Hampshire Partnership NHS Trust

What
Loss of personal data.

How much
607 records.

Why
An unencrypted laptop containing personal data relating to staff and patients was stolen from an employee’s hotel room.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that all mobile data storage devices are sufficiently encrypted. All staff must be made aware of the data controller’s policy for the storage of personal data and be trained to follow it. Compliance with these policies must be monitored.

Reason for action
The laptop was unencrypted and stolen from the employee while he was attending a conference.

When
26 June 2009

Links
View PDF of the Hampshire Partnership NHS Trust Undertaking (Breach Watch Archive)

Jubilee Managing Agency Ltd

What
Loss of personal data.

How much
Around 2,100 records.

Why
An unencrypted disc containing personal data was lost.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that all mobile data storage devices are sufficiently encrypted. Personal data must not be kept any longer than absolutely necessary. Written data protection procedures must adopted. All staff must be made aware of the data controller’s policy for the storage of personal data and be trained to follow it.

Reason for action
The disc was unencrypted and contained data relating to policies which had expired, or been cancelled, in some cases over 10 years ago. An investigation revealed that staff had insufficient internal training.

When
23 June 2009

Links
View PDF of the Jubilee Managing Agency Ltd Undertaking (Breach Watch Archive)

Manchester City Council

What
Loss of personal data.

How much
1,754 records.

Why
Two unencrypted laptops were stolen from the internal audit offices in the Town Hall.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that appropriate security measures are in place to ensure that laptops are safely stored and encrypted. Only personal data absolutely necessary for audit purposes may be downloaded to mobile devices  All staff must be made aware of the data controller’s policy for the storage of personal data and be trained to follow it.

Reason for action
The laptops were not encrypted, password protected, or secured to immovable objects, in breach of a number of the data controllers’s internal policies and procedures, in which all staff had received training.

When
16 June 2009

Links
View PDF of the Manchester City Council Undertaking (Breach Watch Archive)

Amicus Legal Ltd

What
Loss of personal data.

How much
100,000 records.

Why
An unencrypted laptop containing personal data was stolen from the locked hotel room of a contracted consultent.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that appropriate security measures are in place to restrict access to areas where personal data is stored. Any data held on portable media must be encrypted. All staff must be made aware of this policy, including contracted consultants.

Reason for action
The data controller did not ensure sufficient security measures were in place to prevent the transfer of the data in question on to a privately owned and unencrypted personal laptop.

When
28 May 2009

Links
View PDF of the Amicus Legal Ltd Undertaking (Breach Watch Archive)

Hampshire Partnership NHS Trust

What
Loss of personal data.

How much
1,161 records.

Why
1,161 Trust payslips containing employee personal data were lost.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that the transporting of all personal data should be risk assessed, and where appropriate, tracked. A review of all internal post procedures should be conducted for security purposes. All staff must receive adequate data protection training.

Reason for action
It could not be explained where or how the payslips had gone missing.

When
19 December 2008

Links
View PDF of the Hampshire Partnership NHS Trust Undertaking (Breach Watch Archive)

Virgin Media Limited

What
Loss of personal data.

How much
3,383 records.

Why
An unencrypted compact disc containing the personal data of 3,383 customers passed on to the data controller by Carphone Warhouse was lost.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that media devices used to transport and store personal data are encrypted and that any contracts between the data controller and any data processors require this.

Reason for action
The lost CD was unencrypted and the arrangement between the data controller and data processor was insufficient.

When
17 September 2008

Links
View PDF of the Virgin Media Limited Undertaking (Breach Watch Archive)

Skipton Financial Services Limited

What
Inappropriate processing of personal data

How much
Unknown.

Why
An unencrypted laptop computer was stolen from Moore Stephens Consulting, who had been engaged to provide professional consultancy services to SFS in relationship to a software development project.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that sensitive personal data must be encrypted. Risk assessments must be carried out to confirm the adequacy and effectiveness of technical and organisational security measures, including those taken by third parties.

Reason for action
The ICO had received a complaint about the data controller’s breach of the Seventh Data Protection Principle.

When
18 February 2008

Links
View PDF of the Skipton Financial Services Limited Undertaking (Breach Watch Archive)

Southampton City Primary Care Trust

What
Loss of personal data.

How much
168 records.

Why
168 Trust payslips containing employee personal data were lost.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that the transporting of all personal data should be risk assessed, and where appropriate, tracked. A review of all internal post procedures should be conducted for security purposes. All staff must receive adequate data protection training.

Reason for action
It could not be explained where or how the payslips had gone missing.

When
13 January 2008

Links
View PDF of the Southampton City Primary Care Trust Undertaking (Breach Watch Archive)

The Foreign and Commonwealth Office

What
Loss of personal data

How much
Unknown.

Why
The ICO was informed by Ukvisas that there had been a breach of security in the VFS online visa application facility. The security breach resulted in the personal data of persons applying for visas to enter being viewable by others.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that the VFS on-line application websites will not be re-opened and will be replaced by visa4UK. A strategic review of data processing will be undertaken by UKvisas in order to strengthen Data Protection Act risk management processes and a detailed audit carried out of the data processor’s data security procedures. The website will be regularly monitored and adequate and relevant data protection will be given to all UKvisas staff on an ongoing basis.

Reason for action
The ICO had received a complaint about the data controller’s breach of the Seventh Data Protection Principle.

When
19 October 2007

Links
View PDF of the Foreign and Commonwealth Office Undertaking (Breach Watch Archive)

The Northern Ireland Office

What
Inappropriate processing of personal data

How much
Unknown.

Why
The data controller failed to respond to a subject access request made by the data subject relating to the processing of personal data.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that all subject access requests received by the data controller are dealt with in compliance with the provisions contained within Section 7 of the Data Protection Act. Adequate and relevant training is provided to all employees who are engaged in the process of dealing with subject access requests.

Reason for action
The ICO had received a complaint about the data controller’s failure to respond to a subject access request.

When
9 July 2007

Links
View PDF of the Northern Ireland Office Undertaking (Breach Watch Archive)