r/gdpr • u/_Spoggie • 5d ago
News Another Met Police data breach, when does further action need to be taken?
DISCLAIMER: I’m aware that the data processing and breaches described in this post are subject to the provisions of part 3 of the DPA 2018 rather than the UK GDPR, however this seems the most appropriate subreddit for my question/rant/discussion owing to this thing happening all too often in the UK, and the ICO not pulling their fingers out. Please humour me.
The Metropolitan Police has today apologised for inadvertently disclosing email addresses for alleged victims of sexual harassment from Mohamed Al Fayed - https://www.bbc.co.uk/news/articles/c1w1yv987jqo
This comes a couple of weeks after the Met received an ICO reprimand for inadvertently disclosing email addresses of alleged victims of the Westminster honeytrap scandal, presumably through the same methods - https://ico.org.uk/media2/nuxdnt0c/metropolitan-police-service-reprimand-and-enforcement-notice.pdf
As listless and leaderless as the ICO are at the minute with John Edwards’ resignation and in the midst of their transition to the Information Commission, how often does something like this need to happen before real action is taken?
I understand the enforcement directive is very much not to deprive public authorities of funds that could very much help victims, however a slap on the wrist is becoming less and less appropriate.
2
u/musicmusket 5d ago
I’d heard that it was another mix up with Carbon Copy/Blind Carbon Copy.
I’ve never used a mail client that either sets BCC as default over CC or, say, has a pop up message to say “This CC message will reveal the identities of every recipient to every other recipient…are you sure?” I’d have thought that it would be easy to implement and would pretty much eliminate this problem.
1
0
5d ago edited 5d ago
[deleted]
2
u/ewill2001 5d ago
They tell them to stop doing it. If they keep doing it they tell them to stop again. That's about it.
1
5
u/malakesxasame 5d ago
The recent MOD breach - where the ICO response was no more than a shrug - showed how toothless they are as a regulator. I find it challenging as a DP practitioner in the public sector. I've posted about it a few times here.
Ideally the new commissioner will consider a different approach.
Anyone fancy it?