| |
|
| |
|
| |
|
|
|
| |
Author:Breachaware |
Date:
6th August 2012 |
Read full article |
| |
A monetary penalty of £175,000 was issued to Torbay Care Trust after sensitive personal information relating to 1,373 employees was published on the Trust’s website. |
 |
| |
|
| |
Marston Properties |
| |
|
|
|
| |
Author:Breachaware |
Date:
6th August 2012 |
Read full article |
| |
An undertaking to comply with the seventh data protection principle has been signed by Marston Properties. This follows the loss of 37 staff members’ details when the filing cabinet the information was stored in was sent to a recycling centre and crushed. |
 |
| |
|
| |
West Lancashire Borough Council |
| |
|
|
|
| |
Author:Breachaware |
Date:
13th July 2012 |
Read full article |
| |
An undertaking to comply with the seventh data protection principle has been signed by West Lancashire Borough Council. This follows the theft of a business continuity bag containing emergency response documents and personal data relating to 370 council employees. |
 |
| |
|
| |
South Yorkshire Police |
| |
|
|
|
| |
Author:Breachaware |
Date:
26th June 2012 |
Read full article |
| |
An undertaking to comply with the seventh data protection principle has been signed by South Yorkshire Police. This follows the inclusion of personal data relating to drug offences, in response to a Freedom of Information request made by a journalist. |
 |
| |
|
| |
Belfast Health and Social Care Trust |
| |
|
|
|
| |
Author:Breachaware |
Date:
19th June 2012 |
Read full article |
| |
A monetary penalty notice of £225,000 has been served to Belfast Health and Social Care Trust following a serious breach of the Data Protection Act. The breach led to the sensitive personal data of thousands of patients and staff being compromised. The Trust also failed to report the incident to the ICO. |
 |
| |
|
| |
Brighton and Sussex University Hospitals NHS Trust |
| |
|
|
|
| |
Author:Breachaware |
Date:
1st June 2012 |
Read full article |
| |
A monetary penalty notice for £325,000 has been served on Brighton and Sussex University Hospitals NHS Trust following the discovery of highly sensitive personal data belonging to tens of thousands of patients and staff – including some relating to HIV and Genito Urinary Medicine patients – on hard drives sold on an Internet auction site in October and November 2010. |
 |
| |
|
| |
Holroyd Howe Independent Ltd |
| |
|
|
|
| |
Author:Breachaware |
Date:
23rd May 2012 |
Read full article |
| |
An undertaking to comply with the seventh data protection principle has been signed by Holroyd Howe Independent Ltd. This follows the release of a document containing details of employees’ pay to a former employee. |
 |
| |
|
| |
Aneurin Bevan Health Board |
| |
|
|
|
| |
Author:Breachaware |
Date:
30th April 2012 |
Read full article |
| |
An undertaking to comply with the seventh data protection principle has been signed by the Aneurin Bevan Health Board. This follows an incident where a sensitive report - containing explicit details relating to a patient’s health - was sent to the wrong person. This breach was also the subject of a monetary penalty. |
 |
| |
|
| |
Safe and Secure Insurances Services Limited |
| |
|
|
|
| |
Author:Breachaware |
Date:
25th April 2012 |
Read full article |
| |
An undertaking to comply with the seventh data protection principle has been signed by Safe and Secure Insurances Services Limited. This follows the purchase of a hard drive from the Internet which contained personal data relating to the company’s clients. |
 |
| |
|
| |
Toshiba Information Systems UK Ltd |
| |
|
|
|
| |
Author:Breachaware |
Date:
17th April 2012 |
Read full article |
| |
An undertaking to comply with the seventh data protection principle has been signed by Toshiba Information Systems UK Ltd. This follows a web design error that created the potential for unauthorised access to individual’s personal data. |
 |
| |
|
| |
Leicestershire County Council |
| |
|
|
|
| |
Author:Breachaware |
Date:
17th April 2012 |
Read full article |
| |
An undertaking to comply with the seventh data protection principle has been signed by Leicestershire County Council, following the theft of a briefcase containing sensitive personal data from a social worker’s home. |
 |
| |
|
| |
Brecon Beacons National Park Authority |
| |
|
|
|
| |
Author:Breachaware |
Date:
17th April 2012 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Brecon Beacons National Park Authority. This follows two data security incidents which relate to the unauthorised disclosure of personal data on the data controller’s website. |
 |
| |
|
| |
South London Healthcare NHS Trust |
| |
|
|
|
| |
Author:Breachaware |
Date:
11th April 2012 |
Read full article |
| |
An undertaking to comply with the seventh data protection principle has been signed by South London Healthcare NHS Trust. This follows the loss of two unencrypted memory sticks, the leaving of a clipboard with ward lists attached in a grocery store and a failure to adequately secure some patient paper files when not in use. All of the information was recovered. |
 |
| |
|
| |
Hertfordshire County Counci |
| |
|
|
|
| |
Author:Breachaware |
Date:
11th April 2012 |
Read full article |
| |
An undertaking to comply with the seventh data protection principle has been signed by Hertfordshire County Council. This follows the loss of an Attendance and Pupil Support consultation folder in January 2011. |
 |
| |
|
| |
Pharmacyrepublic Ltd |
| |
|
|
|
| |
Author:Breachaware |
Date:
27th March 2012 |
Read full article |
| |
An Undertaking has been signed by Pharmacyrepublic Ltd following the theft of a patient medication system containing the medication details of 2000 patients. The system, which was supplied by another firm, should have been securely returned to them by Pharmacyrepublic Ltd before the premises were vacated. |
 |
| |
|
| |
Lancashire Constabulary |
| |
|
|
|
| |
Author:Breachaware |
Date:
14th March 2012 |
Read full article |
| |
An undertaking to comply with the seventh data protection principle has been signed by the Lancashire Constabulary. This follows the discovery of a missing person’s report on a street in Blackpool. A monetary penalty has also been issued to the authority in connection with this incident |
 |
| |
|
| |
Enable Scotland (Leading the Way) |
| |
|
|
|
| |
Author:Breachaware |
Date:
9th March 2012 |
Read full article |
| |
An undertaking to comply with the seventh data protection principle has been signed by Enable Scotland (Leading the Way), after two unencrypted memory sticks and papers containing the personal details of up to 101 individuals were stolen from an employee’s home. |
 |
| |
|
| |
Dr Pervinder Sanghera of Arthur House Dental Care |
| |
|
|
|
| |
Author:Breachaware |
Date:
1st March 2012 |
Read full article |
| |
An undertaking to comply with the seventh data protection principle has been signed by Dr Pervinder Sanghera of Arthur House Dental Care. This follows the discovery of an unencrypted memory stick containing personal and limited sensitive personal data relating to patients and employees of the practice. |
 |
| |
|
| |
London Borough of Croydon |
| |
|
|
|
| |
Author:Breachaware |
Date:
1st March 2012 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by London Borough of Croydon. This follows the theft of a bag belonging to a social worker from a public house in London. The bag contained a hard copy file of papers concerning a child who is in the care of the Council. This incident was also subject to a monetary penalty which was announced earlier this month. |
 |
| |
|
| |
Durham University |
| |
|
|
|
| |
Author:Breachaware |
Date:
1st March 2012 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Durham University. This follows the disclosure of personal information in training materials published on its website. |
 |
| |
|
| |
Community Integrated Care |
| |
|
|
|
| |
Author:Breachaware |
Date:
1st March 2012 |
Read full article |
| |
An undertaking to comply with the seventh data protection principle has been signed by Community Integrated Care, a national social care charity. This follows the theft of an unencrypted laptop containing personal and sensitive personal data. |
 |
| |
|
| |
London Borough of Croydon |
| |
|
|
|
| |
Author:Breachaware |
Date:
