Data Loss - What to Do

The Information Commissioner's Office (ICO) has issued guidance for organisations that lose personal data, having reported that it has been notified of nearly 100 such incidents to date.

One of the less intuitively obvious suggestions is to think carefully about whether all the potentially affected people need to be notified. For example, notifying all your customers about a security glitch which in reality affects only a small proportion of them may produce a flood of enquiries and requests for further information from unaffected people, as well as possibly undermining their confidence in your organisation.

What is advisable is to obtain an accurate understanding as soon as possible of the scale of the loss and the potential impact on the people whose personal information has been lost. For example, if the information is such as to make identity fraud a possibility, it is likely to be more important to notify the people concerned than if the lost information is simply a list of names and addresses (which could be obtained easily from other sources).

The ICO advises that there are four important elements to consider when creating a breach management plan. These are:

1. Containment and recovery;
2. Assessment of ongoing risk;
3. Notification of breach; and
4. Evaluation and response.

The guidance is recommended reading for any organisation which holds personal data and should be considered as part of your data risk management strategy. It can be found here.

See also the ICO’s good practice guides on data security management.

In 2008, the Financial Services Authority published its report on data security in financial services. The report contains much useful information and advice on the maintenance of good data security.

View the eight data protection principles.

Data security is an important but widely neglected issue for many organisations. Failure to follow adequate data protection procedures can have severe consequences, not only from the point of view of fines, but also damage to reputation and possible claims for losses suffered by those whose data has been compromised. We can assist you in helping to make sure that your legal risks due to data loss are minimised.
View my profile
Jonathan Foy
Partner and Notary Public
T: 01727 735630 (DDI)
E:  
The contents of this article are intended for general information purposes only and shall not be deemed to be, or constitute legal advice. We cannot accept responsibility for any loss as a result of acts or omissions taken in respect of this article.

Latest News

A recent case ( Whitham v Club 24 Ltd. t/a Ventura ) sheds further light o...
A consultation on ways of making it easier for social housing providers t...
HM Revenue and Customs (HMRC) will be targeting 6,000 Swiss bank accounts ...
There has recently been a further case on long-term sickness and a worker&...
Creating a commercial database and keeping it up to date is an expensive b...
When a supplier to a marquee company was not paid for goods it had supplie...
The Supreme Court has denied HM Revenue and Customs (HMRC) the right of ap...
Under the Disability Discrimination Act 1995 (now superseded by the Equ...
HM Revenue and Customs (HMRC) have announced that the Mortgage Verificatio...
The Privacy and Electronic Communications (EC Directive) (Amendment) Regu...
The Bribery Act 2010 came into force on 1 July 2011. Under Section 2 of ...
In Williamson & Soden Solicitors v Briars , the Employment Appeal T...
HM Revenue and Customs (HMRC) have announced that, from 1 January 2012, su...
The Forum of Private Business (FPB) has reported a noticeable increase in ...
It is common for service charges to be paid ‘on account’ of th...
There are generally strict time limits that apply when presenting a claim ...
The penalties for engaging in anti-competitive behaviour are very substant...
The Government is proposing to integrate the operation of the Income Tax a...
When an elderly woman passed away, her daughter, who was her personal repr...
The Ministry of Justice (MoJ) has issued for consultation proposals for in...
In July, the Equality and Human Rights Commission (EHRC) announced that it...
When one business uses the trade marks of another, an action may be able t...
Company liquidations have edged up in the first quarter of 2011, with 4,12...
Every year the firm's Christmas party presents employees with the chance t...
If you are used to taking part of your company income by way of dividends ...
The Health and Safety Executive (HSE) has published provisional fatal inj...
When does a commercial property become vacant under a lease agreement? Thi...
  Luke Tucker Harrison, Senior Associate Solicitor in Debenhams Otta...
An advertising and media company run by a Mr Casey sought to register the ...
A recent survey of businesses carried out by the Institute of Chartered Ac...
Following its Resolving Workplace Disputes consultation and the Red Tape C...
Operators of Amusement With Prizes (AWP) machines who receive VAT refunds ...
Under the Agency Workers Regulations 2010 (AWR), which came into force o...
MoneySavingExpert.com (MSE) founder Martin Lewis has won summary judgment...
A developer who completely demolished a property when he only had permissi...
Two companies have been fined a total of £450,000 and ordered to pay...
The law relating to the fiduciary duties of directors is stricter than man...
News that HM Revenue and Customs (HMRC) are to create a dedicated team of ...
The Supreme Court has handed down its decision in a case concerning the em...
On 1 October 2011, changes to the Housing Grants, Construction and Regene...
Following Lord Justice Jackson’s report on his review of civil litig...
As reported previously, the Working Time Regulations 1998 (WTR) as they ...
A covenant can either represent a commitment to do something or a commitme...
Readers are reminded that an application to reclaim VAT incurred in anothe...
Employers are reminded that new National Minimum Wage (NMW) rates came int...
When a licensing application cannot be heard because insufficient informat...
The Privacy and Electronic Communications (EC Directive) (Amendment) Regu...
Earlier this year, the Government published a consultation document entitl...
The Government is calling on businesses to have their say in the latest ...
An employee wishing to bring a claim of unfair dismissal must do so before...
HM Revenue and Customs (HMRC) have won a major battle in the Supreme Court...