Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
iPhone 5 rumor rollup for the week ending Feb. 10
Forget Public Cloud or Private Cloud, It's All About Hyper-Hybrid
Apple passes HP as largest tech company
How to get the IRS' attention: Forge nearly $8 million in tax returns, steal identities
Much of Western U.S. is a 3G wasteland, says FCC
How the Phoenix Suns basketball team takes on social media attacks
Microsoft details Windows 8 for ARM devices
Resume Makeover: How an Information Security Professional Can Target CSO Jobs
Blogger exposes major Google Wallet security flaw
Web app lets enterprise set security, sharing for Google Apps users
Cloudscaling to offer OpenStack private cloud platform
Macs take on the enterprise
Valentine's Day Patch Tuesday: Microsoft to issue 9 patches, 4 critical
Mobile World Congress sneak peek: Quad-core smartphones, Ice Cream Sandwich & more


/
Send to a friend Feedback

Security concerns prompt Safe Harbor site changes

Related linksToday's breaking news
Send to a friendFeedback


Security concerns prompted a U.S. government agency to remove two features from its Web site designed to aid the flow of personal information and commerce between the U.S. and the European Union, according to a notice posted on the site.

A self-certification form and the "Safe Harbor list" were removed last Thursday from Safe Harbor, a Web site operated by the Department of Commerce, "in order to review the security of the information submitted to the Department by U.S. organizations," according to a posting on the site.

Though the data in question was removed from the site when security questions were raised, "we haven't found any compromised data," said a Department of Commerce official.

Sensitive information that could potentially have been exposed includes sales levels and numbers of employees of member companies, said the official, adding that it's not clear yet whether that information did in fact become available. Seventy-two companies are involved in the Safe Harbor program including Microsoft, Intel and Hewlett-Packard.

Despite sections of the Web site being offline, Safe Harbor is "still taking plenty of inquiries each day" via fax, the official said.

The Safe Harbor site was established to help smooth over differences in the way the E.U. and the U.S. regulate online privacy and to aid in cross-border commerce. In 1998, the E.U. passed the Directive on Data Protection, which prohibits the transfer of personal information to non-European nations who don't meet with standards set out in the directive. In order to ensure continued flow of information, the U.S. created a "safe harbor" system -- implemented in the Safe Harbor Web site -- for U.S. companies doing business in Europe.

When agreeing to become a Safe Harbor member, a company pledges to make the information it has gathered about individuals accessible, changeable and secure. Companies must also notify users that information is being collected and why, give them the opportunity to opt out and may only pass the information on to other Safe Harbor or Directive on Data Protection-compliant bodies.

The two removed features are expected to be reintroduced soon, "hopefully by tomorrow," the Department of Commerce official said.

"We're not going to fast-track this," the official said. "We're going to look at this very carefully."

The IDG News Service is a Network World affiliate.

Related Links

 
NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.