ArticlesBase.com - Free Articles Directory
Free Online Articles Directory
25.07.2008 Sign In Register Hello Guest
Email:
Password:
Remember Me 
forgot your password?


Records Management and End of Life Electronics, a Happy Ending?

Author: Laura Gabel Author Ranking Blue | Posted: 14-01-2008 | Comments: 0 | Views: 31 | Rating:  (70) Article Popularity - Blue (?) Got a Question? Ask.
Sign Up Now!

It weighs less than a pound and can fit in the palm of an adult hand. It's made up of aluminum, stainless steel, plastic, and a host of other things. It can hold many secrets. What is it? A hard drive.

Most records managers know that the control and management of the information contained on a hard drive is one of their primary concerns. In every profession, it's what you don't know that can hurt
you. In the case of obsolete computer equipment, which is generally loaded with data, ignorance is not bliss.

Records management responsibilities traverse along many avenues: corporate, moral, historical and of course the practical day to day needs of simply locating proper information for internal clients and others in a secure fashion. But external forces are always hovering over every decision and every action a good Records Manager makes. Those external forces include the dynamic and ever changing trio of compliance, legal and regulatory issues.

Managing data includes managing media containing devices, i.e., all the electronics involved in your organization, from their birth till their death. Dealing with end of life electronics should not be the ugly stepchild of records management. It should be a premier part of the whole life cycle. Why? Because the trio of compliance, legal and regulatory issues can hit a brick wall when old electronics are kept too long and for the wrong reasons.

Here are 10 questions that should convey the collision that can occur when improper disposal and spotty data destruction are employed:
What happens if opposing counsel requests discovery material that should have been eliminated?

Does storing more than 4 computers or over 220 pounds of old electronics for more than a month mean you’re holding on to toxic waste?
Who in your company established the required e-waste conformance procedures so you comply with federal requirements such as HIPAA, SOX, GLB, FACTA and RCRA?

Is it a good idea to let your IT department handle hard drive destruction?

Will driving a nail through a platter, reformatting or up chopping the hard drive with an axe solve your privacy law obligations?
Which legal regulations govern your industry regarding the proper disposal of electronic media?
Do you have management support and a line item in your budget that enables your organization to comply with disposal and environmental regulations?

Do you really know what your company does with the computers that are replaced with new units—outside of, “Gee, I think our property management or IT folks handle it?”

Are you familiar with the 'Disposal Rule' of 2005?
Lastly, are you aware that board members, directors, owners, or CEOs can be held personally responsible for a failure to protect private information (especially on old electronics), which could result in civil penalties of up to $10,000?
"End of Life" electronics are security and compliance hotspots. Sixty-five of all organizations today have no practical approach to handling the proper disposal and destruction of confidential electronic data. So let's explore some facts and then look at a couple of proactive steps you can take towards establishing a judicious, planned approach that eliminates risk.
e-Waste is simply electronics that are obsolete, broken, or unwanted, and present an environmental hazard if not handled properly. When it comes to e-waste, probably the biggest danger for records management professionals is doing nothing. Hoarding old computers is a rampant practice and a dangerous one. What can be dangerous about letting old computers sit? Outside of the R.M. standard of trying to maintain “fresh and live” information so it can be accessed at a later time, there are two types of dangers inherent in keeping old media containing devices. The first failure is not recognizing you have an environmental hazard on your hands. The second is much more onerous, the failure to eradicate improper data handling can cause embarrassing incidents and exposure to data leaks.

Approximately 4 or more stored, obsolete computers can comprise a compliance issue. By ignoring any one of the environmental and data privacy regulations, a company can find itself at risk. According to the Resource Conservation and Recovery Act (RCRA) used electronics are hazardous waste if: 1) the used electronic equipment is no longer useable and has been determined to be a waste; 2) the material exhibits the characteristic of toxicity; and 3) the used electronic equipment originated from non-residential sources such as businesses, academic institutions, or government agencies. (While in some states disposal of personal electronics is not governed by law, everyone should be aware of the true dangers of toxic waste resident in a computer, and dispose of their used electronic equipment responsibly.)

Conditionally Exempt Small Quantity Generators - those producing less than 220 pounds (100 kilograms) of hazardous waste per month may prefer to manage it as hazardous waste due to the minimal requirements associated with the smaller waste volumes. For specific RCRA generator requirements, refer to 40 CFR 261, 262 and 273. One computer system usually weighs about 28 pounds. Since most computers and monitors are full of toxic elements it's best to conform to RCRA's basic compliance requirements (and legally it may be best to manage even small amounts of waste as "universal waste" and recycle responsibly). To view the full Resource Conservation and Recovery Act you can go to: http://www.eendusa.com/industry_overview.htm#rcra . You can also find this same information in EPA circular EPA530-N-007. Other laws probably apply to your organization, you can find an easy to read chart for your industry at http://www.eendusa.com/compliancechart.pdf .

