The Information Commissioner's Office (ICO) has slapped West Dumbartonshire Council with an enforcement notice, but no fine, after it lost sensitive data despite being told repeatedly by the ICO to train staff on data protection.
An audit of the council by the ICO in January 2013 urged improvements to data protection and staff training, particularly with regard to home working. A follow-up in November 2013 found some improvement, but not all training had been implemented.
Then, in June 2014, an employee took some work home on a laptop containing information on an adoption case and left it in a car. The laptop was subsequently stolen.
However, the ICO stopped short of fining the council. Ken Macdonald, assistant information commissioner for Scotland, explained that the enforcement notice should serve as sufficient warning.
“Time and time again we have told this council to make these changes, and yet they have still not completed everything we set out. We’ve been left with no choice but to issue this formal notice requiring them to act," he said.
“Let’s be clear: what we’re asking for here is a basic requirement for an organisation that is trusted with large amounts of local people’s personal data. When people in Dumbartonshire provide the council with their details, they expect that staff are trained to handle this information properly.
"Unfortunately, more than three years after this was made clear to the council, this still hasn’t happened.”
The council now has to ensure that within six months it has: a mandatory data protection training programme for all staff (including new starters) and refresher training on an annual basis; properly documented and monitored training to ensure its timely completion; and a home-working policy implemented to provide sufficient guidance for staff working remotely.
No doubt other councils that have been fined by the ICO will wonder why West Dumbartonshire Council avoided a similar fate.
AMD Ryzen CPU release dates, specs and price: AMD hints at Ryzen 7 2800X plan to counter 8-core Intel Coffee Lake CPUs
AMD believed to be holding Ryzen 7 2800X in reserve
BT wants to make the public switched telephone network history within eight years
Personal data being purloined by third parties via Facebook Login API
MacOS and iOS are better off apart, says CEO Tim Cook