News


Data Protection - What's it Worth?

On 24th November 2010, the Information Commissioner's Office (ICO) issued its first fines to two organisations for serious breaches of the Data Protection Act 1998 (DPA). Even though both organisations voluntarily notified the breaches to the ICO, the fines were still imposed in light of the highly sensitive nature of the data involved.

In the first instance, a County Council was fined £100,000 for sending two faxes to the wrong recipients on two separate occasions. This resulted in disclosure of details of a child abuse case and details of care proceedings. The Council was fined as the ICO considered that the Council’s procedures had failed to stop the two serious breaches taking place.

The second case involved an employment services company, that was fined £60,000 for the loss of an unencrypted laptop containing personal information relating to 24,000 people who had used community legal advice centres in Hull and Leicester. The data included highly sensitive information, such as information about alleged criminal activity and whether individuals had been a victim of crime. A fine was considered by the ICO to be appropriate given that access to the data could have caused substantial distress to the individuals affected and reasonable steps had not been taken by the company to avoid the loss.

The fines send a strong message to organizations that handle personal data (whether as data controller or processor) to ensure that all employee laptops, USB's, external memory drives and CD Roms are encrypted. Failing to do so is likely to be viewed by the ICO as a breach of the DPA and, if appropriate, a significant fine may be imposed.

Furthermore, although notifying the ICO may be taken into account by the Commissioner when deciding whether or not to impose a fine and how much to fine, it is certainly not an absolute defence to a fine being imposed.

For further information please contact Karen Thomas or Jessica Bent on 01225 425731 or e-mail Karen.thomas@withyking.co.uk or Jessica.bent@withyking.co.uk
 

Posted by:
Emma Chappel
Sector:
Other
Tags:
Creative_Bath, data_protection, legal, Withy_King