UK’s Information Commissioner’s Office (ICO) Imposed a Hefty Fine of £150,000 (approx. $241,000 USD) for Unencrypted Laptop Theft That Contained Sensitive Personal Information

Wilmslow, UK, Feb 8, 2011 –/– The Information Commissioner’s Office (ICO) today served Ealing Council and Hounslow Council with monetary penalties for serious breaches of the Data Protection Act after the loss of two unencrypted laptops containing sensitive personal information.

Ealing Council provides an out of hours service on behalf of both councils, which is operated by nine staff who work from home. The team receive contact from a variety of sources and rely on laptops to record information about individuals.

Two laptops containing the details of around 1,700 individuals were stolen from an employee’s home. Almost 1,000 of the individuals were clients of Ealing Council and almost 700 were clients of Hounslow Council. Both laptops were password protected but unencrypted – despite this being in breach of both councils’ policies. There is no evidence to suggest that the data held on the computers has been accessed and no complaints from clients have been received by the data controllers to date but there was nevertheless a significant risk to the clients’ privacy.

The ICO has served Ealing Council with a monetary penalty of £80,000, while ruling that £70,000 is appropriate for Hounslow Council. Ealing Council breached the Data Protection Act by issuing an unencrypted laptop to a member of staff in breach of its own policies. This method of working has been in place for several years and there were insufficient checks that relevant policies were being followed or understood by staff. Hounslow Council breached the Act by failing to have a written contract in place with Ealing Council. Hounslow also did not monitor Ealing Council’s procedures for operating the service securely.

Deputy Commissioner, David Smith, said:
“Of the four monetary penalties that we have served so far, three concern the loss of unencrypted laptops. Where personal information is involved, password protection for portable devices is simply not enough.

“The penalty against Hounslow Council also makes clear that an organisation can’t simply hand over the handling of the personal information it is responsible for to somebody else unless they ensure that the information is properly protected.

“Both councils have paid the price for lax data protection practices. I hope all organisations that handle personal information will make sure their houses are in order – otherwise they too may have to learn the hard way.”

Following the incident, both councils contacted affected individuals. Both authorities have also put significantly improved policies in place for information security and have agreed to consider an audit by the ICO.


If you need more information, please contact the ICO press office on 0303 123 9070 or visit the website at:

Notes to Editors

1. The monetary penalty served to Ealing Council is available on the ICO website here:


2. The monetary penalty served to Hounslow Council is available on the ICO website here:


3. The Information Commissioner’s Office upholds information rights in the public interest, promoting openness by public bodies and data privacy for individuals.

4. The ICO has specific responsibilities set out in the Data Protection Act 1998, the Freedom of Information Act 2000, Environmental Information Regulations 2004 and Privacy and Electronic Communications Regulations 2003.

5. For more information about the Information Commissioner’s Office subscribe to our e-newsletter at Alternatively, you can find us on Twitter and Linkedin.

6. Anyone who processes personal information must comply with eight principles of the Data Protection Act, which make sure that personal information is:

• Fairly and lawfully processed
• Processed for limited purposes
• Adequate, relevant and not excessive
• Accurate and up to date
• Not kept for longer than is necessary
• Processed in line with your rights
• Secure
• Not transferred to other countries without adequate protection

The ICO Press Office
Phone: +0303 123 9070

Address (head office)
Information Commissioner’s Office
Wycliffe House
Water Lane
Cheshire SK9 5AF

Like us on Facebook

Do you like this post? Subscribe to our RSS feed ===========================


Related posts:

  1. ICO Fines Two Councils £180,000 for Serious Data Breaches
  2. UK’s ICO: Cambridgeshire County Council Breaches Data Protection Act
  3. ICO Fines Nursing and Midwifery Council £150,000 ($233,000 USD) for Breaching the Data Protection Act
  4. Small Businesses Warned about the Importance of Encryption, after London Sole Trader Fined £5,000
  5. Sony Fined £250,000 ($395,000 USD) After Millions of UK Gamers’ Details Compromised
  6. ICO Fines Glasgow City Council £150,000 ($233,000 USD) for the Loss of Two Unencrypted Laptops