Wigan Council

What
Loss of sensitive personal data.

How much
43,000 records.

Why
An unencrypted laptop was stolen from a locked office.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that all mobile data storage devices are sufficiently encrypted. All staff must be made aware of the data controller’s policy for the storage of personal data and be trained to follow it.

Reason for action
The personal data contained on the unencrypted laptop was downloaded onto it in breach of Council policy.

When
18 August 2009

Links
View PDF of the Wigan Council Limited Undertaking (Breach Watch Archive)

NHS Education for Scotland

What
Loss of sensitive personal data.

How much
6,377 records.

Why
An unencrypted laptop containing the personal data of 6,377 individuals was stolen from a locked office.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that all mobile data storage devices are sufficiently encrypted. All staff must be made aware of the data controller’s policy for the storage of personal data and be trained to follow it.

Reason for action
The laptop was not encrypted as it not intended to taken off NES premises and was therefore not considered a “mobile device” under NES internal policy at the time.

When
14 August 2009

Links
View PDF of the NHS Education for Scotland Undertaking (Breach Watch Archive)

Imperial College Healthcare NHS Trust

What
Loss of sensitive personal data.

How much
6,000 records.

Why
Six laptops were stolen from a secure area within the hospital on two separate occasions. In a separate incident a small number of paper records were lost.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that all mobile data storage devices are sufficiently encrypted. Measures must be taken to ensure the physical security of all such devices containing personal information. All staff must be made aware of the data controller’s policy for the storage of personal data and be trained to follow it.

Reason for action
One of laptops was unencrypted despite containing sensitive personal data.

When
29 July 2009

Links
View PDF of the Imperial College Healthcare NHS Trust Undertaking (Breach Watch Archive)

East Cheshire NHS Trust

What
Loss of sensitive personal data.

How much
About 60 records.

Why
Personal data relating to over 60 patients were found in a garden in Newcastle-under-Lyme. This followed an office move during which an external company was retained to clear out scrap and rubbish from vacated premises.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that in all cases where third party supplies of goods or services will have access to personal data, a written contract must be entered into prior to work beginning which covers data security requirements. Staff must be made aware of the data controller’s policy for the storage and use of personal data and be appropriately trained to follow that policy.

Reason for action
The data controller did not enter into any written contract with the external company, nor where its actions appropriately supervised. It was noted during the clearance operations that boxes of data were being disposed of in open skips, but the data controller failed to react to this in time to prevent loss of some records.

When
27 July 2009

Links
View PDF of the East Cheshire NHS Trust Undertaking (Breach Watch Archive)

NHS Lothian

What
Loss of personal data.

How much
162 records.

Why
A document wallet containing 25 paper files was temporarily left in a shop. In a second incident an unencrypted USB memory stick was lost.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that all mobile data storage devices are sufficiently encrypted. Network systems are to be introduced to prevent the use of unauthorised personal memory devices to download personal data being processed by NHS Lothian. Measures must be taken to ensure the physical security of all paper files containing personal information. All staff must be made aware of the data controller’s policy for the storage of personal data and be trained to follow it. Compliance with these policies must be monitored.

Reason for action
The USB memory stick was unencrypted and was the personal property of an employee. In both cases the employees failed to comply with NHS Lothian security requirements.

When
21 July 2009

Links
View PDF of the NHS Lothian Undertaking (Breach Watch Archive)

London Borough of Sutton

What
Loss of sensitive personal data.

How much
About 119 records.

Why
Numerous Incidents:

  • A paper file containing personal data relating to 73 individuals receiving social care went missing from an office.
  • A document package relating to childcare proceedings was left with the neighbour of an intended recipient and subsequently went missing.
  • An unencrypted laptop containing personal data to 9 children was stolen from a locked cupboard on a children’s hospital ward.
  • An unencrypted laptop containg social care data relating to 39 individuals was stolen from the home of an employee of the data controller.
  • 9 administration computers used to access dara in the data controller’s network were stolen, but some files may have been downloaded onto the computer’s hard drives in breach of policy.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that all mobile data storage devices are sufficiently encrypted. Measures must be taken to ensure the physical security of all such devices containing personal information. All staff must be made aware of the data controller’s policy for the storage of personal data and be trained to follow it.

Reason for action
The various breaches demonstration a lack of security, both physical and technical. The sheer amount of breaches betrayed an overall organisational weakness.

When
29 July 2009

Links
View PDF of the London Borough of Sutton Undertaking (Breach Watch Archive)

Dr Paul Thomas

What
Loss sensitive of personal data.

How much
“A large number” of records.

Why
The Suffolk Primary Care Trust’s Practice server was found in the Gipping Valley Practice car park by one of the data controller’s employees. The Server held data relating to a large number of patients and staff.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that the decommissioning process regarding Practice servers and other such devices has been completed successfully in order to ensure the safety of any personal data.

Reason for action
The decommissioning process did not ensure the security of personal data.

When
10 July 2009

Links
View PDF of the Dr Paul Thomas Undertaking (Breach Watch Archive)

Nightingale Practice

What
Loss sensitive of personal data.

How much
7,700 records.

Why
10 back up tapes and a USB portable hard drive were stolen. The USB hard drive and five of the back up tapes were not encrypted.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that the physical security of personal data be ensured. All portable media devices containing personal data must be encrypted. All staff must be made aware of the data controller’s policy for the storage of personal data and be trained to follow it.

Reason for action
Physical security was adequate, as the devices were kept in a locked firesafe in a locked and alarmed environment, but the lack of encryption was unacceptable.

When
10 July 2009

Links
View PDF of the Nightingale Practice Undertaking (Breach Watch Archive)

Neath Port Talbot County Borough Council

What
Loss of personal data.

How much
65 records.

Why
An unencrypted USB memory stick containing the personal data of children looked after the data controller was lost.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that all mobile data storage devices are sufficiently encrypted. All staff must be made aware of the data controller’s policy for the storage of personal data and be trained to follow it.

Reason for action
The memory stick was not encrypted or password protected.

When
9 July 2009

Links
View PDF of the Neath Port Talbot County Borough Council Undertaking (Breach Watch Archive)

Oldham Council

What
Loss of sensitive personal data.

How much
220 records.

Why
13 unencrypted laptops were stolen during a burglary at secure council offices, with the exception of one stolen from a staff members car and another that was stolen during the course of a youth activity evening.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that all mobile data storage devices are sufficiently encrypted. All staff must be made aware of the data controller’s policy for the storage of personal data and be trained to follow it.

Reason for action
Three of these unencrypted laptops held sensitive personal data and the council did not take adequate steps to safeguard the data, either through encryption, or better physical security in respect of the two laptops stolen outside of council property.

When
7 July 2009

Links
View PDF of the Oldham Council Undertaking (Breach Watch Archive)