Simple clear advice in plain English

ICO fines two councils for data-protection failures

Over £1m in penalties now handed out by Information Commissioner's Office

Concept image representing data protection rules
Two councils fined for failing to keep sensitive information about children secure

A further two councils have been fined by the Information Commissioner's Office (ICO) for failing to keep data secure.

Croydon Council was fined £100,000 after a bag containing papers relating to the care of a child sex abuse victim was stolen from a London pub.

An £80,000 fine was given to Norfolk County Council for disclosing information about allegations against a parent and the welfare of their child to the wrong recipient.

Stephen Eckersley, ICO head of enforcement, said: "We appreciate that people working in roles where they handle sensitive information will – like all of us – sometimes have their bags stolen.

"However, this highly personal information needn't have been compromised at all if Croydon Council had appropriate security measures in place.

"One of the most basic rules when disclosing highly sensitive information is to check and then double-check that it is going to the right recipient. Norfolk County Council failed to have a system for this and also did not monitor whether staff had completed data-protection training."

Both breaches occurred in April last year, according to the ICO which said the councils in question has taken remedial action. But Eckersley commented that "this does not excuse the fact that vulnerable children and their families should never have been put in this situation."

These latest penalties bring the total amount served by the ICO to organisations found in serious breach of the Data Protection Act to over £1m.

Reader Comments

Human error and data protection

It's telling that the ICO should have to point out that individuals should "check and then double check" that sensitive information is being sent to the right person. It's a fundamental problem that people aren't being provided with tools that help avoid simple human errors. When handling sensitive data, surely some simple functions are essential: - workflow that ensures that a second person checks what is being sent and to who - two-factor authentication - reliable revocation so misdirected files can be protected We've been discussing this over on our blog and have published a checklist to help identify the key elements that will help a href="http://www.iseeuglobal.com/information-governance-strategy-secure-data-transfer/" enforce data protection /a .

Posted by ISEEU Global, 16 Feb 2012

   

Add your comment

Please keep comments constructive and free from abuse of any kind and swearing. If you wish to link to a product or service online, please do so in such a way that makes it clear that it is not spam. If you are connected to any such product you should make that clear.

We may use your comments in the magazine. We may edit your comments for clarity or to remove unacceptable material. We will attribute your comments but not share your email address.

We request your email address and record your Internet Address (IP address) in order to block spam from our site. We will never share this information without your permission.

All comments are reviewed by the Computeractive Team before being published. Please bear with the slight delay this causes, you don't need to post more than once.

Click here to read our Privacy Policy

Click here to read our site Terms & Conditions

Related articles

European commission

European Commission publishes stronger data protection proposals

Privacy plans that give people more control over what personal information is held about them are welcomed by some, but businesses fear 'onerous' burden

Oliver Letwin Tory MP

Privacy watchdog says Oliver Letwin broke data protection laws

Information commissioner says dumping constituents' letters in park bin was an offence

Norwich City College of Further and Higher Education

Norwich City College has breached data protection laws, says ICO

Students' sensitive personal information was put in a skip, but Norwich City College promises to dispose of confidential waste securely in future

Content Recommendation

Question & Answer

Q.Why is Windows Backup skipping files?

> Read the answer

Q.Why do my scanned documents display gibberish?

> Read the answer

Q.How can I convert MTS files to edit in Windows Movie...

> Read the answer

Best deals on the web

img

Samsung NP350E7C-A04UK

£349.99- Buy it now

img

Toshiba Satellite C850D-11Q (PSCC2E-00R00JEN)

£279.97- Buy it now

img

Lenovo G580 (MAANJUK)

£379.99- Buy it now

Updating your subscription status Loading

Most popular articles

No matching document

Poll

Do you have Windows 8?

Jargon Buster

Computing terms explained in plain English

VGA

Video Graphics Array. Standard socket for connecting a monitor to a computer.

Great shopping deals from Computeractive

Information currently unavailable