Robert Bond

Firms need to learn from data protection crackdown

Data processing must be checked to ensure data is handled fairly and lawfully, explains Robert Bond

Written by Robert Bond

All businesses need to be aware of the implications of the recent Information Commissioner’s Office (ICO) investigation against Ian Kerr trading as The Consulting Association.

The ICO found that he was processing personal information on more than 3,200 workers, which he was selling on to construction companies, including 14 firms against which Enforcement Notices have been served.

While Kerr’s activities were illegal and the information commissioner was able to prosecute him for failing to comply with the Data Protection Act 1998 (DPA), there was apparently no such option to proceed directly against the construction companies.

An Enforcement Notice requires organisations to either take or refrain from taking specified steps to ensure they comply with the law. The ICO can prosecute those who commit criminal offences under the DPA, and failure to comply with an Enforcement Notice is a criminal offence.

Deputy information commissioner David Smith highlighted the issue when he said: “Fourteen firms paid for personal details about construction workers without those people knowing. The individuals were denied the opportunity of explaining or correcting what may have been inaccurate personal information about them and which could have jeopardised their employment prospects in the industry.”

As a result of the lessons from this case, it is clear that all business sectors that use personal data as part of hiring and firing decision-making processes need to re-think their strategy and have in place suitable policies and procedures.

The ICO is focusing on compliance by businesses and expecting them to not only “say what they do” through the use of clear privacy notices but also “do what they say” by complying with those notices and the obligations under the eight data protection principles, which include “fair and lawful processing” of personal data.

Businesses should audit their data processing activities to understand and minimise risk.

Robert Bond is a partner and head of intellectual property, technology and commercial at law firm Speechly Bircham

  • Have your say
  • Send to a friend
  • Print this
  • Share

reader comments

related articles

Man at computerSecurity

Keep data on the right side of the law

Rosemary Jay spells out the legal requirements that all organisations must take into account when formulating their storage strategies 22 Sep 2009

 

One in five firms have breached Data Protection Act

New British standard for data protection aims to help establish best practice 02 Jun 2009

ICO uncovers secret construction worker database

Builder blacklist in clear violation of Data Protection Act 06 Mar 2009

Data watchdog to move on construction firms as illegal database owner is fined

Man received almost £500,000 for details on construction workers 20 Jul 2009

Private investigator fined £5,000 for breaching Data Protection Act

The Knutsford Crown Court’s decision follows the ICO’s (Information Commissioner’s Office) investigation that revealed Kerr’s covert operation 20 Jul 2009

related whitepapers

today's top stories

Police hunt for moles with security software

Lancashire Constabulary to monitor data input of 7,000 staff in bid to prevent intelligence leaks 09 Feb 2010

PaperlinX outsources IT and comms to Bull and BT

Paper company spends €22m on five-year deal for desktop management, helpdesk and datacentre services 05 Feb 2010

Social tools take KM to a new level

Technology expert David Tebbutt explains how – and why – organisations should integrate social networking tools into their knowledge management strategy 02 Feb 2010

EDS court defeat puts vendors on their guard

BSkyB’s victory in a long-running court case against EDS has serious implications for the IT industry 02 Feb 2010

Law firm monitors web traffic violations

Bucks declining global security appliance sales with unified threat management (UTM) platform deployment 01 Feb 2010

Advertisement

Security: The New Face of Intrusion Prevention
An outline of traditional IPS functionality, modern developments and how IPS can be deployed easily.

UK businesses’ attitudes to Cloud Computing revealed

Features results from a survey of over 200 Computing readers.

Advertisement

Keep up to date with the latest products, services and technologies from the world's leading IT companies; ITHound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

Internet Explorer 6

Internet Explorer 6

Following recent concerns about the security of Internet Explorer 6 are you planning to phase it out?

View poll results

Latest audio and video articles

Tony McAlisterVideo

Video Q&A: Tony McAlister, CTO, Betfair - Part one

On changing the skills development strategy at the online gambling firm - part one of a two-part video interview 05 Nov 2009

Video

Nokia shows upcoming handset technologies

Mobile phone features of tomorrow take the stage 21 Oct 2009

Latest in-depth articles

Analysis

Police hunt for moles with security software

Lancashire Constabulary to monitor data input of 7,000 staff in bid to prevent intelligence leaks 09 Feb 2010

Businessman with eye patch, dagger and tie round head, sitting at laptopFeatures

Are you sure you're not a pirate?

It is alarmingly easy for an IT leader to unwittingly exceed the scope of a software licence, and the chances of being caught out have never been greater, as technology lawyers Mark Weston and Paul Gershlick explain 09 Feb 2010

Primary Navigation