Recommendation 1: As a matter of good practice, all organisations handling or sharing significant amounts of personal information should clarify in their corporate governance arrangements where ownership and accountability lie for the handling of personal information. This should normally be at senior executive level, giving a designated individual explicit responsibility for ensuring that the organisation handles personal information in a way that meets all legal and good-practice requirements. Audit committees should monitor the arrangements and their operation in practice.
Recommendation 2: As a matter of best practice, companies should review at least annually their systems of internal controls over using and sharing personal information; and they should report to shareholders that they have done so. The Combined Code on Corporate Governance requires all listed companies to review ‘all material controls, including financial, operational and compliance controls and risk management systems’ ... It would be surprising and worrying not to see information risks addressed explicitly in the Statements of Internal Control for such companies. We hope that bodies such as the Confederation of British Industry will develop guidance to help companies ensure their controls and disclosures are adequate. If approaches on these lines are not successful in improving high-level accountability for giving assurance on information risks, we would expect the Financial Reporting Council to intervene.
UK: the Data Sharing Review and corporate governance
Labels:
audit,
audit committee,
code,
combined code,
financial reporting,
shareholder,
uk
Subscribe to:
Post Comments (Atom)
Cool Followers
Popular entries
-
Incident: Sick Kids physician loses portable hard-drive with unencrypted personal health informationA physician from Sick Kids hospital who decided to travel with a portable hard-drive containing unencrypted health information on 3,300 pat...
-
According to an article in USA Today, Facebook is following in the footsteps of Google and others by using targeted ads. I'm not at all ...
-
On June 23, Australia's Parliamentary Joint Committee on Corporations and Financial Services published a report titled Better sharehold...
-
Apparently the American government is about to implement its latest version of the no-fly list, without data mining using commercial sources...
-
INSOL Europe recently published a report titled Harmonisation of Insolvency Law at EU Law Level : see here ( pdf ). The report outlines di...
-
Section 309 of the California Corporations Code provides that a director must act in good faith, in the manner in which he/she believes to...
-
The Information and Privacy Commissioner of Alberta released a very interesting order today, considering whether the right to freedom of exp...
-
"Police tried to calm the teen, but Holyfield became combative, according to the statement. Officers fired the stun gun at him after he...
-
The International Organization of Securities Commissions has published a revised edition of its Objectives and Principles of Securities Reg...
-
Several months ago the Court of Appeal gave judgment in Moore Stephens (a firm) v Stone & Rolls Ltd [2008] EWCA Civ 644 and it would ap...
Comments
Post a comment on: UK: the Data Sharing Review and corporate governance