ICO reveals even more data breaches
In the year since the HMRC breach, some 277 incidents have been reported to the Information Commissioner’s Office.


In the year since HM Revenue and Customs lost the records of 25 million people, some 277 data breaches have been reported to the Information Commissioner's Office(ICO).
Information Commissioner Richard Thomas is set to give a speech at RSA Europe later today, where he is expected to slam the government's move to large databases and call for all organisations to minimise the personal data they hold.
Of the 277 reported to the ICO, just 80 were from the private sector, with the rest in the public sector. The NHS was responsible for 75, while central government reported 28 and local authorities reported 26. The remaining 47 were from other public sector bodies.
The ICO added it is investigating the 30 most serious cases.
Thomas said in a statement: "The number of breaches brought to our attention is serious and worrying. I recognise that some breaches are being discovered because of improved checks and audits as a welcome result of taking data security more seriously. More laptops have now been encrypted and thousands of staff have been trained. But the number of breaches notified to us must still be well short of the total."
That such breaches continue to occur in the face of previous high profile cases and the threat of enforcement is alarming, Thomas said, adding that data loss can leave individuals open to abuse, fraud and even physical harm.
"Addresses of service personnel, police and prison officers and battered women have also been exposed. Sometimes lives may be at risk," Thomas said.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Phil Booth, the national coordinator of lobby group NO2ID, said: "The snooping-obsessed government is losing more personal information than ever, because it has seized more than ever. You can't trust a stalker state."
The government has been criticised for creating a database state, and keeping too much information on citizens especially in the face of the soon-to-be launched national identity card.
The ICO renewed its call for stronger powers, saying it was working with the government to ensure moves to allow it to impose stricter penalties are implemented as soon as possible. However, Thomas remains sceptical about requiring organisations to report such breaches, believing each case requires a different response.
So far this year, the ICO has taken enforcement action generally a letter requiring changes to data processes at the risk of prosecution against Orange Personal Communications, HMRC, the Ministry of Defence, the Department of Health, Virgin Media, Skipton Financial Services, the Foreign and Commonwealth Office, and Carphone Warehouse.
Freelance journalist Nicole Kobie first started writing for ITPro in 2007, with bylines in New Scientist, Wired, PC Pro and many more.
Nicole the author of a book about the history of technology, The Long History of the Future.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd
-
New Zealand privacy commissioner tipped to become next ICO head
News John Edwards is said to be an 'anti-Facebook' regulator who would fit well in the UK's plans to clamp down on big tech
By Bobby Hellard
-
What is a freedom of information (FOI) request?
In-depth We look at the mechanism citizens can use to hold public bodies to account
By Dale Walker
-
ICO hints at Facebook hypocrisy over data protection goals
News Elizabeth Denham asks Facebook to drop appeal after CEO's call for greater internet regulation
By Bobby Hellard
-
ICO to investigate Google over GDPR violations
News UK Watchdog to liaise with other European regulators over 'forced consent' push by the tech giant
By Bobby Hellard
-
ICO myth-busts on the flow of data post Brexit
News The Information Commissioner explains how data will move between the UK and EU in a no-deal scenario
By Bobby Hellard
-
Leave.EU faces big fine over data law breaches
News Information commissioner reveals Leave.EU was fined a total of £75,000 for “serious breaches”
By Alan Martin
-
ICO website knocked offline for more than 24 hours
News The outage was caused by an “unprecedented electrical surge” that damaged its host’s circuits
By Keumars Afifi-Sabet
-
Elizabeth Denham appointed ICO boss
News Denham will be tasked with helping the UK leave the EU without any knock-on effects on privacy
By Clare Hopping