Consultation on Revised Fines for Serious Data Breaches
The Ministry of Justice has announced the Government's consultation on revised fines for serious breaches of the Data Protection Act.
In Civil Monetary Penalties: Setting the Maximum Penalty proposals are made for a maximum £500,000 fine. The powers to impose civil monetary penalties were granted to the Information Commissioner's Office (ICO) by being added to the Data Protection Act (DPA) 1998 (Sections 55A to 55E) through section 144 of the Criminal Justice and Immigration Act 2008.
The civil monetary penalty would apply in serious contraventions of section 4(4) of the DPA by the data controller, of a kind likely to cause substantial damage or substantial distress, and the contravention was either deliberate or "the data controller knew or ought to have known that there was a risk that the contravention would occur, and that such a contravention would be of a kind likely to cause substantial damage or substantial distress, but failed to take reasonable steps to prevent the contravention".
The closing date for comments is the 21st December 2009 and a paper summarising the responses to the consultation will be published by 11th January 2010.
Update later on 17th November 2009: Just caught up with the news and heard the ICO is investigating whether T-Mobile has been selling their mobile phone customers' records illegally.
Posted on: 17 November 2009 at 14:09 hrs

Comments are filtered automatically and should appear shortly after they been checked.