Fines for data protection breaches: how serious does the breach need to be?
In overturning a fine imposed by the Information Commissioner against the Scottish Borders Council, the UK’s First-tier Tribunal (Information Rights) ruled that the breach in question was insufficiently serious to warrant a financial penalty. This begs the question: how serious does a breach need to be before a fine will be imposed?
The council had hired a third-party supplier to scan hard copies of pension files containing personal data onto CDs. The supplier disposed of approximately 1,600 of the files into recycling bins at a supermarket, where they were discovered by a member of the public. The files were taken into police custody. No actual harm was found to have been suffered.
The power of the Information Commissioner to award a monetary fine of up to £500,000 for data protection breaches is discretionary. However, before a monetary penalty can be assessed, the breach must either be deliberate or something that a controller either knew or ought to have known would result in substantial damage or distress and then failed to prevent…
If you are registered and logged in to the site, click on the link below to read the rest of the Walker Morris briefing. If not, please register or sign in with your details below.
News from Walker Morris
News from The Lawyer
Briefings from Walker Morris
The FCA has published the above consultation paper, which sets out its intended approach to the implementation of a price cap for high-cost, short-term credit.
The DCLG has published revised criteria for deciding which local planning authorities are to be regarded as ‘poor performers’ in relation to their handling of planning applications.
Analysis from The Lawyer
The law school war shows no signs of ending. But we have, perhaps, reached the end of the beginning.
New EU rules and lawyers’ increased comfort with digital formats are sparking a sea-change in the way law firms manage their documents