09 Jun 2009
The Information Commissioner’s Office (ICO) has found insurer Amicus Legal in breach of the Data Protection Act after the firm reported an unencrypted laptop was stolen containing personal information relating to 100,000 customers.
Andy Tomkins, Amicus Legal chief executive, has signed a formal undertaking outlining that the firm will take reasonable measures to keep personal information secure in future, including encrypting all portable devices.
Sally-Anne Poole, ICO head of enforcement and investigations, said the case was serious because it involved the data of 100,000 customers, including sensitive information relating to legal advice.
"This breach illustrates that even though a contractor lost the data, it is the data controller – Amicus Legal – which is responsible for the security of the information. It is vital that personal information is handled properly and in compliance with the Data Protection Act," she said.
Since November 2007, 161 data security breaches have been reported to the ICO from the private sector.
Poole urged all chief executives to take personal responsibility for treating data protection as a corporate governance issue affecting the whole organisation.
"They have to make sure that safeguarding the personal information of customers and staff is embedded in their organisational culture," she said.
The ICO said failure to meet the terms of the undertaking is likely to lead to further enforcement action.
Have your say on this article
Newsletters
Latest stories from Security Technology
You may also like
Security Technology jobs
Technology Patent Wars
Case studies from large organisations across all sectors
... And rich media, and flexible working, and peaks in traffic ...
Upcoming Events
Join us for this Computing web seminar, in which the Head of BI at the Co-operative Group Nick Colebourn will be explaining just how he reigned in the Group’s sprawling database estate and how significant savings were realised and data quality improved as a result.
Date: 31 May 2012
Time: 11:00 AM
Live June 13th 11:00am: Register now. During this web seminar we will be looking at the sorts of incidents that can bring data centres grinding to a halt and what can be done about them.
Date: 13 Jun 2012
Time: 11:00 am
Receive the latest jobs direct to your inbox
Are you being paid what you are worth?