Search

How can we help?

Icon

“Systematic Failings” on Data Protection leads to a £15,000 fine

Following on from the case reported last month on data protection (”Failing to anonymise – the cost”), a nursing home in Northern Ireland has received a fine of £15,000 from the Information Commissioner’s Office (“ICO”), following the burglary of the home of one of its staff members.

During the burglary, an unencrypted work laptop was stolen. The laptop contained sensitive personal data, including medical information, on the nursing home’s 29 residents (including “do not resuscitate” orders) and personal data on the 46 members of staff.

The ICO’s subsequent investigation found the nursing home had no policies in place regarding the use of encryption, working from home and the storage of mobile devices. Data security training was also found to be lacking. In issuing the fine, the ICO said there had been “systematic failings” at the nursing home.

The fine was issued despite the nursing home referring themselves to the ICO, no complaints being made by any of the staff or residents’ families and no confirmation that the information had been further disseminated. In determining the level of the fine, the nursing home received some credit for having self-reported its breach to the ICO.

The ICO’s subsequent investigation found the nursing home had no policies in place regarding the use of encryption, working from home and the storage of mobile devices.

The amount of the fine reflected the size of the business, with the ICO stating that a bigger organisation experiencing a similarly serious breach should expect to receive a much larger fine. The case therefore acts as a timely reminder that all businesses must take their legal duties to look after personal data seriously and should ensure adequate policies, procedures and equipment are in place.  Simply having a work laptop password protected will not fulfil this duty.

For useful data protection factsheets, checklists and templates, please visit employmentbuddy.com 

For further advice on how to protect your business against data protection and privacy claims, please contact our employment lawyers on employment@clarkslegal.com 

About this article

Disclaimer

This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

About this article

Read, listen and watch our latest insights

art
  • 06 October 2017
  • Commercial Real Estate

Real estate fraud – help us help you to eliminate the risk

One of the biggest benefits of the digital and information age has been the increased agility in carrying transactions – these are now able to take place almost instantaneously. This increased agility has brought with it the problem of increased vulnerability – especially to the risk of fraud.

art
  • 03 October 2017
  • Construction

Off-Site Goods and Materials: Legal Issues

There is no doubt that off-site manufacture is being embraced by the industry.

art
  • 03 October 2017
  • Construction

A victory for common sense – actual cost relevant to compensation event assessment

A defining principle of the NEC3 is that the parties should deal with issues as they arise and not save these up to the end. Hence the provision in the standard form contract allowing for forecast assessments of compensation events. However, this principle can get forgotten when the parties fail to comply with the contractual machinery and timeframes or the compensation events are disputed. A case from earlier this year in the Northern Ireland courts has looked at the question of whether actual costs are relevant to the assessment of compensation events: Northern Ireland Housing Executive…

art
  • 28 September 2017

Michael Sippitt writes for Thomson Reuters on: Migration and Modern Slavery

Until lawyers start to pursue high-profile negligence cases, the status quo is likely to remain unchanged.Modern slavery is a term that has entered our political and legal lexicon over the past decade or so but it is still something that is largely misunderstood.

art
  • 19 September 2017
  • Construction

Modern slavery in construction supply chains: does your business comply

‘Modern Slavery’ is a term which encapsulates slavery, servitude, forced or compulsory labour, and human trafficking.

art
  • 15 September 2017
  • Employment

ACAS publishes guidance on supporting parents with ill or premature babies

ACAS has published guidance providing important information for both employees and employers in relation to premature births or full-term births where a child is ill.