Guidance Software calls for rethink on data protection rules
Forensics software company claims rules governing where data can be stored could impede enterprise business growth.

Data protection laws that prevent people from storing data in overseas clouds could be inhibiting enterprise business growth.
That's the view of Sam Maccherola, general manager for EMEA at data forensics vendor Guidance Software, who has called on European lawmakers to overhaul the rules governing where people can store their data.
"Europe is such a small, condensed area and you've got the globalisation of organisations taking place, but moving data from country-to-country is problematic...and I think it's almost an impediment to cloud [growth] in Europe," he told IT Pro.
"Unless the EU changes something in terms of data privacy and the regulation surrounding it, it will continue to be an impediment to business growth."
Maccherola also took aim at the fines handed out by data protection regulators, claiming they need to be drastically stepped up or corporations will continue to flout the rules.
For example, despite ever-tightening data protection laws governing how people's data can be processed and stored, the punishments companies face for failing to follow them are not keeping pace.
"I don't understand the rationale behind all these strict data regulations [if they are not being backed] by real fines, because there are no real ramifications if a [company's] data is stolen," said Maccherola.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"Until corporations have to disclose [that a data breach] has taken place, and the fines remain somewhat nominal, they won't understand the risks associated with losing data and things won't change."
This could potentially be rectified if the European Commission's draft General Data Protection Regulation proposals get the go ahead.
This aims to update the Commission's data protection legislation so that it takes into account the impact of globalisation and newer technology trends, such as cloud computing.
It is also designed to replace numerous other pieces of legislation with a single document.
"Without a doubt, that [sizeable fines] is the missing component because the rationale behind [data protection regulations] makes great sense, but corporations are not taking responsibility because they don't have to," he added.
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
Tech leaders worry AI innovation is outpacing governance
News Business execs have warned the current rate of AI innovation is outpacing governance practices.
By Emma Woollacott
-
Top data security trends
Whitepaper Must-have tools for your data security toolkit
By ITPro
-
SEC data breach rules branded “worryingly vague” by industry body
News The new rules announced last week leave many questions unanswered, according to security industry experts
By Ross Kelly
-
The gratitude gap
Whitepaper 2023 State of Recognition
By ITPro
-
Nintendo hacker forced to pay company 25-30% of earnings for life
News Gary Bowser pled guilty to hacking charges in 2021
By Rory Bathgate
-
Meta sues ‘data scraping for hire’ service that collected info on 600k users
News Meta says tackling data scraping will require a “collective effort” from platforms and policymakers
By Ross Kelly
-
Building a data governance strategy in 2023
In-depth Data governance will continue to expand as attitudes change and businesses look to optimise the value of their data
By Keri Allan
-
FCC plans strict overhaul of 15-year-old US data breach regulations
News Telcos could no longer be able to use negligence as a defence for data breaches as the FCC also seeks to hasten public notification of breaches
By Rory Bathgate