Complying with data storage and retention laws - it makes good business sense

June 2011 Security Services & Risk Management, Information Security, Financial (Industry)

As the world becomes increasingly digitalised, organisations are storing more and more data electronically, much of which is mission critical and essential to running their business. The integral nature of this data to the business world, as well as events such as the Enron debacle, led governments around the world to begin passing various pieces of legislation around the protection of electronically stored information.

Compliance with legislation in this regard has forced organisations around the world to examine their data policies and adopt new guidelines for the retention, processing and destruction of electronic records and communication. One of the most notable regulations not only for the United States where this law was passed but for organisations around the world, particularly those is the financial sector, was Sarbanes-Oxley, or SOX.

Since the introduction of this regulation there have been many others from various countries, all of which affect multinational corporations or any business which has dealings with these countries. South Africa is no exception, and the most notable piece of law in this regard is the Electronic Communications and Transactions (ECT) Act which came into effect in August 2002 and is aimed at creating a legal framework for governing electronic documentation and transactions. The South African Revenue Service (SARS) also requires that companies keep documentation for a minimum of five years for tax purposes, and the Johannesburg Stock Exchange (JSE) has its own regulations around data retention that listed companies need to comply with.

With all of these regulations that must be adhered to at the risk of strict financial and business penalties, compliance has become not so much a matter of sticking to the letter of the law, but more about business continuity, which after all was the reason behind these laws being imposed worldwide in the first place. However these laws have also meant that requirements for data storage have increased dramatically, as in many cases, for instance the legal profession, they require all electronic documentation and communications to be kept, even junk e-mails and spam. The financial sector also has very strict guidelines as to what information must be kept and for how long, and these regulations mean that the required amount of storage continues to increase along with the volumes of electronic data.

One of the major issues that impacts data storage is having the incorrect software for backups, which results in duplicate copies of the same documents and communications being stored, wasting space and as a result costing money that need not be spent on excessive storage capacity. By introducing software with de-duplication technology, organisations can ensure that only one copy of electronic data will be stored, reducing space requirements dramatically.

The reality is that more laws governing electronic data are in the pipeline, and businesses need to be able to keep their information securely in order to comply. However this does not mean that data retention needs to cost the earth, as a smart strategy around backup and retention can not only aid in compliance but can safeguard the continuity of the business by ensuring that mission critical data is always available for recovery should a crisis occur.

Storage is however not a ‘one size fits all’ technology, and there are various solutions available, including disk storage, tape storage and even cloud storage technology, with both on-site and off-site options available.

Which solution is best for any particular organisation depends on the size and needs of the business, so it is advisable to deal with a backup and security expert who can help to ensure that the solutions that are put into place will meet the needs of today and into the future.

Storage, backup and recovery should form part of strategic business planning to ensure that current and future needs can be met, that businesses comply with all of the regulations related to their industry and business dealings, and that the correct software is in place to optimise the effectiveness of storage solutions and minimise the impact to the bottom line while still remaining effective and ensuring business continuity. It just makes good business sense.

Fred Mitchell, Symantec Division manager at Drive Control Corporation
Fred Mitchell, Symantec Division manager at Drive Control Corporation

For more information contact Fred Mitchell, Drive Control Corporation, +27 (0)11 201 8927, [email protected]





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

SA’s strained, loadshedding-prone grid faces cyberthreats
Power Management Information Security
South Africa’s energy sector, already battered by decades of underinvestment and loadshedding, faces another escalating crisis; a wave of cyberthreats that could turn disruptions into catastrophic failures. Attacks are already happening internationally.

Read more...
Almost 50% of companies choose to pay the ransom
News & Events Information Security
This year’s Sophos State of Ransomware 2025 report found that nearly 50% of companies paid the ransom to get their data back, the second-highest rate of ransom payment for ransom demands in six years.

Read more...
Risk management and compliance enforcement
Security Services & Risk Management
Having a risk management and compliance programme (RMCP) is not just a procedural formality; it is a legal requirement under Section 42 of the Financial Intelligence Centre Act (FICA).

Read more...
The dangers of poor-quality solar cables
Security Services & Risk Management Smart Home Automation
Reports indicate that one in six fires attended by South African firefighters is linked to substandard solar installations, often due to faulty wiring or incompatible components.

Read more...
Growing risks for employers
Security Services & Risk Management
With South Africa’s unemployment rate exceeding 32% and expected to rise beyond 33% this year, desperation is fuelling deception in the job market. Trust is no longer a given, it is a gamble.

Read more...
Chubbsafes celebrates 190 years
Gunnebo Safe Storage Africa News & Events Security Services & Risk Management
Chubbsafes marks its 190th anniversary in 2025 and as a highlight of the anniversary celebrations it is launching the Chubbsafes 1835, a limited edition 190th-anniversary collector’s safe.

Read more...
New law enforcement request portal
News & Events Security Services & Risk Management
inDrive launches law enforcement request portal in South Africa to support safety investigations. New portal allows authorised South African law enforcement officials to securely request user data related to safety incidents.

Read more...
Continuous AML risk monitoring
Access Control & Identity Management Security Services & Risk Management Financial (Industry)
AU10TIX, launched continuous risk monitoring as part of its advanced anti-money laundering (AML) solution, empowering businesses to detect behavioural anomalies and emerging threats as they arise.

Read more...
Back-up securely and restore in seconds
Betatrac Telematic Solutions Editor's Choice Information Security Infrastructure
Betatrac has a solution that enables companies to back-up up to 8 TB of data onto a device and restore it in 30 seconds in an emergency, called Rapid Access Data Recovery (RADR).

Read more...
Growing risks for employers
Security Services & Risk Management
With South Africa’s unemployment rate exceeding 32% and expected to rise beyond 33% this year, desperation is fuelling deception in the job market. Trust is no longer a given, it’s a gamble.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.