ICO will fine up to £500K for data loss
7th April 2010
From Tuesday 6 April, the Information Commissioner’s Office (ICO) will get enhanced powers to fine organisations up to £500,000 for serious breaches of the Data Protection Act. Previously the maximum fine was a paltry £5,000. The tougher measures will be imposed alongside compulsory audit notices to central government departments found culpable for data breaches. The new powers for the UK's privacy watchdog are designed to deal with serious personal data breaches that arise through negligent behaviour. Precautions an organisation had previously applied as well as the circumstances of a breach will be taken into account in deciding a fine.
Revised guidelines state that the most severe fines will be imposed in cases where the "data controller has seriously contravened the data protection principles and the contravention was of a kind likely to cause substantial damage or substantial distress".
The enhanced powers for the ICO were approved by parliament three months ago. However a recent survey found that two thirds of 500 city workers (65 per cent) are still blissfully unaware that they could cost their organisation £500K if their actions cause a “deliberate or negligent” breach of personal data. The study, sponsored by Cyber-Ark Software, found that employers are often doing little or nothing to inform workers of important changes in UK data privacy rules.
The survey found that 64 per cent of those quizzed carry customer data on mobile devices, with only 12 per cent using encryption to protect data from prying eyes in the event of a loss. A further 50 per cent of mobile devices are protected only by basic password defences, and 38 per cent store sensitive data without any protection at all.
Check Point has recently written a white paper on the subject, you can view it on the Imerja website.