Site navigation

Data Breaches Risk Domestic Abuse Victims’ Lives, ICO Warns

Elizabeth Greenberg

,

data breaches
The Information Commissioner’s Office (ICO) has issued a warning to organisations after several data breaches affecting domestic abuse survivors and victims. 

After reprimanding seven organisations in the past 14 months for data breaches affecting victims of domestic abuse, the ICO has called on organisations to step up their data handling protocols to prevent further danger.

The reprimands, which have occurred since June 2022, include:

  • Four cases of organisations revealing the safe addresses of the victims to their alleged abuser. In one case a family had to be immediately moved to emergency accommodation.
  • Revealing identities of women seeking information about their partners to those partners.
  • Disclosing the home address of two adopted children to their birth father, who was in prison on three counts of raping their mother.
  • Sending an unredacted assessment report about children at risk of harm to their mother’s ex-partners.

Organisations involved include a law firm, a housing association, an NHS trust, a government department, local councils, and a police service.

According to the ICO, the root causes for the breaches vary, but common themes are a lack of staff training and failing to have robust procedures in place to handle personal information safely.

“These families reached out for help to escape unimaginable violence, to protect them from harm and to seek support to move forward from dangerous situations. But the very people that they trusted to help, exposed them to further risk,” John Edwards, the UK information commissioner said.

“This is a pattern that must stop. Organisations should be doing everything necessary to protect the personal information in their care. The reprimands issued in the past year make clear that mistakes were made and that organisations must resolve the issues that lead to these breaches in the first place.

“Getting the basics right is simple – thorough training, double checking records and contact details, restricting access to information – all these things reduce the risk of even greater harm.

“Protecting the information rights of victims of domestic abuse is a priority area for my office, and we will be providing further support and advice to help keep people safe.”

The ICO has already revised its approach to public sector enforcement last year, aiming to reduce the impact of fines on the public by working more closely with the public sector, encouraging compliance with data protection law to prevent harms before they happen.

The reprimands provide clear instructions to these organisations on how to improve their data protection practices, and other organisations can apply the lessons to their own activities so similar incidents are less likely to happen.

Advice and Guidance for Personal Data Handling 

The ICO has also released guidance for organisations to keep personal and private data secure.

If an organisation works with people experiencing domestic abuse, it should make sure relevant staff know how to handle their data with extra care and can accommodate any requests for privacy.

This could include specific training, placing notes on files, ensuring staff include information about data-handling when taking part in handovers, or regularly reminding all staff of the processes.


Recommended reading


Regularly checking contact information is also vital to protect people’s data from being disclosed to an old address, email address, or contact number.

Organisations should also ensure they put in proper measures to mitigate any inappropriate access to personal data, whether it be implementing passwords or access controls.

Going back to basics, like always double checking information that is shared, is also key in preventing breaches.

Tailored and role-specific training is also advised for organisations dealing with delicate data.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data