All the latest UK technology news, reviews and analysis

ICO urges government to jail data thieves

by Dan Worth

13 Sep 2011

Be the first to comment

  • Tweet this
ICO's Christopher Graham

Information commissioner Christopher Graham has again urged the government to take a tougher stance on data thieves by giving magistrates the power to jail those found guilty of breaching section 55 of the Data Protection Act (DPA).

The call comes after the Information Commissioner's Office (ICO) revealed details of a case in which an employee of Barclays Bank, Sarah Langridge, used her position to spy on the bank details of a woman accusing her husband of a sex attack.

The woman in the case recognised Langridge in court during the trial and contacted the bank and the police over concerns that her account may have been accessed illegally.

Police found that Langridge had accessed the woman's account on eight occasions, which she claimed was to find more information about the woman accusing her husband of the attack.

Brighton Magistrates' Court fined Langridge £800 and ordered her to pay costs of £400 and a £15 victim's surcharge.

Graham maintained that the sentencing underlined a clear and urgent need for stronger penalties to be available to magistrates to prosecute personal data thieves.

"It beggars belief that, in an age where our personal information is being stored and accessed by more organisations than ever, the penalties for abusing the system still do not include the possibility of a prison sentence, even in the most serious cases," he said.

"I note the outcome of this latest case and I remain concerned that the courts are not able to impose the punishment to fit the crime in all cases, because the current penalty for this all too common offence is limited to a fine."

It is currently an offence under section 55 of the DPA to "knowingly or recklessly, without the consent of the data controller, obtain or disclose personal data". The maximum fine a magistrate can issue is £5,000, while a Crown Court can issue an unlimited fine.

Graham is to appear before the Justice Select Committee on Tuesday to make his case for jail time to deter data thieves, at a time when the number of allegations under section 55 have risen 18 per cent in 2010/11 compared with 2008/09.

The ICO also referred to several previous cases in which the regulator had successfully brought prosecutions against individuals that had resulted only in fines, such as two employees from T-Mobile selling data on customers to other businesses.

The calls echo statements made by Graham in August when he said that those guilty of phone hacking should face tougher sentences to give the DPA more authority.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

31%

1%

12%

56%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Project Manager - Credit Risk - Finance IT - Investment Bank

Project Manager - Credit Risk - Finance IT - Investment...

Infrastructure Configuration Manager/Analyst/Data Modeler/IB

Infrastructure Configuration Manager/Analyst/Data Modeler...

Lead Perl Developer, Apache, SQL, Unix/Linux, INVESMENT BANK

Lead Perl Developer, Apache, SQL, Unix/Linux, Shell Scripting...

Perl Developer, Web and JEE App Servers, INVESTMENT BANK

**Perl /Java Developer, Web/ JEE application servers...

To send to more than one email address, simply separate each address with a comma.