Breach of the data protection peace
With the ICO rarely fining for breaches of the Data Protection Act, are businesses breaking rules as they can get away with it or is the ICO bringing about some other type of corporate telling off?

You don't have to read too far into the Information Commissioner's Office (ICO) website to find its mission statement. The ICO has been established to "Uphold information rights in the public interest, promoting openness by public bodies and data privacy for individuals."
Lone justice?
With this declaration in mind, one might naturally question the statistics pertaining to recent judiciary actions carried out by the ICO. Reports earlier this year highlighted the fact just 36 out of 2,565 data breaches were acted upon by the ICO, with only four cases resulting in monetary fines.
Security vendors from far and wide have used this apparent' shortfall in regulatory discipline as a platform for reinforcing the effectiveness of their data protection products. So as the Data Protection Act (DPA) and issues relating to information compliance gain an ever-greater number of column inches, is it time to question whether we are at an industry tipping point and about to fall?
Is it time to question whether we are at an industry tipping point and about to fall?
"The reports noting that just one per cent of data breaches have been fined by the ICO risk undermining its power to force companies to take their internal security measures seriously," said Nigel Hawthorn, vice president of EMEA marketing for Blue Coat Systems.
"When the ICO increased the maximum fine tenfold from 50,000 to half a million pounds last year, this should have sent a clear message to the market that companies needed to get their house in order. But why bother sharpening the ICO's teeth if they are not prepared to bite?"
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Industry opinion appears to lay part of the blame for compliance issues on the proliferation of devices and flexibility of new work practices. Both of these factors are further fuelled by the consumerisation of IT, which makes it increasingly difficult for companies to protect data and increasingly easy to lose it.
Matthew Tomlinson, a board director at secure network specialist Secure Data, said we will see an increase in audits and fines from the ICO over the coming years, but companies really need to take responsibility for data protection and start policing themselves.
"In practice it is unrealistic for the ICO to audit every company; they do not have the resources or the capacity," he said.
"However, we are seeing larger corporations already beginning to police themselves due, foremost, to the fear of public backlash if they were to have a major data breach. You only have to look at the recent Sony data breach to see the public affect it has on the company."
-
Cisco takes aim at AI security at RSAC with ServiceNow partnership
News The companies claim Cisco AI Defense and ServiceNow SecOps will help address new challenges raised by AI
By Jane McCallion
-
Why veterans can excel in data centers – and could help the IT sector address its skill shortages
In-depth Ex-military workers can bring software and hardware to civilian roles
By John Loeppky
-
Homeland Security warns businesses of Oracle and SAP ERP vulnerabilities
News Oracle and SAP urge customers to apply patches to secure systems against hackers
By Keumars Afifi-Sabet
-
Most CEOs steal IP from previous employers
News Emotionally-driven decisions put companies at risk, finds security report
By Keumars Afifi-Sabet
-
70% of UK bosses have no training to deal with cyber attacks
News Britain's business leaders are woefully underprepared for breaches, report shows
By Adam Shepherd
-
Three foolproof ways CEOs and CISOs can work together more effectively
In-depth How involved is your Chief Information Security Officer (CISO) in business decisions?
By Caroline Preece
-
Three suffers another data breach
News Personal data gets exposed to the wrong customers via My3 portal
By Adam Shepherd
-
Over 133,000 Three mobile customers hit by data breach
News Names, addresses and other information may have been accessed by criminals
By Jane McCallion
-
CEO's pay should be linked to security performance, says government committee
News New report recommends that CEOs be held directly accountable for data breaches
By Adam Shepherd
-
ICO and mobile networks join forces to cut spam text messages
News EE, O2, Three, Vodafone have all signed up to the scheme that will rely on consumers reporting spam texts
By Clare Hopping