PogoWasRight.org

Menu
  • About
  • Privacy
Menu

UK: Company directors use council employee to illegally access tenants’ details

Posted on March 31, 2012 by pogowasright.org

A Slough letting agent and one of its directors who unlawfully obtained details about their tenants from a rogue employee at Slough Borough Council have been found guilty of committing offences under Section 55 of the Data Protection Act 1998 (DPA).

At Reading Magistrates yesteday, SAI Property Investments Limited, trading as IPS Property Services and represented at the hearing by Director Mr Punjab Sandhu, was fined £260.00 for two offences under the Act and ordered to pay a £15 victim surcharge and £702.08 prosecution costs. Another director at the company, Sundeep Jaswal, was fined £260.00 for two offences and ordered to pay a £15 victim surcharge and £351.03 prosecution costs.

Ounkar Singh Nainu – who supplied both men with information relating to individuals in receipt of Housing and Council Tax Benefit, whilst employed at the council as a Customer Service Advisor – has been fined £690.00 for three offences and ordered to pay a £15 victim surcharge and £351.03 prosecution costs.

The first offence took place in September 2009 when Jaswal made contact with Nainu and asked him to obtain personal data about some of their tenants from housing benefit records. This information was provided without the Council’s knowledge and used by the company to chase up their tenant’s outstanding debts. An unsuccessful attempt was then made to obtain further information from the Council’s records in March 2010.

The Council received an anonymous tip-off that Nainu had been illegally accessing the data, and launched an immediate investigation before reporting the matter to the ICO.

Information Commissioner, Christopher Graham, said:

“This case clearly demonstrates the contempt that all three individuals held for the privacy rights of the people affected.

“The council employee was responsible for handling important information relating to some of the council’s most vulnerable residents. He abused his position hoping to make money and found two unscrupulous individuals who were happy to acquire this information through any means necessary.

“This case highlights the need for a more appropriate range of deterrent punishments to be made available to the courts. There must be no further delay in introducing tougher powers to enforce the Data Protection Act, otherwise unscrupulous individuals will continue to see a mere fine as a price worth paying.”

Unlawfully obtaining or accessing personal data is a criminal offence under Section 55 of the DPA. Offenders can be fined up to £5000 at Magistrates Court or an unlimited amount at Crown Court. This also applies to attempts under the Criminal Attempts Act. The ICO continues to call for more effective deterrent sentences, including custodial, to be made available to courts to prevent the unlawful use of personal information.

 Source: Information Commissioner’s Office
The fines aren’t huge, but I posted this because it was handled as a criminal offense. Would that more willful shenanigans like these were treated as criminal in both the U.K. and U.S.
Category: BreachesNon-U.S.

Post navigation

← Judge Allows Actress Suing IMDb Over Age Revelation to Go Forward on Lawsuit
Girls Around Me app raises concerns about stalking →

Now more than ever

Search

Contact Me

Email: [email protected]

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • The Markup caught 4 more states sharing personal health data with Big Tech
  • Privacy in the Big Sky State: Montana’s Consumer Privacy Law Gets Amended
  • UK Passes Data Use and Access Regulation Bill
  • Officials defend Liberal bill that would force hospitals, banks, hotels to hand over data
  • US Judge Invalidates Biden Rule Protecting Privacy for Abortions
  • DOJ’s Data Security Program: Key Compliance Considerations for Impacted Entities
  • 23andMe fined £2.31 million for failing to protect UK users’ genetic data

RSS Recent Posts on DataBreaches.net

  • CoinMarketCap Hacked, Scrambles to Remove Malicious Wallet Verification Popup
  • Montana Attorney General launches investigation into Lee Enterprises data breach
  • AT&T gets preliminary approval for $177 million data breach settlement
  • Aflac notifies SEC of breach suspected to be work of Scattered Spider
  • Former JBLM soldier pleads guilty to attempting to share military secrets with China
©2025 PogoWasRight.org. All rights reserved.