skip navigation

Data Loss - What to Do

The Information Commissioner's Office (ICO) has issued guidance for organisations that lose personal data, having reported that it has been notified of nearly 100 such incidents to date.

One of the less intuitively obvious suggestions is to think carefully about whether all the potentially affected people need to be notified. For example, notifying all your customers about a security glitch which in reality affects only a small proportion of them may produce a flood of enquiries and requests for further information from unaffected people, as well as possibly undermining their confidence in your organisation.

What is advisable is to obtain an accurate understanding as soon as possible of the scale of the loss and the potential impact on the people whose personal information has been lost. For example, if the information is such as to make identity fraud a possibility, it is likely to be more important to notify the people concerned than if the lost information is simply a list of names and addresses (which could be obtained easily from other sources).

The ICO advises that there are four important elements to consider when creating a breach management plan. These are:

1. Containment and recovery;
2. Assessment of ongoing risk;
3. Notification of breach; and
4. Evaluation and response.
 

Data security is an important but widely neglected issue for many organisations. Failure to follow adequate data protection procedures can have severe consequences, not only from the point of view of fines, but also damage to reputation and possible claims for losses suffered by those whose data has been compromised. We can assist you in helping to make sure that your legal risks due to data loss are minimised.

Related Articles

   
  Construction Industry VAT Changes Ahead
  Who Pays the Rates?
  Tenancy Deposit Protection Schemes - Rules
  Tips for Business Borrowers
  Tax Free Perks
  GDPR Guidance
  E-Commerce Law on Disclosure - Compliance Guide
  Enforcing Copyright - The Basics
  ICO 'Must Do' Data Protection Guide
  VAT and Electronic Goods - Take Care
  Informing and Consulting Employees
  A Guide to the Agency Workers Regulations
  Corporate Manslaughter and Gross Negligence Manslaughter
  Settlement Agreements
  Workplace Stress - An Employer's Duties
  False Claims on a CV - What to Do
  The Equality Act 2010 - A Guide for Employers
  Written Statement of Employment Particulars
  Insolvency and Pre-Packs
   
The contents of this article are intended for general information purposes only and shall not be deemed to be, or constitute legal advice. We cannot accept responsibility for any loss as a result of acts or omissions taken in respect of this article.
 
 
Home | About Us | Our Services | Our People | Firm News | Library | Contact Us
Bobbetts Mackan Solicitors & Advocates
Ground Floor, Griffin House, 15-16 Lower Park Row, Bristol BS1 5BN
T 0117 929 9001 F 0117 3164900
VAT Registered No. 137 8318 52
24hr Criminal defence helpline Tel 0117 9298987
E info@bobbetts.com

Authorised and regulated by the Solicitors Regulation Authority (SRA). SRA number 70535.

Copyright © Bobbetts Mackan. All rights reserved
Terms and conditions
[smaller] Change text size [larger]