[Last Call] Learn about multicloud storage options and how to improve your company's cloud strategy. Register Now

x
?
Solved

data sharing with 3rd parties - non technical question

Posted on 2013-12-02
5
Medium Priority
?
468 Views
Last Modified: 2013-12-06
Do the organisations you work for have any requirements to share data with 3rd parties, for whatever reason?

I am trying to establish who in your organisations keep track on any data sharing agreements with 3rd parties - and whether you keep a central list of all data sharing - or any risks you can share in not keeping tabs on data sharing agreements? i.e. no central oversight of data sharing agreements with 3rd parties - whats the risk?

albeit not a tech question with your jobs handling data I assume you may be the ones who have to get data ready for sharing with 3rd parties, hence may have some insight in this area.
0
Comment
Question by:pma111
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 77

Accepted Solution

by:
slightwv (䄆 Netminder) earned 1000 total points
ID: 39690321
We have MOU's with all outside parties that receive our data and with parties that supply data to us.

If you don't have some 'legal' document that outlines the terms then the receiving parties can do whatever they want with the data.  Like sell it, give it to competing organizations, etc...

If your company needs to share it with someone, they need to dictate what can and cannot be done with it.
0
 
LVL 3

Author Comment

by:pma111
ID: 39690323
Also interested if your data sharing policies formally state any security measures that need to be used when transferring data. I think in the UK their is the context of subject access whereby members of the public can ask an organisation what data they hold about them and why and by law this has to be provided.
0
 
LVL 3

Author Comment

by:pma111
ID: 39690337
Thanks slightwv - I was also interested in the risks of not having anyone in your company not having complete corporate oversight on what data is shared with whom, and any risks associated with not having a corporate oversight of what data sharing you have coming in/going out the organisation.

I appreciate you have to have the rules on what the data can be used for etc.

Does someone in your organisation keep tabs on what data sharing is going on?
0
 
LVL 77

Expert Comment

by:slightwv (䄆 Netminder)
ID: 39690391
We have many lawyers that do many things...  I can't go into great detail about my employer.

Most organizations also have a document data flow somewhere.  If data is shared, then that is data flow (even if it is on CD and mailed).  It should be documented.

As far as the risks go:  If the data is worth collecting and storing in the first place, is it not worth protecting?

A lot depends on the data itself.  Imagine how many companies would LOVE to get their hands on their competitors data.

Just internally, do you let all employees know what all other employees are making?  Not a great idea.  Access and dissemination of payroll data should be documented just like any other data.
0
 
LVL 23

Assisted Solution

by:David
David earned 1000 total points
ID: 39690398
In the American culture, at least, people are very prone to sue -- almost as if you just look at them funny.  Mis-use of someone's else property (data), and/or privacy violations (personally identifiable information) is illegal, to some degree or another.  So to your last comment, corporate governance should prescribe what is, and what is not, permitted.

Our security policy calls for data in transit, and at rest, to be encrypted.  For example, the transfer might utilize a virtual private network with an encrypted tunnel, rather than the traditional FTP exchange.  Another good approach is for the target system to pull data up (only), rather than accepting pushed data.

Lastly, a very overlooked aspect is to determine data retention -- and its consequent destruction.  For example, you may have to keep email for some number of years -- but it would be very unwise to simply put your backup media out in the day's trash.
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Lotus Notes has been used since a very long time as an e-mail client and is very popular because of it's unmatched security. In this article we are going to learn about  RRV Bucket corruption and understand various methods to Fix "RRV Bucket Corrupt…
Backups and Disaster RecoveryIn this post, we’ll look at strategies for backups and disaster recovery.
Using examples as well as descriptions, and references to Books Online, show the documentation available for datatypes, explain the available data types and show how data can be passed into and out of variables.
In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB. To learn more check out our webinar on MongoDB administration for MySQL DBA: https://www.percona.com/resources/we…
Suggested Courses

656 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question