Limit Impact of Human Error on Data Protection

A member of Gwent police force is facing possible dismissal, after accidentally sending an email attachment containing the results of criminal records bureau (CRB) checks to a journalist.  The serious breach of 10 000 individual’s sensitive personal data  occurred through simple human error, when the excel spreadsheet containing full names, date of birth and occupations of individuals in roles requiring CRB checks going back to 2001, was sent with the journalists email address unknowlingly automatically added to the intended recipients.  Gwent police have immediately tightened I.T security systems so a similar incident cannot happen again.  However the huge impact of this simple human error could have been drastically lessened had the CRB data had been encrypted or linked to a password protected file, rather than openly attaching to an email.  Institutions are urged to always use the highest levels of I.T security when sending sensitive personal data electronically. For the full report see http://www.theregister.co.uk/2010/04/16/gwent_police_data/

Posted on 20/04/2010