Thomas Bridge 07 June 2013

ICO fines Glasgow £150k for data breach

Glasgow City Council has been fined £150,000 following the loss of two unencrypted laptops, one of which contained personal information about 20,143 residents.

The monetary penalty, issued by the Information Commissioner’s Office (ICO), came after the laptops – containing the town hall’s creditor payment history file and 6,069 individuals’ bank account details - were stolen from council offices in May last year.

Complaints of theft and a lack of security had already been made about the council premises where the theft took place.

One laptop had been locked in a storage drawer and the key placed in an unlocked drawer with the second laptop.

This breach of the Data Protection Act comes two years after Glasgow was issued with an enforcement notice for losing an unencrypted memory stick containing personal data.

Despite previous warnings, the latest ICO investigation found Glasgow had issued a number of staff with unencrypted laptops – some of which were later encrypted - after encountering software problems. In total, the ICO found 74 unencrypted laptops remain unaccounted for at the town hall, six of which have been stolen.

Glasgow is now required to carry out a full audit of its IT assets used to process personal data and arrange for all its managers to receive asset management training. The local authority will also carry out an annual check of devices.

The ICO’s assistant commissioner for Scotland, Ken Macdonald, said: ‘Glasgow City Council was issued with an enforcement notice back in 2010 after a similar incident where an unencrypted memory stick was lost. To find out that these poor practices have returned some two years later shows a flagrant disregard for the law and the people of Glasgow.

‘The council should be held to account, and the penalty goes some way to achieving that.’

A Glasgow City Council spokesman said: ‘This data loss should not have happened and we took immediate steps to ensure it does not happen again. It is important to note that the number of unencrypted laptops was already coming down when this theft occurred.

‘The council co-operated fully with the ICO and wrote to everyone potentially affected to advise them of the data loss. The ICO acknowledges there is no evidence that any bank accounts have been targeted, that the council immediately informed it of the theft and that we carried out significant remedial action.’

SIGN UP
For your free daily news bulletin
Highways jobs

Social Worker

Durham County Council
£35,412 - £39,152 / £40,777- £45,091 p.a. i.e. pre-progression Grade 9/ post -progression Grade 11
We are seeking a dedicated and enthusiastic social worker to play a key role within the Social Care Direct team, which serves as the vital ‘front of h Durham
Recuriter: Durham County Council

Deputy Manager, Children’s Homes Service

Durham County Council
Grade 11 £40,777 - £45,091
Deputy Manager – Pioneering New Project Supporting Young People’s Transition to Independence   Salary
Recuriter: Durham County Council

Year 5/6 Teacher plus TLR2 for Quality of Education

Durham County Council
M3 to UPS3 £35,674 to £51,048
Year 5/6 Teacher  M3 to UPS3 £35,674 to £51,048 + TLR2 (£3,527) for Quality of Education Full Time, Whole Time Permanent Required from 1 January 2026 Ferryhill
Recuriter: Durham County Council

Business Administration Apprentice

Durham County Council
£7.55 per hour
Business Administration Apprentice National Apprentice Training Wage £7.55 per hour Temporary – required from 6 January 2026 until 31 August 2027 37 h Cassop
Recuriter: Durham County Council

Administrative Assistant

Durham County Council
£25,185 - £25,989 pro-rata
Admin Assistant Grade 3 £25,185 - £25,989 pro-rata Part Time - 18.75 hours per week / Term time only  Temporary – required from 6 January 2026 until 3 Cassop
Recuriter: Durham County Council
Linkedin Banner