Search

How can we help?

Icon

“Systematic Failings” on Data Protection leads to a £15,000 fine

Following on from the case reported last month on data protection (”Failing to anonymise – the cost”), a nursing home in Northern Ireland has received a fine of £15,000 from the Information Commissioner’s Office (“ICO”), following the burglary of the home of one of its staff members.

During the burglary, an unencrypted work laptop was stolen. The laptop contained sensitive personal data, including medical information, on the nursing home’s 29 residents (including “do not resuscitate” orders) and personal data on the 46 members of staff.

The ICO’s subsequent investigation found the nursing home had no policies in place regarding the use of encryption, working from home and the storage of mobile devices. Data security training was also found to be lacking. In issuing the fine, the ICO said there had been “systematic failings” at the nursing home.

The fine was issued despite the nursing home referring themselves to the ICO, no complaints being made by any of the staff or residents’ families and no confirmation that the information had been further disseminated. In determining the level of the fine, the nursing home received some credit for having self-reported its breach to the ICO.

The ICO’s subsequent investigation found the nursing home had no policies in place regarding the use of encryption, working from home and the storage of mobile devices.

The amount of the fine reflected the size of the business, with the ICO stating that a bigger organisation experiencing a similarly serious breach should expect to receive a much larger fine. The case therefore acts as a timely reminder that all businesses must take their legal duties to look after personal data seriously and should ensure adequate policies, procedures and equipment are in place.  Simply having a work laptop password protected will not fulfil this duty.

For useful data protection factsheets, checklists and templates, please visit employmentbuddy.com 

For further advice on how to protect your business against data protection and privacy claims, please contact our employment lawyers on employment@clarkslegal.com 

Disclaimer

This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

About this article

Read, listen and watch our latest insights

art
  • 24 September 2026
  • Public Procurement

Procurement challenges: What documents and information are bidders entitled to?

A tricky feature of public procurement challenges for unsuccessful bidders is that contracting authorities usually hold all the cards. When the outcome of a tender conducted under the Procurement Act 2023 has been decided, authorities must provide bidders with an Assessment Summary containing their scores for each of the award criteria and those of the successful bidder and an explanation for those scores.

art
  • 23 September 2026
  • Corporate and M&A

GDPR Privacy Policies: Key requirements for organisations

When an organisation is creating a website or app to reach users or potential customers drafting a Privacy Policy may be an afterthought. However, failure to write a Privacy Policy, which complies with the relevant legislation, can have serious consequences.

Pub
  • 17 September 2026
  • Employment

Employment law changes in 2026: What you need to know

Stay ahead of the latest UK employment law changes. Watch our on demand webinar with Monica Atwal and Harry Berryman covering key HR developments and employment law updates for 2026.

art
  • 16 September 2026
  • Employment

Received an Employment Tribunal Claim? 6 Things Employers Should NOT Do

We are well and truly underway with implementation of the Employment Rights Act 2025 (“ERA 2025”) and October brings the next tranche of changes that employers will need to be ready for.

art
  • 14 September 2026
  • Corporate and M&A

Key provisions found in a Shareholders’ Agreement – SHA Series Part 2 of 5

Discover the key provisions in a shareholders’ agreement, including ownership, decision-making, share transfers, exits and leaver clauses.

art
  • 11 September 2026
  • Privacy and Data Protection

Data Protection Breaches – Personal Liability for Employees

It is well known that employers have obligations under the Data Protection Act 2018 (the “Act”) but, perhaps lesser known, is that employees can be held personally liable for certain actions amounting to criminal offences under the Act.