DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

UK: West Dunbartonshire Council warned of court action by ICO over data protection failures

Posted on April 28, 2016 by Dissent

A Scottish council has been rapped by the regulator for repeatedly failing to train staff around data protection.

West Dunbartonshire Council were told to implement training on several occasions, as well as being advised to put in place a policy around home working. But their failure to do so ultimately contributed to a data breach that led to a child’s medical reports being stolen.

The Information Commissioner’s Office carried out an audit of the council in January 2013. The audit gave a reasonable assurance of the council’s compliance with the law, but made recommendations for areas that needed improvement, including training for all staff and adopting a home working procedure. A follow-up audit in November 2013 showed progress, but showed some of the recommendations still had not been implemented.

In July 2014, the council reported a data breach to the ICO, after an employee had a bag containing confidential information stolen. The employee had taken details of an adoption case out of the office to work on from home, but a laptop and paperwork left in their car overnight were stolen.

An ICO investigation found the employee had not been given training on the Data Protection Act, and the council still had no guidance to staff on handling personal information when working from home. The council avoided a fine as the breach did not cause substantial damage or distress.

The council has now been issued with an enforcement notice obliging it to implement training and guidance, or face court action.

Ken Macdonald, Assistant Information Commissioner for Scotland, said:

“Time and time again we have told this council to make these changes, and yet they have still not completed everything we set out. We’ve been left with no choice but to issue this formal notice requiring them to act.

“Let’s be clear, what we’re asking for here is a basic requirement for an organisation that is trusted with large amounts of local people’s personal data. When people in Dunbartonshire provide the council with their details, they expect staff are trained to handle this information properly. Unfortunately, more than three years after this was made clear to the council, this still hasn’t happened.”

The ICO is the regulatory body in Scotland for data protection issues and Ken Macdonald leads its offices in Scotland and Northern Ireland. Scotland also has its own Information Commissioner to regulate the Freedom of Information (Scotland) Act that covers Scottish public authorities.

SOURCE: ICO


Related:

  • Little Rock Psychologist Indicted by Federal Grand Jury for Defrauding Medicare and Arkansas Blue Cross Blue Shield
  • Software companies must be held liable for British economic security, say MPs
  • Russia arrests young cybersecurity entrepreneur on treason charges
  • UK privacy regulator has seen ‘collapse in enforcement activity,’ rights coalition says
  • Ph: Department of the Interior and Local Government to probe alleged data breach by hackers
  • Cyberattack disables Onsolve Code Red emergency alert system across St. Louis region (1)
Category: Government SectorHealth DataNon-U.S.Theft

Post navigation

← U.S. Steel Accuses China of Hacking
Whistle-blowing hacker to become founding member of new political party in Latvia →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • ANNOUNCE: A new resource to help small and mid-sized HIPAA-regulated entities
  • Askul says 740,000 sets of data breached in cyberattack
  • Google and Apple roll out emergency security updates after zero-day attacks
  • Doxers Posing as Cops Are Tricking Big Tech Firms Into Sharing People’s Private Data
  • Virginia Urology Silent on Possible Data Breach as Purported Patient Data Begins to Leak
  • Village of Golf Manor considering paying ransom amid cyberattack (1)
  • Teen who allegedly stole millions of personal data records arrested in Spain
  • Akira ransomware: FBI tallies 250 million in payouts
  • IE: HSE confirms second ransomware attack but ‘no evidence’ patient data was stolen
  • Examining impact of federal relief program after major healthcare cyberattack — Research Brief

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Slovenian officials weaponize data-privacy laws against investigative journalism
  • End-of-Year 2025 State and Federal Developments in Minors’ Privacy
  • Tool allows stealthy tracking of Signal and WhatsApp users through delivery receipts
  • Oh Great, Smart Glasses That Record Everything You Say
  • CBP Agents Held This U.S. Citizen for Hours Until He Agreed To Let Them Search His Electronic Devices

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.