Search

How can we help?

Icon

“Systematic Failings” on Data Protection leads to a £15,000 fine

Following on from the case reported last month on data protection (”Failing to anonymise – the cost”), a nursing home in Northern Ireland has received a fine of £15,000 from the Information Commissioner’s Office (“ICO”), following the burglary of the home of one of its staff members.

During the burglary, an unencrypted work laptop was stolen. The laptop contained sensitive personal data, including medical information, on the nursing home’s 29 residents (including “do not resuscitate” orders) and personal data on the 46 members of staff.

The ICO’s subsequent investigation found the nursing home had no policies in place regarding the use of encryption, working from home and the storage of mobile devices. Data security training was also found to be lacking. In issuing the fine, the ICO said there had been “systematic failings” at the nursing home.

The fine was issued despite the nursing home referring themselves to the ICO, no complaints being made by any of the staff or residents’ families and no confirmation that the information had been further disseminated. In determining the level of the fine, the nursing home received some credit for having self-reported its breach to the ICO.

The ICO’s subsequent investigation found the nursing home had no policies in place regarding the use of encryption, working from home and the storage of mobile devices.

The amount of the fine reflected the size of the business, with the ICO stating that a bigger organisation experiencing a similarly serious breach should expect to receive a much larger fine. The case therefore acts as a timely reminder that all businesses must take their legal duties to look after personal data seriously and should ensure adequate policies, procedures and equipment are in place.  Simply having a work laptop password protected will not fulfil this duty.

For useful data protection factsheets, checklists and templates, please visit employmentbuddy.com 

For further advice on how to protect your business against data protection and privacy claims, please contact our employment lawyers on employment@clarkslegal.com 

Disclaimer

This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

About this article

Read, listen and watch our latest insights

art
  • 28 January 2020
  • Employment

Reduced percentage for requesting an information and consultation agreement in the workplace

In 2005, The European Parliament and Council Directive 2002/14/EC was transposed into UK law, setting out a framework for implementing information and consultation agreements with employees if validly requested (the ICE Regulations).

art
  • 28 January 2020
  • Immigration

Government likely to rely on MAC Report for the new immigration system

The Migration Advisory Committee has released an extensive report on the Points-Based System and Salary Thresholds. This was commissioned by the Government in July and September of last year.

art
  • 27 January 2020
  • Immigration

The Official Launch – Fast Track Global Talent Visa

The government has highlighted through its vision of an Australian-style points-based immigration system, that it will focus on attracting the best talent to the UK. It has already confirmed that it will invest up to £300 million over the next 5 years to fund experimental and imaginative mathematical sciences research through the best global talent.

art
  • 27 January 2020
  • Employment

Subject Access Request Compliance Update

Despite the consultation period for their draft Right of Access Guidance remaining open until the 12th February, the Information Commissioner’s Office (the “ICO”) has amended its published guidance on the timescales for Data Subject Access Request (“DSAR”) compliance.

art
  • 24 January 2020
  • Litigation and dispute resolution

Working with foreign principals – am I protected by the Regulations?

The Commercial Agents (Council Directive) Regulations 1993 (the “Regulations”) give commercial agents important rights, and in particular the right to receive compensation or indemnity on termination of the agency agreement.One issue which we are often consulted on is whether the Regulations apply to an agent who works for a foreign company, and/or is working outside of the UK. Foreign companies, particularly those based outside of the EU, are often unaware of the Regulations, and can have an unwelcome surprise when they terminate an agency agreement and are faced with an unexpected compensation claim.

art
  • 24 January 2020
  • Employment

Paid Parental Bereavement Leave

Following our previous blog on the consultation for parental bereavement leave, yesterday the Government laid down the new regulations before Parliament which will come into force on 6 April 2020.