Nottingham County Council fined £70,000 for data leak

The data of 3,000 vulnerable people was accessible through Google

The ICO has hit Nottingham County Council with a 70,000 fine for failing to safeguard its citizens' data, which led to anyone being able to view the information online.

The problem was exposed when a member of the public was able to read the data online stored in the council's Home Care Allocation System (HCAS) following a Google search. Nottingham County Council didn't implement any kind of security to stop people being able to access files, such as a login.

The data, which is thought to have been accessible for over five years, held details on whether disabled and elderly people were in hospital and included the gender, addresses, postcodes and care requirements of the individuals. The concern was that criminals could access the data and use the information to break into peoples' homes while they were away.

"This was a serious and prolonged breach of the law. For no good reason, the council overlooked the need to put robust measures in place to protect people's personal information, despite having the financial and staffing resources available," ICO Head of Enforcement Steve Eckersley said.

Advertisement - Article continues below
Advertisement - Article continues below

"Given the sensitive nature of the personal data and the vulnerability of the people involved, this was totally unacceptable and inexcusable. Organisations need to understand that they have to treat the security of data as seriously as they take the security of their premises or their finances."

The breach was first reported in June 2016, when it contained a directory of 81 service users and the data of more than 3,000 people. Not included in the data was the patients' names, although the ICO said it would be easy enough for people to find this information out from other sources if they wanted to.

Featured Resources

What you need to know about migrating to SAP S/4HANA

Factors to assess how and when to begin migration

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

Testing for compliance just became easier

How you can use technology to ensure compliance in your organisation

Download now

Best practices for implementing security awareness training

How to develop a security awareness programme that will actually change behaviour

Download now



How to protect against a DDoS attack

25 Oct 2019
Information Commissioner

What is the Information Commissioner’s Office (ICO)?

5 Sep 2019
data breaches

Ex-Equifax CIO to serve four months for insider trading

2 Jul 2019
data breaches

Ex-Equifax CIO to serve four months for insider trading

2 Jul 2019

Most Popular

data governance

Brexit security talks under threat after UK accused of illegally copying Schengen data

10 Jan 2020
cyber security

If not passwords then what?

8 Jan 2020
Policy & legislation

GDPR and Brexit: How will one affect the other?

9 Jan 2020
web browser

What is HTTP error 503 and how do you fix it?

7 Jan 2020