ICO demands overhaul of data security…
By Nick Heath
Published: 25 January 2008 15:21 GMT
Retailer Marks & Spencer (M&S) could face prosecution if it does not comply within two months to the overhaul of its data security after losing 26,000 employees' pension details.
Security from A to Z
Click on the links below to find out more...
A is for Antivirus
B is for Botnets
C is for CMA
D is for DDoS
E is for Extradition
F is for Federated identity
G is for Google
H is for Hackers
I is for IM
J is for Jaschan (Sven)
K is for Kids
L is for Love Bug
M is for Microsoft
N is for Neologisms
O is for Orange
P is for Passwords
Q is for Questions
R is for Rootkits
S is for Spyware
T is for Two-factor authentication
U is for USB sticks/devices
V is for Virus variants
W is for Wi-fi
X is for OS X
Y is for You
Z is for Zero-day
The Information Commissioner's Office (ICO) has threatened the retail giant with possible prosecution after the unencrypted data on a laptop was stolen from a contractor in April 2007.
Names, addresses, national insurance numbers and information about pension plans - including wages but not bank account details - of the UK workers were on the machine.
M&S now has until 1 April to ensure all laptop hard drives are fully encrypted.
The ICO served the enforcement notice on 23 January after M&S would not agree to the ICO publicising the changes it demanded in data security at the company.
A spokesman for the ICO said: "There is no evidence that any employees suffered ID fraud but there is always that risk with this type of information."
Mick Gorrill, assistant commissioner at the ICO, added in a statement: "It is essential that before a company allows personal information to leave its premises on a laptop there are adequate security procedures in place to protect personal information, for example, password protection and encryption.
"If organisations fail to introduce safeguards to protect information they risk losing the trust and confidence of both employees and customers."
The data was stolen from the home of the MD of a company that was preparing pension change statements for M&S.
The ICO found that M&S breached the Data Protection Act by not taking appropriate measures to ensure the security of its data by making sure the laptop data was encrypted.
The enforcement notice says the Information Commissioner Richard Thomas takes the view that damage or distress is likely as a result of personal data getting into the hands of unauthorised persons.
A spokeswoman for M&S said: "We have been working with the ICO since we knew what had happened. We have been encrypting all hard drives since October last year."
She said the firm had informed all employees by letter the moment it found out about the theft, set up a helpline for affected workers and provided them with unlimited credit checks with Experian.
Last year Gordon Brown announced that the ICO would be given increased powers to conduct spot checks of government departments.
The Information Commissioner has called for these powers to be extended to cover all public bodies and private sector organisations.
Why does any company allow this sort of data to be...
Anonymous
it would seem industry cannot be trusted with pers...
Karen Challinor
How to squeeze the last drops of savings from an outsourcing contract
Revealed: The apps you'll have on your phone in 2012
Clouds clear as Microsoft gives Azure a January launch date
UK ID cards rollout hit by delay as launch date revealed
The software that can save you big bucks? You've already got it
London, 22 days holiday, car, laptop, phone, pension. This life changing opportunity will provide the successful candidate travel opportunities, ...
There is also many other benefits such as car/ car allowance, company pension scheme, mobile phone and a laptop! Area Sales Manager / Sales Engineer ...
You will be looking to get a great pension scheme, private healthcare, car allowance, bonuses and flexi-time Hays Information Technology Ltd is a ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Petra Papinniemi
Legal Eye: Ecommerce held back by outdated laws
No wonder no one's buying...
Matthew Cushen
E-tailers: Be choosy overseas
Markets are not always what they seem
Tim Ferguson
'If you look at iPlayer from a distance, it's still very web 1.0'
Q&A: Erik Huggers, director, BBC's Future, Media and Technology
Kit Burden
Legal Eye: Tech could brighten retailers' gloom
Regulation and recession loom
Matthew Cushen
Retailers: Look to emerging markets
Comment: Massive opportunities if you get the IT right
Julian Goldsmith
How Zavvi lost its Virginity
IT director Tony Johnson on the retailer's changing web strategy