Case Studies

Council’s data disclosure

by Mark Rowe

The Information Commissioner’s Office (ICO) has ordered the Council of the Isle of Scilly to implement new data protection policies and training after two data breaches involving the disclosure of personal data.

The first breach occurred in June 2013 when an attachment inadvertently included in an email revealed personal data related to a disciplinary hearing. A further incident in September 2013 involved two documents containing sensitive personal data, ending up in public circulation. Poor data sharing, including staff using personal email accounts and paper documents not being properly redacted meant details of an investigation into the conduct of a former head teacher were disclosed publicly.

ICO Head of Enforcement, Stephen Eckersley, said: “Personal data must be handled securely and safely. The council has failed to do so and must now make immediate changes.

“The people of the Isles of Scilly need to be confident their council understands and complies with the law. Our undertaking will help ensure they do so.”

The council has agreed to implement mandatory data protection training, with refresher training to be updated regularly. They must also draft appropriate guidance on the safe transfer of personal data by email and consider the use of encryption. The council must also draft a redaction policy.

Related News

  • Case Studies

    Crisis communications survey

    by Mark Rowe

    The Business Continuity Institute (BCI) has launched its latest annual Emergency & Crisis Communications Report, sponsored by the crisis comms SaaS product…

  • Case Studies

    Essex van

    by Mark Rowe

    Tower Security is patrolling clients’ premises and homes with a new Mercedes-Benz Citan. The Essex-based contract security firm says it compared servicing…

Newsletter

Subscribe to our weekly newsletter to stay on top of security news and events.

© 2024 Professional Security Magazine. All rights reserved.

Website by MSEC Marketing