ICO Puts Legal Profession In The Dock Over Data Breaches

The Information Commissioner’s Office (ICO) has expressed concerns at the number of data breaches involving barristers and solicitors, after 15 incidents involving members of the legal profession  were reported in the past three months.

It has reminded the industry that it has to keep personal information secure as it is often very sensitive, which means the scope for damage from a data breach “could meet the statutory threshold for issuing a financial penalty.” This could mean a penalty of up to £500,000 for a serious breach of the Data Protection Act.

Troubling Breaches

The ICO is especially concerned because the legal profession still tends to be mostly paper based, and legal professionals also often carry around large quantities of information in folders or files when taking them to or from court, or storing them at home – increasing the risk of a data breach.

“The number of breaches reported by barristers and solicitors may not seem that high, but given the sensitive information they handle, and the fact that it is often held in paper files rather than secured by any sort of encryption, that number is troubling,” said the Information Commissioner, Christopher Graham.

“It is important that we sound the alarm at an early stage to make sure this problem is addressed before a barrister or solicitor is left counting the financial and reputational damage of a serious data breach,” said Graham.

He said that the ICO has published a number of tips to help barristers and solicitors look after the personal information they handle. This includes advice on how to keep paper documents secure and not leave them in a car overnight, but instead lock the information away when not in use.

The ICO also advised lawyers to consider data minimisation techniques in order to ensure they are only carrying the information they require. It also advised them to store personal information on an encrypted memory stick.

ICO Breach

Lawyers should also consider when emailing personal information, whether the information needs to be encrypted or password protected. The ICO also said information should be deleted or disposed of securely no longer need it.

Last month, the ICO faced criticism when it admitted its own staff had breached data privacy regulations in the past 12 months. The “non-trivial incident” was apparently hidden inside the 84-page annual report, which is the same document in which information commissioner Christopher Graham asked for more powers and more funding for the UK’s privacy watchdog.

What do you know about ICO and its counterparts? Take our quiz!

Tom Jowitt

Tom Jowitt is a leading British tech freelancer and long standing contributor to Silicon UK. He is also a bit of a Lord of the Rings nut...

Recent Posts

Craig Wright Sentenced For Contempt Of Court

Suspended prison sentence for Craig Wright for “flagrant breach” of court order, after his false…

3 days ago

El Salvador To Sell Or Discontinue Bitcoin Wallet, After IMF Deal

Cash-strapped south American country agrees to sell or discontinue its national Bitcoin wallet after signing…

3 days ago

UK’s ICO Labels Google ‘Irresponsible’ For Tracking Change

Google's change will allow advertisers to track customers' digital “fingerprints”, but UK data protection watchdog…

3 days ago

EU Publishes iOS Interoperability Plans

European Commission publishes preliminary instructions to Apple on how to open up iOS to rivals,…

4 days ago

Momeni Convicted In Bob Lee Murder

San Francisco jury finds Nima Momeni guilty of second-degree murder of Cash App founder Bob…

4 days ago