ICO wants prison for data offences after 'shocking' case

Serious data offences should carry the threat of prison, the head of the ICO says.

Arrest

Serious breaches of the Data Protection Act should warrant prison sentences, according to information commissioner Christopher Graham.

The calls came after a "shocking" case which saw a bank cashier pleading guilty to accessing the personal data of a sex attack victim. The man convicted for that attack was the cashier's husband.

Sarah Langridge - a former employee of Barclays Bank claimed she wanted to build a picture of the woman who had accused her husband so she accessed the victim's bank accounts.

Langridge accessed the victim's records on eight separate occasions over the eight months when her husband's court case was ongoing.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

This crime has the potential to devastate ordinary people's lives. The existing paltry fines are not enough to deter.

"The details of this case are truly shocking. The victim had a harrowing enough experience at the hands of her attacker; the revelation that her attacker's wife was then rooting through all her personal details, for whatever purpose, would have caused even further distress," Graham is due to say today in an appearance before the Justice Select Committee. "I note the outcome of this latest case, and I remain concerned that the courts are not able to impose the punishment to fit the crime in all cases, because the current penalty for this all too common offence is limited to a fine rather than the full range of possible sentences, including prison for the most serious cases."

Graham targeted section 55 offences, otherwise known as blagging of personal data. This section of the Data Protection Act makes it an offence to "knowingly or recklessly, without the consent of the data controller, obtain or disclose personal data."

"This crime has the potential to devastate ordinary people's lives. The existing paltry fines are not enough to deter," Graham continued.

"If courts were able to impose the full range of sentences from fines to jail terms, including other sanctions such as community service where appropriate, we would at last have an effective deterrent to stop people engaging in this criminal activity."

A recent example of a Section 55 offence involved two former T-Mobile employees. David Turley and Darren Hame were fined a total of 73,700 after stealing customer data before selling it on.

Advertisement - Article continues below

The current penalty for committing the offence is a maximum 5,000 fine if the case is heard in a Magistrates Court. An unlimited fine is available if a case goes up to the Crown Court.

Graham has been calling for tougher sentences for a while now. Back in October last year, in a response to a Ministry of Justice call for comment on the effectiveness of data protection law, the information commissioner said prison sentences should be a deterrent against breaking the law.

Featured Resources

What you need to know about migrating to SAP S/4HANA

Factors to assess how and when to begin migration

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

Testing for compliance just became easier

How you can use technology to ensure compliance in your organisation

Download now

Best practices for implementing security awareness training

How to develop a security awareness programme that will actually change behaviour

Download now
Advertisement

Recommended

Visit/security/internet-security/354417/avast-and-avg-extensions-pulled-from-chrome
internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019
Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019
Visit/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico
Information Commissioner

What is the Information Commissioner’s Office (ICO)?

5 Sep 2019
Visit/data-protection/33450/bounty-fined-by-ico-for-unlawfully-sharing-member-data
data protection

Bounty fined by ICO for unlawfully sharing member data

15 Apr 2019

Most Popular

Visit/policy-legislation/data-governance/354496/brexit-security-talks-under-threat-after-uk-accused-of
data governance

Brexit security talks under threat after UK accused of illegally copying Schengen data

10 Jan 2020
Visit/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7
Microsoft Windows

What to do if you're still running Windows 7

14 Jan 2020
Visit/operating-systems/microsoft-windows/354526/memes-and-viking-funerals-the-internet-reacts-to-the
Microsoft Windows

Memes and Viking funerals: The internet reacts to the death of Windows 7

14 Jan 2020
Visit/network-internet/broadband/354530/openreach-offers-free-full-fibre-installation-for-thousands-of
broadband

Openreach offers free full-fibre installation for thousands of homes

14 Jan 2020