Site navigation

ICO Fines UK Gov £500,000 For New Years Honours Data Breach

Graham Turner

,

New Years Honour data breach
The Information Commissioner’s Office (ICO) has fined the Cabinet Office £500,000 for disclosing postal addresses of the 2020 New Year Honours recipients online.

The ICO found that the Cabinet Office breached data protection law when as it failed have the appropriate measures – both technical and organisational – in place to stop the breach.

The 27 December, 2019 breach saw the Cabinet Office publish a file on the government website containing the names and unredacted addresses of more than 1,000 people announced in the New Year Honours list.

People from a wide range of professions across the UK were affected, including individuals with a high public profile such as Sir Elton John, Gabby Logan and Nadiya Hussain.

After becoming aware of the data breach, the Cabinet Office removed the weblink to the file. However, the file was still cached and accessible online to people who had the exact webpage address.

The personal data was available online for well over two hours and was accessed 3,872 times.

Due to the data being published in the public domain, the ICO received three complaints from affected individuals who raised personal safety concerns resulting from the breach. The Cabinet Office was also contacted by 27 individuals with similar concerns.


Recommended


Speaking about the breach, Steve Eckersley, ICO Director of Investigations, said: “When data breaches happen, they have real life consequences. In this case, more than 1,000 people were affected. At a time when they should have been celebrating and enjoying the announcement of their honour, they were faced with the distress of their personal details being exposed.

“The Cabinet Office’s complacency and failure to mitigate the risk of a data breach meant that hundreds of people were potentially exposed to the risk of identity fraud and threats to their personal safety.

“The fine issued today sends a message to other organisations that looking after people’s information safely, as well as regularly checking that appropriate measures are in place, must be at the top of their agenda.”

The breach came as a result of a new IT system introduced in 2019, intended to process the public nominations for the New Years Honours.

The IT system was set up incorrectly by the Cabinet Office, which meant that the system generated a CSV file that included postal address data.

Due to tight timescales to get the New Year Honours list published, the HAS operations team decided to amend the file instead of modifying the IT system. However, each time a new file version was generated, the postal address data was automatically included in the file.


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

We will keep you up to date on the pivotal issues impacting the sector and let you know about key upcoming events to ensure that you don’t miss out on what’s going on across the Scottish tech community.

Click here to subscribe.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data