Mark Whitehead 01 September 2017

County fined £70,000 for 'serious and prolonged' data breach

Nottinghamshire County Council has apologised for leaving vulnerable people’s personal information exposed online after being fined £70,000 by data protection watchdogs.

It admitted that leaving the gender, addresses, postcodes and care requirements of elderly and disabled people in an online directory which had no basic security or access restrictions such as a username or password was a mistake.

A member of the public raised the alarm after realising they could access and view the data without logging in and worried it could be used by criminals to target vulnerable people.

Information Commissioner’s Office head of enforcement Steve Eckersley said it had been a 'serious and prolonged' breach of the Data Protection Act.

'For no good reason, the council overlooked the need to put robust measures in place to protect people’s personal information, despite having the financial and staffing resources available.

'Given the sensitive nature of the personal data and the vulnerability of the people involved, this was totally unacceptable and inexcusable.'

Caroline Baria, the council's adult social care service director, said: 'Nottinghamshire County Council takes its responsibility for data security extremely seriously so we are very sorry that this error occurred and wholeheartedly accept the information commissioner’s findings.

'As soon as this matter came to our attention we removed the home care directory from the internet and reported the incident to the commissioner.

'At the time the directory included partial addresses and a brief outline of the care needs of 81 people who have required home care services, but the information did not contain any names or house numbers.

'A full review of procedures has been carried out and we are now using a different system for home care providers outside of the internet.'

SIGN UP
For your free daily news bulletin
Highways jobs

Practice Supervisor (Permanence & Reunification)

North Yorkshire Council
£47,181 - £51,356 per annum
Thank you for your interest in joining our Children and Young People’s service. Scarborough, North Yorkshire
Recuriter: North Yorkshire Council

Fleet Technical Officer

Derbyshire County Council
Grade 9 £32,347 - £34,317 per annum
You must also be able to demonstrate a basic level of understanding of the Operator’s Licence compliance requirements Derbyshire
Recuriter: Derbyshire County Council

LGR Programme Director

Worcestershire County Council
Up to £120k
This is a once in a generation opportunity to shape the future of local government in Worcestershire. Worcestershire
Recuriter: Worcestershire County Council

Team Manager - Future First

London Borough of Richmond upon Thames and London Borough of Wandsworth
£51,540 – £62,451 per annum
Team ManagerFuture... Wandsworth, London
Recuriter: London Borough of Richmond upon Thames and London Borough of Wandsworth

Developer Obligations Officer

The Royal Borough of Windsor & Maidenhead
£39,526 - £43,613 per annum
We have an exciting opportunity for a Developer Obligations Officer to join us! Maidenhead, Berkshire
Recuriter: The Royal Borough of Windsor & Maidenhead
Linkedin Banner