Editorial & Analysis
Also by this author
Popular
Technology Categories
- Security (282)
- Desktop Virtualization (233)
- Uncategorised (224)
- Public/Private clouds (223)
- Applications (220)
- Business Continuity (213)
- Server Virtualization (192)
- BYOD (192)
- Network Virtualization (181)
- Storage Virtualization (170)
- Big Data (155)
- Availability (149)
- Network Perfomance Management & Monitoring (143)
- Archiving & Back-Up (136)
- Consolidation (128)
- Wireless LAN (122)
- Performance Management (120)
- Software as a Service (SaaS) (115)
- Infrastructure as a Service (IaaS) (113)
- Network Capacity Planning & Management (112)
- Systems Management (111)
- Hosted solutions / applications (111)
- Network equipment, Repeaters, Hubs, Bridges, Switches, Routers (110)
- Governance, Risk & Compliance (105)
- Data Deduplication (103)
- Servers/Hardware (96)
- Mobile Security (92)
- Virtualization Security (91)
- IP Convergence (90)
- Storage as a Service (88)
- Storage Area Networking (SAN) (87)
- Storage Networking – IP storage,Infiniband & iSCSi (86)
- Disk Storage, Flash, SSD, Optical (85)
- Application Delivery Network (84)
- Capacity Management (83)
- Wireless Security (77)
- Automation (77)
- Business Intelligence (76)
- Unified Communications (76)
- Energy Efficiency (76)
- Enterprise Mobility Management (74)
- Mobile Device Management (71)
- Flexible & Smarter Working (70)
- Risk Management (69)
- Campus Networks (67)
- Design & Build (65)
- Recovery (65)
- Platform as a Service (PaaS) (63)
- Managed Security Services (61)
- Content Monitoring/Filtering (56)
- Identity & Network Access Control/Management (52)
- Managed Network Security Services (50)
- Smartphones/Tablets (49)
- Managed Hosting (49)
- Email Archiving & Management (49)
- Business Impact Analysis (48)
- Risk Analysis (47)
- Enterprise Content & Document Management (46)
- Collaboration Tools/Applications (45)
- Network Attached Storage / NAS (44)
- Fibre Channel over Ethernet FCoE) (43)
- Mobile Enterprise Applications (43)
- Cabling (41)
- Mobile Platforms (41)
- IPv6 (40)
- Storage Resource Management (SRM) (40)
- Penetration Testing/Risk & Vulnerability Assessment (38)
- Thin Provisioning (38)
- Information Lifecycle Management (ILM) (38)
- Workflow & Process (36)
- Load Balancing (36)
- Optical Networks (35)
- Forensics (34)
- E-Discovery (30)
- VPN/SSL (29)
- Regulation & legislation (29)
- Unified Threat Management (29)
- Power & Protection (29)
- IP Telephony (28)
- Tape Storage (27)
- ISP's (26)
- Communications-Enabled Business Process (24)
- Enterprise Search & retrieval (24)
- HPC (23)
- Metropolitan Networks (22)
- Mesh Networks (21)
- Collaborative Communications servers (Exchange etc) (21)
- Video/Web Conferencing (20)
- Encryption/PKI/Digital Certificates (20)
- Field Services (17)
- IP PBX (16)
- Transparency (15)
- Openflow/Software Defined Networking (14)
- Audio Conferencing (14)
- Wireless Expense Management (11)
- Instant Messaging (11)
- Risk frameworks (11)
- Fixed Mobile Convergence (10)
- Data Masking (9)
- Classification (8)
- SIP Trunking (8)
- Social Software (7)
- Data Erasure (6)
- Presence (6)
- BS25999 (5)
- HVAC (5)
Popular Categories
Scottish council fined for data breach
12 Sep 2012
Another hefty fine for data protection breach meted out by the ICO
The Information Commissioner’s Office (ICO) has meted out another hefty penalty for data protection infringements, this time to Scottish Borders Council (SBC), for £250,000.
Documents relating to council staff, including pensions, bank account and salary details, were dumped in a supermarket recycling bank after they had been handed over by the Council to a third-party company for digitisation. It was only when a member of the public tipped off the police about the more than 600 files was action taken.
The ICO found that SBC put no contract in place with the third-party processor, sought no guarantees on the technical and organisational security protecting the records and did not make sufficient attempts to monitor how the data was being handled.
Ken Macdonald, ICO Assistant Commissioner for Scotland, said: "This is a classic case of an organisation taking its eye off the ball when it came to outsourcing. When the Council decided to contract out the digitising of these records, they handed large volumes of confidential information to an outside company without performing sufficient checks on how securely the information would be kept, and without even putting a contract in place.
"It is only good fortune that these records were found by someone sensible enough to call the police. It is easy to imagine other circumstances where this information could have exposed people to identity fraud and possible financial loss through no fault of their own.
"If one positive can come out of this, it is that other organisations realise the importance of properly managing third parties who process personal data. The Data Protection Act is very clear where the responsibility for the security of that information remains, and what penalties await those who do not comply with the law."
Meanwhile, the Council has voiced its dismay at the fine in an official statement. Tracey Logan, chief executive of SBC, said: “It is very disappointing to receive such a high monetary penalty from the ICO especially in the current economic climate.”
“We do acknowledge the seriousness of this breach and have already taken steps to ensure data protection continues to be a priority across the council. We are fully committed to complying with the terms set out in the ICO’s undertaking,” she said, before adding that, “this additional expenditure is obviously unhelpful at a time when public funding is already stretched.”

