Search

How can we help?

Icon

“Systematic Failings” on Data Protection leads to a £15,000 fine

Following on from the case reported last month on data protection (”Failing to anonymise – the cost”), a nursing home in Northern Ireland has received a fine of £15,000 from the Information Commissioner’s Office (“ICO”), following the burglary of the home of one of its staff members.

During the burglary, an unencrypted work laptop was stolen. The laptop contained sensitive personal data, including medical information, on the nursing home’s 29 residents (including “do not resuscitate” orders) and personal data on the 46 members of staff.

The ICO’s subsequent investigation found the nursing home had no policies in place regarding the use of encryption, working from home and the storage of mobile devices. Data security training was also found to be lacking. In issuing the fine, the ICO said there had been “systematic failings” at the nursing home.

The fine was issued despite the nursing home referring themselves to the ICO, no complaints being made by any of the staff or residents’ families and no confirmation that the information had been further disseminated. In determining the level of the fine, the nursing home received some credit for having self-reported its breach to the ICO.

The ICO’s subsequent investigation found the nursing home had no policies in place regarding the use of encryption, working from home and the storage of mobile devices.

The amount of the fine reflected the size of the business, with the ICO stating that a bigger organisation experiencing a similarly serious breach should expect to receive a much larger fine. The case therefore acts as a timely reminder that all businesses must take their legal duties to look after personal data seriously and should ensure adequate policies, procedures and equipment are in place.  Simply having a work laptop password protected will not fulfil this duty.

For useful data protection factsheets, checklists and templates, please visit employmentbuddy.com 

For further advice on how to protect your business against data protection and privacy claims, please contact our employment lawyers on employment@clarkslegal.com 

Disclaimer

This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

About this article

Read, listen and watch our latest insights

art
  • 21 February 2020
  • Construction

Construction projects and adverse conditions: What are the rules?

Whilst it’s not unusual for adverse weather to affect the UK, it always seems to come as something of a surprise to us. However, what does ‘adverse weather’ actually mean in law? How do you determine any entitlement to money or time? And what should you do if your project suffers delay as a result of bad weather?

art
  • 20 February 2020
  • Immigration

The Global Talent Visa is here: What are the key changes?

The Global Talent visa officially opened today and has been added to Appendix W (or Workers) of the Immigration Rules. Ironically, this latest visa category is not within the Point-Based System, and it is unclear how it will function when the new Points-Based System route opens in 2021.

art
  • 20 February 2020
  • Employment

New ACAS guidance on the use of NDA’s

ACAS has recently published guidance on the use of Non-Disclosure Agreements (NDA’s).

art
  • 19 February 2020
  • Immigration

An end to low-skilled migrant workers: Government announces its policy for the 2021 immigration system

The Government has today released its Policy Statement on the UK’s Points Based Immigration System.

art
  • 18 February 2020
  • Employment

Parental Bereavement Pay and Leave – new laws as of April 2020

As of 6th April 2020, new laws will come into force giving employees the right to both parental bereavement leave and pay.

art
  • 13 February 2020
  • Employment

Roses are red, Violets are blue, Workplace Romance, What should employers do?

Love is in the air And maybe the workplace to But fear not employers Here’s what you need to do…