TOTAL: {[ getCartTotalCost() | currencyFilter ]} Update cart for total shopping_basket Checkout

The Privacy Advisor | UK—Local Authority Ordered To Update Privacy Procedures and Training Following Data Breaches Related reading: A view from Brussels: Behavioral advertising is an unstoppable current

rss_feed

""

The UK Information Commissioner’s Office (ICO) has ordered the Council of the Isle of Scilly to implement new data protection policies and training after two data breaches involving the disclosure of personal data.

The first breach occurred in June 2013 when an attachment inadvertently included in an email revealed personal data relating to a disciplinary hearing.

A further incident then occurred in September 2013 when two documents containing sensitive personal data ended up in public circulation. Poor policies and procedures on data-sharing, including staff using personal email accounts and paper documents not being properly redacted, meant details of an investigation into the conduct of a former head teacher were publicly disclosed.

The council has therefore agreed via an undertaking to implement mandatory data protection training, with refresher training to be updated regularly. The council must also draft appropriate guidance on the safe transfer of personal data via email and consider the use of encryption. It must also draft an appropriate data redaction policy.

A copy of the ICO undertaking is available here.

Comments

If you want to comment on this post, you need to login.