1st March 2012 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by London Borough of Croydon. This follows the theft of a bag belonging to a social worker from a public house in London. The bag contained a hard copy file of papers concerning a child who is in the care of the Council. This incident was also subject to a monetary penalty which was announced earlier this month. |
 |
| |
|
| |
Durham University |
| |
|
|
|
| |
Author:Breachaware |
Date:
1st March 2012 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Durham University. This follows the disclosure of personal information in training materials published on its website. |
 |
| |
|
| |
Community Integrated Car |
| |
|
|
|
| |
Author:Breachaware |
Date:
1st March 2012 |
Read full article |
| |
An undertaking to comply with the seventh data protection principle has been signed by Community Integrated Care, a national social care charity. This follows the theft of an unencrypted laptop containing personal and sensitive personal data. |
 |
| |
|
| |
Cheshire East Council |
| |
|
|
|
| |
Author:Breachaware |
Date:
15th February 2012 |
Read full article |
| |
A monetary penalty of £80,000 has been issed to Cheshire East Council after an email containing sensitive personal information about an individual of concern to the police was distributed to 180 unintended recipients. |
 |
| |
|
| |
Croydon Council |
| |
|
|
|
| |
Author:Breachaware |
Date:
13th February 2012 |
Read full article |
| |
A monetary penalty of £100,000 has been issed to Croydon Council after a bag containing papers relating to the care of a child sex abuse victim was stolen from a London pub. |
 |
| |
|
| |
Craven District Counci |
| |
|
|
|
| |
Author:Breachaware |
Date:
10th February 2012 |
Read full article |
| |
Craven District Council have signed an undertaking to comply with the seventh data protection principle, following incidents where the council failed to take appropriate steps to ensure that personal information was kept secure |
 |
| |
|
| |
Bolton Council |
| |
|
|
|
| |
Author:Breachaware |
Date:
10th February 2012 |
Read full article |
| |
Bolton Council have signed an undertaking to comply with the seventh data protection principle, following incidents where the council failed to take appropriate steps to ensure that personal information was kept secure. |
 |
| |
|
| |
Dacorum Borough Council |
| |
|
|
|
| |
Author:Breachaware |
Date:
10th February 2012 |
Read full article |
| |
Dacorum Borough Council have signed an undertaking to comply with the seventh data protection principle, following incidents where the council failed to take appropriate steps to ensure that personal information was kept secure. |
 |
| |
|
| |
Brighton and Hove Council |
| |
|
|
|
| |
Author:Breachaware |
Date:
10th February 2012 |
Read full article |
| |
Brighton and Hove Council emailed the details of another member of staff’s annual salary - and the deductions made from this - to 2,821 council workers. A third party also informed the ICO of a historic breach which occurred in May 2009 when an unencrypted laptop was stolen from the home of a temporary employee. |
 |
| |
|
| |
Basingstoke and Deane Borough Council |
| |
|
|
|
| |
Author:Breachaware |
Date:
10th February 2012 |
Read full article |
| |
Basingstoke and Deane Borough Council breached the Data Protection Act on four separate occasions during a two month period last year. The breaches included an incident in May when an individual was mistakenly sent information relating to 29 people who were living in supported housing. |
 |
| |
|
| |
E*Trade Securities Ltd |
| |
|
|
|
| |
Author:Breachaware |
Date:
3rd February 2012 |
Read full article |
| |
An undertaking to comply with the seventh data protection principle has been signed by E*Trade Securities Ltd. This follows a report to the Commissioner concerning missing client files. The files contained limited sensitive personal data including identification documents. |
 |
| |
|
| |
Praxis Care Limited |
| |
|
|
|
| |
Author:Breachaware |
Date:
18th January 2012 |
Read full article |
| |
Praxis Care Limited breached both the UK Data Protection Act and the Isle of Man Data Protection Act by failing to keep peoples’ data secure. An unencrypted memory stick, containing personal information relating to 107 Isle of Man residents and 53 individuals from Northern Ireland, was lost on the Isle of Man. |
 |
| |
|
| |
Chartered Institute of Public Relations |
| |
|
|
|
| |
Author:Breachaware |
Date:
18th January 2012 |
Read full article |
| |
An undertaking has been signed by the Chartered Institute of Public Relations, following the loss of up to 30 membership forms on a train. The organisation didn’t have a policy in place for handling personal data outside of the office at the time of the incident. |
 |
| |
|
| |
Individual |
| |
|
|
|
| |
Author:Breachaware |
Date:
16th December 2011 |
Read full article |
| |
A receptionist who unlawfully obtained her sister-in-law’s medical records in order to find out about the medication she was taking has been found guilty of an offence under section 55 of the Data Protection Act.
Usha Patwal, of Romford, was given a two year conditional discharge and ordered to pay £614 prosecution costs by Havering Magistrates Court today. ...more |
 |
| |
|
| |
Alan M Casson & Associates |
| |
|
|
|
| |
Author:BreachAware |
Date:
6th December 2011 |
Read full article |
| |
An Undertaking to comply with the seventh principle of the DPA has been signed by Alan M Casson & Associates, after two unencrypted laptops and back up media had been stolen during a burglary of their premises. The laptops contained personal data relating to 8000 current and past patients.
...more |
 |
| |
|
| |
Godalming College |
| |
|
|
|
| |
Author:BreachAware |
Date:
6th December 2011 |
Read full article |
| |
An Undertaking to comply with the seventh principle of the DPA has been signed by the Principal of Godalming College, after the was notified that an email with an attachment containing sensitive personal data had been sent inadvertently to lower-sixth form students. The email should have been sent to their tutors and the sender had not intended to send the attachment, but merely a link to it.
...more |
 |
| |
|
| |
Richard Dominic Preston |
| |
|
|
|
| |
Author:BreachAware |
Date:
6th December 2011 |
Read full article |
| |
An Undertaking to comply with the seventh principle of the DPA has been signed by Richard Dominic Preston following the theft of a laptop computer from Mr Preston's home address. The laptop contained documents relating to cases on which Mr Preston had been instructed, together with email correspondence.
...more |
 |
| |
|
| |
The London Borough of Southwark |
| |
|
|
|
| |
Author:BreachAware |
Date:
21st November 2011 |
Read full article |
| |
An Undertaking to comply with the seventh principle of the DPA has been signed by The London Borough of Southwark, further to the inappropriate disposal personal of an iMac computer and paper records. The matter was brought to the attention of the when the afore mentioned items were found by a member of the public in a skip being used to cleanse a decommissioned and vacant property, which was part of a complex previously owned by the data controller. A substantial volume of sensitive personal data relating to around 7,200 individuals was contained on the iMac and within the paper records detailing ethnicity, medical history and criminal convictions.
...more |
 |
| |
|
| |
Central Essex Community Services |
| |
|
|
|
| |
Author:BreachAware |
Date:
21st November 2011 |
Read full article |
| |
An Undertaking has been signed by Central Essex Community Services after the loss of a birth book containing information about the general health of 249 mothers and their babies. The book which should have been stored in a locked filing cabinet was stored on top of the cabinet in a locked room due to no secure storage space being available. The book has never been recovered.
...more |
 |
| |
|
| |
Ruth Crawford QC, |
| |
|
|
|
| |
Author:BreachAware |
Date:
16th November 2011 |
Read full article |
| |
An Undertaking to comply with the seventh principle of the DPA has been signed by Ruth Crawford QC, further to the theft of an unencrypted laptop computer which contained the sensitive personal data of a number of individuals who were involved in cases on which the data controller was instructed to act.
