You are here: silicon.com > Software > Security Strategy

Security Strategy

£500,000 fine coming for businesses that lose data?

Watchdog gets teeth - but only after more than 700 data breaches

Tags: ico, information commissioner's office, data loss, data breach

By Nick Heath

Published: 12 November 2009 16:10 GMT

Organisations that lose individuals' data could face a fine of up to £500,000 under proposals being considered by the government.

From next year, the privacy watchdog the Information Commissioner's Office (ICO) will be able to fine companies that recklessly or maliciously breach the Data Protection Act (DPA). The Ministry of Justice yesterday launched a public consultation on the maximum amount such fines can run to - a figure it proposes should be set at £500,000.

In its consultation document the MoJ said it chose £500,000 because it did not want the penalty to be more than "10 per cent of the highest annual turnover of a small company".

As well as being imposed for malicious or reckless breaches of the DPA, the fine could also be used by the ICO against companies who have:

  • Stored or processed personal data in a country outside of Europe that does not have adequate data protection legislation
  • Kept data for longer than is necessary for the organisation
  • Obtained personal data unlawfully
  • Accidentally deleted that data

Under the ICO's current powers, the strongest sanction the watchdog has against organisations that lose data is to serve it with an enforcement notice requiring it to improve data security or face legal action.

Deputy information commissioner, David Smith, welcomed the ICO's new powers and said they would help stop more breaches from occurring.

"We are keen to encourage organisations to achieve better data protection compliance and we expect that the prospect of a significant fine for reckless or deliberate data breaches will focus minds at board level," he said in a statement.

The announcement coincides with the latest ICO figures showing that 711 businesses, government bodies and charities have suffered data security breaches over the past two years.

Companies that are reckless with personal data could face a £500,000 fine from the Information Commissioner's Office
Companies that are reckless with personal data could face a £500,000 fine from the Information Commissioner's Office
(Photo credit: swanksalot via Flickr under the following Creative Commons Licence)

Of these organisations more than 200 were private companies and 209 were NHS health trusts and bodies.

Earlier this year the high level of losses among NHS trusts prompted the ICO to write to the Department of Health warning it needed to improve data security at health trusts.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Contract Manager - Community Health - NHS

A client of Huxley Associates is looking to add a Contract Manager to their business services directorate for an initial 6 month contract. You will ...

NHS Public Health Information Specialist

A dynamic and growing NHS client is seeking an experienced Public Health Analyst to join their team for a period of 3-6 months. You shall be coming ...

NHS Public Health Analyst

A modern and well-performing NHS organisation based in London are seeking a Public Health Analyst to come work with them on a sessional basis for a ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: