nettihen Posted January 22, 2019 Posted January 22, 2019 Can a school make the following statement to staff: ...if I have not followed the guidance rules as set out above and a serious data breach is the result of my own negligence, I may be liable for any subsequent fine... Opinions please and thank you in advance. Netti
Bionic Posted January 22, 2019 Posted January 22, 2019 Can a school make the following statement to staff: ...if I have not followed the guidance rules as set out above and a serious data breach is the result of my own negligence, I may be liable for any subsequent fine... Opinions please and thank you in advance. Netti :D nice try!! 1
elsiegee40 Posted January 22, 2019 Posted January 22, 2019 Can a school make the following statement to staff: ...if I have not followed the guidance rules as set out above and a serious data breach is the result of my own negligence, I may be liable for any subsequent fine... Opinions please and thank you in advance. Netti I’d say there is a chance that could happen. The ICO will research who is responsible. If the employee was clearly acting outside the employer’s practice and procedures then the employee could be held liable. It would only happen after the employer had answered a lot of difficult questions on how it is possible though. @GrumbleDook? 1
Sonic007 Posted January 22, 2019 Posted January 22, 2019 You forgot to add... "In the event you can not pay the fine your home may be repossessed by the school and used as extra classrooms". 2
GREED Posted January 22, 2019 Posted January 22, 2019 I wold suggest this would come down to the robustness of the organisations procedures - having a list of rules to follow with no safeguards, check, etc does not make it a get out for any/all data breeches/issues going forward. If the organisation can show that they did everything possible to train, support and protect staff from mistakes (often the common cause on minor incidents), then OK, plus if the staff member deliberately went and did something bad, then very possibly they can and should. But the ICO will firstly look to the organisation. I think too, a fine can only be levied by the ICO directly, the organisation cannot just pass that on, or even pay it and then subsequently fine the staff member - unless something was explicitly written into contracts and the likes. 2
tmoon-mint Posted January 22, 2019 Posted January 22, 2019 Is this relevant? https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2018/12/former-headteacher-prosecuted-for-unlawfully-obtaining-school-children-s-personal-information/ 2
elsiegee40 Posted January 22, 2019 Posted January 22, 2019 Is this relevant? https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2018/12/former-headteacher-prosecuted-for-unlawfully-obtaining-school-children-s-personal-information/ I had forgotten that one. An individual employed by a school fined for a Data breach. Yes, it is relevant! 1
nettihen Posted January 22, 2019 Author Posted January 22, 2019 Thank you everyone for your really helpful feedback. It’s reassuring for me! I’m new to this website and still trying to find my way around but finding it very helpful. Thanks again 🙏👍
enjay Posted January 23, 2019 Posted January 23, 2019 I think the answer is (as is so often the case), "sort of". As has been highlighted above, there are instances where the individual has been fined not the organisation, but that was at the ICO's discretion. I don't know how much success an organisation would have in passing on a fine the ICO imposed on the organisation. 1
rom1984 Posted January 23, 2019 Posted January 23, 2019 (edited) Bit of a yes/no. The GDPR/DPA is to regulate data controllers and processors so the ICO would not enforce against an individual as they do not have a legal framework to do so. The individual is not the controller/processor the organisation is in the schools case. With that said there are criminal offences within the DPA 2018 that could be brought against the individual, they are; False statement made in response to an information notice Destroying or providing false information Unlawful obtaining of personal data Re-identification of de-identified personal data Alteration of personal data to prevent disclose Edited January 23, 2019 by rom1984 2
GrumbleDook Posted January 24, 2019 Posted January 24, 2019 The only bit I would add to what @rom1984 has said is ... don't forget that there are other aspects of law to consider including CMA. The Morrisons case is still going through appeal so there could be a large precendent there. Remember that just because the member of staff was negligent, it doesn't mean that the school did everything they could have done. The school *is* the controller. 1
PotNoodleTech Posted January 24, 2019 Posted January 24, 2019 I had forgotten that one. An individual employed by a school fined for a Data breach. Yes, it is relevant! It's different though as the person who was fined had already left the school and was not an employee any more. Netti wishes to fine current employees. Surely the school would get the fine?
elsiegee40 Posted January 24, 2019 Posted January 24, 2019 It's different though as the person who was fined had already left the school and was not an employee any more. Netti wishes to fine current employees. Surely the school would get the fine? If there is a breach, the ICO will investigate and may fine the school or the employee or both. The school may not pass the fine on to the employee 1
rom1984 Posted January 24, 2019 Posted January 24, 2019 I've got to admit I'm not a massive fan of the wording in the original post as it's slightly misleading, although I can see what the school is trying to say. Maybe a reword to something along the lines of; "Failure to comply with the schools information/data security polices and procedures could result in disciplinary action, including dismissal. In some cases you may also be liable for criminal proceedings which could result in individual fines and/or imprisonment." In your DP training you can then expand on what are these "in some case" - for example the examples listed above or non compliance with the Computer Misuses Act. 1
enjay Posted January 28, 2019 Posted January 28, 2019 Maybe a reword to something along the lines of; "Failure to comply with the schools information/data security polices and procedures could result in disciplinary action, including dismissal. In some cases you may also be liable for criminal proceedings which could result in individual fines and/or imprisonment." Our AUP says "The school may take disciplinary action against anyone found in contravention of this Policy; where appropriate this may include legal action." but I prefer your wording, as your wording covers legal action being brought by someone other than the school. 2
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now