...more |
 |
| |
|
| |
Phoenix Nursey School |
| |
|
|
|
| |
Author:BreachAware |
Date:
16th November 2011 |
Read full article |
| |
An Undertaking to comply with the seventh principle of the DPA has been signed by Phoenix Nursey School, further to the loss of a backup tape and accompanying device which contained details of pupils, parents and guardians as held on the schools information management system. Consideration was given to the fact that a nominal amount of the data lost in this incident consisted of information as to the physical or mental health of the data subjects.
...more |
 |
| |
|
| |
Oliver Letwin MP |
| |
|
|
|
| |
Author:BreachAware |
Date:
15th November 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Oliver Letwin MP. Following the disposal of a number of documents containing personal data in public waste-bins. |
 |
| |
|
| |
Rochdale Metropolitan Borough Council |
| |
|
|
|
| |
Author:BreachAware |
Date:
3rd November 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by the chief executive of Rochdale Metropolitan Borough Council. This follows an incident earlier this year in which an unencrypted USB stick containing some personal data relating to thousands of local residents was lost.
...more |
 |
| |
|
| |
Newcastle Youth Offending Team |
| |
|
|
|
| |
Author:BreachAware |
Date:
28th October 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Newcastle Youth Offending Team. This follows the theft of an unencrypted laptop containing sensitive personal data.
...more |
 |
| |
|
| |
University Hospitals Coventry & Warwickshire NHS Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
27th October 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by University Hospitals Coventry & Warwickshire NHS Trust. This follows two separate incidents involving the loss of personal data by the Trust.
...more |
 |
| |
|
| |
Spectrum Housing Group |
| |
|
|
|
| |
Author:BreachAware |
Date:
19th October 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Spectrum Housing Group. This follows a non-secure e-mail with an excel attachment containing personal data relating to employees of the data controller, being sent in error to an unintended recipient outside of the organisation. It was also discovered that data within hidden pivot cells forming part of the spreadsheet could be revealed.
...more |
 |
| |
|
| |
Dumfries and Galloway Council |
| |
|
|
|
| |
Author:BreachAware |
Date:
17th October 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Dumfries and Galloway Council. This follows the accidental online disclosure of current and former employees personal data in response to a Freedom of Information (Scotland) Act request.
...more |
 |
| |
|
| |
Association of School and College Leaders (ASCL). |
| |
|
|
|
| |
Author:BreachAware |
Date:
5th October 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by the General Secretary of the Association of School and College Leaders (ASCL). This follows theft of a laptop containing sensitive personal data from the home of an employee.
...more |
 |
| |
|
| |
Holly Park School |
| |
|
|
|
| |
Author:BreachAware |
Date:
5th October 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Holly Park School. This follows the theft of an unencrypted laptop containing personal data relating to nine pupils.
...more |
 |
| |
|
| |
Dartford and Gravesham NHS Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
4th October 2011 |
Read full article |
| |
An Undertaking has been signed by Dartford and Gravesham NHS Trust following the accidental destruction of 10,000 archived records. The records which should have been kept in a dedicated storage area were put in a disposal room due to lack of space.
...more |
 |
| |
|
| |
Poole Hospital NHS Foundation Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
4th October 2011 |
Read full article |
| |
An Undertaking has also been signed by Poole Hospital NHS Foundation Trust after two diaries containing information relating to the care of 240 midwifery patients - were stolen from a nurses car. The diaries included patients names, addresses and details of previous visits and were used by the nurse during out of hours duty.
...more |
 |
| |
|
| |
Eastleigh Borough Council |
| |
|
|
|
| |
Author:BreachAware |
Date:
20th September 2011 |
Read full article |
| |
An Undertaking to comply with the third and seventh data protection principles has been signed by Eastleigh Borough Council. This follows the potential disclosure of a document containing sensitive personal data.
...more |
 |
| |
|
| |
Child Exploitation Online Protection Centre (CEOP) and its parent organisation the Serious Organised Crime Agency (SOCA). |
| |
|
|
|
| |
Author:BreachAware |
Date:
15th September 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by the Child Exploitation Online Protection Centre (CEOP) and its parent organisation the Serious Organised Crime Agency (SOCA). This follows the discovery that CEOPs website reporting forms were being transmitted insecurely.
...more |
 |
| |
|
| |
Royal Liverpool & Broadgreen University Hospitals NHS Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
15th September 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Royal Liverpool & Broadgreen University Hospitals NHS Trust. This follows two separate incidents involving the loss of personal data by the Trust.
...more |
 |
| |
|
| |
Eastern and Coastal Kent Primary Care Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
14th September 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Eastern and Coastal Kent Primary Care Trust. This follows the loss of a CD containing personal data during a move of office premises.
...more |
 |
| |
|
| |
Walsall Council |
| |
|
|
|
| |
Author:BreachAware |
Date:
9th September 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Walsall Council. This follows the accidental disposal of postal vote statements in a skip by the councils data processor. The council did not have a written agreement with the data processor selected to store this personal data.
...more |
 |
| |
|
| |
London Ambulance Service NHS Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
7th September 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by London Ambulance Service NHS Trust. This follows the theft of a personal unencrypted laptop containing patient data.
...more |
 |
| |
|
| |
University Hospital of South Manchester NHS Foundation Trust. |
| |
|
|
|
| |
Author:BreachAware |
Date:
7th September 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by University Hospital of South Manchester NHS Foundation Trust. This follows the loss of an unencrypted memory stick containing personal information relating to approximately 87 patients. |
 |
| |
|
| |
The Scottish Childrens Reporter Administration |
| |
|
|
|
| |
Author:BreachAware |
Date:
2nd September 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by the Scottish Children's Reporter Administration. This follows the sending of an email containing sensitive personal data relating to a child's court hearing to an unknown third party and the temporary loss of 9 case files relating to the safety and welfare of children during an office move. |
 |
| |
|
| |
Luton Borough Council. |
| |
|
|
|
| |
Author:BreachAware |
Date:
2nd September 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Luton Borough Council. This follows a self reported breach concerning a flaw in the encryption function of a number of Council issue memory sticks. The flaw could allow memory sticks to be formatted removing encryption protection.
...more |
 |
| |
|
| |
London Borough of Greenwich |
| |
|
|
|
| |
Author:BreachAware |
Date:
10th August 2011 |
Read full article |
| |
An Undertaking to comply with the seventh principle of the DPA has been signed by the London Borough of Greenwich. This follows two incidents where sensitive personal data was inadvertently disclosed, due to the Council's failure to implement appropriate wording in their ICT policy, stating that the sending of sensitive personal data in business related emails to external webmail addresses should be avoided.
...more |
 |
| |
|
| |
Lush Cosmetics Ltd. |
| |
|
|
|
| |
Author:BreachAware |
Date:
9th August 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Lush Cosmetics Ltd. This follows a malicious intrusion on their website which compromised approximately 5000 customer credit cards.
...more |
 |
| |
|
| |
Bay House School |
| |
|
|
|
| |
Author:BreachAware |
Date:
8th August 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Bay House School after the personal details of nearly 20,000 individuals, including some 7,600 pupils, were put at risk during a hacking attack on its website.
...more |
 |
| |
|
| |
HCA International Limited. |
| |
|
|
|
| |
Author:BreachAware |
Date:
5th August 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by HCA International Limited. This follows the theft of two unencrypted laptops containing sensitive personal data from one of the groups hospitals in March.
...more |
 |
| |
|
| |
Wandle Housing Association. |
| |
|
|
|
| |
Author:BreachAware |
Date:
4th August 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by the Chief Executives of Wandle Housing Association. This follows the discovery of an unencrypted USB stick containing thousands of tenant records and financial data in a London pub.
