Search

How can we help?

Icon

“Systematic Failings” on Data Protection leads to a £15,000 fine

Following on from the case reported last month on data protection (”Failing to anonymise – the cost”), a nursing home in Northern Ireland has received a fine of £15,000 from the Information Commissioner’s Office (“ICO”), following the burglary of the home of one of its staff members.

During the burglary, an unencrypted work laptop was stolen. The laptop contained sensitive personal data, including medical information, on the nursing home’s 29 residents (including “do not resuscitate” orders) and personal data on the 46 members of staff.

The ICO’s subsequent investigation found the nursing home had no policies in place regarding the use of encryption, working from home and the storage of mobile devices. Data security training was also found to be lacking. In issuing the fine, the ICO said there had been “systematic failings” at the nursing home.

The fine was issued despite the nursing home referring themselves to the ICO, no complaints being made by any of the staff or residents’ families and no confirmation that the information had been further disseminated. In determining the level of the fine, the nursing home received some credit for having self-reported its breach to the ICO.

The ICO’s subsequent investigation found the nursing home had no policies in place regarding the use of encryption, working from home and the storage of mobile devices.

The amount of the fine reflected the size of the business, with the ICO stating that a bigger organisation experiencing a similarly serious breach should expect to receive a much larger fine. The case therefore acts as a timely reminder that all businesses must take their legal duties to look after personal data seriously and should ensure adequate policies, procedures and equipment are in place.  Simply having a work laptop password protected will not fulfil this duty.

For useful data protection factsheets, checklists and templates, please visit employmentbuddy.com 

For further advice on how to protect your business against data protection and privacy claims, please contact our employment lawyers on employment@clarkslegal.com 

Disclaimer

This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

About this article

Read, listen and watch our latest insights

art
  • 15 August 2025
  • Employment

Employment Rights Bill – Get your tailored action plan now!

The Employment Rights Bill is a major piece of legislation which significantly overhauls worker’s rights.

art
  • 13 August 2025
  • Commercial Real Estate

Proposed Ban of upwards only rent reviews

In an effort to save the high street, the government has proposed to ban upwards only rent reviews in commercial leases, without any consultation with professional bodies. It has caught the commercial property sector completely by surprise.

art
  • 12 August 2025
  • Privacy and Data Protection

From WeTransfer to WhatsApp: How Unapproved Tools and “Shadow IT” Could Threaten UK GDPR Compliance

Businesses and self-employed professionals are in a constant pursuit of efficiency and productivity.  There are, as a result, no end of tools and products available to smooth digital workflows. 

art
  • 07 August 2025
  • Immigration

New simplified British Citizenship route for Irish Citizens now in force

From 22 July 2025, eligible Irish citizens who have been resident in the UK for five years can now register as British citizens under a new, simplified route.

art
  • 06 August 2025
  • Employment

Enhanced redundancy packages explained

It is difficult for employees and employers alike when the time comes to make redundancies across a business. For those impacted, it can be particularly difficult to understand the terms used, and what your entitlements are as an employee.

art
  • 06 August 2025
  • Litigation and dispute resolution

Product liability reform: New Product Regulation and Metrology Act 2025

The law on product safety is set to undergo reform as the new Product Regulation and Metrology Act 2025 was passed in July.