Search

How can we help?

Icon

“Systematic Failings” on Data Protection leads to a £15,000 fine

Following on from the case reported last month on data protection (”Failing to anonymise – the cost”), a nursing home in Northern Ireland has received a fine of £15,000 from the Information Commissioner’s Office (“ICO”), following the burglary of the home of one of its staff members.

During the burglary, an unencrypted work laptop was stolen. The laptop contained sensitive personal data, including medical information, on the nursing home’s 29 residents (including “do not resuscitate” orders) and personal data on the 46 members of staff.

The ICO’s subsequent investigation found the nursing home had no policies in place regarding the use of encryption, working from home and the storage of mobile devices. Data security training was also found to be lacking. In issuing the fine, the ICO said there had been “systematic failings” at the nursing home.

The fine was issued despite the nursing home referring themselves to the ICO, no complaints being made by any of the staff or residents’ families and no confirmation that the information had been further disseminated. In determining the level of the fine, the nursing home received some credit for having self-reported its breach to the ICO.

The ICO’s subsequent investigation found the nursing home had no policies in place regarding the use of encryption, working from home and the storage of mobile devices.

The amount of the fine reflected the size of the business, with the ICO stating that a bigger organisation experiencing a similarly serious breach should expect to receive a much larger fine. The case therefore acts as a timely reminder that all businesses must take their legal duties to look after personal data seriously and should ensure adequate policies, procedures and equipment are in place.  Simply having a work laptop password protected will not fulfil this duty.

For useful data protection factsheets, checklists and templates, please visit employmentbuddy.com 

For further advice on how to protect your business against data protection and privacy claims, please contact our employment lawyers on employment@clarkslegal.com 

Disclaimer

This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

About this article

Read, listen and watch our latest insights

art
  • 12 February 2020
  • Employment

Not all one-off acts will be a ‘provision, criterion or practice’

The Court of Appeal (“CA”) in Ishola v Transport for London (“TFL”) has given guidance on the meaning of ‘provision, criterion or practice’ (PCP), an essential element for claims of indirect discrimination and failure to make reasonable adjustments.

art
  • 07 February 2020
  • Commercial Real Estate

The Registration Gap – a warning

The transfer of ownership in registered freehold or leasehold land or the grant of a registerable lease does not take effect until registered at the Land Registry. This means that from the date of the transfer/lease until the date of registration such rights are said to exist in ‘equity’ only and the legal estate does not vest in the new owner/tenant until registration is complete. The gap between the date of the transfer/lease and the date the legal estate vests in the new owner/tenant is often referred to as the ‘registration gap’

art
  • 07 February 2020
  • Corporate and M&A

Investor Relief

The Finance Act 2016 introduced investor relief which is essentially a tax relief for Capital Gains in a similar way to the operation of Entrepreneurs Relief. On qualification any capital gain is reduced from the usual capital gains rate – currently 20% to 10%.

art
  • 07 February 2020
  • Corporate and M&A

What does the new decade herald for EMI Option Schemes?

The Enterprise Management Initiative (EMI) option scheme is a tax efficient incentive scheme designed to incentivise employees by enjoying the rewards of growth and business success usually on a sale

art
  • 07 February 2020
  • Employee Ownership Trust

The growth of Employee Ownership Trusts

Since the enactment of the Finance Act 2014, the popularity and acceptance of the Employee Ownership Trust (“EOT”) as an exit option for business owners has continued to gain support from lawyers, accountants, the Institute of Chartered Accountants in England and Wales and business owners themselves.

art
  • 07 February 2020
  • Corporate and M&A

Director’s Duties Can Survive Insolvency Process

In the recent high court case Re Systems Building Services Group Ltd , there was considerable debate and judgement made on whether a director’s general duties, as outlined in section 171 to 177 of the Companies Act 2006, survive a company’s entry into a formal insolvency process.