...more |
 |
| |
|
| |
Lewisham Council |
| |
|
|
|
| |
Author:BreachAware |
Date:
4th August 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by the Chief Executives of Lewisham Council . This follows the discovery of an unencrypted USB stick containing thousands of tenant records and financial data in a London pub.
...more |
 |
| |
|
| |
Kirklees Metropolitan Council |
| |
|
|
|
| |
Author:BreachAware |
Date:
29th July 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Kirklees Metropolitan Council. This follows the inappropriate disclosure of personal data by care workers contracted by Kirklees Metropolitan Council.
...more |
 |
| |
|
| |
University of York |
| |
|
|
|
| |
Author:BreachAware |
Date:
20th July 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by the University of York after it failed to close a test area on its website that contained thousands of students personal details. While no direct link was available for the test area from the University's website, 148 records were inappropriately accessed. |
 |
| |
|
| |
Lancashire Police Authority |
| |
|
|
|
| |
Author:BreachAware |
Date:
19th July 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Lancashire Police Authority (LPA). This follows the inappropriate disclosure of personal data on the LPAs website containing sensitive personal data.
...more |
 |
| |
|
| |
Northamptonshire Healthcare NHS Foundation Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
18th July 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Northamptonshire Healthcare NHS Foundation Trust. This follows the loss of one individuals medical records.
...more |
 |
| |
|
| |
Ms Raisa Saley |
| |
|
|
|
| |
Author:BreachAware |
Date:
5th July 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Ms Raisa Saley, Barrister at law, further to the loss of a bundle of court papers which contained a considerable volume of sensitive personal data relating to a number of individuals from the same family.
...more |
 |
| |
|
| |
Basildon and Thurrock University Hospitals NHS Foundation Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
1st July 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Basildon and Thurrock University Hospitals NHS Foundation Trust. This follows the transmission of a fax containing sensitive personal data to the wrong recipient.
...more |
 |
| |
|
| |
Dunelm Medical Practice, |
| |
|
|
|
| |
Author:BreachAware |
Date:
1st July 2011 |
Read full article |
| |
An Undertaking to comply with the seventh principle of the DPA has been signed by Dunelm Medical Practice, further to the inappropriate facsimilie transmission and subsequent disclosure of two patient's electronic discharge letters, which contained sensitive personal data, including medical information.
...more |
 |
| |
|
| |
East Midlands Ambulance Service NHS Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
1st July 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by East Midlands Ambulance Service NHS Trust. This follows the transmission of a fax containing sensitive personal data to the wrong recipient.
...more |
 |
| |
|
| |
the Ipswich Hospital NHS Trust. |
| |
|
|
|
| |
Author:BreachAware |
Date:
1st July 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by the Ipswich Hospital NHS Trust. This follows the discovery of 29 patient records containing sensitive personal data in a public place.
...more |
 |
| |
|
| |
Lancashire Teaching Hospitals NHS Foundation Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
1st July 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Lancashire Teaching Hospitals NHS Foundation Trust. This follows the faxing of sensitive personal data to a member of the public on more than one occasion.
...more |
 |
| |
|
| |
Cherubs Community Playgroup |
| |
|
|
|
| |
Author:BreachAware |
Date:
28th June 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Cherubs Community Playgroup. This follows the theft of an unencrypted laptop containing personal information relating to approximately 47 families.
...more |
 |
| |
|
| |
Internet Eyes Limited |
| |
|
|
|
| |
Author:BreachAware |
Date:
14th June 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by CCTV monitoring website Internet Eyes Limited. This follows a complaint about a clip posted on video sharing website YouTube that contained an identifiable image of a person in a shop. The clip appeared to have been uploaded by a viewer who had used the CCTV footage streamed to their computer from the Internet Eyes website.
...more |
 |
| |
|
| |
Surbiton Childrens Centre Nursery |
| |
|
|
|
| |
Author:BreachAware |
Date:
14th June 2011 |
Read full article |
| |
An An Undertaking to comply with the seventh data protection principle has been signed by Surbiton Childrens Centre Nursery. This follows the theft of a teachers bag containing an unencrypted memory stick and paperwork.
...more |
 |
| |
|
| |
North Lanarkshire Council |
| |
|
|
|
| |
Author:BreachAware |
Date:
8th June 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by North Lanarkshire Council. This follows the theft of hard copy documents containing sensitive personal data.
...more |
 |
| |
|
| |
Aspergers Children & Carers Together |
| |
|
|
|
| |
Author:BreachAware |
Date:
27th May 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by the charity Aspergers Children & Carers Together (ACCT). This follows the theft of an unencrypted laptop containing sensitive personal data last Christmas.
...more |
 |
| |
|
| |
Co-operative Life Planning Limited |
| |
|
|
|
| |
Author:BreachAware |
Date:
26th May 2011 |
Read full article |
| |
An Undertaking to comply with the seventh principle of the DPA has been signed by Co-operative Life Planning Limited, further to the inappropriate disclosure of an electronic file, which contained a considerable volume of customer's personal data.
...more |
 |
| |
|
| |
Somerset County Council |
| |
|
|
|
| |
Author:BreachAware |
Date:
13th May 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Somerset County Council. This is a result of a teenagers social care records having been sent to the wrong family.
...more |
 |
| |
|
| |
Wheelbase Motor Project. |
| |
|
|
|
| |
Author:BreachAware |
Date:
7th May 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Wheelbase Motor Project. This follows the theft of an unencrypted portable hard drive storing sensitive personal data concerning 50 individuals. |
 |
| |
|
| |
Freehold Community School |
| |
|
|
|
| |
Author:BreachAware |
Date:
21st April 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Freehold Community School. This follows the theft of an unencrypted laptop and paperwork containing personal information relating to 90 pupils from a teachers car.
...more |
 |
| |
|
| |
NHS Birmingham East and North |
| |
|
|
|
| |
Author:BreachAware |
Date:
20th April 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by NHS Birmingham East and North. This follows the discovery that Trust employees could access electronic files unrelated to the department they worked in.
...more |
 |
| |
|
| |
University College London Hospitals NHS Foundation Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
19th April 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by University College London Hospitals NHS Foundation Trust. This follows the discovery of an unencrypted memory stick off Trust premises. The memory stick contained sensitive personal data relating to 750 Trust patients.
...more |
 |
| |
|
| |
Borough of Poole |
| |
|
|
|
| |
Author:BreachAware |
Date:
19th April 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by the Borough of Poole. The Council reported that faxes had been sent to the wrong number on three occasions last year.
...more |
 |
| |
|
| |
Norwich City College of Further and Higher Education |
| |
|
|
|
| |
Author:BreachAware |
Date:
19th April 2011 |
Read full article |
| |
An Undertaking to comply with the seventh principal of the DPA has been signed by Norwich City College of Further and Higher Education, detailing two instances, where a total of 80 student files, some of which contained sensitive personal data including medical information, were inappropriately disposed of.
...more |
 |
| |
|
| |
NHS Liverpool Community Health |
| |
|
|
|
| |
Author:BreachAware |
Date:
11th April 2011 |
Read full article |
| |
NHS Liverpool Community Health has signed an Undertaking after it breached the Data Protection Act (DPA) by losing papers relating to the medical history of 31 children and their birth mothers during a premises move in October last year. The ICOs investigation found that NHS Liverpool had no formal contract in place with the removal company to handle personal data - a requirement of the Act - and had no process in place to ensure personal data was kept secure throughout the move.
