Search

How can we help?

Icon

“Systematic Failings” on Data Protection leads to a £15,000 fine

Following on from the case reported last month on data protection (”Failing to anonymise – the cost”), a nursing home in Northern Ireland has received a fine of £15,000 from the Information Commissioner’s Office (“ICO”), following the burglary of the home of one of its staff members.

During the burglary, an unencrypted work laptop was stolen. The laptop contained sensitive personal data, including medical information, on the nursing home’s 29 residents (including “do not resuscitate” orders) and personal data on the 46 members of staff.

The ICO’s subsequent investigation found the nursing home had no policies in place regarding the use of encryption, working from home and the storage of mobile devices. Data security training was also found to be lacking. In issuing the fine, the ICO said there had been “systematic failings” at the nursing home.

The fine was issued despite the nursing home referring themselves to the ICO, no complaints being made by any of the staff or residents’ families and no confirmation that the information had been further disseminated. In determining the level of the fine, the nursing home received some credit for having self-reported its breach to the ICO.

The ICO’s subsequent investigation found the nursing home had no policies in place regarding the use of encryption, working from home and the storage of mobile devices.

The amount of the fine reflected the size of the business, with the ICO stating that a bigger organisation experiencing a similarly serious breach should expect to receive a much larger fine. The case therefore acts as a timely reminder that all businesses must take their legal duties to look after personal data seriously and should ensure adequate policies, procedures and equipment are in place.  Simply having a work laptop password protected will not fulfil this duty.

For useful data protection factsheets, checklists and templates, please visit employmentbuddy.com 

For further advice on how to protect your business against data protection and privacy claims, please contact our employment lawyers on employment@clarkslegal.com 

About this article

Disclaimer

This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

About this article

Read, listen and watch our latest insights

art
  • 18 September 2019
  • Immigration

Adult Dependent Relative Visa

It is unfortunate that many of us have an adult relative, or we know someone, who has an adult relative, who is all alone in a country where they are hardly able to take care of themselves. If your adult relative is dependent on you, then you may be able to sponsor them to join you in the UK so that you can take care of them.

art
  • 16 September 2019
  • Immigration

The Tier 4 Student Visa – An overview of the “Maintenance Requirement”

The UK’s student visa is known as a Tier 4 visa under the points-based system of the UK’s Immigration rules. The route primarily applies to students over the age of 16 from outside of the European Economic Area (EEA).

art
  • 16 September 2019
  • Employment

Stalking Protection Act: What employers need to know

Clarkslegal Managing Partner, Monica Atwal explains the steps organisations may need to take if a member of their staff becomes a victim of stalking.

art
  • 11 September 2019
  • Privacy and Data Protection

Case Analysis: R (Bridges) v CCSWP and SSHD [2019] EWHC 2341

On 4 September 2019 the world’s first decision regarding the privacy implications of facial recognition was handed down by the High Court in Cardiff. The implications of the case were of such significance that both the Information Commissioner and Surveillance Camera Commissioner joined as Interveners.

art
  • 10 September 2019
  • Employment

Assessment of whether disability is long-term

A claimant will be disabled, under the Equality Act 2010, if they have a mental or physical impairment and that impairment has a substantial and long term adverse effect on their ability to carry out normal day to day activities. An impairment is likely to be viewed as ‘long-term’ if it has lasted for at least 12 months, is likely to last for at least 12 months or it is likely to last for the rest of the person’s life.

art
  • 06 September 2019
  • Employment

How employers can avoid presenteeism in the workplace

According to a recent survey conducted by State of the Global Workplace, organisations with high scores for employee engagement showed just over 20% higher levels of profitability compared to those who did not value the practice as much. The same survey revealed that barely 7% of UK employees are actively engaged at work.