ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/reg/register.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    Council loses children in care data

Stoke-on-Trent City Council loses a USB stick containing sensitive data of children in care.

By Tom Brewster, 22 Nov 2010 at 13:42

USB

The UK’s data protection watchdog - the Information Commissioner's Office (ICO) - has taken action against Stoke-on-Trent City Council after the authority lost a USB stick containing sensitive information on 40 children in care.

A member of the public discovered the memory stick, which was unencrypted and not password protected, before returning it to the council.

The data included court reports and details of care proceedings.

Having breached the Data Protection Act, the local authority has been told to implement steps to ensure personal data stored by the body is adequately secured.

The council has agreed to encrypt portable and mobile devices used to store and transmit personal data, while staff education will be ramped up.

“When handling sensitive personal information, particularly information relating to the care of vulnerable children, it is important that authorities ensure the necessary measures are in place to protect this information,” said Sally-Anne Poole, Enforcement Group Manager at the ICO.

Yet again, the ICO has not given out a fine for the breach.

“This incident occurred before 6 April so the powers now available to the information commissioner to issue penalties of up to £500,000 for serious breaches of the Data Protection Act, could not be considered," said Poole.

One of the central reasons why Google was not issued with a fine after the Street View Wi-Fi scandal was because the data was collected before the ICO's extra powers came into force.

An ICO spokesperson told IT PRO the council could “potentially” have been hit with a fine if the breach occurred after the penalty powers were granted.

The spokesperson also confirmed a fine would be handed to an as yet unnamed body or individual “in the near future,” after information commissioner Christopher Graham indicated a penalty would be handed out before the end of the month.

Email to a friend

Print this page

< Previous   Public Sector : News Next >

1 comments

You need to Login or Register to comment.

Not again

It is very concerning to hear that organisations are not learning from each others' mistakes such as the NHS, police forces and local councils. This information is highly sensitive and should be treated as such, particularly as the technology is available via encryption, end point security, biometric technology and as a basic introducing password access. It would be more encouraging to see the ICO taking a stronger stance on the issue too.

By MSC_247 on Monday Nov 22

0 people out of 0 found this comment useful.

Did you find it useful?

 Sponsored Links

advertisement
advertisement

    Register for IT PRO

You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Sponsored Links
Advertisement