...more |
 |
| |
|
| |
City of York Council |
| |
|
|
|
| |
Author:BreachAware |
Date:
5th April 2011 |
Read full article |
| |
An Undertaking to comply with the seventh principal of the DPA has been signed by City of York Council, further to the inappropriate disclosure of an individuals personal data, which occurred as a result of the information in question being erroneously included with documentation sent to an unrelated third party.
...more |
 |
| |
|
| |
Royal Cornwall Hospitals NHS Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
4th April 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Royal Cornwall Hospitals NHS Trust. This follows the inappropriate disclosure of third party sensitive personal data on two occasions, in response to a subject access request.
...more |
 |
| |
|
| |
Warrington and Halton Hospitals NHS Foundation Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
1st April 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Warrington and Halton Hospitals NHS Foundation Trust. This follows the theft on an unencrypted laptop containing sensitive personal data relating to 110 patients.
...more |
 |
| |
|
| |
Ms Phillimore |
| |
|
|
|
| |
Author:BreachAware |
Date:
23rd March 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Ms Phillimore, a barrister. This follows Ms Phillimore leaving a file containing sensitive personal data in an unattended motor vehicle, from which the file was stolen.
...more |
 |
| |
|
| |
Wolverhampton City Council |
| |
|
|
|
| |
Author:BreachAware |
Date:
15th March 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Wolverhampton City Council. This follows a report in the press about the theft of a skip and the subsequent fly tipping of its contents. The skip contained personal data including bank details, employment records and medical information. The data was traced back to a local community leisure centre. The council confirms that leisure centre staff should not have disposed of personal data in a skip. The information has now been securely destroyed.
...more |
 |
| |
|
| |
Doncaster Metropolitan Borough Council |
| |
|
|
|
| |
Author:BreachAware |
Date:
25th February 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Doncaster Metropolitan Borough Council. This follows the disclosure of third party data by the council during court proceedings.
...more |
 |
| |
|
| |
Aramark Ltd |
| |
|
|
|
| |
Author:BreachAware |
Date:
24th February 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Aramark Ltd. This follows the theft of an unencrypted laptop and paperwork containing employees personal data.
...more |
 |
| |
|
| |
Cambridgeshire County Council |
| |
|
|
|
| |
Author:BreachAware |
Date:
23rd February 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Cambridgeshire County Council. This follows the loss of an unencrypted memory stick containing sensitive personal data.
...more |
 |
| |
|
| |
Identity and Passport Service |
| |
|
|
|
| |
Author:BreachAware |
Date:
21st February 2011 |
Read full article |
| |
The Identity and Passport Service has signed an Undertaking which commits the organisation to taking remedial action after the found it in breach of the Data Protection Act for losing the passport renewal applications of 21 individuals.
...more |
 |
| |
|
| |
Anglesey County Council |
| |
|
|
|
| |
Author:BreachAware |
Date:
18th February 2011 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Isle of Anglesey County Council. This follows the mailing of housing and council tax benefit letters containing financial personal data to the wrong recipients. The council did not have a written agreement in place with the data processor selected to distribute the letters on its behalf. See the text of the Undertaking here.
...more |
 |
| |
|
| |
Gwent Police |
| |
|
|
|
| |
Author:BreachAware |
Date:
11th February 2011 |
Read full article |
| |
Gwent Police has signed an Undertaking which commits the organisation to taking remedial action after the found it in breach of the Data Protection Act for accidentally emailing results of Criminal Reference Bureau (CRB) checks performed by the force to a member of the public.
...more |
 |
| |
|
| |
NHS Blood and Transplant |
| |
|
|
|
| |
Author:BreachAware |
Date:
21st January 2011 |
Read full article |
| |
NHS Blood and Transplant has signed an Undertaking which commits the organisation to being more robust in checking information is accurate. This follows the discovery that organ donation preferences of 444,031 people were recorded inaccurately on the Organ Donation Register, which is managed by NHS Blood and Transplant, due to a software error.
...more |
 |
| |
|
| |
Scottish Court Service |
| |
|
|
|
| |
Author:BreachAware |
Date:
5th January 2011 |
Read full article |
| |
A formal Undertaking has been signed by the Scottish Court Service. Following a newspaper report about a data breach by the Court Service, the discovered that papers containing personal information had been lost by the editor of a series of law reports. The court service had failed to check how this individual intended to keep the information secure.
...more |
 |
| |
|
| |
Stoke-on-Trent City Council |
| |
|
|
|
| |
Author:BreachAware |
Date:
22nd November 2010 |
Read full article |
| |
A formal Undertaking has been signed by Stoke-on-Trent City Council, agreeing to comply with the seventh data protection principle. This follows the discovery of an unencrypted social services memory stick in Hanley containing information about 40 children.
...more |
 |
| |
|
| |
Google Inc |
| |
|
|
|
| |
Author:BreachAware |
Date:
19th November 2010 |
Read full article |
| |
Senior Vice President of Google, Alan Eustace, has signed an Undertaking on behalf of Google Inc. which commits the company to putting into place improved training measures on security awareness and data protection issues for all employees. The company has also said it will require its engineers to maintain a privacy design document for every new project before it is launched. The payload data that Google inadvertently collected in the UK will also be deleted.
...more |
 |
| |
|
| |
Independent Parliamentary Standards Authority (IPSA) |
| |
|
|
|
| |
Author:BreachAware |
Date:
12th November 2010 |
Read full article |
| |
A formal Undertaking has been signed by Andrew McDonald, CEO of the Independent Parliamentary Standards Authority (IPSA), agreeing to comply with the seventh data protection principle. This follows an internal database being left insecure for a period of some 21 hours following IT maintenance. The insecurity resulted in the potential compromise of personal data relating to 332 MPs.
...more |
 |
| |
|
| |
Rainforest Alliance Ltd |
| |
|
|
|
| |
Author:BreachAware |
Date:
11th November 2010 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by the Rainforest Alliance Ltd. This follows the theft of an unencrypted laptop holding personal and financial data relating to employees and job applicants.
...more |
 |
| |
|
| |
Portsmouth City Council |
| |
|
|
|
| |
Author:BreachAware |
Date:
2nd November 2010 |
Read full article |
| |
A formal Undertaking has been signed by Portsmouth City Council following the inappropriate disclosure of personal information relating to an individuals physical and mental health. The council failed to redact documents correctly in a subject access request and so accidentally disclosed information about another individual.
...more |
 |
| |
|
| |
North West London Hospitals NHS Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
19th October 2010 |
Read full article |
| |
The Chief Executive of the North West London Hospitals NHS Trust has signal a formal Undertaking after a doctor left medical information about 56 patients on a tube train.
...more |
 |
| |
|
| |
Lord Chief Justice of Northern Ireland |
| |
|
|
|
| |
Author:BreachAware |
Date:
19th October 2010 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by the Lord Chief Justice of Northern Ireland. This follows the inappropriate disclosure of personal data in an email from his office earlier this year.
...more |
 |
| |
|
| |
Healthcare Locums Plc (HCL) |
| |
|
|
|
| |
Author:BreachAware |
Date:
14th October 2010 |
Read full article |
| |
A formal Undertaking has been signed by Healthcare Locums Plc (HCL). A hard drive containing doctors security clearance and visa information had been sold on an auction website before being returned to HCL.
...more |
 |
| |
|
| |
Forth Valley NHS Board |
| |
|
|
|
| |
Author:BreachAware |
Date:
30th September 2010 |
Read full article |
| |
A formal Undertaking has been signed by Forth Valley NHS Board. The Information Commissioners Office was informed that an unencrypted memory stick with no password protection and containing personal information held by the Board had been handed in to the press.
...more |
 |
| |
|
| |
East & North Hertfordshire NHS Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
20th September 2010 |
Read full article |
| |
A formal Undertaking has been signed by East & North Hertfordshire NHS Trust after an unencrypted USB stick containing sensitive personal data was lost by a member of staff on a train journey.
