The Information Commissioner’s Office (ICO) today served Ealing Council and Hounslow Council with monetary penalties for serious breaches of the Data Protection Act after the loss of two unencrypted laptops containing sensitive personal information.
Two laptops containing the details of around 1,700 individuals were stolen from an employee’s home. Almost 1,000 of the individuals were clients of Ealing Council and almost 700 were clients of Hounslow Council. Both laptops were password protected but unencrypted – despite this being in breach of both councils’ policies. There is no evidence to suggest that the data held on the computers has been accessed and no complaints from clients have been received by the data controllers to date but there was nevertheless a significant risk to the clients’ privacy.
The ICO has served Ealing Council with a monetary penalty of £80,000, while ruling that £70,000 is appropriate for Hounslow Council. Ealing Council breached the Data Protection Act by issuing an unencrypted laptop to a member of staff in breach of its own policies. This method of working has been in place for several years and there were insufficient checks that relevant policies were being followed or understood by staff.
Deputy Commissioner, David Smith, said:
“Of the four monetary penalties that we have served so far, three concern the loss of unencrypted laptops. Where personal information is involved, password protection for portable devices is simply not enough.
The penalty against Hounslow Council also makes clear that an organisation can’t simply hand over the handling of the personal information it is responsible for to somebody else unless they ensure that the information is properly protected. Both councils have paid the price for lax data protection practices. I hope all organisations that handle personal information will make sure their houses are in order – otherwise they too may have to learn the hard way.”
For further information visit http://www.ico.gov.uk/
If you would like further advice or guidance on eSecurity then email email@example.com you may also be interested in using our online audit tool to look at data security within your school.
The tool covers all aspects of eSafeguarding: from roles and responsibilities within your school to password procedures and rules about taking equipment off-site. After you have answered the questions, you will get a summary of relevant guidance and action that needs to be taken, which can be printed off or saved.
The online tool, which has been designed for a non-technical audience, will tell you at a glance if your eSafeguarding is up to scratch, and if not, how to improve it. To start auditing your provision now, click here.