ICO logo

ICO mulls tougher action on privacy

Annual report findings could lead to an increase in fines for Data Protection Act breaches

Written by Madeline Bennett

The Information Commissioner’s Office (ICO) released its annual report earlier this month, with a call for chief executives to prioritise protection of their customers’ sensitive data.

Speaking at the launch of the report, Information Commissioner Richard Thomas said that organisations in the private and public sector need to raise their game. “Over the past year, we have seen far too many careless and inexcusable breaches of people’s personal information,” he argued. “The roll call of organisations that have admitted serious security lapses is frankly horrifying.”

The report mentioned a wide range of previous incidents to highlight the scale of the privacy problem, including Liverpool City Council being fined £300 in December 2006 for failure to comply with the Data Protection Act (DPA); and an investigation into high street banks, such as NatWest and Barclays, which revealed that customer data was being thrown away into rubbish bins outside the banks’ premises.

The privacy watchdog is likely to use the information in the report as evidence of the need for stronger enforcement powers.

Earlier this year, Thomas called for the automatic right to inspect and audit companies suspected of breaching the DPA. Currently, this requires the company’s consent.

George Gardiner of law firm Gardiner & Co said the report highlights the need for greater powers for the privacy watchdog. “The problem is the ICO is under-funded and has inadequate powers. As a result, it cannot investigate complaints, nor can it take effective action,” he argued. “The ICO says that in 2006/2007 it fielded 24,000 complaints and enquiries, yet it has only managed 16 prosecutions in the past 12 months.”

Cliff Evans, ID management lead at consultancy Capgemini, agreed that the weight of evidence supports the Information Commissioner’s calls for stronger powers. “But more auditing work has an implication on resources. The ICO needs to communicate with organisations and make them more aware of their responsibilities,” he added.

The high level of incidents outlined in the report could also lead to renewed calls for the government to introduce US-style data breach notification legislation. This requires organisations to inform individuals of any incidents that could expose their personal information.

Alex Brown, a partner in the Communications, Outsourcing and Technology Group at law firm Simmons & Simmons, pointed out that this type of legislation already exists in Europe through the E-Privacy Directive, which is part of the Telecoms Regulatory Framework.

Under the directive, communications providers, such as ISPs and telcos, are required to notify their customers about network security breaches. “One current proposal is to expand this requirement to cover general data security breaches,” Brown said. “An EU working party is also considering the possibility of expanding the directive to cover other organisations, rather than just communications providers, as the recent serious security breaches have not involved the telcos.”

Brown added that the most likely outcome of the report would be more severe penalties. “We could see the level of fines go up,” he said.

Tags:

reader comments

related articles

ICO logo

Privacy watchdog urges crack down on data breaches

ICO annual report outlines vast number of "unacceptable privacy breaches" during previous year 11 Jul 2007

 

ICO consults on strategy

The UK's Information Commissioner is to review the way that it enforces data protection 05 Jul 2007

Tougher privacy rules on the cards

Proposals include more data protection audits and privacy seals for IT products 08 May 2007

Privacy watchdog demands stronger powers

The ICO calls for greater powers to investigate privacy breaches 01 May 2007

When to come clean about breaches

Should firms be bound by law when it comes to coming clean about data break-ins? 09 Jul 2007

Privacy controls need to be integrated into IT design

The Royal Academy of Engineering has reported on how engineering can of help protect personal data 28 Mar 2007

Experts welcome new Information Commissioner powers

Sharpening of data protection watchdog's teeth should reduce security breaches 26 Nov 2008

Experts welcome new Information Commissioner powers

Sharpening of data protection watchdog's teeth should reduce security breaches 25 Nov 2008

Privacy tzar speaks out against data breach notification laws

But Information Commissioner admits breach levels remain worrying 29 Oct 2008

related whitepapers

today's top stories

CIOs must embrace collaboration tools

Author Don Tapscott gives Angelica Mari his reasons for promoting social networking tools and says transparency is the key to security 04 Dec 2008

On a quest to build a connected society

BT Design’s JP Rangaswami talks to Gareth Morgan about his pivotal role in the telecoms giant’s efforts to deliver universal broadband and his plans to tap into the creativity of the open source community 04 Dec 2008

IT leaders must stand by India

A sense of perspective is the most important response from IT leaders to the attacks in Mumbai 04 Dec 2008

Case study: Clifford Chance

Law firm implements Sun platform and reduces datacentres to gain efficiency and cost synergies 03 Dec 2008

Should CRM be more sociable?

As vendors rush to add more social networking bells and whistles to their CRM products, some experts warn that users must tread carefully when venturing into online communities 03 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Doctors looking at a computerAnalysis

Watchdog wants IT to cure privacy woes

Information Commissioner Richard Thomas is urging organisations to put privacy protection at the top of their procurement and development criteria 04 Dec 2008

Colin McDonaldComment

Web 2.0 has potential to transform staff training

Employees can sharpen their IT skills through using the latest interactive training tools, writes Colin McDonald 04 Dec 2008

Advertisement

Primary Navigation