...more |
 |
| |
|
| |
Yorkshire Building Society (YBS) |
| |
|
|
|
| |
Author:BreachAware |
Date:
26th August 2010 |
Read full article |
| |
A formal Undertaking has been signed by Yorkshire Building Society (YBS), after an unencrypted laptop belonging to the former Chelsea Building Society (CBS), which had recently merged with YBS, was stolen from its Cheltenham premises. The laptop contained a substantial part of the CBS customer database.
...more |
 |
| |
|
| |
DSG Retail |
| |
|
|
|
| |
Author:BreachAware |
Date:
25th August 2010 |
Read full article |
| |
A formal Undertaking has been signed by DSG Retail, following the discovery of customers credit agreements in or near a skip at one of the companys PC World stores. The documents related to transactions made two years prior and had been kept beyond the period recommended by DSGs policies for holding personal data.
...more |
 |
| |
|
| |
Royal Wolverhampton Hospitals NHS Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
24th August 2010 |
Read full article |
| |
A formal Undertaking has been signed by Royal Wolverhampton Hospitals NHS Trust after the loss of over 100 of its patient records. The The Information Commissioners Office was alerted to the loss of a CD which contained scans of 112 patient records from the Intensive Care Unit of New Cross Hospitals Heart and Lung Unit. The CD was discovered at a bus stop near the hospital and was unencrypted with no password protection.
...more |
 |
| |
|
| |
Tunbridge Wells Equitable Friendly Society Limited |
| |
|
|
|
| |
Author:BreachAware |
Date:
19th August 2010 |
Read full article |
| |
A formal Undertaking has been signed by Tunbridge Wells Equitable Friendly Society Limited trading as The Childrens Mutual, after an annual account statement containing confidential personal data was sent in error to the wrong recipient.
...more |
 |
| |
|
| |
Birmingham Childrens Hospital NHS Foundation Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
14th July 2010 |
Read full article |
| |
A formal Undertaking has been signed by Birmingham Childrens Hospital NHS Foundation Trust, agreeing to comply with the seventh data protection principle. This follows the loss of two unencrypted laptops which were stolen from the Medical Day Centre, containing sensitive personal data relating to a number of the Trusts patients.
...more |
 |
| |
|
| |
Kent Police |
| |
|
|
|
| |
Author:BreachAware |
Date:
18th June 2010 |
Read full article |
| |
Adrian Leppard, temporary Chief Constable of Kent Police, has now signed a formal Undertaking to ensure that staff whose roles require them to have access to confidential information outside the office are provided with secure transportation and storage facilities.
...more |
 |
| |
|
| |
NHS Stoke-on-Trent |
| |
|
|
|
| |
Author:BreachAware |
Date:
15th June 2010 |
Read full article |
| |
NHS Stoke-on-Trent has signed a formal Undertaking after 2,000 paper physiotherapy records were not filed within its archive system and may have accidentally been destroyed or misfiled. The organisation will apply physical security measures in respect of paper medical records, particularly when they are in transit.
...more |
 |
| |
|
| |
Basingstoke and North Hampshire NHS Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
15th June 2010 |
Read full article |
| |
Basingstoke and North Hampshire NHS Trust has signed a formal Undertaking after an excel spreadsheet, containing 917 patients pathology results, was emailed via an unsecure address to another department. The spreadsheet was not password protected and the receiving department had no business need to have access to the excessive amount of clinical records.
...more |
 |
| |
|
| |
Lampeter Medical Practice |
| |
|
|
|
| |
Author:BreachAware |
Date:
3rd June 2010 |
Read full article |
| |
Dr Rowena Mathew, Head of Practice of Lampeter Medical Practice, has signed a formal Undertaking after an unencrypted memory stick containing the personal details of 8,000 patients was reported lost to the ICO.
...more |
 |
| |
|
| |
West Berkshire Council |
| |
|
|
|
| |
Author:BreachAware |
Date:
2nd June 2010 |
Read full article |
| |
West Berkshire Council has signed a formal Undertaking to ensure that portable and mobile devices used to store and transmit personal data are encrypted. The Information Commissioners Office (ICO) found it in breach of the Data Protection Act (DPA) following the loss of a USB stick containing the sensitive personal information of children and young people.
...more |
 |
| |
|
| |
Eastbourne Borough Council |
| |
|
|
|
| |
Author:BreachAware |
Date:
7th May 2010 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Eastbourne Borough Council. This follows the theft of an unencrypted laptop containing personal data from the Towner Gallery in January.
...more |
 |
| |
|
| |
Kings College London |
| |
|
|
|
| |
Author:BreachAware |
Date:
5th May 2010 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Kings College London. This follows two incidents in which computers containing sensitive personal data were stolen from its academic offices at teaching hospitals.
...more |
 |
| |
|
| |
NCL (Bahamas) Ltd |
| |
|
|
|
| |
Author:BreachAware |
Date:
4th May 2010 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by NCL (Bahamas) Ltd. This follows the suspected theft of a computer printout containing payroll details for the companys 80 UK employees.
...more |
 |
| |
|
| |
Bolton Youth Offending Team |
| |
|
|
|
| |
Author:BreachAware |
Date:
4th May 2010 |
Read full article |
| |
A formal Undertaking has been signed by Bolton Youth Offending Team, agreeing to comply with the seventh data protection principle. This follows the theft of a camcorder with video footage containing sensitive personal data relating to three individuals.
...more |
 |
| |
|
| |
South Yorkshire Pensions Authority |
| |
|
|
|
| |
Author:BreachAware |
Date:
28th April 2010 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by South Yorkshire Pensions Authority. This follows the loss of an unencrypted CD containing personal data of 9,140 pension scheme members.
...more |
 |
| |
|
| |
St James Primary School |
| |
|
|
|
| |
Author:BreachAware |
Date:
23rd April 2010 |
Read full article |
| |
A formal Undertaking has been signed by St James Primary School, agreeing to comply with the seventh data protection principle. This follows the theft of a memory stick containing sensitive personal data relating to a number of pupils.
...more |
 |
| |
|
| |
Ysgol Bro Famau |
| |
|
|
|
| |
Author:BreachAware |
Date:
22nd April 2010 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by the headteacher of Ysgol Bro Famau, in Denbighshire. This follows the theft of the schools administration computer, which contained significant amounts of personal data relating to pupils.
...more |
 |
| |
|
| |
Birmingham and Solihull Mental Health NHS Foundation Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
22nd April 2010 |
Read full article |
| |
A formal Undertaking has been signed by Sue Turner, CEO, of the Birmingham and Solihull Mental Health NHS Foundation Trust agreeing to comply with the fifth and seventh data protection principles. This follows the theft of an unencrypted laptop computer which contained personal data relating to some 1,500 of Trusts patients and some 450 staff.
...more |
 |
| |
|
| |
Warwickshire County Council |
| |
|
|
|
| |
Author:BreachAware |
Date:
31st March 2010 |
Read full article |
| |
The Information Commissioners Office has found Warwickshire County Council in breach of the Data Protection Act following the theft of two laptops and the loss of a memory stick. The Chief Executive of Warwickshire County Council has signed a formal Undertaking to ensure that portable and mobile devices used to store and transmit personal data are encrypted.
...more |
 |
| |
|
| |
Zurich Insurance plc |
| |
|
|
|
| |
Author:BreachAware |
Date:
24th March 2010 |
Read full article |
| |
An Undertaking has been signed by Zurich Insurance plc after the Information Commissioners Office found the company in breach of the Data Protection Act. Zurich Insurance plc lost an unencrypted back-up tape containing financial personal information belonging to 46,000 policy holders of Zurich Private Client, Zurich Special Risk and Zurich Business Client, which are all part of Zurich Insurance plc.
