New legislation 'has a major impact on data security'

IT contractors have been advised that new legislation will have a significant impact on the way UK companies formulate their data security procedures.
European data protection law stipulates that any data obtained by a UK company is subject to the same protection guarantee whether it is processed in this country or outside the European Economic Area (EEA), according to Out-law.com, which is operated by legal firm Pinsent Masons.
In an effort to ensure this is done, as of this week European firms are required to insert clauses guaranteeing this into any contract with a non-EEA processor, according to Pinsent Masons' Louise Townsend.
These clauses will also take into account the fact that the non-EEA processor may also subcontract the data.
"A data importer must not subcontract without the prior written consent of the data exporter and then only by way of a written agreement imposing the same obligations
the data importer remains fully liable for the activities of its sub-processors," Ms Townsend added.
Earlier this month, software manufacturer CA claimed that poor standards of information security in UK firms are damaging their reputations.
