ICO hits two councils with £140k penalties after email errors PDF Print E-mail
Monday, 28 November 2011 11:04

The Information Commissioner has slapped two local authorities with monetary fines worth a combined £140,000, saying he wanted to send “a clear message” to the social care sector.

The breaches of the Data Protection Act both involved the sending of emails containing sensitive information to unintended recipients.

The Information Commissioner, Christopher Graham, rounded on the local government sector for its "sloppiness", claiming that there was “too much of this sort of thing going on”.

Worcestershire County Council was hit with an £80,000 penalty after a member of staff emailed highly sensitive personal information about vulnerable people to 23 unintended recipients in March this year.

The individual had clicked on an additional contact list before sending the email, which was only intended for internal use.

According to the ICO, Worcestershire had:

  • failed to take appropriate measures to guard against the unauthorised processing of personal data, such as providing employees with appropriate training and clearly distinguishing between internal and external email distribution lists, and
  • failed to properly consider an alternative means of handling the information, such as holding it in a secure system that could only be accessed by members of staff who needed to see it.

The employee realised they had made an error immediately and sought to contact the unintended recipients to ensure that the information was deleted.

“Fortunately, on this occasion all of the unintended recipients worked for registered organisations used to operating within the council’s protocols about handling sensitive data,” the ICO said.

North Somerset Council has meanwhile been given a monetary penalty of £60,000. The ICO said that in this case, a member of staff sent five emails – two of which contained highly sensitive and confidential information about a child’s serious case review – to the wrong NHS employee.

The incidents took place during November and December 2010 and arose because the council's employee had selected the wrong email address when creating a personal distribution list.

Despite being told about the error by the unintended recipient, the employee continued to email information on a further three occasions.

Two Assistant Directors at North Somerset raised the issue with the employee on 9 December but later that day a fifth incident took place. The NHS organisation verbally confirmed to the local authority that it destroyed the emails after their own internal investigation was complete.

According to the ICO, North Somerset had some policies and procedures in place but had failed to ensure that relevant staff received appropriate data protection training. The watchdog has called on the council to adopt a more secure means to send information electorically, “including encryption and ensuring that managers sign off email distribution lists”.

Both Worcestershire and North Somerset have agreed to take remedial action.

Christopher Graham, said: “Personal information in cases involving vulnerable people is about the most sensitive personal information imaginable. It is of great concern that this sort of information was simply sent to the wrong recipients by staff at two separate councils.

“It was fortunate that in both cases at least the email recipients worked in a similar sector and so were used to handling sensitive information. This mitigating factor has been taken into account in assessing the amount of the penalties.”

The Information Commissioner said that people who handled highly sensitive personal information needed to understand the real weight of responsibility that came with keeping it secure.

“Of course this includes having the correct training and policies in place, but it’s also about common sense," he said. "Considering whether email is the appropriate medium, checking and double checking that the right recipients will receive the information – and measures like encryption and data minimisation – should be routine.”

Graham added: “I hope these penalties send a clear message to those working in the social care sector. The Information Commissioner takes this sloppiness seriously – and so should you.”

The penalties levied on Worcestershire and North Somerset bring the total of local authorities fined by the ICO to five. The other local authorities to have to pay out were Surrey County Council (£120,000), Hertfordshire County Council (£100,000), Ealing Council (£80,000) and Hounslow Council (£70,000).

The watchdog has been working on a business case to be submitted to the Ministry of Justice that would give it stronger powers to conduct compulsory audits of local authorities’ and NHS organisations’ data protection compliance.

See also: Privacy matters

Philip Hoult

 

Add comment

The use of pseudonyms is permitted. Supplying an email address is optional and will not be published or used for any purpose other than notifying you of new comments on this article (if requested below).

All comments will be moderated before publication. We reserve the right not to publish comments that are offensive, defamatory or irrelevant to the topic.


