NEWS Powergen breached the principles of the Data Protection Act 1998 when it left the information in an insecure area of the web site, according to assistant data protection commissioner, Phil Jones. But he explained that the DPC has no power to take punitive action when data protection principles are breached, and the best it can do is issue formal enforcement notices. However, no such notice will be issued to Powergen, as the DPC says there is no conclusive evidence that there are any current security issues with the company's site and it is not interested in issues that are now past. Phil Jones, assistant commissioner at the DPC, explained: "Parliament didn't give us enforcement powers. We don't have a 'rapping over the knuckles' power. Only a tiny minority of breaches of principle end up in enforcement notices." Jones added that enforcement notices were difficult to obtain. He said: "The process is complex and time-consuming, and the enforcement notices can be appealed. Virtually everyone we issue one against appeals." IT worker John Chamberlain informed silicon.com of the security breach in July after finding card details and personal information belonging to other Powergen customers when he went to pay his own bill online. Powergen initially accused Chamberlain of hacking its website, although the company later retracted that claim admitting the information had been outside the security gate due to a technical error. Chamberlain expressed his disappointment with the DPC's decision. He told silicon.com: "They've met with Powergen and accepted what it said without consulting me. I was not contacted by the DPC during the investigation." The leaked DPC document also states that the threat of adverse publicity in the press is more effective than any action it might take in preventing companies making security errors. Chamberlain added: "It sounds to me like they're saying the press will do a better job than the DPC as a deterrent. That means only large companies will be affected. But what about smaller companies that the press aren't interested in?"
Data Protection Commissioner washes hands of Powergen
The Data Protection Commissioner (DPC) has no power to take action against Powergen over the security breach that left 7,000 customer debit card details unsecured on its web server in July.
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
CIO challenges: Bringing your iPad to work
The arrival of personal technology in the office is a challenge for all organisations. The technology is here, but not...
-
2012 Olympics: Is your business prepared?
Athletes prepare for all kinds of conditions and problems in competition. With the London-hosted Olympics fast...
-
10 safety tips for business in 2012
Remember 2011? It seems like so long ago, with the speed of IT moving faster all the time. Data keeps growing, social...
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters





