Outsourcing personal employee data cost council £250,000 in penalties

-

A Council whose former employees’ pension records were found in an over-filled paper recycle bank in a supermarket car park has been fined £250,000 for the data breach.

Scottish Borders Council employed an outside company to digitise the records, but failed to seek appropriate guarantees on how the personal data would be kept secure. That prompted the Information Commissioner to use his powers under the Data Protection Act to impose a Civil Monetary Penalty of £250,000 on the Council.

The Data Protection Act requires that, if you decide to use another organisation to process personal data for you, you remain legally responsible for the security of the data and for protecting the rights of the individuals whose data is being processed.

But Scottish Borders Council put no contract in place with the third party processor, sought no guarantees on the technical and organisational security protecting the records and did not make sufficient attempts to monitor how the data was being handled.

Get our essential weekday HR news and updates.

This field is for validation purposes and should be left unchanged.
Keep up with the latest in HR...
This field is hidden when viewing the form
This field is hidden when viewing the form
Optin_date
This field is hidden when viewing the form

 

It is believed more than 600 files were deposited at the recycle bins, containing confidential information and, in a significant number of cases, salary and bank account details. The files were spotted by a member of the public who called police, prompting the recovery of 676 files. A further 172 files deposited on the same day but at a different paper recycling bank are thought to have been destroyed in the recycling process.

Latest news

Exclusive: London bus drivers’ ‘dignity’ at risk as strikes loom over welfare concerns

London bus drivers raise concerns over fatigue and lack of facilities as potential strikes escalate long-standing welfare issues.

Whistleblowing reports ‘surge by up to 250 percent’ at councils as new rights take effect

Whistleblowing cases are rising across UK councils as stronger workplace protections come into force, though concerns remain about underreporting of serious issues.

Bullying and harassment to become regulatory breaches under new FCA rules

New rules will bring bullying and harassment into regulatory scope, as firms face rising reports of workplace misconduct.

Personalising the Benefits Experience: Why Employees Need More Than Just Information

This article explores how organisations can move beyond passive, one-size-fits-all communication to deliver relevant, timely, and simplified benefits experiences that reflect employee needs and life stages.
- Advertisement -

Grant Wyatt: When the love dies – when staying is riskier than quitting

When people fall out of love with their employer, or feel their employer has fallen out of love with them, what follows is rarely a clean exit.

£30bn pension savings window opens for employers ahead of 2029 reforms

UK employers could unlock billions in National Insurance savings by expanding pension salary sacrifice schemes before new limits take effect in 2029.

Must read

Alexandra Farmer: Is targeted flexible working as beneficial as a four-day week for the masses?

Alexandra Farmer explores the implications of the results of one of the largest trials of a four-day working week in the UK.

David Chandler: How HR teams can sprint ahead in the battle for talent

"With employment levels at a record high in an ever-increasing employee-driven market, the challenge is on for HR leaders when it comes to retaining and nurturing talent."
- Advertisement -

You might also likeRELATED
Recommended to you