Posts

Showing posts with the label data retension

Why other Hotel Chains could Fall Victim to a ‘Marriott-style’ Data Breach

Image
A guest article authored by Bernard Parsons, CEO, Becrypt Whilst I am sure more details behind the Marriott data breach will slowly come to light over the coming months, there is already plenty to reflect on given the initial disclosures and accompanying hypotheses. With the prospects of regulatory fines and lawsuits looming, assimilating the sheer magnitude of the numbers involved is naturally alarming. Up to 500 million records containing personal and potentially financial information is quite staggering. In the eyes of the Information Commissioner’s Office (ICO), this is deemed a ‘Mega Breach’, even though it falls short of the Yahoo data breach. But equally concerning are the various timeframes reported. Marriott said the breach involved unauthorised access to a database containing Starwood properties guest information, on or before 10th September 2018. Its ongoing investigation suggests the perpetrators had been inside the company’s networks since 2014. Starwood disclosed its own...

Marriott Hotels 4 Year Hack Impacts Half a Billion Guests!

Image
A mammoth data breach was disclosed by hotel chain Marriott International today (30 Nov 18), with a massive 500 million customer records said to have been compromised by an "unauthorized party".  The world's largest hotel group launched an internal investigation in response to a system security alert on 8th September 2018, and found an attacker had been accessing the hotel chain's "Starwood network" and customer personal data since 2014, copying and encrypting customer records. In addition to the Marriott brand, Starwood includes W Hotels, Sheraton, Le Méridien and Four Points by Sheraton.  You are at risk if you have stayed at any of the above hotel brands in the last 4 years The Marriott statement said for around 326 million of its guests, the personal information compromised included "some combination" of, name, address, phone number, email address, passport number, date of birth, gender and arrival & departure information. ...

Application Development GDPR Compliance Guidance

Last week  IBM developerWorks released a three-part guidance series I have written to help  Application Developers develop GDPR compliant applications. Developing GDPR Compliant Applications Guidance Part 1: A Developer's Guide to the GDPR Part 2: Application Privacy by Design Part 3: Minimizing Application Privacy Risk The GDPR The General Data Protection Regulation (GDPR) was created by the European Commission and Council to strengthen and unify Europe's data protection law, replacing the 1995 European Data Protection Directive. Although the GDPR is a European Union (EU) regulation, it applies to any organizations outside of Europe that handle the personal data of EU citizens. This includes the development of applications that are intended to process the personal information of EU citizens. Therefore, organizations that provide web applications, mobile apps, or traditional desktop applications that can indirectly process EU citizen's personal data ...

Snoopers’ Charter Law Eroding our Digital Privacy is Sneaking In

Image
The UK parliament re-opened for business today with a new UK government, which means a new raft of laws. While the media and the public were pre-occupied with rights eroding laws on unions to take strike action, and the possible replacement of the Human Rights Act, there was another proposed law in the list which seriously erodes another fundamental human right, our right to privacy. In the last coalition government the Liberal Democrats blocked this law on privacy grounds, but with the LibDems blown away in last month's general election, there is nothing to stop a Conservative majority government placing the Snoopers' Charter law. Anti Austerity and Pro Union Protesters in London after the opening of Parliament The Snooper's Charter is actually the nickname for the Communications Data Bill. The intended bill will grant ‘official’ permission for UK government agencies to read our email, listen to our phone calls and access our web browsing history. The law require...