Feeds

Two councils hit with big fines for laptop blunder

Unencrypted data gaffe hits Hounslow, Ealing

Beginner's guide to SSL certificates

The UK's information watchdog has slapped two London councils with hefty penalties for failing to encrypt personal data on laptops that were stolen by thieves.

Ealing Council and Hounslow Council were both found to be in serious breach of the Data Protection Act, ruled the Information Commissioner's Office today.

It said two laptops that contained details of approximately 1,700 people were stolen from an employee's home. Around 1,000 of the individuals were clients of Ealing Council and almost 700 were on Hounslow Council's books.

Although the laptops were password-protected, the data itself was unencrypted, noted the ICO.

The failure of both councils, whose out-of-hours service is provided by Ealing Council, to encrypt the laptops was in breach of council policy.

"There is no evidence to suggest that the data held on the computers has been accessed and no complaints from clients have been received by the data controllers to date," said the ICO.

However, it handed down a £80,000 penalty to Ealing Council and a £70,000 penalty to Hounslow Council because the theft of the unencrypted laptops represented what it described as "a significant risk to the clients' privacy."

The ICO said Ealing Council breached the Data Protection Act by issuing an unencrypted laptop to an employee having ignored its own policies on the handling of sensitive client information.

Hounslow breached the Act by failing to have a written contract in place with Ealing Council to ensure the procedure for operating the service was adequately securing client data.

The ICO said that both councils had since tightened their security policies and contacted the individuals affected by the unencrypted data blunder.

"Both council have paid the price for lax data protection practices," said ICO deputy commissioner David Smith.

"I hope all organisations that handle personal information will make sure their houses are in order - otherwise they too may have to learn the hard way." ®

Protecting against web application threats using SSL

More from The Register

next story
Hey, Scots. Microsoft's Bing thinks you'll vote NO to independence
World's top Google-finding website calls it for the UK
Phones 4u slips into administration after EE cuts ties with Brit mobe retailer
More than 5,500 jobs could be axed if rescue mission fails
Apple CEO Tim Cook: TV is TERRIBLE and stuck in the 1970s
The iKing thinks telly is far too fiddly and ugly – basically, iTunes
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
Huawei ditches new Windows Phone mobe plans, blames poor sales
Giganto mobe firm slams door shut on Microsoft. OH DEAR
Phones 4u website DIES as wounded mobe retailer struggles to stay above water
Founder blames 'ruthless network partners' for implosion
Found inside ISIS terror chap's laptop: CELINE DION tunes
REPORT: Stash of terrorist material found in Syria Dell box
OECD lashes out at tax avoiding globocorps' location-flipping antics
You hear that, Amazon, Google, Microsoft et al?
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.