Solved

data sharing with 3rd parties - non technical question

Posted on 2013-12-02
5
453 Views
Last Modified: 2013-12-06
Do the organisations you work for have any requirements to share data with 3rd parties, for whatever reason?

I am trying to establish who in your organisations keep track on any data sharing agreements with 3rd parties - and whether you keep a central list of all data sharing - or any risks you can share in not keeping tabs on data sharing agreements? i.e. no central oversight of data sharing agreements with 3rd parties - whats the risk?

albeit not a tech question with your jobs handling data I assume you may be the ones who have to get data ready for sharing with 3rd parties, hence may have some insight in this area.
0
Comment
Question by:pma111
  • 2
  • 2
5 Comments
 
LVL 76

Accepted Solution

by:
slightwv (䄆 Netminder) earned 250 total points
ID: 39690321
We have MOU's with all outside parties that receive our data and with parties that supply data to us.

If you don't have some 'legal' document that outlines the terms then the receiving parties can do whatever they want with the data.  Like sell it, give it to competing organizations, etc...

If your company needs to share it with someone, they need to dictate what can and cannot be done with it.
0
 
LVL 3

Author Comment

by:pma111
ID: 39690323
Also interested if your data sharing policies formally state any security measures that need to be used when transferring data. I think in the UK their is the context of subject access whereby members of the public can ask an organisation what data they hold about them and why and by law this has to be provided.
0
 
LVL 3

Author Comment

by:pma111
ID: 39690337
Thanks slightwv - I was also interested in the risks of not having anyone in your company not having complete corporate oversight on what data is shared with whom, and any risks associated with not having a corporate oversight of what data sharing you have coming in/going out the organisation.

I appreciate you have to have the rules on what the data can be used for etc.

Does someone in your organisation keep tabs on what data sharing is going on?
0
 
LVL 76

Expert Comment

by:slightwv (䄆 Netminder)
ID: 39690391
We have many lawyers that do many things...  I can't go into great detail about my employer.

Most organizations also have a document data flow somewhere.  If data is shared, then that is data flow (even if it is on CD and mailed).  It should be documented.

As far as the risks go:  If the data is worth collecting and storing in the first place, is it not worth protecting?

A lot depends on the data itself.  Imagine how many companies would LOVE to get their hands on their competitors data.

Just internally, do you let all employees know what all other employees are making?  Not a great idea.  Access and dissemination of payroll data should be documented just like any other data.
0
 
LVL 23

Assisted Solution

by:David
David earned 250 total points
ID: 39690398
In the American culture, at least, people are very prone to sue -- almost as if you just look at them funny.  Mis-use of someone's else property (data), and/or privacy violations (personally identifiable information) is illegal, to some degree or another.  So to your last comment, corporate governance should prescribe what is, and what is not, permitted.

Our security policy calls for data in transit, and at rest, to be encrypted.  For example, the transfer might utilize a virtual private network with an encrypted tunnel, rather than the traditional FTP exchange.  Another good approach is for the target system to pull data up (only), rather than accepting pushed data.

Lastly, a very overlooked aspect is to determine data retention -- and its consequent destruction.  For example, you may have to keep email for some number of years -- but it would be very unwise to simply put your backup media out in the day's trash.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

From implementing a password expiration date, to datatype conversions and file export options, these are some useful settings I've found in Jasper Server.
These days, all we hear about hacktivists took down so and so websites and retrieved thousands of user’s data. One of the techniques to get unauthorized access to database is by performing SQL injection. This article is quite lengthy which gives bas…
This video shows syntax for various backup options while discussing how the different basic backup types work.  It explains how to take full backups, incremental level 0 backups, incremental level 1 backups in both differential and cumulative mode a…
This videos aims to give the viewer a basic demonstration of how a user can query current session information by using the SYS_CONTEXT function

912 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

25 Experts available now in Live!

Get 1:1 Help Now