St Albans council rapped for data leak in laptop theft
THE theft of a laptop containing postal voters records has resulted in St Albans council being found in breach of the Data Protection Act. The personal information was password-protected but unencrypted and disappeared some time before November 5 when th
THE theft of a laptop containing postal voters' records has resulted in St Albans council being found in breach of the Data Protection Act.
The personal information was password-protected but unencrypted and disappeared some time before November 5 when the council discovered the laptop containing the information and three others had gone missing.
Details of nearly 14,500 local residents were listed on the laptop.
Daniel Goodwin, chief executive for St Albans council, has now signed an undertaking to ensure that staff and contractors are fully aware of security procedures and adequate checks will be carried out on contractors' staff.
You may also want to watch:
The council has already encrypted laptops and other portable devices used to store and transmit personal data and appropriate physical security measures have been put in place to prevent unauthorised access to it.
Mr Goodwin said this week: "We apologise again to all those people whose details were contained on the missing laptop.
- 1 Rapid community COVID-19 testing launches in Hertfordshire
- 2 Which Herts communities have seen the biggest rises and falls in COVID-19?
- 3 Police swoop on organised gangs as part of major operation
- 4 How many people in St Albans were fined for breaking COVID rules?
- 5 Remembering one-of-a-kind local legend Lee Bozier
- 6 Hitchin and Harpenden MP responds to questions over new £2,500 a month part-time role
- 7 Charity for older people has busiest year ever during pandemic
- 8 Oaklands College principal leaving after 10 years
- 9 Why is there a 50mph speed limit on small section of A414?
- 10 Number of COVID patients in Herts hospitals falls slightly
"At the time of the disappearance of the laptops, the council, as a precautionary measure, arranged for CIFAS, the UK's fraud prevention service, to provide protection to those residents whose data was on the missing laptop.
"We have also conducted a root and branch review of our IT services and made improvements to our data security, some of which are set out in the undertaking. "While we had policies in place on data security these were not followed. They are being followed now and all staff have been reminded how important this is. The action that we have taken will help prevent anything happening like this again."
Sally-Anne Poole, head of enforcement and investigations at the Information Commissioners Office (ICO) said: "When organisations store large volumes of personal details on portable computers, encryption is essential. They must ensure staff and contractors are trained to handle personal information securely to avoid the risk of information falling into the wrong hands."
But she said the ICO was pleased that the council had taken comprehensive remedial action informing residents affected by the breach.