Since SFTP is a readily available alternative, I think any risk
assessment would say it should be used unless there is some amazingly
good reason for not doing so.
Donald Henderson
Information Compliance Manager
Perth and Kinross Council
-----Original Message-----
From: The UK Records Management mailing list
[mailto:[log in to unmask]] On Behalf Of Phil Bradshaw
Sent: 20 May 2011 11:20
To: [log in to unmask]
Subject: FTP and Personal data
We have a contract wth a company that manages and hosts tachograph data
for some of our drivers. we have done due dilidence and have a data
processing agreement. However the data transfer is done by FTP :
1. Driver uploads his data to one of our PC's 2. It is then transmitted
by FTP direct to the host
Data is essentially driver name, driving licence number, and hours
worked. Not sensitive and not likely to be of much interest or
embarrassment if leaked / intercepted. Nevertheless FTP is inherently
unsecure and sent in clear text which can easily be intercepted, should
anyone wish to sniff it out.
Views please on whether we are breaching principle 7 or given the nature
of the data are our methods 'appropriate'.
To view the list archives go to:
https://www.jiscmail.ac.uk/cgi-bin/webadmin?A0=RECORDS-MANAGEMENT-UK
To unsubscribe from this list, send an email to [log in to unmask]
with the words UNSUBSCRIBE RECORDS-MANAGEMENT-UK
For any technical queries re JISC please email [log in to unmask]
For any content based queries, please email
[log in to unmask]
Securing the future... - Improving services - Enhancing quality of
life - Making best use of public resources.
The information in this email is solely for the intended recipients.
If you are not an intended recipient, you must not disclose, copy,
or distribute its contents or use them in any way: please advise
the sender immediately and delete this email.
Perth & Kinross Council, Live Active Leisure Limited and
TACTRAN do not warrant that this email or any attachments are
virus-free and does not accept any liability for any loss or damage
resulting from any virus infection. Perth & Kinross Council may
monitor or examine any emails received by its email system.
The information contained in this email may not be the views of
Perth & Kinross Council, Live Active Leisure Limited or TACTRAN.
It is possible for email to be falsified and the sender cannot be
held responsible for the integrity of the information contained in it.
Requests to Perth & Kinross Council under the Freedom of
Information (Scotland) Act should be directed to the Freedom of
Information Team - email: [log in to unmask]
General enquiries to Perth & Kinross Council should be made to
[log in to unmask] or 01738 475000.
General enquiries to Live Active Leisure Limited should be made
to
[log in to unmask] or 01738 492440.
General enquiries to TACTRAN should be made to
[log in to unmask] or 01738 475775.
Securing the future... - Improving services - Enhancing quality of
life - Making best use of public resources.
To view the list archives go to: https://www.jiscmail.ac.uk/cgi-bin/webadmin?A0=RECORDS-MANAGEMENT-UK
To unsubscribe from this list, send an email to [log in to unmask] with the words UNSUBSCRIBE RECORDS-MANAGEMENT-UK
For any technical queries re JISC please email [log in to unmask]
For any content based queries, please email [log in to unmask]
|