Advertisement
Promo

Security threats Toolkit

Data Breaches

Privacy tsar: 277 data breaches since November

Tom Espiner ZDNet.co.uk

Published: 29 Oct 2008 13:14 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The information commissioner has criticised the mishandling of personal data by the private and public sectors, in the light of hundreds of data breaches reported to his office over the past year.

In a speech to the RSA Conference Europe 2008 on Wednesday, Richard Thomas said that 277 data breaches had been reported since last November. Thirty serious incidents, in both the public and private sectors, are still under investigation.

"I can reveal today that the number of data breaches reported to my office has soared to 277 since November 2007," said Thomas. "There have been 28 breaches by central government; 75 within the NHS and other health bodies; with 80 reported in the private sector. We are currently investigating 30 of the most serious cases."

Thomas said that, in the past year, his office has taken enforcement action regarding data losses against HM Revenue & Customs, the Ministry of Defence, the Department of Health, the Foreign and Commonwealth Office, Virgin Media, Skipton Financial Services, Carphone Warehouse, TalkTalk and Orange.

Thomas urged industry and government leaders to avoid being "asleep at the helm" when it comes to safeguarding information. Both the public and private sectors must be aware of the risks of abuse of massive databases of personal data, said Thomas.

"It is time for the penny to drop," said Thomas. "The more databases that are set up and the more information exchanged from one place to another, the greater the risk of things going wrong. The more you centralise data collection, the greater the risk of multiple records going missing or wrong decisions about real people being made. The more you lose the trust and confidence of customers and the public, the more your prosperity and standing will suffer."

Thomas said that organisations must adhere to the principles of data minimisation, retaining as little data as possible, to avoid damage to their reputation through data loss.

On Wednesday, the Home Office defended its proposed National Identity Register, the huge, centralised database behind the ID cards scheme.

The government department has also proposed a centralised database containing the details of communications made by every UK citizen, including telephone caller and receiver, email sender and recipient, and web-browsing habits. The Home Office said that such far-reaching databases were necessary due to the evolution of technology.

"The communications revolution has been rapid in this country and, because of changes in technology, the way in which we collect communications data needs to change too. If it does not, we will lose this vital capability that we currently have and that we all take for granted in fighting and solving crime," said a Home Office spokesperson. "Of course, there is a balance between privacy and our liberty, which is why we have said we will be consulting on this and seeking a political consensus."

Regarding the proposed communications database, the Home Office added that "no decisions have been taken" and that it will be "consulting in the new year".

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?


More in this Special Report

The top five internal security threats

The top five internal security threats

It's widely known that internal staff are the biggest threat to IT security, but what specifically should an employer watch out for? more

Keeping mobile data from going walkabout

Keeping mobile data from going walkabout

Mobile email is no longer the preserve of upper management but providing access to company information on the go has its risks more

Lib Dems call for data guardians

Lib Dems call for data guardians

The Liberal Democrats are seeking the introduction of data guardians into the public and private sector, to protect citizens' information rights more

Worker suspended over loss of prisoner data

Worker suspended over loss of prisoner data

An employee at Home Office contractor PA Consulting has been suspended after the loss of a memory stick holding the unencrypted details of every prisoner in England and Wales more

Ministry of Justice reports nine data breaches

Ministry of Justice reports nine data breaches

The ministry reported the data breaches, affecting around 45,000 people, to the Information Commissioner's Office in the last financial year more

Foreign Office reports five data breaches since 2007

Foreign Office reports five data breaches since 2007

The data breaches at the Foreign and Commonwealth Office are thought to have affected less than 188 people in total more

ICO: Gov't ignoring data-sharing hazards

ICO: Gov't ignoring data-sharing hazards

The government is blindly pursuing data-sharing plans without heeding the potential pitfalls, information commissioner Richard Thomas has claimed more

Lords presses government for data-breach law

Lords presses government for data-breach law

The House of Lords has again urged the government to introduce a data-breach notification law, adding that banks should be liable for e-fraud losses more

Video: Get the most out of your data

Video: Get the most out of your data

How do companies deal with information management? Jonathan Steel, CEO of tech-research firm The Bathwick Group, gives insights based on a recent ZDNet.co.uk benchmark survey more

Justice minister urges overhaul of gov't data handling

Justice minister urges overhaul of gov't data handling

Michael Wills has called for the government to handle data transactions as carefully as financial transactions more

MoD announces data-protection action plan

MoD announces data-protection action plan

The ministry has published a plan of how it intends to meet 51 data-policy recommendations made as part of review into the loss of MoD laptops more

Systemic failure blamed for HMRC data loss

Systemic failure blamed for HMRC data loss

Two reports have found the loss by HMRC of 25 million child-benefit claimant details was 'entirely avoidable' more

Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

Climate research centre compromised

One of the UK's leading climate change research centres has had a security breach. The Climate Research Unit at the University of East Anglia (UEA) suffered a compromise of information,... More

1 comment

Government web-monitoring plans on hol...

Government plans to compel ISPs to process and store details of all web communications have been put on hold until after the next election. The Home Office told ZDNet UK on Wednesday... More

1 comment

Watchdog reveals illegal sale of phone...

The Information Commissioner's Office is preparing a prosecution file against a mobile operator's employees who allegedly sold on thousands of customers' details to a competitor. The... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters