Chris McClean serves Security & Risk Professionals. See the full Analyst bio.
Visit Forrester.com to learn how we make Security & Risk Professionals successful every day.
Play fair... or they'll come after your secrets
Posted by Chris McClean on September 25, 2007
I’m not usually one for ‘this-could-happen-to-you’ stories, but I’m still having trouble getting over last month’s story about grocery giant Tesco having to turn over 11 million emails to the UK’s Competition Commission for their investigation into possible anti-competitive practices against its suppliers.
Besides the sympathy headaches I have for the poor interns that have to spend the next year sifting for keywords like “monopolize”, “price gouge”, and “illegal”, I’m curious how the company is going to handle the privacy and confidentiality issues of turning over this amount of information. For example, what are the chances this will expose other data relevant to the two other investigations the Competition Commission launched against the company this summer, much less exposing personal employee information?
I’m even more curious about how Tesco enforces the promise in its corporate responsibility report that the company is “determined that everyone involved in (its) supply chain benefits from their relationship with Tesco.” If the company can demonstrate how this works, it’s good news for the Commission... and certainly much easier on those poor interns.
search forrester's blogs
Secure the digital business future.
Attend Forrester’s Forum for Security & Risk Professionals EMEA, June 10-11, London UK
Analyst Blogs
- Andras Cser (30)
- Andrew Rose (17)
- Chris McClean (54)
- Christopher Sherman (1)
- Edward Ferrara (19)
- Eve Maler (19)
- Heidi Shey (9)
- John Kindervag (28)
- Khalid Kark (13)
- Laura Koetzle (2)
- Nick Hayes (5)
- Rick Holland (20)
- Stephanie Balaouras (50)
Top Categories
- GRC (21)
- Enterprise Risk Management (10)
- Governance Risk and Compliance (2)
- IT Risk Management (2)
- IT security (2)
- acquisitions (1)
- BC/DR (1)
- BT Resiliency (1)
- Business continuity (1)
- business technology resiliency (1)
- See all
Archives
- March 2013 (1)
- February 2013 (1)
- November 2012 (1)
- May 2012 (2)
- March 2012 (1)
- November 2011 (1)
- October 2011 (1)
- September 2011 (1)
- May 2011 (1)
- February 2011 (2)
- January 2011 (1)
- December 2010 (1)
- November 2010 (1)
- See all
Comments
re: Play fair... or they'll come after your secrets
Chris, you've raised a great point about the conflict between investigations and employee privacy rights. How can companies turn over the information needed for electronic discovery while not turning over so much as to violate employees privacy? This problem comes up even more frequently in the case of internal investigations. The best practice to proactively prevent problems is to be sure that HR is part of the investigations team from start to finish along with the privacy officer. They each add their own expertise of applicable laws.