The Information Commissioner’s Office used its new power to issue fines for serious data protection breaches for the first time. Hertfordshire County Council was fined £100,000 and employment services company A4e was fined £60,000.
What happened
- The council’s staff had twice faxed highly sensitive information about child sexual abuse and care proceedings to the wrong recipients.
- A4e was fined after an unencrypted laptop containing personal information about around 24,000 people was stolen from an employee’s home.
- Information Commissioner Christopher Graham said it was difficult to imagine information more sensitive than that relating to a child sex abuse case.
- The ICO had been able to impose penalties of up to £500,000 since April 2010.
Why it mattered
The fines marked the start of financial enforcement by the UK regulator, turning data protection from a compliance formality into a board-level risk.
Lessons for organisations
Encrypt laptops and removable media, and put safeguards around manual processes such as faxing, emailing, and posting sensitive information. ISO/IEC 27001 and Cyber Essentials both treat device encryption and access control as core controls, and staff training should cover handling of sensitive records.
Sources: Hunton Andrews Kurth Privacy Blog, 5RB
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.