Monday, 27 June 2011

Massive data leak at Guildford borough council

It's recently come to my attention that, a fortnight or so ago, there was a massive breach of data security at Guildford borough council.

My understanding is that emails containing the council records of hundreds (if not thousands) of people were sent to the wrong people instead of the people who the records were about. Perhaps most gratingly for the council, this incident occurred just days after a glowing report on the council's data security by an outside inspector had been published.

Apparently the data leak occurred simply because some council official selected the wrong mailing list when sending out the emails. Now, call me over cautious, but I would have thought that when you've got emails containing that amount of personal data you'd have some sort of system in place to double check before the emails are sent that they're going to the correct people.

I imagine the council will have acted to alert the people affected as soon as possible but in a case like this the real test will be in what measures are taken to prevent the incident from happening again. If I find out what measures have (or have not) been taken then I'll be sure to do an update about them.

No comments:

Post a Comment

I'm indebted to Birkdale Focus for the following choice of words:

I am happy to address most contributions, even the drunken ones if they are coherent, but I am not going to engage with negative sniping from those who do not have the guts to add their names or a consistent on-line identity to their comments. Such postings will not be published.

Anonymous comments with a constructive contribution to make to the discussion, even if it is critical will continue to be posted. Libellous comments or remarks I think may be libellous will not be published.

I will also not tolerate personation so please do not add comments in the name of real people unless you are that person. If you do not like these rules then start your own blog.

Oh, and if you persist in repeating yourself despite the fact I have addressed your point I may get bored and reject your comment.

The views expressed in comments are those of the poster, not me.