Search

How can we help?

Icon

“Systematic Failings” on Data Protection leads to a £15,000 fine

Following on from the case reported last month on data protection (”Failing to anonymise – the cost”), a nursing home in Northern Ireland has received a fine of £15,000 from the Information Commissioner’s Office (“ICO”), following the burglary of the home of one of its staff members.

During the burglary, an unencrypted work laptop was stolen. The laptop contained sensitive personal data, including medical information, on the nursing home’s 29 residents (including “do not resuscitate” orders) and personal data on the 46 members of staff.

The ICO’s subsequent investigation found the nursing home had no policies in place regarding the use of encryption, working from home and the storage of mobile devices. Data security training was also found to be lacking. In issuing the fine, the ICO said there had been “systematic failings” at the nursing home.

The fine was issued despite the nursing home referring themselves to the ICO, no complaints being made by any of the staff or residents’ families and no confirmation that the information had been further disseminated. In determining the level of the fine, the nursing home received some credit for having self-reported its breach to the ICO.

The ICO’s subsequent investigation found the nursing home had no policies in place regarding the use of encryption, working from home and the storage of mobile devices.

The amount of the fine reflected the size of the business, with the ICO stating that a bigger organisation experiencing a similarly serious breach should expect to receive a much larger fine. The case therefore acts as a timely reminder that all businesses must take their legal duties to look after personal data seriously and should ensure adequate policies, procedures and equipment are in place.  Simply having a work laptop password protected will not fulfil this duty.

For useful data protection factsheets, checklists and templates, please visit employmentbuddy.com 

For further advice on how to protect your business against data protection and privacy claims, please contact our employment lawyers on employment@clarkslegal.com 

Disclaimer

This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

About this article

Read, listen and watch our latest insights

Pub
  • 21 January 2020
  • Commercial Real Estate

Found the perfect restaurant venue? Watch out for hidden costs

The Restaurant Consultant’s step-by-step guide to what you should do if you find the perfect restaurant venue and what hidden costs to watch out for.

art
  • 17 January 2020
  • Employment

Minimum wage: Don’t get caught out

Government consultation on Labour Market Enforcement strategy for 2020/2021 is open until 24 January 2020. At the same time, a report by the Resolution Foundation released this month shows that, as legal minimum wage rates have risen, so has non-compliance.

art
  • 17 January 2020
  • Employment

Driver subjected to sexual advances and biased grievance process was constructively dismissed

A female driver who was sexually harassed by her manager and supervisor has won her claim for constructive unfair dismissal.

art
  • 17 January 2020
  • Employment

A birthday to remember? A legal secretary loses age discrimination claim after 50th birthday “well wishes”

In Munro v Sampson Coward LLP, a legal secretary claimed she was subjected to age discrimination when a colleague, who was of a similar age to her, made a comment about her 50th birthday.

art
  • 15 January 2020
  • Immigration

How to meet the financial requirement for a spouse visa: Salaried and non-salaried employment FAQs

Following on from our previous blog, there are a number of sources of income which can be relied on to meet the financial requirement for a spouse visa.

art
  • 14 January 2020
  • Corporate and M&A

Lending money to Directors

It is not unusual for a Company to lend money to a director of a Company, nor is it unlawful. However, there are a number of points to consider, including declarations of interest and how this sits with the constitution of the Company and a directors’ statutory duties generally and also the treatment of the loan from a tax perspective – not only for the director but the Company too.