Latest News

June 18, 2013

Cabinet Office publishes guidance for Whitehall on use of private emails

The Cabinet Office has issued guidance to central government departments on the use of private email. Read more
June 18, 2013

Blogger plans to take libel battle with council to Court of Appeal

A blogger who lost a claim for libel against a council and its chief executive and was ordered to pay £25,000 in damages has indicated this month that she will file her notice of appeal. Read more
June 17, 2013

Supreme Court set to rule this week on overlapping powers of local authority

A London council will find out this week whether it has been successful in its appeal to the Supreme Court in a highways case examining a local authority’s overlapping powers. Read more
June 17, 2013

DCLG publishes guide to reporting on and filming council meetings

The Department for Communities and Local Government has published a guide to reporting on council meetings, amid claims that many local authorities are still prohibiting filming. Read more
June 13, 2013

ICO fires warning on fax use after fining NHS trust £55,000

The Information Commissioner’s Office has issued a warning to organisations that use fax machines to send out sensitive information after the watchdog fined an NHS trust £55,000. Read more
June 12, 2013

ICO doubles data protection enforcement casework in 2012/13

The Information Commissioner’s Office more than doubled its data protection enforcement casework in 2012/13, it has emerged. Read more

 

Features

Hospital iStock 000010501389XSmall 146x219
June 06, 2013

The new role for local authorities in public health

Lee Parkhill summarises the key elements of the new legal framework for public health and highlights some issues for local authorities to consider. Read more
Equality 146x219
May 23, 2013

Best value revisited

Nicholas Dobson looks at the issue of Best Value and analyses the High Court's recent ruling on the Barnet outsourcing. Read more
May 02, 2013

Caldicott 2: To share or not to share

Dame Fiona Caldicott's long awaited report on service user confidentiality in the health and social care system was published last week. Eleanor Tunnicliffe explains how the findings affect all organisations working in the health and social care… Read more
May 02, 2013

Disclosure of documents in procurement disputes

Bidders who miss out on a procurement will often want to get hold of documents to see if they can bring legal action. Helen Prandy looks at the issues this raises. Read more
April 17, 2013

In a blaze of publicity

The Department for Communities and Local Government is seeking power to direct local authorities’ compliance with the Publicity Code. The move raises significant issues, write Olwen Dutton and Peter Keith-Lucas. Read more

 

 

Knowledge Bank

May 18, 2012

Managing in a Political Environment

Author: Nicholas Dobson, Pannone This paper outlines the changing role of the local government lawyer in the context of the legal, political and constitutional framework of local government. This paper looks at the legal powers that underpin the role of local authorities, including the new general…
April 19, 2012

General Power of Confidence – ‘A New Hope’?

Author: Nicholas Dobson, Pannone The general power of competence has been designed to give councils the confidence to act, using the power as their primary tool, without needing to refer back to central government. The question is: will the new power deliver?
March 27, 2012

Predetermination and Bias - Can Careless Talk Still Cost Decisions?

Author: Nicholas Dobson, Pannone Ministers entered government much exercised about the law surrounding predetermination. In the opinion of some, this was a conspiracy by local government lawyers to undermine the democratic process. And they were going to have none of it! The 2010 Conservative Party…
March 15, 2012

Recent developments in freedom of information

Author: Anya Proops, 11KBW The body of jurisprudence relating to freedom of information has continued to develop apace over the last year. The exponential growth in appeals being heard by both the first-tier and upper tribunals has meant that practitioners are having to work ever harder to keep…

Older news and features

May 23, 2013

Best value revisited

April 17, 2013

In a blaze of publicity

March 14, 2013

Data mining

February 27, 2013

Information caselaw update

Click here for full section archive

Wilkin Chapman Goolden

Featured Jobs


CLICK HERE to search all current vacancies

Featured Courses & Events

LGTV logo final 280 pxl

Services v2

Yellow pages iStock 000009762383XSmall cropTo access details of individual advertisers, please click on the relevant banner below.

To search all entries in the Local Government Lawyer Services Directory, please click here

 

 


 Shout_to_the_top_looking_left_iStock_000006002590XSmall_98x74 Latest Blog Posts


 


 

Ballot_iStock_000006080605XSmall_thumb

Snap Judgement

What is your view of the proposed changes to Legal Aid for judicial review cases?