Torbay Care Trust in Torquay has been fined £175,000 after it published the sensitive details of over 1,000 employees on the Trust’s website.

Staff at the Trust published the information in a spreadsheet on their website in April 2011 and only realised when a member of the public reported it 19 weeks later.

The data covered the equality and diversity responses of 1,373 staff and included individuals’ names:-

  • Dates of birth
  • National Insurance numbers
  • Religion
  • Sexuality

The Information Commissioners Office’s investigation found that the Trust had no guidance for staff on what information shouldn’t be published online and had inadequate checks in place to identify potential problems.

Stephen Eckersley, Head of Enforcement, said:

“We regular speak with organisations across the health service to remind them of the need to look after people’s data. The fact that this breach was caused by Torbay Care Trust publishing sensitive information about their staff is extremely troubling and was entirely avoidable. Not only were they giving sensitive information out about their employees but they were also leaving them exposed to the threat of identity fraud.

“While organisations can publish equality and diversity information about staff in an aggregated form, there is no justification for unnecessarily releasing their personal information. We are pleased that the Trust are now taking action to keep their employees’ details secure.”

With the proposed European Data Protection Act the scope of what is classified as Personally Identifiable Information (PII) will be better defined but will include more than most business think is actually covered.

It is time businesses undertook thorough risk assessments of their exposure to the PII data leakages because the proposed new fines are potentially up to 2% of global turnover.

Read my summary of the proposed European Data Protection Act here.

.


6 responses to “Torbay Care Trust (NHS) fined £175,000 for breaching the Data Protection Act”

  1. […] sensitive personal information relating to 1,373 employees was published on the Trust’s website. https://brianpennington.co.uk/2012/08/06/torbay-care-trust-nhs-fined-175000-for-breaching-the-data-pr… 1 June 2012 a monetary penalty notice for £325,000 has been served on Brighton and Sussex […]

    Like

  2. […] 6 August 2012 a monetary penalty of £175,000 was issued to Torbay Care Trust after sensitive personal information relating to 1,373 employees was published on the Trust’s website. https://brianpennington.co.uk/2012/08/06/torbay-care-trust-nhs-fined-175000-for-breaching-the-data-pr… […]

    Like

  3. […] 6 August 2012 a monetary penalty of £175,000 was issued to Torbay Care Trust after sensitive personal information relating to 1,373 employees was published on the Trust’s website. https://brianpennington.co.uk/2012/08/06/torbay-care-trust-nhs-fined-175000-for-breaching-the-data-pr… […]

    Like

  4. 2012 was a big year for the Data Protection Act with record fines and breaches, see the full 2012 list here. « Brian Pennington Avatar

    […] 6 August 2012 A monetary penalty of £175,000 was issued to Torbay Care Trust after sensitive personal information relating to 1,373 employees was published on the Trust’s website. Read the details here. […]

    Like

  5. Who has breached the Data Protection Act in 2012? Find the complete list here. « Brian Pennington Avatar

    […] 6 August 2012 A monetary penalty of £175,000 was issued to Torbay Care Trust after sensitive personal information relating to 1,373 employees was published on the Trust’s website. Read the details here. […]

    Like

  6. internet security, cyber threat intelligence, cyber defense, information security services, information security, penetration testing,…

    […]Torbay Care Trust (NHS) fined £175,000 for breaching the Data Protection Act « Brian Pennington[…]…

    Like

Leave a comment