Powys Gets Biggest ICO Fine Yet For DPA Breach

Powys County Council has been fined £130,000 for a serious breach of the Data Protection Act (DPA) by the Information Commissioner’s Office (ICO).

This is the largest fine issued by the commission since it was given the powers to do so in April 2010 and, according to Assistant Commissioner for Wales Anne Jones, this latest in a series of breaches in the sector shows a worrying trend. “There is clearly an underlying problem with data protection in social services departments and we will be meeting with stakeholders from across the UK’s local government sector to discuss how we can support them in addressing these problems,” she said.

Third time lucky?

Powys County Council breached the DPA in February this year when staff members sent details of an unrelated child protection case to a member of the public, along with information relating to their own children.

According to a statement by the ICO: “Two separate reports about child protection cases were sent to the same shared printer. It is thought that two pages from one report were then mistakenly collected with the papers from another case and were sent out without being checked. The recipient mistakenly received the two pages of the report and knew the identities of the parent and child whose personal details were included in the papers. The recipient made a complaint to the council and a further complaint was also submitted by the recipient’s mother via her MP.”

This breach, according to the statement, was not the council’s first. A similar incident, reported to the ICO in June 2010, occurred when a social worker sent information relating to another unrelated vulnerable child to the same member of the public, who also knew that child.

The council had insisted that the first incident was a one-off error and promised to put training in place to avoid further incidents. At the time of the second breach, seven months later, the council had still not made such training mandatory for social work staff, nor had any been provided.

The ICO had warned the council to introduce mandatory training and to tighten up its security measures, or face stronger measures, and now the ICO has threatened to take the council to court if it does not clean up its act.

Jones added, “This is the third UK council in as many weeks to receive a monetary penalty for disclosing sensitive information about vulnerable people. It’s the most serious case yet and it has attracted a record fine. The distress that this incident would have caused to the individuals involved is obvious and made worse by the fact that the breach could have been prevented if Powys County Council had acted on our original recommendations.”

Iris Cheerin

View Comments

  • Fining a corporate public body is like fining the victim for being mugged. Individuals should be made to pay the fine, from the Chief executive down to the person committing the offence.

    Exactly the same as a driving speeding fine on company business - its the individual who has to pay the fine.

Recent Posts

Raimondo Downplays Huawei Smartphone Chip

US Commerce Secretary Gina Raimondo says Huawei's flagship smartphone chip 'years behind' US technology, shows…

17 hours ago

Cloud Companies Reject Broadcom VMware Pricing Changes

Cloud companies, business user groups say Broadcom price changes do not address their concerns, as…

17 hours ago

UK Lawsuit Claims Grindr Shared HIV Status

Dating app Grindr sued over claims it shared sensitive user data, including HIV status, with…

18 hours ago

Meta Opens Quest VR OS To Third Party Gadget Makers

Meta Platforms opens operating system behind Quest virtual reality headsets to third parties amidst competition…

18 hours ago

EU Prepares Action Against ‘Addictive’ TikTok Lite Features

European Commission may ban rewards feature in recently launched TikTok Lite that it calls 'toxic…

19 hours ago

TikTok Says New US Ban Effort Would ‘Trample Free Speech’

US House of Representatives passes new bill combining TikTok measures with foreign aid, may face…

1 day ago