Do You Know Where Your Employees' Data Is?

HR departments must take extra care when using SaaS.

InformationWeek Boardroom Journal - May 2010 InformationWeek Boardroom Journal Logo
Download the entire May 2010 issue of
InformationWeek Boardroom Journal
,
distributed in an all-digital format (registration required).

Human resources execs, pressed to control costs and increase efficiency, are increasingly turning to third-party services providers to process sensitive data. Everything from payroll data to performance reviews to health care and personal background information is being handled in remote data centers maintained by third parties.

Any company considering using these services needs to take extra precautions. "Be mindful of geography," says Jonathan Novich, founder of The Code Works, a staffing and recruitment consultant. "Know where the data is coming from, where it's being held. And consult a lawyer."


More Cloud Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

As more software-as-a-service vendors process very sensitive employee or company data, that's where security and geography become concerns. The attention SaaS providers pay to these details varies, contends Scott Blackmer, founding partner of InfoLawGroup, an information law specialist in Salt Lake City. "It's not always clear how they're going to provide security, who handles data, where they handle it, who handles breaches, and how they handle them," Blackmer says. "Those are things that can get a company into trouble."

SaaS providers say privacy and security are some of their key assets. SuccessFactors, for instance, says it has layers of security covering data access, handling, and storage. The protections were enough to persuade a multinational giant with 2 million employees worldwide to sign up recently.

Figuring out where data's being stored and processed is particularly important for customers of SaaS and other types of cloud computing such as infrastructure as a service, where a provider rents out capacity that can be anywhere in its network of data centers.

"Some cloud providers say they can store data anywhere around the world, and they won't tell you where it is," says Robert Gellman, a privacy and information policy consultant. "That's a real problem. What if they decide to store data in a country where you have a dispute or in a country where the government wants to look into your data?"

To read the rest of the article,
Download the May 2010 issue of InformationWeek Boardroom Journal


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links