It’s sobering to realize that you cannot bury your old computers and media containing devices. You must plan for their retirement and eventually make sure that there are adequate funeral arrangements, especially in the case of data. Assuming that an internal IT staff is "handling it" is like asking the bookkeeper to perform an audit. Retiring information technology assets is a demanding and full time job. An inadvertent release of sensitive data can send a blaze of bad PR your company’s way!

Stockpiled e-waste increases risk. Big risks include compliance fines of up to $10,000 for senior officers. Need more reasons? Employees are the Number One cause of security breaches which could spell ruin for a company. A Ponemon Data Breach Study “contends that each company surveyed in the study sacrificed roughly $2.5 million in lost business, based on their incidents” (Cost of Data Breaches Rises Sharply by Matt Hines, eWeek.com, October 20, 2006). Additionally, sitting equipment encourages theft and a potential loss of data. There are many ways to handle data destruction including the what, when and how it needs to be done. You may determine that on site verifiable destruction is your best option. However, it’s best to work with an independent electronic recycling firm that can give you options and advice depending on your type of media and security levels you require. Another risk factor is not having a proper data destruction policy and using it. Proper destruction can prevent your company from needless and harmful legal discovery.

There are many concerns, issues and challenges surrounding electronic waste and data destruction, so acknowledge that computer obsolescence is here to stay and start taking steps. Establish a solid e-cycling program, do research, attend conferences, ask questions and work with a reputable, local electronic recycler and data destruction company, one that can, for your peace of mind, provide traceable, documented and responsible materials disposition. Still wondering about the answers to some of those 10 questions? You can test your knowledge by taking an e-cycling quiz at http://www.eendusa.com/ecycling_quiz.htm
Here are six simple reasons that should compel all Records Management professionals to e-cycle: 1) Safeguard your data, 2) Prevent legal problems, 3) Improve the environment, 4) Green your company’s image, 5) Free up costly office space, 6) Reduce landfill usage.

Ignoring your e-waste problem is like wishing your garbage would take itself out, after a while it stinks. According to a Gartner IT Asset Management Conference 2006 Survey, "Ultimately, the most expensive cost associated with PC disposal is the cost for failure to dispose of PCs (and the data residing on the drives) appropriately,” As Records Management executives, you must start handling your end of life electronics properly, because the consequences of doing nothing or it wrong are severe.

Rate this Article: Current: 0 / 5 stars - 0 vote(s).

Article Source: http://www.articlesbase.com/regulatory-compliance-articles/records-management-and-end-of-life-electronics-a-happy-ending-304214.html

Print this Article Print article   Email to a Friend Send to friend   Publish this Article on your Website Publish this Article   Send Author Feedback Author feedback  
About the Author:

Prior to her association with e-EndUSA, Laura served in senior positions with organizations in several types of industries. As senior vice president of marketing and sales for a diversified international services, financial, telemarketing, and wood component technology concern, Laura managed the corporate marketing, sales, and information systems technology departments. Additionally, Laura has held positions as vice president, client relations for an outplacement consulting and management firm; as production director for a magazine; as vice president of admissions for a private college; as western region marketing manager for the largest airline, travel, and tourism school in the United States. Laura received B.A. and M.L.S. degrees from the University of Pittsburgh.

Laura is certified by the International Electronics Recyclers Institute (IERI), an educational affiliate organization of the International Association of Electronics Recyclers (IAER) in: Downstream Due Diligence. She is also a member of Women in Technology and the Ft. Detrick Business Alliance.

Submitting articles has become one of the most popular means of generating quality backlinks and targeted traffic to your website. Join us today - It's Free!

Article Comments

Comment on this article Comment on this article
Your Name
Your Email:
Comment Body
Enter Validation Code: Captcha


Related Articles

Techniques For RoHS Class Compliance
By: Sandra Noble | 12/11/2007 | Regulatory Compliance
The Restriction of Hazardous Substances (RoHS) Directive 2002/95/EC is a directive of the European Parliament. It restricts the use of six hazardous materials in the manufacture and sale of various electrical and electronic equipment in the European Union. The materials are lead, cadmium, mercury, chromium (VI), PBB (poly-brominated biphenyls) and PBDE (polybrominated diphenyl ethers).

Computer Security 101 - are you at Risk?
By: Niall Roche | 20/10/2007 | Security
With the number of identity theft victims growing every day, it is no surprise that computer security is a big concern for most computer users. With the increase in attacks on computers and theft of sensitive information,firewalls and virus protection programs have gone from being rarely used on home computers to being things even the most technologically challenged users want to have installed.

The RoHS Lead Free Directive and How to Comply
By: Sandra Noble | 26/11/2007 | Regulatory Compliance
Health hazards caused by discarded electrical and electronic products are an increasing reality worldwide. The danger arises mainly from lead in components, though other materials may also be toxic. The RoHS directive is one of the affirmative actions used to protect the environment, established by the European Union (EU).

