1000 Data Protection Breaches

United Kingdom

The Information Commissioner’s Office (“ICO”) has expressed concern that the number of Data Protection Act (“DPA”) breaches notified to the ICO since November 2007 has exceeded 1000.

Given that the majority of data protection breaches are due to human or technical error (e.g. staff disclosing personal data to the wrong people or automated machines sending out personal information to the wrong addresses) the ICO is urging organisations to ensure that staff are appropriately trained in the handling of personal data.

David Smith, Deputy Information Commissioner said:

Extra vigilance is required so that people’s personal information does not end up in the wrong hands.”

He urges organisations to have clear security and disclosure procedures in place so that staff can understand them, they can be properly implemented and complied with.

On 6 April this year, the ICO was given new powers to impose monetary penalties of up to £500,000 on organisations who commit the most serious data protection breaches.

For further details and to view our previous article, please click here.

In view of this, it is now even more important for organisations to ensure that appropriate technical and organisational measures are applied to the handling of personal data so that organisations minimise the risk of receiving significant financial and reputational sanctions.

If you would like further information on this subject or on your obligations under the DPA, please let us know.