Ministry of Justice hit with £140K data breach fine
Information Commissioner's Office hits out after prison staff email sensitive information about inmates to several people.

The Ministry of Justice has been hit with a 140,000 data breach fine after details about all the prisoners serving at a Welsh jail were emailed to several inmates' families.
The incident came to light in August 2011 after one of the recipients alerted HMP Cardiff about receiving a spreadsheet stating the names, ethnicities, addresses, sentence length and release date information about all 1,182 of the prison's inmates.
The document was attached to an email about a forthcoming visit, and also contained coded information about the offences the inmates had carried out.
These types of incidents are extremely rare but this does not mean that we are complacent.
An internal investigation into the incident also revealed the same error had occurred on two other occasions the previous month, with the details being forwarded on to two further families.
Neither of these incidents was reported at the time, and all three recipients were visited by the police and prison staff to ensure the information was deleted.
Even so, the Ministry of Justice has been ordered to pay a 140,000 fine by the Information Commissioner's Office (ICO) for breaching the Data Protection Act.
The breach was reported to the ICO a month after the third breach took place, with an investigation by the data protection watchdog flagging several areas of concern regarding the organisation's approach to data handling.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
For example, the investigation revealed unencrypted floppy disks were regularly used to transfer large volumes of data between prison networks, while a lack of audit trails means the disclosures would have gone unnoticed if the breach had not been reported in the first place.
David Smith, the deputy commissioner and director of data protection, said although the fallout from the breach was contained the leaked information could potentially have put the affected prisoners and their families at risk.
"The potential damage and distress that could have been caused by this serious data breach is obvious. Disclosing this information not only had the potential to put the prisoners at risk, but also risked the welfare of their families through the release of their home addresses," explained Smith.
"It is only due to the honesty of a member of the public that the disclosures were uncovered as early as they were and that it was still possible to contain the breach," he added.
In a statement to IT Pro, a Ministry of Justice spokesperson said the organisation takes information security "very seriously" and assured those concerned that it took "immediate steps" to recover the leaked data.
"These types of incidents are extremely rare but this does not mean that we are complacent," the statement continued.
"A thorough investigation was held by the prison who immediately altered their procedures, and further changes were implemented across the prison estate."
-
M&S suspends online sales as 'cyber incident' continues
News Marks & Spencer (M&S) has informed customers that all online and app sales have been suspended as the high street retailer battles a ‘cyber incident’.
By Ross Kelly
-
Manners cost nothing, unless you’re using ChatGPT
Opinion Polite users are costing OpenAI millions of dollars each year – but Ps and Qs are a small dent in what ChatGPT could cost the planet
By Ross Kelly
-
TikTok to open first European data centre in Ireland
News The move could signify a desire to shift its operations away from the US as well as secure its position in the European market
By Sabina Weston
-
MPs in a muddle over GDPR and storing voters' personal data
News Labour MP Chris Bryant says his staff were told to delete constituents' data
By Bobby Hellard
-
Trump resort will not be charged for breaching data laws
News Presidential hopeful's Scottish golf course failed to register under the Data Protection Act for four years
By Adam Shepherd
-
Banks urged to share data but warned over security
News Experts voice concern over security of open API recommendations
By Rene Millman
-
EU centralises European open data through one portal
News Open Data Portal will enable public sector bodies to share information
By Rene Millman
-
Experts question sheer scale of data storage required by Snooper's Charter
News Who will foot bill for physical infrastructure to house UK's browsing histories?
By Jane McCallion
-
Snapchat's T&Cs update could put user data at risk
News Kaspersky said giving the service permission to share pictures with third parties could lead to a serious breach of privacy
By Clare Hopping
-
Transport Systems Catapult launches data sources catalogue
News Intelligent Mobility Data Index could push forward smart transport innovation in the UK
By Caroline Preece