Fines for data protection breaches: how serious does the breach need to be?
In overturning a fine imposed by the Information Commissioner against the Scottish Borders Council, the UK’s First-tier Tribunal (Information Rights) ruled that the breach in question was insufficiently serious to warrant a financial penalty. This begs the question: how serious does a breach need to be before a fine will be imposed?
The council had hired a third-party supplier to scan hard copies of pension files containing personal data onto CDs. The supplier disposed of approximately 1,600 of the files into recycling bins at a supermarket, where they were discovered by a member of the public. The files were taken into police custody. No actual harm was found to have been suffered.
The power of the Information Commissioner to award a monetary fine of up to £500,000 for data protection breaches is discretionary. However, before a monetary penalty can be assessed, the breach must either be deliberate or something that a controller either knew or ought to have known would result in substantial damage or distress and then failed to prevent…
If you are registered and logged in to the site, click on the link below to read the rest of the Walker Morris briefing. If not, please register or sign in with your details below.
News from Walker Morris
News from The Lawyer
Briefings from Walker Morris
The Company Names Tribunal was set up to adjudicate disputes arising under section 69(1) of the Companies Act 2006.
When a court assesses the amount of costs payable by one party in litigation proceedings to another, the costs may be assessed on either a standard basis or an indemnity basis.
Analysis from The Lawyer
Which firms are cutting it in this era of slimline rosters, and who are the GC new brooms making clean sweeps? The Lawyer can reveal all
The law school war shows no signs of ending. But we have, perhaps, reached the end of the beginning.