23 May 2012 11:17


News
AIM  | Data  | HMRC  | ICO  | ICO  | Information Commissioner
Twitter RSS Newsletter Send to a friend
1

ICO spells out £500,000 penalty plans

14 January 2010   Lyn Whitfield

The Information Commissioner’s Office has issued guidance on how it will use its new powers to impose penalties of up to £500,000 for breaches of the Data Protection Act.

The guidance says the ICO will only issue a monetary penalty notice if there has been a “serious” breach of the DPA, if the breach was likely to cause “substantial” damage or distress and if the breach was deliberate or the data controller failed to take "reasonable steps" to prevent it.

However, it gives a number of examples of how the ICO will decide whether these conditions have been met that suggest NHS data controllers could fall foul of the new penalties if NHS organisations continue to commit the kind of breaches that have been reported over the past two years.

For example, it says a “serious” contravention of the act might include “medical records containing sensitive personal data [being] lost following a security breach during an office move.”

And it says “substantial” distress might include “medical details [being] stolen and an individual suffering worry and anxiety that his sensitive data will be made public, even if his concerns do not materialise.”

The guidance says the ICO does not expect businesses, public bodies and other organisations covered by the new powers to treat data protection as an add-on to their normal activities, but as an “integral” part of them.

It therefore indicates that the ICO will regard risk assessments, policies to encrypt laptops and removable devices, and codes of conduct for employees as “reasonable steps” that it would expect to see in place.

The ICO has issued increasingly strong calls for businesses and public bodies to improve data security since HM Revenue and Customs lost the details of millions of child benefit claimants on two unencrypted CDs that were put in the post in November 2007.

It has expressed particular frustration with NHS bodies, which have been responsible for a disproportionate number of the breaches of the DPA that have been reported to it since the HMRC scandal.

The guidance says the aim of the new monetary penalties is to create an effective sanction for breaches of the act and to deter others from breaching it. However, it says that the sector, size and financial resources of an organisation will be taken into account when deciding the level of financial penalty to apply.

Information Commissioner, Christopher Graham, said: “These penalties are designed to act as a deterrent and to promote compliance with the Data Protection Act.

“I remain committed to working with voluntary, public and private bodies to help them stick to the rules and comply. But I will not hesitate to use these tough new sanctions for the most serious cases where organisations disregard the law.”

Any money raised by the new powers will be paid into the Consolidated Fund run by the Treasury. The new measures only apply to data controllers and not their employees or private individuals.

Link: The Information Commissioner’s Office.


Related Articles:

News: ICO could fine trusts up to £500k | 13 November 2009
News: Two Scottish NHS bodies rapped by ICO | 16 September 2009
News: Five trusts breach DPA | 15 July 2009
1 News: NHS told to secure patient data | 27 May 2009
4 News: Four more organisations breach DPA | 30 April 2009
News: NHS Camden rapped by ICO | 25 March 2009
News: Another PCT rapped over data loss | 18 February 2009
News: Brent PCT rapped over data loss | 9 February 2009
1 News: 2008 'a year of data breaches' | 29 October 2008
Last updated: 13 January 2010 13:32

© 2009 E-HEALTH-MEDIA LTD. ALL RIGHTS RESERVED.


Please wait... loading

 
Add a comment

Register: To add a comment you must be registered.

Register

 

Login:

Email address:


Forgot your email address?contact


 
Password:


Forgot your password?prompt

 

Remember me

Login



EHealth Media Limited
EHealth Insider is managed and maintained by EHealth Media © 2012
Registered Office: 11 Campana Road, London SW6 4AS
Registered No. 4214439 | Vat No. 774 4008 29
About us | Advertise | Terms and conditions | Privacy policy | Contact us