Using an External Hard Drive to Keep your Data Safe
By: Niall Roche | 07/04/2007 | Hardware
If you want to keep your data completely safe, you should look into types of data backup that do not require constant power supplies. While discs such as CDs and DVDs are a good way to make a smaller, permanent backup, external hard drives are another great way to back up your data safely....

Hard Drive Backup Solutions
By: Aaron Walker | 09/04/2007 | Hardware
Are you wondering if there's an inexpensive way to backup the data on your hard disk? There is! While DVDs cost a bit more than CDs...........

Do You Backup All of the Digital Pictures You Keep On Your Computer?
By: Connie McAboy | 16/04/2008 | Travel
This article will describe why it is important to back up computer information, namely your digital photos, and recommends the best solution: online digital backup.

RoHS Chemicals Legislation In Europe and China
By: Sandra Noble | 31/10/2007 | Non-Fiction
About 35 million tons of electrical and electronic items are discarded worldwide every year. Leakage of chemicals in land fills from such discarded equipment pose serious environmental pollution problems. Legislation has been enacted in EU member countries and in China to arrest such pollution.

Tips To Keep Your Laptop Safe
By: Lorne Wilkinson | 12/04/2007 | Computers
Having a laptop computer these days is just as important as having your desktop machine. You need to have access to the internet, your email, and other important data at all times. It's important to remember that the same problems that data recovery, spyware and viruses can cause on your...

Got a Question? Ask.

Ask the community a question about this article:

Frequently Asked Questions

What is section 33-44-809 of the sc code as ...
By: Sue | 23-07-2008
what is section 33-44-809 of the sc code as pertaining to certificate of existence as an llc and someone else trying to use a company which is already in existence.

For a conventional loan, can you gross-up the ...
By: Charlie | 23-07-2008
For a conventional loan, can you gross-up the social security income on the mortgage application? And if so, by what % ______%  ? Thank You!

How many modems can you connect to one incoming ...
By: phil | 23-07-2008
how many modems can you connect to one incoming cable service?

Wireless bridge
By: LPC | 23-07-2008
How to install a bridge PNA85 from my router to a receiver?

Red sox golf bag
By: cass | 23-07-2008
where can I buy a boston red sox golf bag

Computer and DVD hook up to stereo
By: jj | 23-07-2008
computer tower is hooked up to hgtv rgb input but no sound(via tv or stereo speakers). what's wrong? hdtv hooked up to hd cable box which is hooked up to stereo receiver video input and that is working fine (can listen to tv via stereo speakers). Receiver model is sony str-d311. ultimate goal is to use stereo speakers for computer, DVD (dvd can only be heard via tv) as well.

Q&A Powered by:
Powered by Yedda 

Latest Regulatory Compliance Articles

Why Training Is Needed To Use Fire Extinguishers Effectively
By: Thomas Pretty | 24/07/2008
A look at the different types of fire extinguisher and why training should be undertaken so staff members know how to use them effectively.

Comply With Fsa and Fos Guidelines With Phone Call Recording Equipment
By: PXR5 | 24/07/2008
In February this year, the FSA banned one trader for using high pressure sales tactics and misleading customers. Traders can expect a similar fate if they fail to comply with guidelines. Call recording is one way to ensure that your business covers it back in this respect.

How PASMA Have Worked Towards A Safer Working World
By: Thomas Pretty | 21/07/2008
A look at the work of PASMA and how training modules have worked with government legislation to ensure the safety of those working with scaffolding.

Be a Dynamic and Effective Compliance Officer
By: Jide Oniwinde | 19/07/2008
The compliance officer is a gatekeeper whose role is to stop and prevent wrong doing in the firm. The compliance officer is there to maintain the integrity of the firm and be the first line of defence against fraud, market abuse, misconduct. The compliance officer is there to demonstrate the firm’s discharge of its duties of due care, skill and diligence. The role is usually mandatory under financial services regulations.

Risk Management Framework
By: Jide Oniwinde | 19/07/2008
Risk management should remain relevant and be adding measurable value to the business. Components of risks should be expressed in the simplest form possible so that it will not be overcomplicated for others in the business to comprehend.

5 Rules to Succeed in Filing an Insurance Claim
By: Jonathan Cooper | 17/07/2008
This article presents 5 important steps to take to assure that your legitimate insurance claim is not denied on technical grounds.

What Is Involved In A Fire Risk Assessment?
By: Thomas Pretty | 17/07/2008
A look at the legal necessity for a fire risk assessment and how the process is conducted.

IPAF; Ensuring The Safety Of Those Working At Height
By: Thomas Pretty | 17/07/2008
A look at how IPAF work with governments to produce training schedules that will increase the safety of those working on powered access machinery.

Article Categories






Give Feedback

Sign up for our email newsletter

Receive updates, enter your email below