Permanent overhaul of how non-production data is used
Posted on 22. Jul, 2010 by Huw Price in Test data
How did you greet the news that organisations will soon have to notify customers and regulators of any data breaches?
The EU passed its data breach notification rules last October and they will be rolled out to all member states in 2011. Chances are, many of us thought two things…
One – the rules only apply to telecoms service providers so that’s not a concern and two, the majority of major breaches so far have concerned misplaced laptops and other human (comedy of) errors.
But guess what. The EU has said that it is looking to extend the regulations to all organisations that process personal data, whether that be a supermarket or a bank and daft legislation is coming up soon…
And – non production systems used for in-house development, testing, and training purposes are generally open. So how long before they come under the same remit? After all, a copy is a copy and can be subject to any number of misuses or simple ‘human error’.
Needless to say, the proposed tightening up will mean stiff sanctions and significant fines for companies that fall foul of them.
So perhaps these moves will induce the birth of a new approach to how test data is generated. OK. Enough with the midwifery metaphors. It just seems that a permanent overhaul of how non production data is used is inevitable.
3 Responses to “Permanent overhaul of how non-production data is used”
Trackbacks/Pingbacks
-
-
22. Jul, 2010
[...] This post was mentioned on Twitter by Huw Price, Grid Tools. Grid Tools said: Time to take a look at test data generation techniques http://lnkd.in/MAhJmH [...]




Shobita
02. Aug, 2010
I’ve been looking around the site but would like a little more clarification as to how a Grid-Tools solution would help my company under this legislation?
Huw Price
09. Aug, 2010
Our software solutions help to protect test data. We can de-identify, scramble and mask sensitive records as well as create synthetic data from scratch.
This could help your company with said data breach rules because using a direct copy of a production database for testing and development could be considered a significant breach of the legislation.
Take care when making direct copies of production data to provision test or development data, and look into solutions for data masking or data creation.