ICO hits Stock-on-Trent City Council with £120,000 data breach fine
Data watchdog takes action after city council solicitor sent "highly sensitive" data about children in its care to the wrong address.

Stoke-On-Trent City Council has been fined 120,000 by the Information Commissioner's Office (ICO) following a "serious" breach of the Data Protection Act (DPA).
The breach occurred when 11 emails containing "highly sensitive" information about several children and two adults in the council's care was accidentally sent to the wrong address.
An investigation by the data protection watchdog revealed the council solicitor responsible for sending the emails also breached the local authority's own rules by failing to send the information using a secured network.
It is particularly worrying that a breach in 2010 highlighted similar concerns.
It also emerged the council had neglected to rollout the required encryption software and was aware that staff were sending emails via unsecured networks.
Stephen Eckersley, head of enforcement at the ICO, said, if the information had been encrypted, the information would have remained secure.
"Instead, the authority has received a significant penalty for failing to adopt what is a simple and widely used security measure," he said.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"It is particularly worrying that a breach in 2010 highlighted similar concerns around encryption at the authority, but the issue was not properly resolved."
He also went on to confirm the council has now signed a legal notice, vowing to improve the data protection training provided to staff and tighten up security around the electronic transmission of data.
In a statement to IT Pro, the council said it has now introduced a secure remote access system for staff working from home and added encryption to all of its portable devices.
A secure email portal that allows the organisation to send sensitive information to non-council workers has also been established, and all unencrypted and non-council devices have now been blocked.
In line with the ICO's ruling, the council must also introduce a staff training programme for all employees that handle personal data, who must complete the course by February 2013.
Staff must also commit to undergoing regular refresher courses and new employees will be banned from handling sensitive data until they complete it.
Steve Sankey, assistant director of business technology at the council, said: "We have implemented a lot of new procedures and security measures that will help to prevent future breaches.
"It was prudent after the Information Commissioner's Office notified us of our weaknesses that we acted immediately to improve the situation."
-
Asus ZenScreen Fold OLED MQ17QH review
Reviews A stunning foldable 17.3in OLED display – but it's too expensive to be anything more than a thrilling tech demo
By Sasha Muller
-
How the UK MoJ achieved secure networks for prisons and offices with Palo Alto Networks
Case study Adopting zero trust is a necessity when your own users are trying to launch cyber attacks
By Rory Bathgate
-
AI recruitment tools are still a privacy nightmare – here's how the ICO plans to crack down on misuse
News The ICO has issued guidance for recruiters and AI developers after finding that many are mishandling data
By Emma Woollacott
-
“You must do better”: Information Commissioner John Edwards calls on firms to beef up support for data breach victims
News Companies need to treat victims with swift, practical action, according to the ICO
By Emma Woollacott
-
LinkedIn backtracks on AI training rules after user backlash
News UK-based LinkedIn users will now get the same protections as those elsewhere in Europe
By Emma Woollacott
-
UK's data protection watchdog deepens cooperation with National Crime Agency
News The two bodies want to improve the support given to organizations experiencing cyber attacks and ransomware recovery
By Emma Woollacott
-
ICO slams Electoral Commission over security failures
News The Electoral Commission has been reprimanded for poor security practices, including a failure to install security updates and weak password policies
By Emma Woollacott
-
Disgruntled ex-employees are using ‘weaponized’ data subject access requests to pester firms
News Some disgruntled staff are using DSARs as a means to pressure former employers into a financial settlement
By Emma Woollacott
-
ICO reprimands Coventry school over repeated data protection failures
News The ICO said the academy trust failed to follow previous guidance, which caused a serious data breach
By Emma Woollacott
-
ICO dishes out fine to HelloFresh for marketing spam campaign
News HelloFresh failed to offer proper opt-outs, the ICO said, and customers weren’t warned their data would be used for months after they cancelled
By Emma Woollacott