IT Systems and Data Protection

01.09.17

County fined £70,000 over ‘inexcusable’ personal data breach

Nottinghamshire County Council has been fined £70,000 by the Information Commissioner’s Office (ICO) following a serious data protection breach that left vulnerable people’s personal information online for five years.

Despite the Data Protection Act requiring organisations to keep personal data secure, the local authority posted the gender, addresses, postcodes and care requirements of elderly and disabled people in an online directory which didn’t have basic security or access restrictions.

The matter was only discovered after a member of the public using a search engine was able to access and view the data without the need to log in. The information also revealed whether or not the vulnerable people were still in hospital.

Steve Eckersley, ICO head of enforcement, said this was a serious and prolonged breach of the law.

“For no good reason, the council overlooked the need to put robust measures in place to protect people’s personal information, despite having the financial and staffing resources available,” he added.

“Given the sensitive nature of the personal data and the vulnerability of the people involved, this was totally unacceptable and inexcusable. Organisations need to understand that they have to treat the security of data as seriously as they take the security of their premises or their finances.”

The council had launched its ‘Home Care Allocation System’ (HCAS), an online portal allowing social care providers to confirm that they had capacity to support a particular service user, in July 2011. When the breach was reported in June 2016, the HCAS contained a directory of 81 service users. It is understood the data of 3,000 people had been posted in the five years the system was online.

Although the names of the service users were not included, the ICO noted that a determined person would be able to identify them. The regulator added that the county council offered no mitigation.

Responding to the fine, Caroline Baria, adult social care service director at Nottinghamshire County Council, said the local authority takes its responsibility for data security extremely seriously “so we are very sorry that this error occurred and wholeheartedly accept the Information Commissioner’s findings”.

“As soon as this matter came to our attention we removed the home care directory from the internet and reported the incident to the commissioner,” she said. “At the time, the directory included partial addresses and a brief outline of the care needs of 81 people who have required home care services, but the information did not contain any names or house numbers.

“A full review of procedures has been carried out and we are now using a different system for home care providers outside of the internet.”

Nottinghamshire is the latest authority to have been reprimanded by the ICO, with Basildon Borough Council recently being hit with a £150,000 fine after publishing personal information online and Gloucester City Council being hit with a £100,000 penalty aster a cyber-attack exposed information about its employees to hackers.

Have you got a story to tell? Would you like to become a PSE columnist? If so, click here

Comments

There are no comments. Why not be the first?

Add your comment

 

public sector executive tv

more videos >

latest public sector news

Funding inequalities could destroy public services in rural areas

20/11/2017Funding inequalities could destroy public services in rural areas

Central government funding per resident in county authorities was almost 50% below large cities last year, with councils saying the situation cou... more >
Major growth investment includes £1.7bn city transport fund

20/11/2017Major growth investment includes £1.7bn city transport fund

The government has today announced that it will release £1.7bn of extra funding for cities ahead of Wednesday’s Budget. Prime mi... more >
Counties and districts clash over suggestion to scrap two-tier authorities

20/11/2017Counties and districts clash over suggestion to scrap two-tier authorities

A report suggesting that scrapping district councils could save £2.9bn a year has prompted anger from the District Councils Network (DCN). ... more >

editor's comment

25/10/2017Take a moment to celebrate

Devolution, restructuring and widespread service reform: from a journalist’s perspective, it’s never been a more exciting time to report on the public sector. That’s why I could not be more thrilled to be taking over the reins at PSE at this key juncture. There could not be a feature that more perfectly encapsulates this... read more >

last word

The importance of openness after Grenfell

The importance of openness after Grenfell

Following the recent Grenfell Tower tragedy, Lord Porter, chairman of the LGA, argues that if the public are going to have faith in the safety testing process then everything must be out in the o... more > more last word articles >
Funding inequalities could destroy public services in rural areas

20/11/2017Funding inequalities could destroy public services in rural areas

Central government funding per resident in county authorities was almost 50% below large cities last year, with councils saying the situation could quickly deteriorate, new research released toda... more >
Major growth investment includes £1.7bn city transport fund

20/11/2017Major growth investment includes £1.7bn city transport fund

The government has today announced that it will release £1.7bn of extra funding for cities ahead of Wednesday’s Budget. Prime minister Theresa May made the announcement, which in... more >

the raven's daily blog

Visual.ONS: How to compete with the big data aggregators

13/11/2017Visual.ONS: How to compete with the big data aggregators

Advertisement feature Christopher Gallagher, territory manager at SAS, explains how big data can be used by the public sector to find innovative solutions to common problems.  I have been really impressed by the work of Visual.ONS – the team at the Office for National Statistics, who are responsible for exploring imaginati... more >
read more blog posts from 'the raven' >

comment

Driving forward a healthier Scotland

10/11/2017Driving forward a healthier Scotland

Dundee City Council is leading the way in boosting electric vehicle (EV) uptake in Scotland, writes Rebecca Wallace from the local authority&rsqu... more >
A smarter approach to digital transformation

10/11/2017A smarter approach to digital transformation

Catherine Bright, Smarter Digital Services (SDS) manager, explains how a partnership of 12 councils across Kent and Surrey are jointly funding a ... more >
Delivering on estates

10/11/2017Delivering on estates

Sam Ulyatt, strategic category commercial director at the Crown Commercial Service (CCS), on how a new framework can help public sector organisat... more >
Open for business

10/11/2017Open for business

Clare Moore, senior specialist of valuation and disposals at the Homes and Communities Agency (HCA), explains how public sector bodies looking to... more >

interviews

‘The HSCN is the realisation of industry best practice’

30/06/2017‘The HSCN is the realisation of industry best practice’

Keith Smith, public sector business development manager at Virgin Media Business, tells PSE’s Luana Salles that health and social care orga... more >
HSCN: The enabler for a more joined-up public sector

26/06/2017HSCN: The enabler for a more joined-up public sector

Mark Hall, Chief Assurance Officer at Redcentric, discusses NHS Digital’s project, the new Health and Social Care Network (HSCN) and what b... more >
Maintaining the momentum for further devolution

25/04/2017Maintaining the momentum for further devolution

Ahead of this year’s mayoral elections, Lord Kerslake, the former head of the Civil Service, tells PSE’s David Stevenson why the argu... more >
New social care funding misses the point

13/04/2017New social care funding misses the point

Clive Betts MP, chair of the Communities and Local Government (CLG) Committee, reflects on the social care funding released in this year’s ... more >

public sector focus

View all News