Breach of the data protection peace
With the ICO rarely fining for breaches of the Data Protection Act, are businesses breaking rules as they can get away with it or is the ICO bringing about some other type of corporate telling off?

Is this just the beginning of what will become a more rigid and strict approach to data protection act breaches? Industry chatter suggests we have seen this all before PCI started by not fining and allowing companies to miss their deadlines, but things are now much stricter and the fines are filtering through.
On the face of it, name and shame' legislation is still arguably very thin here in Europe, but the European Commission is currently weighing up whether it should enforce mandatory data breach notifications. With breaches increasing in regularity, most would argue the penalties are likely to become more severe.
"While it is true that between 6 April 2010 and 22 March 2011 the ICO concluded that in 2,565 cases compliance with the Data Protection Act was unlikely, over half of these complaints concerned subject access requests whereby an individual has either not been provided with all of the information an organisation holds about them or has not received this information within 40 days. The majority of these types of request will be resolved before there's a need for further enforcement action," said the ICO.
Most would argue the penalties are likely to become more severe.
The organisation added: "The figure for reported cases where information has been disclosed or lost and a monetary penalty is therefore more likely is only around a quarter of the total mentioned. These vary from minor administrative errors where enforcement action would not be appropriate to serious data losses which led to the ICO imposing a monetary penalty."
So, did the ICO make short shrift of its work practices when first questioned with a Freedom of information (FoI) request initially put forward by encryption firm ViaSat? For the most part, the answer is yes.
Has the industry attempted to fuel debate over data security and compliance issues to sell software licenses as a result? Generally speaking, the answer is yes.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Do we need to take an industry-wide more stringent approach to data security, compliance and regulation as a whole? Without question, it is a yes.
-
M&S suspends online sales as 'cyber incident' continues
News Marks & Spencer (M&S) has informed customers that all online and app sales have been suspended as the high street retailer battles a ‘cyber incident’.
By Ross Kelly
-
Manners cost nothing, unless you’re using ChatGPT
Opinion Polite users are costing OpenAI millions of dollars each year – but Ps and Qs are a small dent in what ChatGPT could cost the planet
By Ross Kelly
-
Homeland Security warns businesses of Oracle and SAP ERP vulnerabilities
News Oracle and SAP urge customers to apply patches to secure systems against hackers
By Keumars Afifi-Sabet
-
Most CEOs steal IP from previous employers
News Emotionally-driven decisions put companies at risk, finds security report
By Keumars Afifi-Sabet
-
70% of UK bosses have no training to deal with cyber attacks
News Britain's business leaders are woefully underprepared for breaches, report shows
By Adam Shepherd
-
Three foolproof ways CEOs and CISOs can work together more effectively
In-depth How involved is your Chief Information Security Officer (CISO) in business decisions?
By Caroline Preece
-
Three suffers another data breach
News Personal data gets exposed to the wrong customers via My3 portal
By Adam Shepherd
-
Over 133,000 Three mobile customers hit by data breach
News Names, addresses and other information may have been accessed by criminals
By Jane McCallion
-
CEO's pay should be linked to security performance, says government committee
News New report recommends that CEOs be held directly accountable for data breaches
By Adam Shepherd
-
ICO and mobile networks join forces to cut spam text messages
News EE, O2, Three, Vodafone have all signed up to the scheme that will rely on consumers reporting spam texts
By Clare Hopping