• Home
  • Consultancy
  • Training
  • Products
  • Events
  • Case Studies
  • About us
Home

New Standard Assisting Organisations Comply with the Data Protection Act

Background and Objectives

In May 2009, British Standards Institution (BSI) published the first ever standard to focus on the management of personal information. It has been developed to enable organisations to develop and implement a personal information management system (PIMS), thus providing an infrastructure for improving compliance with data protection legislation and, in particular, the Data Protection Act 1998 (DPA).

The development of BS 10012 can be seen as a response to the increasing focus on personal data protection and the fact that more and more organisations are opting to keep data. As Richard Thomas, Information Commissioner commented on 7 January 2009 to a Justice Select Committee "It is often said that it is now cheaper to store data than delete it." The seemingly endless spate of recent high profile data losses also, undoubtedly, contributed to the development of this Standard.

The BS 10012 Standard enables organisations, from both the public and private sectors in the UK to put in place an infrastructure for maintaining and improving compliance with the DPA.

Framework Approach based on Continuous Improvement

BS 10012 is not a prescriptive Standard. It adopts a 'framework' approach within which organisations can more effectively manage personal information. Organisations can create bespoke management systems which include processes to address risk assessment, training and awareness as well as key data protection issues such as the sharing, retention, disposal and disclosure of information. Organisations are encouraged to ensure sufficient guidance and resources are allocated to data protection and that a positive culture exists in which data protection can occur. The Standard follows the classic ‘Plan-Do-Check-Act’ model of continuous improvement as utilised by standards such as ISO 27001 and BS 25999.

Benefits

Ultima Risk Management believes that the introduction of BS 10012 represents an important milestone in providing organisations with an ideal framework to adopt in order to improve compliance with the DPA. As Lisa Dargan Business Development Director at URM explains "Protecting personal information is a key and growing issue for organisations of all sizes and from both the private and public sectors. Being able to demonstrate to key stakeholders including customers and suppliers that your organisation complies with the DPA has always been a challenge. BS 10012 represents a major breakthrough in this respect and will enable organisations to demonstrate that they are handling personal information in a structured and responsible way. I would strongly recommend that any organisation which needs to demonstrate its compliance with the DPA, reviews and adopts this Standard.

Further Information

For more information on BS 10012 please go to BSI product page on BS 10012.

If you are interested in understanding how your own organisation can benefit from adopting this Standard, please email info@ultimariskmanagement.com

  • Consultancy Introduction
  • Information Security (ISO 27001)
    • Information Security (ISO 27001)
    • Relationship between ISO 27002 & ISO 27001
    • How to Comply with ISO 27002 or Certify to ISO 27001
    • ISO 27001 Awareness Training
    • ISO 27001 Case Studies
  • Information Security (PCI DSS)
    • Information Security (PCI DSS)
    • Stages of Compliance to PCI-DSS
  • Information Security (DMA DataSeal)
  • Business Continuity Management (BS 25999)
    • Business Continuity Management (BS 25999)
    • Significance of BS 25999
    • How to deploy BS 25999 - Lifecycle Stages
    • Crisis Management Simulation Exercises
    • New ISO Standard for BCM - ISO 22301
  • IT Service Management (ITIL & ISO 20000)
    • IT Service Management (ITIL & ISO 20000)
    • Significance of ITIL & ISO 20000
    • How to deploy ITIL or certify with ISO 20000
  • Data Protection
    • Data Protection - Introduction
    • URM's approach to Data Protection
    • BS 10012 - New DPA Standard
  • Information Risk Management
    • Information Risk Management
    • URM's approach to Information Risk Management
  • Software Asset Management
    • Software Asset Management
    • URM's approach to Software Asset Management
  • Polices & Procedures
    • Polices & Procedures
    • URM's approach to Polices & Procedures

Copyright © Ultima Risk Management, 2010. All Rights Reserved

  • contact us
  • careers
  • terms of use
  • privacy
  • site map