NHS trust and local council hit back at ICO fines
Public sector organisations dispute cases that netted the data protection watchdog £415,000.
The second breach involved the disclosure of foster care details for two young children to their mother. As a result, both children had to be moved to alternative accommodation.
Following an investigation by the ICO, the breaches were attributed to the settings used on a council child information system called Protocol.
While we accept the breaches occurred, we do not agree with the rationale behind the financial penalty that has been imposed.
Its findings showed that, in the first breach, Protocol contained insufficient information about the children involved and did not allow people to check documents before they were posted out.
The default settings of Protocol were blamed for the second breach, which automatically included foster carer's details in the children's placement information records. It is also claimed there was no process in place to check these records once they have been printed.
David Smith, the ICO's deputy commissioner and director of data protection, said: "These were two very similar data breaches which occurred within a short space of time, and both involved highly confidential and sensitive personal data.
"It is the responsibility of all organisations especially where children or other vulnerable people are involved to keep sensitive personal data secure," said Smith.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
In statement to IT Pro, Telford and Wrekin Council said the fine should be reduced by 18,000 in recognition of how promptly it will be paid.
"While we accept the breaches occurred, we do not agree with the rationale behind the financial penalty that has been imposed," said the statement.
"We believe the fine goes against the ICO's own guidance, which states an organisation should not be fined when it has taken reasonable steps to prevent a breach, which we believe we have."
-
NHS supplier DXS International confirms cyber attack – here’s what we know so farNews The NHS supplier says front-line clinical services are unaffected
-
LastPass hit with ICO fine after 2022 data breach exposed 1.6 million users – here’s how the incident unfoldedNews The impact of the LastPass breach was felt by customers as late as December 2024
-
23andMe 'failed to take basic steps' to safeguard customer dataNews The ICO has strong criticism for the way the genetic testing company responded to a 2023 breach.
-
Two more NHS Trusts have been hit with cyber attacks – here’s what we know so farNews A flaw in a third-party device management tool appears to be the source of the incident
-
NHS England launches cyber charter to shore up vendor security practicesNews Voluntary charter follows a series of high-profile ransomware attacks
-
NHS supplier hit with £3m fine for security failings that led to attackNews Advanced Computer Software Group lacked MFA, comprehensive vulnerability scanning and proper patch management
-
Cyber attack delayed cancer treatment at NHS hospitalNews A cyber attack at Wirral University Teaching Hospital in 2024 delayed critical cancer treatment for patients, documents show.
-
Alder Hey Children’s Hospital confirms hackers gained access to patient data through digital gateway serviceNews Europe’s busiest children’s hospital confirmed attackers were able to steal data from a compromised digital gateway service

