Close This website uses modern features that are not supported by your browser. Click here for more information.
Please upgrade to a modern browser to view this website properly. Google Chrome Mozilla Firefox Opera Safari
your legal news hub
Sub Menu
Search

Search

Filter
Filter
Filter
A A A

UK companies may need to disclose security breaches

Publish date: 21 February 2007
Issue Number: 1171
Diary: Legalbrief eLaw
Category: Corruption

UK companies may be forced to disclose when customer data has been lost or stolen, according to the UK Information Commissioner\'s Office.

This follows some US states enacting laws forcing the disclosure of personal data security breaches. UK experts called for similar legislation last week after building society Nationwide was hit with a £980 000 fine for a data breach, reports Out-Law.com. Currently the ICO, which is responsible for monitoring compliance with the Data Protection Act, cannot force an organisation to disclose a breach unless it can prove that it is the only way to treat data in a fair manner. Nationwide was fined last week for having inadequate systems and protections for data that came to light after an employee had a laptop stolen from his home. Though the employee told the company about the incident straight away, it is reported that he did not inform Nationwide that customer data was on the machine until after a three-week holiday. Full Out-Law.com report

We use cookies to give you a personalised experience that suits your online behaviour on our websites. Otherwise, you may click here to learn more, or learn how to block or disable cookies. Disabling cookies might cause you to experience difficulties on our website as some functionality relies on cookie information. You can change your mind at any time by visiting “Cookie Preferences”. Any personal data about you will be used as described in our Privacy Policy.