ICO takes action against Home Office, NHS Trusts
By Miya Knights,
The Information Commissioner’s Office (ICO) has found the Home Office and two National Health Service (NHS) Trusts in breach of the Data Protection Act (DPA).
The Home Office action follows the loss of an unencrypted memory stick by a contractor, PA Consulting in August 2008 that held the sensitive personal details of thousands of individuals, including those serving custodial sentences or who had previously been convicted of criminal offences.
The ICO said the Home Office must, with immediate effect, ensure all portable and mobile devices that are used to store and transmit personal information are encrypted. And contractors processing personal information on its behalf must also use encryption software.
Mick Gorrill, Assistant Information Commissioner at the ICO said the Home Office case was particularly serious, regardless of the fact a contractor lost the data. “It is the data controller (the Home Office) which is responsible for the security of the information,” he said.
“The Home Office recognises the seriousness of this data loss and has agreed to take immediate remedial action. It has also agreed to conduct future audits to ensure compliance with the Act,” he added.
Sir David Normington, the Permanent Secretary, is signing a formal undertaking on behalf of the Home Office outlining that it will process personal information securely in the future.
At the same time, the ICO has also required Abertawe Bro Morgannwg University NHS Trust and Tees, Esk and Wear Valleys NHS Foundation Trust, to sign formal undertakings that they will process personal information in line with the DPA.
The action comes after an unencrypted laptop containing the sensitive personal data of approximately 5,000 patients, including some health records, was stolen from the Abertawe Bro Morgannwg University NHS Trust.
And Tees, Esk and Wear Valleys NHS Foundation Trust informed the ICO that an unencrypted memory stick had been lost containing sensitive personal information relating to patients and trust staff. The trust initiated its own investigation after the data stick was returned to the trust.
In all three cases, the ICO has mandated the implementation of appropriate security measures, including adequate encryption policies and staff and contractor security policy adherence, to ensure that personal details are properly protected.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Public Sector Analysis & Insight
Striving to solve the security skills crisis
The Cyber Security Challenge is doing a fine job, but flat registration growth and weak Government funding are cause for concern, Tom Brewster discovers.
- 2011: The year in news
- Are the cookie laws crumbling already?
- UK rural broadband: too little, and too late
- How the Data Protection Act's death will punish the UK economy
- Education: glad to be a geek
- Plugging public sector data leaks
- Going for Gold - IT at the London Olympics
- Fujitsu: out to steal HP market share
- What will Windows Mango mean for business?
Latest Public Sector Reviews
HTC Flyer review: First Look
- HP TouchPad review: First Look
- RIM BlackBerry PlayBook review - First Look
- MWC 2011: Acer Iconia A100 and A500 reviews – first look videos
- MWC 2011: HP TouchPad review - first look video
- MWC 2011: RIM BlackBerry PlayBook review - first look video
- MWC 2011: HP Pre3 review - first look video
- MWC 2011: Motorola Pro review - first look video
- MWC 2011: HTC Flyer tablet review - first look video
- MWC 2011: Samsung Galaxy Tab 10.1 review – first look video
advertisement
Most popular
- Ubuntu vs. Windows 7 on the business desktop
- York researchers heat storage to speed up data
- OneNote hits Google?s Android
- O2 trials Olympic-scale remote working
- Who to trust after the VeriSign hack?
- Lenovo beats expectations again
- BlackBerry Bold 9790 review
- Will someone rid me of these troublesome Macs?
- Google to promise fairness after Motorola buy
- Welcome to the stay-at-home Olympics
Latest News Videos in Public Sector
Q&A: David Elton, PA Consulting Group
CIOs are increasingly influential, but have to juggle "dual roles", study finds.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.




