Don’t do SECURITY. Do business SECURELY.

ICO issues its first fines for data protection breaches

The UK Information Commissioner issued its first monetary penalties: £100,000 to Hertfordshire County Council and £60,000 to A4e.

The Information Commissioner’s Office used its new power to issue fines for serious data protection breaches for the first time. Hertfordshire County Council was fined £100,000 and employment services company A4e was fined £60,000.

What happened

  • The council’s staff had twice faxed highly sensitive information about child sexual abuse and care proceedings to the wrong recipients.
  • A4e was fined after an unencrypted laptop containing personal information about around 24,000 people was stolen from an employee’s home.
  • Information Commissioner Christopher Graham said it was difficult to imagine information more sensitive than that relating to a child sex abuse case.
  • The ICO had been able to impose penalties of up to £500,000 since April 2010.

Why it mattered

The fines marked the start of financial enforcement by the UK regulator, turning data protection from a compliance formality into a board-level risk.

Lessons for organisations

Encrypt laptops and removable media, and put safeguards around manual processes such as faxing, emailing, and posting sensitive information. ISO/IEC 27001 and Cyber Essentials both treat device encryption and access control as core controls, and staff training should cover handling of sensitive records.

Sources: Hunton Andrews Kurth Privacy Blog, 5RB

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights