Two councils fined for data breaches

Two councils have been fined after staff sent "highly sensitive" personal information to the wrong recipients.

The Information Commissioner's Office (ICO) fined Worcestershire County Council £80,000 after a worker wrongly emailed personal information about a large number of vulnerable people to 23 unintended recipients.

It also fined North Somerset Council £60,000 for a breach of the Data Protection Act in which an employee sent five emails to the wrong NHS employee.

Two of these emails contained highly sensitive and confidential information about a child's serious case review, the ICO said.

Both cases related to incorrect use of email distribution lists.

The ICO found that the error at Worcestershire County Council happened when the employee clicked on an additional contact list before sending the email.

The incidents at North Somerset Council, in November and December 2010, occurred when a council employee selected the wrong email address when creating a personal distribution list.

"Personal information in cases involving vulnerable people is about the most sensitive personal information imaginable," said the information commissioner Christopher Graham.

"People who handle highly sensitive personal information need to understand the real weight of responsibility that comes with keeping it secure."ADNFCR-3406-ID-801226459-ADNFCR

Article courtesy of Aviva PLC. Published 30-11-2011


Comments (0)

Post a Comment
* Your Name:
* Your Email:
(not publicly displayed)
Reply Notification:
Approval Notification:
Website:
* Security Image:
Security Image Generate new
Copy the numbers and letters from the security image:
* Message: