AMI

  • Why AMI
    • Meet the Team
    • Accreditations & Licenses
    • Legislation
    • Charity & CSR
  • Services
    • Safely Collecting
    • Securely Erasing
    • Simply Re-Using IT
    • Data Centre Services
    • Onsite Shredding (DiskShred)
  • Clients
  • News
  • Contact
  • Get a Quote
  • GDPR Event

May 18, 2015

£150,000 penalty for lost devices with personal data

The Information Commissioner’s Office has urged organisations to review their policies on how personal data is handled, after the Nursing and Midwifery Council was issued a £150,000 civil monetary penalty for breaching the Data Protection Act.

The council lost three DVDs related to a nurse’s misconduct hearing, which contained confidential personal information and evidence from two vulnerable children. An ICO investigation found the information was not encrypted.

David Smith, Deputy Commissioner and Director of Data Protection, said:

“It would be nice to think that data breaches of this type are rare, but we’re seeing incidents of personal data being mishandled again and again.
While many organisations are aware of the need to keep sensitive paper records secure, they forget that personal data comes in many forms, including audio and video images, all of which must be adequately protected.

“I would urge organisations to take the time today to check their policy on how personal information is handled. Is the policy robust? Does it cover audio and video files containing personal information? And is it being followed in every case?

“If the answer to any of those questions is no, then the organisation risks a data breach that damages public trust and a possible weighty monetary penalty.”

The council had been couriering evidence relating to a ‘fitness to practise’ case to the hearing venue. When the packages were received the discs were not present, though the packages showed no signs of tampering. Following the security breach the council carried out extensive searches to find the DVDs, but they’ve never been recovered.

David Smith continued:

“The Nursing and Midwifery Council’s underlying failure to ensure these discs were encrypted placed sensitive personal information at unnecessary risk. No policy appeared to exist on how the discs should be handled, and so no thought was given as to whether they should be encrypted before being couriered. Had that simple step been taken, the information would have remained secure and we would not have had to issue this penalty.”

To learn more about how to keep your confidential and sensitive information secure, visit www.ico.gov.uk or to read more stories like this search our news section.

AMI Ireland.

Filed Under: News

Search

About Us

We are the secure IT retirement service provider that generates highest possible revenue back for customers from the ultra-safe recycling of old IT assets.

AMI provides the leading secure IT retirement solution to the largest IT user organisations on the island of Ireland. We provide our customers with a service driven, user friendly, revenue generating solution to the complex challenge of ICT asset disposal. We minimize the risk of harmful data leaks by using the most technologically advanced equipment and processes. We are ranked among the top seven companies in the world for secure data sanitization by ADISA, the world’s leading IT disposal standards body.

  • Linkedin
  • Twitter

Email Newsletter

Are you ready for the new EU Data Protection rules? Simply subscribe to receive our free FREE GDPR guide.


Contact Us

info@amiltd.ie

Contact our sales team directly:
+44 (0) 28 9084 7913

Asset Management Ireland Ltd
Unit 1 Mallusk View
Central Park
Newtownabbey BT36 4FR
Northern Ireland
Tel +44 (0) 28 9084 4400
Fax +44 (0) 28 9084 2312

Asset Management Ireland Ltd
Unit 66 Block 503
Greenogue Business Park
Rathcoole
Dublin D24 F300
Ireland
Tel +353 (0) 1257 3232

  • Home
  • About Us
  • News
  • Contact Us

Copyright © 2017