Advertisement
Promo

Compliance Toolkit

Liverpool guilty of data protection offences

Graeme Wearden ZDNet.co.uk

Published: 28 Dec 2006 14:06 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

UK IT managers should take note of a prosecution brought by the Information Commissioner against Liverpool City Council.

Earlier this month, Liverpool Council was fined £300 after pleading guilty to an offence under the Data Protection Act. It had failed to respond to repeated requests from the ICO to supply data that it may have held on a former employee.

This former employee had made a 'subject access request' under the Data Protection Act for personal information held on her by the Council. After receiving some information from the Council, she then complained to the ICO that some sensitive material relating to her health was missing.

The ICO launched an investigation, but repeated attempts to contact Liverpool Council by phone and letter received no reply. It then issued an information notice demanding a response from the council's chief executive, but again no response was made. Failure to comply with such an information notice is a criminal offence.

"The Data Protection Act gives us all important rights, including the opportunity to find out what information is held on us by an organisation. This right is the very cornerstone of the Act and that is why the legislation is so important," said Mick Gorrill, head of the Regulatory Action Division at the Information Commissioner’s Office.

"Today’s successful prosecution serves as a very useful reminder to organisations that they must comply with subject access requests appropriately and that it is a criminal offence to ignore information notices served by the Information Commissioner," Gorrill added.

The Data Protection Act places a range of obligations on organisations which hold or use personal data. They must keep data up to date, destroy it when it is no longer needed, and answer subject access requests received from individuals.

In practice, this means an added burden on IT staff to ensure that data is securely stored, and can be recovered when needed.

A survey earlier this year found that many UK companies are breaking the DPA, by using live customer data in test environments.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
252 out of 341 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Video icon

Video

Cloud Watch Special Report

Five cloud computing myths exploded

Five cloud computing myths exploded

Analysis The cloud is providing a fertile habitat for the marketeers and their exaggerated claims. We examine the hokum and debunk the five most frequently peddled misconceptions about the cloud

More Special Reports

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters