Share on LinkedInShare on LinkedIn

ARTICLE · 02 MARCH 2010

Tougher Sanctions For Data Protection Breaches

Charles Russell Speechlys LLP
Charles Russell Speechlys LLP
Contributor
Charles Russell Speechlys LLP

Charles Russell Speechlys LLP

Charles Russell Speechlys is an international law firm with a focus on private capital, at the...

View firm profile
Explore more from Charles Russell Speechlys LLP

After some considerable delay after Royal Assent of the Criminal Justice and Immigration Act 2008 on 8 May 2008, the Ministry of Justice finally published in November 2009 its consultation document on the maximum monetary penalty it considers should apply to the new enforcement powers at ss. 55A to 55E of the Data Protection Act 1998 introduced by the 2008 Act, once these sections are brought into effect.

United KingdomPrivacy
Andrew Sharpe
Andrew Sharpe

After some considerable delay after Royal Assent of the Criminal Justice and Immigration Act 2008 on 8 May 2008, the Ministry of Justice finally published in November 2009 its consultation document on the maximum monetary penalty it considers should apply to the new enforcement powers at ss. 55A to 55E of the Data Protection Act 1998 introduced by the 2008 Act, once these sections are brought into effect. The new maximum monetary penalty is to be £500,000.

This is perhaps less than the 10% of annual turnover some had hoped for, in line with the powers of authorities such as the Office of Fair Trading under competition law. However, it is an approach favoured by the Information Commissioner's Office, whose representatives have been quoted at recent conferences as preferring a fixed maximum amount rather than a percentage of some unknown figure as the maximum.

However, the other step that needs to be made before the new enforcement powers can be brought into effect is the approval by the Secretary of State of the Information Commissioner's monetary penalty guidelines. Draft guidelines have been published, so it would appear that once the consultation on the maximum penalty expires on 21 December 2009, all the necessary measures will be in place to bring the monetary penalty provisions of the Data Protection Act 1998 into effect.

In addition to monetary penalties, the Information Commissioner now has no-notice audit rights over public authorities, courtesy of new assessment notice powers included at Part 8 of the Coroners and Justice Act 2009. This is a major step forward in terms of equipping the Information Commissioner with proper enforcement powers, although it is perhaps disappointing that the assessment notice power is restricted to public authorities, rather than all data controllers.

For many years the cost of compliance audits and a full data protection compliance and training programme outweighed the regulatory risk of suffering a breach of the Data Protection Act 1998. Even serious criminal cases ended up with no more than a £5,000 fine. However, the new assessment notices' and monetary penalties' regimes may change the landscape, so that at last full compliance with the Data Protection Act 1998 and its data protection principles may be on the agenda of compliance directors. Implementation of compliance programmes may become urgent, particularly if breach notification is to be introduced.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

See more popular content from