Training

Data protection training breach

by Mark Rowe

The data protection regulator has sought to ‘name and shame’ a Scottish council for repeatedly failing to train staff around data protection.

West Dunbartonshire Council were told to train staff on several occasions, as well as being advised to put in place a policy around home working. But their failure to do so ultimately contributed to a data breach that led to a child’s medical reports being stolen.

The Information Commissioner’s Office (ICO) did an audit of the council in January 2013. The audit gave a reasonable assurance of the council’s compliance with the law, but made recommendations for areas that needed improvement, including training for all staff and adopting a home working procedure. A follow-up audit in November 2013 showed progress, but showed some of the recommendations still had not been carried out.

In July 2014, the council reported a data breach to the ICO, after an employee had a bag containing confidential information stolen. The employee had taken details of an adoption case out of the office to work on from home, but a laptop and paperwork left in their car overnight were stolen.

The ICO found the employee had not been given training on the Data Protection Act, and the council still had no guidance to staff on handling personal information when working from home. The regulator says that the council avoided a fine as the breach did not cause substantial damage or distress. The council has now been issued with an enforcement notice obliging it to implement training and guidance, or face court action.

Ken Macdonald, Assistant Information Commissioner for Scotland, said: “Time and time again we have told this council to make these changes, and yet they have still not completed everything we set out. We’ve been left with no choice but to issue this formal notice requiring them to act. Let’s be clear, what we’re asking for here is a basic requirement for an organisation that is trusted with large amounts of local people’s personal data. When people in Dunbartonshire provide the council with their details, they expect staff are trained to handle this information properly. Unfortunately, more than three years after this was made clear to the council, this still hasn’t happened.”

Related News

  • Training

    MP at HABC

    by Mark Rowe

    Highfield Awarding Body for Compliance (HABC), the exam awarding body, has started 2014 with a visit from its local MP. Doncaster Central…

  • Training

    Resettlement division

    by Mark Rowe

    Tavcom, the Hampshire-based security systems training company, has formed a resettlement division, for the transition of ex-forces personnel into the security sector.…

  • Training

    Emergency Services Show

    by Mark Rowe

    Counter-terrorism is among issues at the annual Emergency Services Show which returns to Hall 5 at the NEC, Birmingham on September 20…

Newsletter

Subscribe to our weekly newsletter to stay on top of security news and events.

© 2024 Professional Security Magazine. All rights reserved.

Website by MSEC Marketing