BreachExchange mailing list archives

follow-up: Midlothian Council fined for personal data breaches


From: security curmudgeon <jericho () attrition org>
Date: Tue, 31 Jan 2012 16:37:45 -0600 (CST)


http://www.bbc.co.uk/news/uk-scotland-edinburgh-east-fife-16780239

29 January 2012 Last updated at 19:03 ET

Midlothian Council fined for personal data breaches

Midlothian Council has been fined £140,000 for sending sensitive personal data about children and their carers to the wrong people.

It is the first Scottish organisation to be served with such a penalty by the Information Commissioner's Office.

The local authority made errors in sending out data on five occasions.

In one case, personal papers about a child and its mother were read by the woman and not her former partner who they were intended for.

The woman made a complaint to her social worker.

Another incident involved documents relating to the status of a foster carer.

They were sent to seven healthcare professionals, none of whom had any reason to see the information.

[..]
_______________________________________________
Dataloss Mailing List (dataloss () datalossdb org)
Archived at http://seclists.org/dataloss/
Unsubscribe at http://datalossdb.org/mailing_list

Small, inexpensive USB drives pose huge threats to organizations left unprotected. 
Download Chapter 1 of CREDANT Technologies eBook
Data Protection to the Rescue
http://www.credant.com/campaigns/external_media_ebook/chapter1/lp/

Current thread: