Jump to content

Recommended Posts

Posted

Can a school make the following statement to staff: ...if I have not followed the guidance rules as set out above and a serious data breach is the result of my own negligence, I may be liable for any subsequent fine...

Opinions please and thank you in advance.

Netti

Posted
Can a school make the following statement to staff: ...if I have not followed the guidance rules as set out above and a serious data breach is the result of my own negligence, I may be liable for any subsequent fine...

Opinions please and thank you in advance.

Netti

 

:D:D nice try!! ;)

  • Thanks 1
Posted
Can a school make the following statement to staff: ...if I have not followed the guidance rules as set out above and a serious data breach is the result of my own negligence, I may be liable for any subsequent fine...

Opinions please and thank you in advance.

Netti

 

I’d say there is a chance that could happen. The ICO will research who is responsible. If the employee was clearly acting outside the employer’s practice and procedures then the employee could be held liable.

 

It would only happen after the employer had answered a lot of difficult questions on how it is possible though.

@GrumbleDook?

  • Thanks 1
Posted

I wold suggest this would come down to the robustness of the organisations procedures - having a list of rules to follow with no safeguards, check, etc does not make it a get out for any/all data breeches/issues going forward. If the organisation can show that they did everything possible to train, support and protect staff from mistakes (often the common cause on minor incidents), then OK, plus if the staff member deliberately went and did something bad, then very possibly they can and should. But the ICO will firstly look to the organisation.

 

I think too, a fine can only be levied by the ICO directly, the organisation cannot just pass that on, or even pay it and then subsequently fine the staff member - unless something was explicitly written into contracts and the likes.

  • Thanks 2
Posted
Thank you everyone for your really helpful feedback. It’s reassuring for me! I’m new to this website and still trying to find my way around but finding it very helpful. Thanks again 🙏👍
Posted

I think the answer is (as is so often the case), "sort of".

 

As has been highlighted above, there are instances where the individual has been fined not the organisation, but that was at the ICO's discretion. I don't know how much success an organisation would have in passing on a fine the ICO imposed on the organisation.

  • Thanks 1
Posted (edited)

Bit of a yes/no. The GDPR/DPA is to regulate data controllers and processors so the ICO would not enforce against an individual as they do not have a legal framework to do so. The individual is not the controller/processor the organisation is in the schools case.

 

With that said there are criminal offences within the DPA 2018 that could be brought against the individual, they are;

 

False statement made in response to an information notice

Destroying or providing false information

Unlawful obtaining of personal data

Re-identification of de-identified personal data

Alteration of personal data to prevent disclose

Edited by rom1984
  • Thanks 2
Posted

The only bit I would add to what @rom1984 has said is ... don't forget that there are other aspects of law to consider including CMA.

 

The Morrisons case is still going through appeal so there could be a large precendent there.

 

Remember that just because the member of staff was negligent, it doesn't mean that the school did everything they could have done. The school *is* the controller.

  • Thanks 1
Posted
I had forgotten that one. An individual employed by a school fined for a Data breach.

 

Yes, it is relevant!

 

It's different though as the person who was fined had already left the school and was not an employee any more. Netti wishes to fine current employees. Surely the school would get the fine?

Posted
It's different though as the person who was fined had already left the school and was not an employee any more. Netti wishes to fine current employees. Surely the school would get the fine?

 

If there is a breach, the ICO will investigate and may fine the school or the employee or both.

 

The school may not pass the fine on to the employee

  • Thanks 1
Posted

I've got to admit I'm not a massive fan of the wording in the original post as it's slightly misleading, although I can see what the school is trying to say.

 

Maybe a reword to something along the lines of;

 

"Failure to comply with the schools information/data security polices and procedures could result in disciplinary action, including dismissal. In some cases you may also be liable for criminal proceedings which could result in individual fines and/or imprisonment."

 

In your DP training you can then expand on what are these "in some case" - for example the examples listed above or non compliance with the Computer Misuses Act.

  • Thanks 1
Posted
Maybe a reword to something along the lines of;

 

"Failure to comply with the schools information/data security polices and procedures could result in disciplinary action, including dismissal. In some cases you may also be liable for criminal proceedings which could result in individual fines and/or imprisonment."

 

Our AUP says "The school may take disciplinary action against anyone found in contravention of this Policy; where appropriate this may include legal action." but I prefer your wording, as your wording covers legal action being brought by someone other than the school.

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...