- Bad Tapes Part 5: From the Ashes Comes New Growth
Bad Tapes Part 5: From the Ashes Comes New Growth
Australian Companies Must Prepare for a New Era of Digital Risk To Take Back Control of Data and Avoid Future Issues
-
3月 28, 2024
ダウンロードDownload Report -
This is part five of a five part report which explores what led to data over-retention on backup tapes, defines the current situation and outlines how to remediate data holdings to reduce ongoing operational costs and regulatory risk. Find out more about this report by reading the introduction or downloading the full Bad Tapes report here.
As Privacy Legislation Gains Teeth and Records Management Moves Files Into the Cloud, Organisations Must Prepare for a New Era of Data Risk.
Sweeping privacy reforms will soon require Australian companies to either de-identify or erase increasing amounts of personal information on request. Meanwhile, panicked and ill-prepared moves to cloud storage are reducing effective data controls.
Once tape archives and data assets have been remediated, act strategically to avoid facing similar problems in the future. To take back control of data and avoid creating new data risk problems in the future, there are a few key actions:
- Clarify the rules and keep them current — Uplift or re-design the policy framework to comply with evolving global regulations and modern technologies. Review the framework regularly to ensure it stays up to date.
- Embed privacy by design — When creating new or modifying existing storage systems, start with a privacy impact assessment to proactively identify and mitigate risk. This way, new initiatives won’t create downstream issues.
- Operationalise retention schedules — Set up a taxonomy for all documentation and train the workforce to save key documents (contracts and financial records) in appropriate storage.
- Assign roles — Data stewards should have accountability over data within select systems and teams. Data committees should be collated to enable a quorum of relevant stakeholders to make defensible disposal decisions.
- Establish de-commissioning procedures — Make sure people know what to do with old systems and data. What must be remediated, how will this happen, who will do it, and when?
- Embrace automation — Explore ways to use technology to make it easier to comply. Implement retention labels and classification to enable automatic alerts that retention periods have been expired and to enable disposal.
出版
3月 28, 2024
主な連絡先
マネージング・ディレクター