...more |
 |
| |
|
| |
Royal London Mutual Insurance Society |
| |
|
|
|
| |
Author:BreachAware |
Date:
3rd March 2010 |
Read full article |
| |
The Information Commissioners Office has found that the Royal London Mutual Insurance Society breached the Data Protection Act (DPA) after eight laptops, two of which contained the personal details of 2,135 people, were stolen from the companys Edinburgh offices. Michael Yardley, Group Chief Executive Officer of the company, has now signed an official Undertaking to ensure that portable and mobile devices including laptops are encrypted.
...more |
 |
| |
|
| |
Redstone Mortgages Ltd |
| |
|
|
|
| |
Author:BreachAware |
Date:
19th February 2010 |
Read full article |
| |
An Undertaking to comply with the seventh data protection principle has been signed by Redstone Mortgages Ltd, following the disclosure of reports containing personal data of over 15,000 mortgage customers last August.
...more |
 |
| |
|
| |
The Alzheimers Society |
| |
|
|
|
| |
Author:BreachAware |
Date:
11th February 2010 |
Read full article |
| |
The Alzheimers Society has signed a formal Undertaking promising to improve security after it reported three seperate breaches involving personal information to the Information Commissioners Office during 2009. The Undertaking also requires staff to be made aware of the Societys policies for the storage, use and disposal of personal information. Staff must receive appropriate training on how to follow these policies.
...more |
 |
| |
|
| |
Bellgrange Mortgages and Insurance Services Ltd |
| |
|
|
|
| |
Author:BreachAware |
Date:
11th January 2010 |
Read full article |
| |
The Information Commissioners Office has found Bellgrange Mortgages and Insurance Services Ltd in breach of the Data Protection Act after clients details were found in two large waste bins intended for the use of local residents. The organisation, based in Stanmore, has signed an official Undertaking to improve data security.
...more |
 |
| |
|
| |
Association of Teachers and Lecturers (ATL) |
| |
|
|
|
| |
Author:BreachAware |
Date:
1st January 2010 |
Read full article |
| |
The Information Commissioners Office has found the Association of Teachers and Lecturers (ATL) in breach of the Data Protection Act after a laptop and memory stick were reported lost or stolen, containing the personal details of over 6,000 union members. ATL General Secretary, Mary Bousted, has now signed an Undertaking to ensure that by 28 February 2010 all portable and mobile devices used to store and transmit personal details are encrypted.
...more |
 |
| |
|
| |
Waseley Hills High School and Sixth Form Centre |
| |
|
|
|
| |
Author:BreachAware |
Date:
15th December 2009 |
Read full article |
| |
A formal Undertaking has been signed by Waseley Hills High School and Sixth Form Centre committing it to take a number of steps to ensure that personal data is processed in compliance with the Data Protection Act. The Information Commissioners Office found it in breach of the Data Protection Act after the theft of personal data of over 1,000 pupils and staff.
...more |
 |
| |
|
| |
Orbit Heart of England Housing Association |
| |
|
|
|
| |
Author:BreachAware |
Date:
11th December 2009 |
Read full article |
| |
A formal Undertaking has been signed by the Orbit Heart of England Housing Association after the Information Commissioners Office found them to be in breach of the Data Protection Act. 57 paper files containing personal data went missing during an office move. Forty-two of the files were recovered in full, but 15 which contain a significant amount of personal data relating to each tenant and, in some cases, members of his or her family, are still missing.
...more |
 |
| |
|
| |
Verity Trustees Ltd |
| |
|
|
|
| |
Author:BreachAware |
Date:
26th November 2009 |
Read full article |
| |
A formal Undertaking has been signed by Verity Trustees Ltd after the Information Commissioners Office found them to be in breach of the Data Protection Act. The Trustees reported the theft of a laptop computer containing the names, addresses, dates of birth, salaries and national insurance numbers of around 110,000 individuals.
...more |
 |
| |
|
| |
Gloucestershire Primary Care Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
13th November 2009 |
Read full article |
| |
Formal Undertakings have been signed by Gloucestershire Primary Care Trust after the Information Commissioners Office found them in breach of the Data Protection Act.
...more |
 |
| |
|
| |
Great Yarmouth and Waveney Primary Care Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
13th November 2009 |
Read full article |
| |
Formal Undertakings have been signed by Great Yarmouth and Waveney Primary Care Trust after the Information Commissioners Office found them in breach of the Data Protection Act.
...more |
 |
| |
|
| |
Ashford and St Peters Hospitals NHS Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
27th October 2009 |
Read full article |
| |
Ashford and St Peters Hospitals NHS Trust has signed an Undertaking and agreed to improve data security after it informed the Information Commissioners Office of a data breach involving the loss or theft of three unencrypted USB sticks containing sensitive patient information. Each of the devices contained the full treatment and full diagnosis history relating to a number of cancer patients. The information on the USB sticks was in Word format - leaving the material easily accessible to anyone with a computer.
...more |
 |
| |
|
| |
NHS Grampian |
| |
|
|
|
| |
Author:BreachAware |
Date:
14th September 2009 |
Read full article |
| |
A formal Undertaking has been signed by NHS Grampian, agreeing to comply with the seventh data protection principle. This follows several data security breaches there in the past few months.
...more |
 |
| |
|
| |
Billing Pharmacy Ltd |
| |
|
|
|
| |
Author:BreachAware |
Date:
14th September 2009 |
Read full article |
| |
A formal Undertaking has been signed by Billing Pharmacy Ltd, agreeing to comply with the seventh data protection principle. This follows the theft of an unencrypted computer containing sensitive personal data for around 1,000 customers.
...more |
 |
| |
|
| |
NHS Education for Scotland |
| |
|
|
|
| |
Author:BreachAware |
Date:
8th September 2009 |
Read full article |
| |
A formal Undertaking has been signed by NHS Education for Scotland, theft of an unencrypted laptop. The laptop contained the personal information of 6377 applicants for medical training positions.
...more |
 |
| |
|
| |
Ipswich Hospital NHS Trus |
| |
|
|
|
| |
Author:BreachAware |
Date:
7th September 2009 |
Read full article |
| |
A formal Undertaking has been signed by Ipswich Hospital NHS Trust, agreeing to comply with the seventh data protection principle. A ward summary list, containing patients personal data, was found outside the hospital premises. A similar incident had occurred in 2008, but some resulting recommendations had not been implemented. ...more |
 |
| |
|
| |
Sandwell Metropolitan Borough Council |
| |
|
|
|
| |
Author:BreachAware |
Date:
4th September 2009 |
Read full article |
| |
A formal Undertaking has been signed by Sandwell Metropolitan Borough Council after an unencrypted memory stick was lost by an employee. The memory stick, which was not password protected, contained sensitive personal information relating to four families, including why children were taken into care or made subject to a Child Protection Plan.
...more |
 |
| |
|
| |
Wigan Council |
| |
|
|
|
| |
Author:BreachAware |
Date:
3rd September 2009 |
Read full article |
| |
Wigan Council has signed an Undertaking after the theft of a laptop computer containing personal information relating to approximately 43,000 children and young people. The laptop included personal details on most children and young people in Wigans schools. The information had been downloaded on to the laptop in breach of council policy.
...more |
 |
| |
|
| |
London Borough of Sutton |
| |
|
|
|
| |
Author:BreachAware |
Date:
21st August 2009 |
Read full article |
| |
London Borough of Sutton has signed an Undertaking following an investigation by the into several data security incidents. These included the loss of a paper file which contained personal data relating to 73 individuals receiving social care and the theft of two unencrypted laptops. A package of documents also went missing when a courier used by the council left it with the recipients neighbour.
