ICO logo

ICO mulls tougher action on privacy

Annual report findings could lead to an increase in fines for Data Protection Act breaches

Written by Madeline Bennett

The Information Commissioner’s Office (ICO) released its annual report earlier this month, with a call for chief executives to prioritise protection of their customers’ sensitive data.

Speaking at the launch of the report, Information Commissioner Richard Thomas said that organisations in the private and public sector need to raise their game. “Over the past year, we have seen far too many careless and inexcusable breaches of people’s personal information,” he argued. “The roll call of organisations that have admitted serious security lapses is frankly horrifying.”

The report mentioned a wide range of previous incidents to highlight the scale of the privacy problem, including Liverpool City Council being fined £300 in December 2006 for failure to comply with the Data Protection Act (DPA); and an investigation into high street banks, such as NatWest and Barclays, which revealed that customer data was being thrown away into rubbish bins outside the banks’ premises.

The privacy watchdog is likely to use the information in the report as evidence of the need for stronger enforcement powers.

Earlier this year, Thomas called for the automatic right to inspect and audit companies suspected of breaching the DPA. Currently, this requires the company’s consent.

George Gardiner of law firm Gardiner & Co said the report highlights the need for greater powers for the privacy watchdog. “The problem is the ICO is under-funded and has inadequate powers. As a result, it cannot investigate complaints, nor can it take effective action,” he argued. “The ICO says that in 2006/2007 it fielded 24,000 complaints and enquiries, yet it has only managed 16 prosecutions in the past 12 months.”

Cliff Evans, ID management lead at consultancy Capgemini, agreed that the weight of evidence supports the Information Commissioner’s calls for stronger powers. “But more auditing work has an implication on resources. The ICO needs to communicate with organisations and make them more aware of their responsibilities,” he added.

The high level of incidents outlined in the report could also lead to renewed calls for the government to introduce US-style data breach notification legislation. This requires organisations to inform individuals of any incidents that could expose their personal information.

Alex Brown, a partner in the Communications, Outsourcing and Technology Group at law firm Simmons & Simmons, pointed out that this type of legislation already exists in Europe through the E-Privacy Directive, which is part of the Telecoms Regulatory Framework.

Under the directive, communications providers, such as ISPs and telcos, are required to notify their customers about network security breaches. “One current proposal is to expand this requirement to cover general data security breaches,” Brown said. “An EU working party is also considering the possibility of expanding the directive to cover other organisations, rather than just communications providers, as the recent serious security breaches have not involved the telcos.”

Brown added that the most likely outcome of the report would be more severe penalties. “We could see the level of fines go up,” he said.

Tags:

reader comments

related articles

ICO logo

Privacy watchdog urges crack down on data breaches

ICO annual report outlines vast number of "unacceptable privacy breaches" during previous year 11 Jul 2007

 

ICO consults on strategy

The UK's Information Commissioner is to review the way that it enforces data protection 05 Jul 2007

Tougher privacy rules on the cards

Proposals include more data protection audits and privacy seals for IT products 08 May 2007

Privacy watchdog demands stronger powers

The ICO calls for greater powers to investigate privacy breaches 01 May 2007

When to come clean about breaches

Should firms be bound by law when it comes to coming clean about data break-ins? 09 Jul 2007

Privacy controls need to be integrated into IT design

The Royal Academy of Engineering has reported on how engineering can of help protect personal data 28 Mar 2007

Updated: ICO confident of greater powers

Data watchdog the Information Commissioners' Office is confident of new powers 27 Nov 2007

MPs make calls for stronger data controls

High profile incidents such as that at HMRC have lead to calls for stronger data legislation 03 Jan 2008

ICO welcomes data breach notification laws

The UK's data watchdog has joined calls for a US-style data loss reporting law 23 Oct 2007

related whitepapers

today's top stories

Learning from the credit crunch to avoid a broadband crunch

While it might be the most pressing issue de jour , the financial system isn’t the only area where government needs to... 10 Oct 2008

How careerism can warp IT procurement

Many working in IT put their career interests before those of their employer when weighing up purchasing options 10 Oct 2008

City in pressing need of skilled IT matchmakers

With the financial services sector plunging ever deeper into an M&A maelstrom, IT leaders are having their systems integration skills and due diligence expertise tested as never before 09 Oct 2008

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Computing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security

We discuss the effect of shotgun mergers and acquisitions on financial services IT staff, and examine the industry regulator's plan to fine directors for information security breaches 09 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job


IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you apply for a job that was advertised on Facebook or a similar social networking site?

Would you apply for a job that was advertised on Facebook or a similar social networking site?

The government is using Facebook to recruit IT staff - would you apply to such an ad?

Previous poll results

Latest audio and video articles

programming codeVideo

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Podcast imageAudio

Computing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security

We discuss the effect of shotgun mergers and acquisitions on financial services IT staff, and examine the industry regulator's plan to fine directors for information security breaches 09 Oct 2008

Latest in-depth articles

Financial Services Authority buildingAnalysis

FSA threatens executives with fines

Senior management to be held accountable for security lapses at banks 09 Oct 2008

Comment

Broadband must be a spending priority

For the economic health of the nation, the government would do better to bankroll an optical fibre rollout rather than prop up profligate banks 09 Oct 2008

Advertisement

Primary Navigation