But they don’t, and that’s not just my personal opinion, but the result of scanning almost 160 DPAs around the world using the excellent free service of Dutch Internet Standards Platform (Internet.nl) , checking web, dns and email security.
First of all though, congratulations to the Autoriteit Persoonsgegevens (AP) | Dutch DPA in Netherlands, the Swedish Integritetsskyddsmyndigheten and the Czech Úřad pro ochranu osobních údajů for sharing 1st place with a perfect 100% score on both web & email security!
To me there is a distinct difference between doing a risk analysis and a data privacy impact assessment (DPIA). Any organization doing risk analysis focuses on valued, threats and weaknesses to themselves, perhaps partially also for their customers. Doing a data privacy impact assessment on the other hand is all about thinking of the potential consequences of humans, be it family, friends, employees, users, customers, clients or make your pick.
A general observation from my side for both is that a lot of people doing either one are not good at imagining what might happen, how it might happen, and potential consequences of bad things happening. I have to confess though, that not having everyone being able to worry too much (…) is probably a good thing.
However, for the sake of this article, I want to point out an important point I just had to repeat in a recent case: the fact that you have told your employees not to send sensitive information by email to anyone doesn’t mean external people won’t send sensitive information to you. Which is why you need to have good email security in place, so that any information sent to you is protected as much as possible. You can be part of the solution, or be part of the problem.
The results shown in these tests shows that a vast majority of DPAs around the world are sadly part of the problem, not the solution. Looking at the results using the links above, you can easily sort based on score or the various security features that are checked and rated using internet.nl.
Opportunities exist for bad actors to abuse, hijack, eavesdrop and stop email & web communication to, and from many of these DPAs. This is because they haven’t deployed proper security rooted in internet standards, best practice recommendations and perhaps also laws & regulations in their respective countries.
Moving forward I intend to track all these DPAs on a regular basis. I will eventually add more as I find them around the world, and report on progress & decline in security for them. I have seen the craziest & most intimate, sensitive personal information being received and sent by mail, no matter what employers or anyone else have taught people. As long as technical security can be improved by simple means – no massive software/hardware investments necessary – I think we should do it.
Unfortunately there are lots of people who’d rather spend hours, days, weeks, months and even years to debate whether this is necessary or not. Some of these actions can be fixed in hours by competent computer operators.
Just get it done.
Originally published on LinkedIn.
