23
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
JamesA will become famous soon enough
Default Data Protection Act

I admin an online community and we may at sometime be collecting information such as names, addresses and phone numbers as the community turns into an official organization. All of the membership management could be handled on the website where members submit this information. Any access to this information would be through a password protected admin panell

A point was raised during discussion in respect to being in complyance with the Data Protection Acts. Information on the Data Protection Comissioners website seems to pertin to storage and inputing of information on a local server and not a remote server where a website is hosted.
A Guide for Data Contollers - Data Protection Commissioner - Ireland
Quote:
A minimum standard of security would include the following:
  • access to central IT servers to be restricted in a secure location to a limited number of staff with appropriate procedures for the accompaniment of any non-authorised staff or contractors;
  • access to any personal data within an organisation to be restricted to authorised staff on a ‘need-to-know’ basis in accordance with a defined policy;
  • access to computer systems should be password protected with other factors of authentication as appropriate to the sensitivity of the information;
  • information on computer screens and manual files to be kept hidden from callers to your offices;
  • back-up procedure in operation for computer held data, including off-site back-up;
  • all reasonable measures to be taken to ensure that staff are made aware of the organisation’s security measures, and comply with them;
  • all waste papers, printouts, etc. to be disposed of carefully;
  • a designated person should be responsible for security and for periodic reviews of the measures and practices in place.
They also say that appropriate security measures must be taken depending on the sensitivity of the information being collected. We wont be collecting anything like credit card numbers so can anyone comment on whether what I'm describing (password protected folders on a remote server) might be compliant?
__________________

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #2 (permalink)  
Old 18-11-2008, 07:56 PM
blacknight's Avatar
Web Slave
 
Join Date: Jan 2006
Location: Ireland
Posts: 7,241
blacknight will become famous soon enoughblacknight will become famous soon enoughblacknight will become famous soon enoughblacknight will become famous soon enoughblacknight will become famous soon enoughblacknight will become famous soon enoughblacknight will become famous soon enoughblacknight will become famous soon enough
Default

The simplest thing to do is ring them and ask. They're very helpful and if you need to register with them they'll walk you through the entire process
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #3 (permalink)  
Old 18-11-2008, 10:15 PM
nevf's Avatar
You can talk to the Face.
 
Join Date: Aug 2006
Location: Ireland, Mayo
Posts: 455
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
nevf has a spectacular aura aboutnevf has a spectacular aura about
Send a message via MSN to nevf Send a message via Skype™ to nevf
Default

Once your site collects the minimum information required to function, and doesn't request more information than actually required. And that only a limited number, preferably one person can access such information, you should be grand.

The one problem I recall is that one site was requested, to remove personal information of people from the public's view.

Also, by the term 'off-site'. That also includes your own personal computer. So just download the odd backup and password protect on your PC, that is seen as okay.

I had to contact them before in relation to a different matter, sound people to talk to.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Reply

Tags
act, data, protection

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads

Thread Thread Starter Forum Replies Last Post
MAPS spam protection - Plesk/VPS Spiralli Server / Technical Administration Tips and Queries 1 07-07-2008 04:22 PM
pay per click data koconnor Pay Per Click Advertising (PPC) 12 11-02-2008 04:10 PM
Data retention ConorP Hosting 12 08-11-2007 09:08 PM


Sponsored links

Pepperjam Network
Paid On Results www.zanox.com


All times are GMT +1. The time now is 06:48 PM.


Powered by: vBulletin Version 3.8.2, Copyright ©2000 - 2009, Jelsoft Enterprises Limited.
Hosted in Ireland by Blacknight - Test your ISP |Irish Hosting Directory| Armchair.ie|Logo by Eden Web Design|Avatars by Afterglow |Latest Blog Entries | VPS HostingAd Management by RedTyger

Search Engine Friendly URLs by vBSEO 3.3.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51