img

Outcome

The ICO considered that he failed to take appropriate measures to secure the data held on the hard-drive. The business owner should have encrypted the data and placed the briefcase in the boot of the car. Despite the fact that the business owner had been a victim of data theft.

The ICO found that the data subjects could suffer substantial distress knowing that the data has been disclosed to unknown third parties and fined the business owner £5,000 (a reduction from £70,000 in recognition of the business owners voluntary notification). This was then covered by his insurance as he was a victim of data theft.

Settlement paid: £5000 without any inclusion of business interruption

img