23 Jun 2009
Manchester City Council has lost two unencrypted laptops containing personal details on at least 1,754 employees at local schools.
The Information Commissioner's Office (ICO) confirmed that the council had breached the Data Protection Act, and that it will have to conform to higher standards.
Manchester City Council chief executive Howard Bernstein signed a formal undertaking (PDF) that the council will ensure that all laptops and other removable devices are encrypted and secured, and that only essential personal information is downloaded to mobile devices.
Bernstein also promised to implement an improved training programme covering the security of personal information.
"Organisations must implement appropriate safeguards to ensure that personal details are handled securely and do not fall into the wrong hands," said Sally-Anne Poole, head of enforcement and investigations at the ICO, in a statement.
"We urge all councils and their executive teams to take responsibility for treating data protection as a corporate governance issue affecting the entire organisation. They have to make sure that safeguarding the personal information of staff is embedded in organisational culture."
Latest stories from Public Sector
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
EU data protection overhaul contains "bureaucratic tick box-proposals", says information commissioner Christopher Graham in exclusive interview with V3
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
INSIDE SALES / BUSINESS DEVELOPMENT WEST LONDON...
QA Tester | Peterborough, Cambridgeshire...
TECHNICAL SALES / ACCOUNT EXECUTIVE / WEST LONDON / MARKET...
TECHNICAL SALES / BUSINESS DEVELOPMENT WEST LONDON...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
Accountability
This is hardly the first loss of a laptop computer by a public body, and it is about time that ALL organisations within the public sector took the Data Protection Act a bit more seriously. Perhaps if the penalties for non-compliance were greater and senior officers were held to be personally accountable under the law, they might start to address this ongoing problem. If however, the only penalty is naming and shaming the organisation concerned, then those guilty of negligence will continue to hide within their organisations and losses of personal data will continue.
Posted by: Michael Abbiss 25 Jun 2009
No data on portable devices
The technology exists to prevent data being stored on laptops/USB drives/CD-ROM/etc - anything other than a server locked in a secure room. The technology also exists to make that data available via an authenticated, secure network connection, whether it be from within the office, home or almost anywhere else. All it needs is the will to put these technologies into place
Posted by: Grunt Gruntson 23 Jun 2009