The Register® — Biting the hand that feeds IT

Regulator gets power to fine for data breaches

Who will be first to pony up?

Understand how application security is evolving

The Information Commissioner's Office now has the power to fine organisations which deliberately or recklessly commit serious breaches of the Data Protection Act.

The Criminal Justice and Immigration Act got Royal Assent today. Sadly the law is not retroactive, so the long list of government departments which have lost or endangered our data in recent months will not be fined.

David Smith, deputy information commissioner, said: "This change in the law sends a very clear signal that data protection must be a priority and that it is completely unacceptable to be cavalier with people’s personal information. The prospect of substantial fines for deliberate or reckless breaches of the Data Protection Principles will act as a strong deterrent and help ensure that organisations take their data protection obligations more seriously."

The ICO has repeatedly asked for stronger powers to investigate and fine companies which are failing to take data protection seriously.

Smith said such tougher sanctions would help reassure the public that their data was safe. The ICO at one point suggested prison sentences for those responsible for the most serious breaches. ®

See what The Register's experts have to say on application security

Don’t Miss

Win a Samsung C6625!

Reg Lucky Draw Windows Mobile handsets up for grabs

Palm_Pre_001_SMIs your cameraphone an oxymoron?

Pic Review iPhone 3G v iPhone 3GS v Palm Pre

Vulture logo with head phonesWindows 7, Bing and security: Mr Ballmer regrets

Steve hopes Microsoft money can buy your love

Sign up, sign up for The Register IT security newsletter

Narrowcasting for the email classes