ICO fine overturned: An eye off the ball but still on the money

more+
less-

For the first time ever, a fine issued by the UK Information Commissioner’s Office (“ICO”) has been overturned on appeal. On 21 August 2013, the UK Information Rights Tribunal (“Tribunal”) handed down its preliminary decision overturning a £250,000 fine, which had been imposed by the ICO against the Scottish Borders Council (“SBC”) for a data security breach. The Tribunal’s decision raises the bar that needs to be met by the ICO in order to impose a fine for a breach of the Data Protection Act 1998 (“DPA”), emphasising that substantial damage or distress must be the likely result of the breach, and not a mere possibility.

BACKGROUND -

On 10 September 2011, a member of the public noticed that a paper recycling bank in a supermarket car park had been overfilled with discarded files. The files contained various confidential personal data, including the name, address, national insurance number and date of birth of former employees and members of the SBC pension scheme and, in some cases, salary and bank account details.

Please see full alert below for more information.

LOADING PDF: If there are any problems, click here to download the file.

Topics:  Appeals, Damages, Data Breach, Data Protection, EU, Fines, ICO, UK

Published In: Civil Procedure Updates, General Business Updates, Privacy Updates

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Morrison & Foerster LLP | Attorney Advertising

Don't miss a thing! Build a custom news brief:

Read fresh new writing on compliance, cybersecurity, Dodd-Frank, whistleblowers, social media, hiring & firing, patent reform, the NLRB, Obamacare, the SEC…

…or whatever matters the most to you. Follow authors, firms, and topics on JD Supra.

Create your news brief now - it's free and easy »