PogoWasRight.org

Menu
  • About
  • Privacy
Menu

UK: Local Authority disclosed personal data on Planning Department website

Posted on November 15, 2010 by pogowasright.org

New Forest District Council breached the Data Protection Act by publishing the personal data of planning applicants on their website, the Information Commissioner said today.

The Information Commissioner’s Office (ICO) received a complaint from a New Forest resident in 2008, after council staff failed to appropriately redact personal data from the resident’s planning application before publication on their website.

The council initially addressed the issue and removed the relevant data. However, the resident continued to monitor the website and reported finding personal data relating to other Hampshire residents over a period of some months.

Following this complaint, the council initially improved their internal redaction procedure and introduced a self monitoring process. However, in July 2010, the ICO established that further personal data was being published on New Forest’s website and contacted the council to address the issue.

The ICO examined the systems in place at the council and interviewed the staff directly responsible for the redaction process. Following this, the ICO was satisfied that the Council were taking the steps needed to lessen the risk of a breach occurring again.

The Council’s Chief Executive, David Yates, has provided the ICO with a personal commitment to continue to employ such measures to ensure maximum compliance with the Data Protection Act.

Sally-Anne Poole, Enforcement Group Manager at the ICO, said:

“The ICO welcomes the measures introduced by New Forest District Council to tackle this problem. While we appreciate it is difficult for any organisation to give a 100% guarantee that they will comply with the Act, we expect authorities to put the most effective data protection measures in place and to ensure they are upheld.
“We will be monitoring other local authorities to scope compliance in this area on a national level. Any council found to have an unacceptable error rate may be subject to regulatory action.”

Source: Information Commissioner’s Office

Category: BreachesNon-U.S.

Post navigation

← LAPD officer resigns after being accused of tapping database on killer’s behalf
Full Frontal Nudity Doesn’t Make Us Safer: Abolish the TSA →

Now more than ever

Search

Contact Me

Email: [email protected]

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • Rules Proposed Under New Jersey Data Privacy Act
  • Using facial recognition? Three recent articles of interest.
  • India publishes consent management rules under Digital Personal Data Protection Act
  • Republicans Move A Step Closer To Repealing Protections For Abortion Clinics
  • Democrats introduce bill that aims to protect reproductive health data
  • Don’t Mind If I Do: Montana Says Hands Off Neural Data
  • 23andMe leadership grilled by lawmakers demanding answers about data security amid bankruptcy sale

RSS Recent Posts on DataBreaches.net

  • School Districts Unaware BoardDocs Software Published Their Private Files
  • A guilty plea in the PowerSchool case still leaves unanswered questions
  • Brussels Parliament hit by cyber-attack
  • Sweden under cyberattack: Prime minister sounds the alarm
  • Former CIA Analyst Sentenced to Over Three Years in Prison for Unlawfully Transmitting Top Secret National Defense Information
©2025 PogoWasRight.org. All rights reserved.