Susan Hall 12 August 2015

How to avoid mishandling data

Data breaches such as those revealed by the campaign group Big Brother Watch aren’t confined to local authorities.

This year alone there have been a range of serious data mishandling incidents in the public sector, not least South Wales Police who were fined £160,000 for losing a video containing evidence from a child sex abuse victim and a £190,000 fine to the Serious Fraud office for wrongful disclosure of evidence obtained in respect of their investigation of BAE Systems.

In the past year, the Information Commissioner’s Office (ICO) has dealt with 84 reported cases of data misuse, prosecuting in 18 instances and issuing fines in 11. Of the 84 cases reported, 37 involved public sector organisations, including one Housing Association. Big Brother Watch has this month called for custodial sentences for serious and persistent data offenders.

Data and access to it is a growing issue. The ICO has also recently cracked down on employers and others, such as insurance companies, who require job or policy applicants to carry out a ‘subject access request’ to GPs and police forces and disclose health records and any convictions or cautions. Enforced subject access requests are now a crime under section 56 DPA – a provision that only came into force in March of this year.

So what can you do to avoid a data disaster?

The most common issues of data mishandling in public services include mislaying USB sticks, failing to change passwords, not disposing of hard drives securely, leaving devices on trains, not putting in place software to remotely wipe out files, and lack of safeguards against access to personal computers.

In my experience, there are a number of reasons behind these issues, namely: lack of training and guidance, budget pressures leading to ill thought out use of IT shortcuts and adoption of ‘Bring Your Own Device’ remote or mobile working situations which are not backed up by appropriate safeguards and policies.

In the case of the social housing provider that was cautioned by the ICO, several documents containing third party personal details were revealed during a litigation process. The necessary documents required for the case were reviewed and redacted and placed on a desk in order to be photocopied, but a different member of staff was subsequently tasked with the photocopying and, in error, the original unreacted documents were copied and disclosed the sensitive information to the other party to the litigation.

The investigation identified that, while checks had been undertaken during the review process, no subsequent checks were made prior to handing them over. It also identified that, whilst data protection training was provided to staff at induction, refresher training was not in place at the time of the incident.

There is absolutely no room for error under today’s rigorous policies. The issue of data mishandling is so sensitive that even the smallest slip up, can result in loss of confidence, loss of revenue and, most importantly, unwelcome exposure for your clients and customers.

So what are the three key actions to safeguard against mishandling of data?

• Analyse policies, enforce them and ensure support training is in place which deals with data handling in an organisation
• Ensure repeated training to account for people taking up new job roles and therefore potential different data handling requirements
• Analyse what led to any breaches in data handling and adapt policies and support training as necessary

Opting out is not an option. Data handling polices and training are a necessary and integral part of any responsible organisation and needs informed and proactive engagement from top to bottom.

Susan Hall is a partner in the intellectual property team at national law firm Clarke Willmott.

Banning urban pesticide use image

Banning urban pesticide use

RSPB and PAN are working on a letter from local councillors calling on the Government to introduce a national ban on urban pesticide use. Find out more below.
SIGN UP
For your free daily news bulletin
Highways jobs

Environmental Health Officer – Food, Health & Safety, Animal Licensing

Ashfield District Council
£36,648 - £39,186 per annum (pay award pending)
We are looking for two talented, committed, and friendly Environmental Health Officer Sutton-In-Ashfield, Nottinghamshire
Recuriter: Ashfield District Council

Town Centres and Markets Manager

Ashfield District Council
£40,221 - £43,421 per annum (pay award pending)
A great opportunity to be involved in shaping and transforming the District of Ashfield Sutton-In-Ashfield, Nottinghamshire
Recuriter: Ashfield District Council

Environmental Protection Officer - Land/Permits

Ashfield District Council
£14,888 - £16,038 per annum (pay award pending)
An opportunity has arisen to recruit a part time Environmental Protection Officer. Sutton-In-Ashfield, Nottinghamshire
Recuriter: Ashfield District Council

Casual Learning Assistant x 5 posts

Rotherham Metropolitan Borough Council
£12.38 per hour (pay award pending)
Casual, variable hours, working as and when required. Rotherham, South Yorkshire
Recuriter: Rotherham Metropolitan Borough Council

Assessment and Review Coordinator

Rotherham Metropolitan Borough Council
£29,777 - £32,076 (pay award pending)
We are looking for someone who shares our vision and aspirations for people – someone who wants to make a difference. Rotherham, South Yorkshire
Recuriter: Rotherham Metropolitan Borough Council
Linkedin Banner

Partner Content

Circular highways is a necessity not an aspiration – and it’s within our grasp

Shell is helping power the journey towards a circular paving industry with Shell Bitumen LT R, a new product for roads that uses plastics destined for landfill as part of the additives to make the bitumen.

Support from Effective Energy Group for Local Authorities to Deliver £430m Sustainable Warmth Funded Energy Efficiency Projects

Effective Energy Group is now offering its support to the 40 Local Authorities who have received a share of the £430m to deliver their projects on the ground by surveying properties and installing measures.

Pay.UK – the next step in Bacs’ evolution

Dougie Belmore explains how one of the main interfaces between you and Bacs is about to change.