...more |
 |
| |
|
| |
Repair Management Services Ltd |
| |
|
|
|
| |
Author:BreachAware |
Date:
20th August 2009 |
Read full article |
| |
A formal Undertaking has been signed by Repair Management Services Ltd (formally MVRA), a trade body that provides advice to businesses involved in motor vehicle repair. It follows the theft of an unencrypted laptop containing the personal information of approximately 36,800 individuals. The laptop, which was stolen from a secure vehicle in a public car park, was password protected but unencrypted.
...more |
 |
| |
|
| |
East Cheshire NHS Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
14th August 2009 |
Read full article |
| |
A formal Undertaking has been signed by after pages from an Accident and Emergency register were found in a garden in Newcastle-under-Lyme. The pages contained sensitive personal data relating to the physical and mental health of over 60 patients. The loss followed an office move involving various departments of the Trust during which an external company was hired, without a written contract, to clear out rubbish from the old premises.
...more |
 |
| |
|
| |
Gipping Valley Practice |
| |
|
|
|
| |
Author:BreachAware |
Date:
12th August 2009 |
Read full article |
| |
A formal Undertaking has been signed by Dr Paul Thomas of the Gipping Valley Practice, Ipswich, agreeing to comply with the seventh data protection principle. This follows the discovery of a Practice server found in the car park of the Practice by an employee of the Suffolk Primary Care Trust. The server contained the sensitive personal data of a large number of Practice patients and the personal data of Practice employees.
...more |
 |
| |
|
| |
Imperial College Healthcare NHS Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
28th July 2009 |
Read full article |
| |
A formal Undertaking has been signed by Imperial College Healthcare NHS Trust at St Marys Hospital, South Wharf Road, London, agreeing to comply with the seventh data protection principle. This follows the theft of six unencrypted laptop computers (two incidents) and the loss of a small number of paper records which, in total, contained personal data relating to some 6,000 of the Trusts patients. |
 |
| |
|
| |
London Clubs International Limited |
| |
|
|
|
| |
Author:BreachAware |
Date:
28th July 2009 |
Read full article |
| |
A formal Undertaking has been signed by London Clubs International Limited agreeing to comply with the seventh data protection principle. This follows the theft of an unencrypted laptop containing the data of approximately 26,000 customers.
...more |
 |
| |
|
| |
NHS Lothian |
| |
|
|
|
| |
Author:BreachAware |
Date:
28th July 2009 |
Read full article |
| |
A formal Undertaking has been signed by NHS Lothian agreeing to comply with the seventh data protection principle. This follows the theft of an unencrypted memory stick and some paper files temporarily left in a shop.
...more |
 |
| |
|
| |
Neath Port Talbot County Borough Council |
| |
|
|
|
| |
Author:BreachAware |
Date:
23rd July 2009 |
Read full article |
| |
A formal Undertaking has been signed by Neath Port Talbot County Borough Council agreeing to comply with the seventh data protection principle. This follows the loss of a memory stick containing information relating to 65 children.
...more |
 |
| |
|
| |
The Highland Council |
| |
|
|
|
| |
Author:BreachAware |
Date:
22nd July 2009 |
Read full article |
| |
A formal Undertaking has been signed by The Highland Council agreeing to comply with the seventh data protection principle. This follows the theft of two laptop computers from the authorities premises in Inverness.
...more |
 |
| |
|
| |
Oldham Council |
| |
|
|
|
| |
Author:BreachAware |
Date:
15th July 2009 |
Read full article |
| |
A formal Undertaking has been signed by Oldham Council agreeing to comply with the seventh data protection principle. This follows the theft of a total of 13 unencrypted laptop computers, of which 3 computers contained personal data relating to a total of some 220 Oldham Council residents. With the exception of one, the computers concerned were stolen from Council premises, eleven computers were stolen in the course of a burglary at secure Council offices, one computer was stolen from a staff members car and one was stolen during the course of a youth activity evening.
...more |
 |
| |
|
| |
Counted4 CIC |
| |
|
|
|
| |
Author:BreachAware |
Date:
15th July 2009 |
Read full article |
| |
A formal Undertaking has been signed by Counted4 CIC of 4 Mary Street, Sunderland, Tyne & Wear, SR1 3NH. agreeing to comply with the seventh data protection principle. This follows the loss of a number of paper records containing sensitive personal information to 84 of the organisations clients. The records were in a locked filing cabinet which appears to have been accidentally destroyed during an office move.
...more |
 |
| |
|
| |
Jubilee Managing Agency Limited |
| |
|
|
|
| |
Author:BreachAware |
Date:
14th July 2009 |
Read full article |
| |
A formal Undertaking has been signed by Jubilee Managing Agency Limited, agreeing to comply with the fifth and seventh data protection principles. This follows the loss of an unencrypted disk containing personal data, including financial details, relating to 2100 policy holders. Some of the data also related to cancelled or expired policies.
...more |
 |
| |
|
| |
Surrey and Sussex Healthcare NHS Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
14th July 2009 |
Read full article |
| |
A formal Undertaking has been signed by Surrey and Sussex Healthcare NHS Trust agreeing to comply with the seventh data protection principle. This follows the loss a ward hand over sheet and the theft of two unencrypted laptop computers containing personal data relating to 23 and up to 80 of the Trusts patients respectively.
...more |
 |
| |
|
| |
The Royal Free Hampstead NHS Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
14th July 2009 |
Read full article |
| |
A formal Undertaking has been signed by The Royal Free Hampstead NHS Trust agreeing to comply with the seventh data protection principle. This follows the loss of an unencrypted computer disk containing personal data relating to some of the Trusts patients.
...more |
 |
| |
|
| |
Nightingale Practice |
| |
|
|
|
| |
Author:BreachAware |
Date:
14th July 2009 |
Read full article |
| |
A formal Undertaking has been signed by the Nightingale Practice, within the City & Hackney Teaching Primary Care Trust of St. Leonards, Nuttall, Street, London, N1 5LZ agreeing to comply with the seventh data protection principle. This follows the theft of 10 back up tapes and a USB portable hard drive, containing personal data relating to some 7,700 of the practices patients. The USB hard drive and 5 of the back up tapes were not encryption protected.
...more |
 |
| |
|
| |
Hampshire Partnership NHS Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
14th July 2009 |
Read full article |
| |
A second formal Undertaking has been signed by The Hampshire Partnership NHS Trust, agreeing to comply with the seventh data protection principle. This follows the theft of an unencrypted laptop computer, containing the personal data of 349 patients and 258 members of staff, from a Trust employee who attended a conference at a London hotel.
...more |
 |
| |
|
| |
Epsom & St Helier University Hospitals NHS Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
14th July 2009 |
Read full article |
| |
A formal Undertaking has been signed by Epsom & St Helier University Hospitals NHS Trust of Wrythe Lane, Carshalton, Sutton, SM5 1AA, agreeing to comply with the seventh data protection principle. This follows the discovery of the insecure storage of hospital records, relating to a large number of the Trusts patients.
...more |
 |
| |
|
| |
Chelsea & Westminster Hospital NHS Foundation Trust |
| |
|
|
|
| |
Author:BreachAware |
Date:
14th July 2009 |
Read full article |
| |
A formal Undertaking has been signed by Chelsea & Westminster Hospital NHS Foundation Trust agreeing to comply with the seventh data protection principle. This follows the theft of an unencrypted USB memory stick containing personal data relating to 143 of the Trusts patients.
...more |
 |