What to Do When the Government Wants Your Data

By Ben Worthen on Tue, August 01, 2006
Tweet it!
Email
Digg
Share this article
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

CIO

On the Friday before Memorial Day in 2002, FBI agents descended on a chain of scuba diving stores across the country called Dive Shops, trying to get data on everyone who had learned how to scuba dive since 1999. In order to help out panic-stricken shop owners, the Professional Association of Diving Instructors, the primary organization that oversees scuba certification, gave the FBI a zip drive containing names and other information on about 2 million Americans who had learned to dive over the previous three years.

It was one example of the private sector’s role in the war on terrorism. The U.S. government has over 30 data mining projects that use private-sector data. And while last year the departments of Justice and Homeland Security spent more than $25 million to purchase commercial records from data brokers such as ChoicePoint and LexisNexis, more often than not investigators get the data they want directly from companies, a tactic publicized by the recent National Security Agency project using telephone records. As the CIO, you are in charge of your company’s data. Therefore it is up to you to indemnify your company against legal liability by following the proper procedures when an investigator wants your data.

The first rule, says Behnam Dayanim, a partner with the law firm Paul, Hastings, Janofsky & Walker, is to take every request to the corporate counsel’s office. “You have to get a court order,” he says, or else you may be violating your company’s ¿privacy policy. Also, it is important to make sure that you comply with the request in the order and don’t give more than you are asked for.

Dayanim says that unless a company has a dedicated staffer to deal with requests from law enforcement (many telecommunications companies do, for example), investigators will most likely contact you through a letter addressed to a vague title like IT manager, or will call a junior-level database administrator directly. It is your responsibility to train your staff so they know that all requests must go through the legal department. “I think you have to hit people over the head with it,” says ¿Dayanim. “Most people’s response is to cooperate, but it exposes the company to a tremendous amount of legal liability. It puts the company at risk.”

$firstKeyword

Get up to speed on IT recruiting.

Learn More »
Loading...
Most Recent Compliance Stories
Automation makes compliance part of day-to-day operations, enabling CIOs to shift time to more important things-like a security strategy that protects the business, rather than simply pleases an auditor. Read this exclusive white paper from compliance leader Tripwire to learn how a Protect, Detect, and Correct compliance strategy can give you back your most precious resource: time.
For many companies, regulatory compliance can already be an overwhelming and confusing area to navigate, and the need to comply with the PCI DSS might feel like yet another burden...
Organizations spend more money on risk management and compliance than they should, largely due to inefficiency. In a complex and changing business environment, manually managed and fragmented risk and compliance programs can cripple organizations' agility, performance, and competitiveness. Success therefore requires that an or­ganization integrate, build, and support business process with an enterprise view of risk and compliance. Governance, risk, and compliance (GRC) software can and must deliver value towards this goal.
Enterprises today do not want to be pinned down to one type of architecture. Instead, they want to enjoy global application delivery via a blend of physical, virtual and cloud computing environments. With F5, IT can provide that flexibility without risking application performance and reliability. This white paper explains how.
A report on why market-leading companies use business analytics to their competitive advantage.
Forrester Research conducted in-depth interviews with users who moved from multiple automated point solutions to Application Performance Management.
Grappling with a sprawl of printing and imaging devices across your organization? It's not uncommon today. Many IT leaders say they lack insight into how devices are being used, which ones need updating, and how to best allocate assets across their company. This challenge is causing escalating costs and is creating inefficiencies. In this webcast, we explore managed print services: what it is, how it improves workflow and why it ultimately reduces IT costs.
Join Aternity, a Gartner Cool Vendor in IT Operations, for a live demo on how Fortune 500 companies are leveraging our award-winning platform to deliver a user-centric approach to Proactive IT Management.

When: Sept. 15th / 11 AM PT / 2 PM ET
Watch this on-demand Webinar with Elaina Stergiades, IDC senior research analyst, to discover how IT organizations can better meet the needs of their internal customers.
This webcast, featuring Jim Malone, Senior Editorial Director from IDG Solutions Group and Juan Jones, Senior Vice ...
New Age of Collaboration - Study Reveals a Balancing Act Between Culture and Technology
Strategic planning is critical for your success, yet new research shows it often falls short in even the best organ...
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Resource Center