DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

UK: Failure to adequately redact results in undertaking for Treasury Solicitor’s Department

Posted on February 26, 2014 by Dissent

In the UK, the Treasury Solicitor’s Department has signed an undertaking with the Information Commissioenr’s Office.

As described in the undertaking, there had been a number self-reported breaches involving exposure of individuals’ information due to incomplete redactions or failure to fully check:

The Information Commissioner (the ‘Commissioner’) was contacted by the data controller on 6 February 2012, 24 August 2012, 30 August 2012 and 3 January 2013 and was made aware of several separate breaches of the Act.

Three of the self-reported breaches involved case files being sent to a claimant’s solicitor and then on to the claimant during the course of litigation with un-redacted third party personal data contained within them. These incidents resulted in the personal data being disclosed in error to third parties.

The fourth and remaining self-reported breach involved a bundle of case papers relating to an unfair dismissal claim. These were sent to an individual during the process of the claim and contained personal data relating to another individual’s separate claim. This incident resulted in third party personal data being disclosed in error.

Although the department had some measures in place, as evidenced by the fact that in the first three breaches, some data had been redacted, the ICO determined that there were gaps in the department’s procedures that needed further improvement. Under the conditions of the undertaking, the department must develop:

(1) a clear, documented procedure for staff to follow when preparing information for disclosure is implemented within 6 months. This should incorporate a defined checking process with emphasis on the steps to be taken prior to release. The procedure should account for both sensitive personal data and personal data relating to third parties;

(2) the communication requirements between Junior and Senior lawyers carrying out the disclosure process is defined by a structured, formal procedure with clear lines of communication and implemented within 6 months. The responsibilities of staff members should be clearly explained within this procedure; and

(3) a mandatory and comprehensive training programme regarding compliance with the Act for all new and existing staff is put in place within 6 months. This should include how training will be presented, tested, refreshed and the frequency of delivery for each.

Category: ExposureGovernment SectorNon-U.S.Paper

Post navigation

← Comparison of Five Data-Breach Bills Currently Pending in the Senate
Minnesota data breach law demonstrates risks of knee-jerk reactions →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Industry Letter – June 23, 2025: Impact to Financial Sector of Ongoing Global Conflicts
  • MNGI Digestive Health settles class action lawsuit stemming from BlackCat attack
  • Four REvil ransomware members released after time served on carding charges
  • Why Dumping Sensitive Data on Network Shares is a Liability
  • A militarily degraded Iran may turn to asymmetrical warfare – raising risk of proxy and cyber attacks
  • Pro-Russian hackers disrupt Dutch government websites ahead of NATO summit
  • Iran-Linked Threat Actors Leak Visitors and Athletes’ Data from Saudi Games
  • UK: Oxford City Council still investigating cyberattack from earlier this month
  • Steelmaker Nucor Says Hackers Stole Data in Recent Attack
  • People’s Republic of China cyber threat activity: Cyber Threat Bulletin

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Sky Views Personal Data as a Potential Weapon in IPTV Piracy War
  • Florida Used a Nationwide Surveillance Camera Network 250 Times To Aid in Immigration Arrests
  • Federal Court Strikes Down HIPAA Reproductive Health Care Privacy Rule
  • The Markup caught 4 more states sharing personal health data with Big Tech
  • Privacy in the Big Sky State: Montana’s Consumer Privacy Law Gets Amended
  • UK Passes Data Use and Access Regulation Bill
  • Officials defend Liberal bill that would force hospitals, banks, hotels to hand over data

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.