Ruth Crawford QC

What

Loss of sensitive personal data.

How much

Unknown.

Why

Theft of an unencrypted laptop from the Data Controller’s home.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that personal media devices used to store data are sufficiently encrypted.

Reason for action

Although it was concluded that the laptop was suitably secure physically, insufficient technical security measures were taken.

When

16 November 2011.

Links

View PDF of the Ruth Crawford QC Undertaking (Via ICO Website)

View PDF of the Ruth Crawford QC Undertaking (Breach Watch Archive)

Phoenix Nursery School

What

Loss of sensitive personal data.

How much

Unknown.

Why

A backup tape and supporting device containing details of pupils, parents and guardians was lost.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that in the future all personal data is encrypted to a sufficient standard and that current operational procedures are reviewed and revised.

Reason for action

While the backup tape did not appear to have been stolen, it could not be located. The data controller contacted all parents and guardians effected by the incident to advise them accordingly. However although the data on the device was recovered in full, the Commissioner’s investigation revealed that the technical measures employed by the school were inadequate.

When

16 November 2011.

Links

View PDF of the Phoenix Nursery School Undertaking (Via ICO Website)

View PDF of the Phoenix Nursery School Undertaking (Breach Watch Archive)

Oliver Letwin, MP

What

Loss of sensitive personal data.

How much

“Numerous”

Why

The data controller was disposing of documents in public waste bins in St James’ Park.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that any documents containing personal data must be disposed in a secure manner, such as shredding, pulping or incineration.

Reason for action

Some of the documents disposed of in the public waste bins included personal information such as names and addresses.

When

15 November 2011.

Links

View PDF of the Oliver Letwin MP Undertaking (Via ICO Website)

View PDF of the Oliver Letwin MP Undertaking (Breach Watch Archive)

Rochdale Metropolitan Borough Council

What

Loss of personal data.

How much

“Thousands”

Why

Loss of an unencrypted USB stick.

Regulator

ICO

Regulatory action

Undertaking issues to ensure that all portable media devices used to store personal data are sufficiently encrypted and that policies and procedures on the storage, processing, transmission and disposal of personal data shall be reviewed and revised by no later than 1 December 2011.

Reason for action

Although much of the data on the USB stick was already available in the public domain it became clear during investigations that data protection training was insufficient and that encrypted memory sticks were not provided in those cases when more private data would have been stored.

When

03 November 2011.

Links

View PDF of the Rochdale Metropolitan Borough Council Undertaking (Via ICO Website)

View PDF of the Rochdale Metropolitan Borough Council Undertaking (Breach Watch Archive)

Newcastle Youth Offending Team

What

Loss of sensitive personal data.

How much

100 records.

Why

Theft of an unencrypted laptop from a home address of an employee of a hired data processor.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that all data processors contracted on the data controllers behalf comply with the principles of the Act and in particular that all potable media devices are sufficiently encrypted.

Reason for action

The data controller did not have an appropriate contract in place with the data processor which stipulated the need to encrypt devices containing personal data.

When

28 October 2011.

Links

View PDF of the Newcastle Youth Offending Team Undertaking (Via ICO Website)

View PDF of the Newcastle Youth Offending Team Undertaking (Breach Watch Archive)

University Hospitals Coventry & Warwickshire NHS Trust

What

Loss of sensitive personal data on two occasions.

How much

One record and 18 records.

Why

A patient’s medical record was allegedly found in a waste bin outside Coventry’s University Hospital by a member of the public. Two months previously the records of 18 patients were found in a public waste bin in a residential apartment block.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that policies relating to the storage, use, disposure and removal from the premises of personal information are made clear to staff and that compliance is monitored.

Reason for action

The short time between the two incidents suggested that insufficient measures were being taken to safeguard personal data.

When

27 October 2011.

Links

View PDF of the University Hospitals Coventry & Warwickshire NHS Trust Undertaking (Via ICO Website)

View PDF of the University Hospitals Coventry & Warwickshire NHS Trust Undertaking (Breach Watch Archive)

Spectrum Housing Group

What

Personal data relating to employees accidently sent to an outside recipient.

How much

200 records.

Why

Records accidently sent to an outside recipient due to the data controllers’ e-mail system automatically predicting the intended recipient based on previous sent messages.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that personal data will only be sent by email when necessary. Data should be made secure and staff should be made aware of company policies.

Reason for action

Insufficient measures were taken to prevent an accidental loss of unsecured personal information.

When

19 October 2011.

Links

View PDF of the Spectrum Housing Group Undertaking (Via ICO Website)

View PDF of the Spectrum Housing Group Undertaking (Breach Watch Archive)

Dumfries and Galloway Council

What

Accidental online disclosure of staff’s personal information.

How much

887 records.

Why

Records were accidently published online in response to a Freedom of Information (Scotland) Act request.

Regulator

ICO

Regulatory action

Undertaking issued to undergo an externally commissioned audit and to put it place checks to prevent another such occurrence.

Reason for action

Insufficient measures were taken to prevent an accidental loss of unsecured personal information.

When

17 October 2011.

Links

View PDF of the Dumfries and Galloway Council Undertaking (Via ICO Website)

View PDF of the Dumfries and Galloway Council Undertaking (Breach Watch Archive)

Association of School and College Leaders

What

Loss of sensitive personal data.

How much

100 records.

Why

Theft of unencrypted laptop from staff member’s home.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that all portable media devices are encrypted.

Reason for action

Although encryption software was provided, whether or not to use it was left to the discretion of staff members.

When

05 October 2011.

Links

View PDF of the Association of School and College Leaders Undertaking (Via ICO Website)

View PDF of the Association of School and College Leaders Undertaking (Breach Watch Archive)

Holly Park School

What

Loss of sensitive personal data.

How much

Nine records.

Why

Theft of an unencrypted laptop from school premises.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that all portable media devices are encrypted and are kept physically secure.

Reason for action

Although the laptop was kept in a locked filling cabinet the office it was housed in was not locked.

When

05 October 2011.

Links

View PDF of the Holly Park School Undertaking (Via ICO Website)

View PDF of the Holly Park School Undertaking (Breach Watch Archive)