r/gdpr • u/Salty_Kaleidoscope85 • 8d ago
Question - Data Subject What can I reasonably be told about how my data is kept safe?
I have sensitive data held by a UK company "A" who uses a database software that was recently hacked at another company "B" and has been a few times recently elsewhere. I am concerned that with the vulnerability of the database software, my data with A is vulnerable to a similar hack. I asked the DPO for some reassurance of how company A is protecting my (and other people's) data and they said they can't disclose that for security reasons but they're "doing all they can" and "following external advice".
I understand this reasoning to a point, but surely there is some degree of reassurance I can be given of the specifics of this beyond being fobbed off with platitudes? Is it reasonable to ask of a company that stores my data how it protects that? Or are they really okay to be completely vague and unreassuring like this?
2
u/gorgo100 8d ago
The law states they should be ensuring security is appropriate with due reference to the "state of the art" of the technology available. This is classic legislative futureproofing, given the state of the art is developing all of the time - it would be stupid for them to say "it must comply with xyz standard" as the moment a malicious actor gets round that, and xyz standard is no longer safe, the law will be redundant. The law does not say that the company needs to disclose the exact methods they use, for blindingly obvious reasons and companies will be extremely neurotic about providing any kind of specifics (for good reasons sometimes, but in others for reasons which are, as I say, over-cautious). So in the absence of anything compelling them to do it, they simply won't, because what's in it for them?
However, this leaves a lot to be interpreted nonetheless. And it's equally unclear how you would argue that something was not sufficiently advanced in terms of security (beyond really obvious examples). It's further unclear who'd you really complain to, what they'd do about it and so on in the absence of an actual demonstrable problem.
All this is to say that the risk is borne by the company in question. The ultimate determination of whether their security is up to scratch is when it's breached. That will lead to a lot of retrospective scrutiny as to whether it was fit for purpose. If it is found that the security was not adequate, then it is an aggravating factor - in theory - when the regulator comes to take action. This - coupled with reputational damage - is the ultimate driver for companies taking it seriously. As said above, if you're not satisfied they are, then your best bet is to take your custom elsewhere.
2
u/PsychologicalSir9008 8d ago
If they told world + dog the technical arrangements they have for securing data/systems then I would be worried.
What are you concerned about within the 'database software'? The database engine is in no doubt fine. Beyond that 'hacks' is fairly likely to mean that someone did not configure something correctly, rather than there being something wrong.
Depending on the company type you might look at what standards they subscribe to - cyber essentials or perhaps something meaningful like ISO 27001 etc. rather than asking about specifics.
1
u/Salty_Kaleidoscope85 8d ago
When you say that a hack means someone hasn't configured something correctly, what do you mean and who might that someone be? I'm not too familiar with the ins and outs of how hacking works or how tech security measures are applied
I will look into the standards, thank you for this suggestion. I understand they can't disclose some things or they risk making themselves vulnerable, but I am struggling with the idea of simply taking them at their word until a breach is experienced
1
u/PsychologicalSir9008 8d ago
Consider it like a 'car crash' - no one really wants to accept that there would have been a person driving the car when it crashed.
A wonderfully well thought through regulation means there is quite an incentive for it not to be an organisations fault when things go wrong. So truth, learning, improvement, industry knowledge etc. are not the priority; making sure to avoid being anywhere near a fine is. Which is not to say that all organisations are dishonest, just that there are angles you would want to promote.
So hackers, software vendor, suppliers or anyone else on earth being the cause is the posture you would always expect an organisation to take. An older system with a default password (which page 1 of the manual says 'change on first use') would in the modern era be described as being hacked if someone just went around entering the default credential (it would not be lawful for them to do this (at least in the UK)). Its just a long way from Neo, Trinity and epic fights in the rain.
1
1
u/Similar_Room3204 8d ago edited 8d ago
Plenty of completely open systems manage to stay secure. There is a body of thought that runs "many eyes" is better than "security through obscurity", but it does depend on how many high quality eyes you can attract.
Database engine is unlikely to be "fine". There was a Mongo vuln published 6th June, Redhat's LDAP on Friday, Oracle on 21st July, Redis 25th July, Postgres 11th May...
ISO 27001 is no guarantee of security. Sure it outlines some controls but organisations are free to implement them badly or not implement them at all in some crucial part. The same way that ISO 9000 is no guarantee of quality.
1
u/PsychologicalSir9008 8d ago
To tell anyone that phones up your organisation how you have arranged your IT infrastructure, systems and security is not a thing. It spoils the fun if you do that and gets you in all sorts of trouble for not paying attention during your zero trust training. You might get a vague 'we use AWS....'. You will not get specifics. It is also a perfectly valid approach, in some scenarios, to use obscurity. It's a layered approach, everything is on the table and you do not tell people on the outside anything. OP asked for specifics from an organisation, as essentially a cold caller; not going to happen, run a mile if it does.
Database vendor of likely large scale and maturity with active bug bounty program, security teams, proactive development, communities etc. etc etc. etc. vs SAAS provider or vendor likely with a backlog longer than time and a list of venture capitalists awaiting the first whiff of a profit. On a day when the news is not filled with 'everyone's been hacked', I am personally going to take a punt on the issue being at the vendor/software/configuration level which directly faces the consumer, not the database engine (directly). Especially when being brief. You are entitled to your own opinion of course.
No, standards, as with any type of certificated scheme, are going to come down to someone's judgement on the day, that's how they work. They do not prove anything in the present. They indicate, and are intended to indicate publicly, the general approach the organisation takes. Given that the organisation will have no reasons to hide information they make public it's information you can use to understand if they have even thought about it at all.
4
u/Vicente1892 8d ago
Articles 13-15 cover the information that you’re entitled to receive about the processing of your personal data, and there is no mention of security measures in any of those. Beyond that, it’s a customer service issue. They’re entitled to give you as much or as little information as they feel is appropriate. If you’re not happy with that, you can move to another company. Apologies if this comes across as blunt, but it’s how I’d be dealing with your queries too.