All the latest UK technology news, reviews and analysis

ICO slaps Welsh council with record £130,000 data breach fine

by Rosalie Marshall

06 Dec 2011

Comment: 1

  • Tweet this

The Information Commissioner's Office (ICO) announced on Tuesday that it has served its highest data protection penalty fine of £130,000 to Powys County Council after details about a child protection case were sent to the wrong recipient.

The ICO gained the power to fine organisations up to £500,000 for serious breaches of the Data Protection Act in April last year, but has been reluctant to do so, preferring to educate rather than punish offenders.

Anne Jones, ICO assistant commissioner for Wales, said that the fine follows two others imposed on UK councils in the past three weeks after the disclosure of sensitive information about vulnerable people.

"It's the most serious case yet and it has attracted a record fine. The ICO has also issued a legal notice ordering the council to take action to improve its data handling. Failure to do so will result in legal action being taken through the courts," she said.

The Powys data protection breach occurred when two separate reports about child protection cases were sent to the same shared printer, according to the ICO.

It is believed that two pages from one report were mistakenly collected with the papers from another case and were sent out without being checked.

The recipient of the two pages of the report knew the parent and child whose personal details were included in the papers, and complained to the council.

No particular individual has been named by the ICO as responsible for the mistake.

"There is clearly an underlying problem with data protection in social services departments and we will be meeting with stakeholders from across the UK's local government sector to discuss how we can support them in addressing these problems," said Jones.

The ICO enforcement notice places a legal requirement on Powys County Council to train its entire staff to follow the council's guidance on the handling of personal data by 31 March 2012, with refresher training provided every three years.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

38%

0%

10%

52%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Java Developer, Algo Trading, FX, Trading Strategies

Java Deveoper/Programmer/Software Engineer, Algo Trading...

Lead and Senior Developers Wanted

Austin Fraser has the pleasure of appointing a number...

Java Developer - Great move up for a Junior Developer

Austin Fraser has the pleasure of appointing a Java Developer...

Senior J2EE Application Developer

Austin Fraser has the pleasure of appointing a Senior...

To send to more than one email address, simply separate each address with a comma.