Search

How can we help?

Icon

“Systematic Failings” on Data Protection leads to a £15,000 fine

Following on from the case reported last month on data protection (”Failing to anonymise – the cost”), a nursing home in Northern Ireland has received a fine of £15,000 from the Information Commissioner’s Office (“ICO”), following the burglary of the home of one of its staff members.

During the burglary, an unencrypted work laptop was stolen. The laptop contained sensitive personal data, including medical information, on the nursing home’s 29 residents (including “do not resuscitate” orders) and personal data on the 46 members of staff.

The ICO’s subsequent investigation found the nursing home had no policies in place regarding the use of encryption, working from home and the storage of mobile devices. Data security training was also found to be lacking. In issuing the fine, the ICO said there had been “systematic failings” at the nursing home.

The fine was issued despite the nursing home referring themselves to the ICO, no complaints being made by any of the staff or residents’ families and no confirmation that the information had been further disseminated. In determining the level of the fine, the nursing home received some credit for having self-reported its breach to the ICO.

The ICO’s subsequent investigation found the nursing home had no policies in place regarding the use of encryption, working from home and the storage of mobile devices.

The amount of the fine reflected the size of the business, with the ICO stating that a bigger organisation experiencing a similarly serious breach should expect to receive a much larger fine. The case therefore acts as a timely reminder that all businesses must take their legal duties to look after personal data seriously and should ensure adequate policies, procedures and equipment are in place.  Simply having a work laptop password protected will not fulfil this duty.

For useful data protection factsheets, checklists and templates, please visit employmentbuddy.com 

For further advice on how to protect your business against data protection and privacy claims, please contact our employment lawyers on employment@clarkslegal.com 

Disclaimer

This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

About this article

Read, listen and watch our latest insights

art
  • 23 December 2019
  • Employment

The Queen’s Speech 2019 – Employment Law Implications

The Queen’s Speech was delivered on 19th December 2019 and sets out details of government’s intentions over the coming year. The key point from an employment law perspective is the introduction of the Employment Bill which will seek to introduce changes

art
  • 23 December 2019
  • Employment

‘Gender critical’ view was not a philosophical belief

In Forstater v CGD Europe & Others, the Claimant’s consultancy contract was terminated after she made comments expressing her views that there are only two sexes and that it is impossible to change sex.The Claimant claimed that this termination was discriminatory on the grounds of ‘philosophical belief’ or lack thereof.

art
  • 20 December 2019

ePrivacy Regulation – The latest!

Amidst the hype of the GDPR in 2018, one other area of data protection reform progressed relatively under the radar – the ePrivacy Regulation. Surprising given the potential impact this could have on an organisations’ marketing practices.

art
  • 20 December 2019
  • Immigration

Queen’s Speech December 2019: The biggest change to Immigration Law in modern times?

It has been a decade since the UK had an effective majority government, and in less than a week of the election, we have seen a substantive legislative agenda in today’s Queen Speech. In this article, we explore the changes to Immigration Law, and how it could be the biggest change in recent history.

art
  • 19 December 2019
  • Employment

Breaking News – Standard Contractual Clauses and Privacy Shield – latest developments with Facebook case

Advocate General, Henrik Saugmandsgaard Øe of the Court of Justice of the European Union (CJEU) has just handed down his opinion in response to a referral by the High Court of Ireland for preliminary rulings of law. The High Court case in question related to complaints made by Max Schrems against Facebook Ireland and Facebook Inc concerning the transfer of Mr Schrems’ personal data to the United States (U.S).

art
  • 19 December 2019
  • Employment

“Nuisance” nurse wins whistleblowing claim

In Smith v Mid Essex Hospital Services NHS Trust, a nurse won his claim for unfair dismissal, with the Employment Tribunal finding he had been dismissed for making protected disclosures.