16.10.2012

Greater Manchester Police force pays £120,000 penalty for data breach

Greater Manchester Police force pays…

twitter icon

An ICO investigation into a data breach at Greater Manchester Police has concluded with the force being fined for failing to take appropriate measures against the loss of personal data. The action was prompted by the theft of a memory stick containing sensitive personal data from an officer’s home. The device, which had no password protection, contained details of more than a thousand people with links to serious crime investigations. The ICO found that a number of officers across the force regularly used unencrypted memory sticks, which may also have been used to copy data from police computers to access away from the office. Despite a similar security breach in September 2010, the force had not put restrictions on downloading information, and staff were not sufficiently trained in data protection. The findings prompted the Information Commissioner to use his powers under the Data Protection Act to impose a Civil Monetary Penalty of £150,000. Greater Manchester Police paid that penalty yesterday, taking advantage of a 20 per cent early payment discount (£120,000). David Smith, ICO Director of Data Protection, said: “This was truly sensitive personal data, left in the hands of a burglar by poor data security. The consequences of this type of breach really do send a shiver down the spine. “It should have been obvious to the force that the type of information stored on its computers meant proper data security was needed. Instead, it has taken a serious data breach to prompt it into action. “This is a substantial monetary penalty, reflecting the significant failings the force demonstrated. We hope it will discourage others from making the same data protection mistakes.” The monetary penalty is paid into the Treasury’s Consolidated Fund and is not kept by the Commissioner. If you are concerned about the how to protect your data, respond to a breach or adhere to a standard like the PCI DSS or ISO27001 please feel free to give me a call/email(07889 183207 - andrew.barratt@ptpconsultingllp.com).

Contact Details Mobile - 07889 183 207 Skype - andrewbarratt andrew.barratt@coalfire.com Andrew is an experienced IT and Information Security Consultant, PCI DSS advisor and QSA. As a…

Follow us for more articles and posts direct from professionals on      
Business Management

Facebook - hacked - are you?

Facebook recently announced that they had been subject to a highly sophisticated attack. Whilst facebook's internal…
Business Management

Coca Cola - CEO hacked

The BBC has recently published that the CEO of coca cola http://www.bbc.co.uk/news/technology-20204671 suffered an IT…
Business Management

It could be you... Euromillions website gets hacked.

The BBC is reporting that http://www.bbc.co.uk/news/world-europe-20118960 the Euromillions French website has been…

More Articles

Business Management

Tricks of the infosec trade - by Pen Test Partner Ken Munro

Sending hackers on a wild goose chase, and ‘playing dead' in front of thieves, are brilliant ploys – but they're not…
Business Management

BYOD - Bring Your Own Disaster!

Bring Your Own Device - perhaps we should call it "Bring Your Own Disaster!" There have been lots of good reasons…
Business Management

Social media perils!

The media has been crawling all over Ashley Cole the England left back criticising him heavily for use of certain…

Would you like to promote an article ?

Post articles and opinions on Manchester Professionals to attract new clients and referrals. Feature in newsletters.
Join for free today and upload your articles for new contacts to read and enquire further.