ICO hits London council with £70,000 data breach fine

Data loss folder

A London council has been hit with a 70,000 fine from the Information Commissioner's Office (ICO) following the loss of sensitive information about 15 local youngsters.

The names, addresses and sexual histories of 15 children and young people living in the London Borough of Barnet were stolen from a council worker's house during a burglary last April.

The potential for damage and distress in this case is obvious.

The thieves stole an encrypted computer and a laptop bag carrying paper records, which contained the youngsters' data.

The breach is the second time in two years the council has found itself at the centre of a data loss incident, after an unencrypted device containing personal information was stolen from another employee's home.

Following an investigation by the ICO into the latest breach, it was concluded that the council had not taken sufficient action to guard against the accidental loss of paper-based records.

In a statement the ICO said: "The council had an information security policy and some guidance for staff on handling sensitive papers, [but] the measures failed to explain how the information should be kept secure."

Simon Entwisle, director of operations at the ICO, said, following the council's earlier data breach, it was a shame that it hadn't taken more care with its residents' data.

"Barnet Council has taken action to keep the personal data they use secure, [but] it is vitally important that organisations have the correct guidance in place to keep sensitive paper records taken outside of the office safe," said Entwisle.

"This includes storing papers containing sensitive information separately from laptops."

In a statement to IT Pro, Barnet Council said it was disappointed by the ICO's decision to issue a fine.

"This data loss was the result of a criminal act where a member of staff had their house broken into and material that was under lock and key stolen," said the statement.

"The ICO also accepts that it was appropriate for the member of staff to have this material at home for this period [and] there is no evidence the material taken was misused in anyway."

Caroline Donnelly is the news and analysis editor of IT Pro and its sister site Cloud Pro, and covers general news, as well as the storage, security, public sector, cloud and Microsoft beats. Caroline has been a member of the IT Pro/Cloud Pro team since March 2012, and has previously worked as a reporter at several B2B publications, including UK channel magazine CRN, and as features writer for local weekly newspaper, The Slough and Windsor Observer. She studied Medical Biochemistry at the University of Leicester and completed a Postgraduate Diploma in Magazine Journalism at PMA Training in 2006.