The theft of unencrypted laptops and portable and mobile devices containing personal information continues to make headlines in the UK. Two organisations in the education sector—the Association of School and College Leaders and Holly Park School—have recently signed undertakings with the UK Information Commissioner’s Office (ICO) following breaches of the Data Protection Act 1998 that involved failures to encrypt sensitive and other personal information held on laptops that were later stolen.


The ICO considers its guidance to be clear—encryption software must be used to protect data that, if lost, is liable to cause individuals damage and distress. The ICO’s view is that such losses are “inexcusable,” as encryption is “one of the most basic security measures and is not expensive to put in place.” Going forward, both organisations have undertaken to encrypt laptops and other portable devices storing personal data and to ensure their employees’ compliance with data protection and IT security policies and procedures.


 

ADVERTISEMENT

PLI,  Earn privacy CPE and CLE credits: Watch anytime online or on our mobile app, topics include AI, privacy, cybersecurity, and data law