The Information Commissioner's Office – the regulator in charge of enforcing data protection laws in the UK – has come down hard on three councils after they failed to protect the security of personal data for which they were the data controllers. St Albans City and District Council agreed to do better after an unencrypted laptop that had been left unsecured on a desk was stolen; the laptop contained postal voters' records and the data had no longer been required on the laptop at the time of the theft. Warwickshire Council also had to give promises about its future conduct after unencrypted and unsecured laptops and memory sticks containing information relating to school pupils and members of staff were stolen. Highland Council faced similar action after personal data relating to people's physical and mental health was inadvertently disclosed.
The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.










