Facebook fine - could it have been £479m ?

According to today's press the #ICO are fining #Facebook £500,000 for breaching the data protection act.  This is the maximum fine allowed under the data protection legislation that was in place when the breach occurred.  
Kyle Taylor, director of campaigning group Fair Vote UK is reported as saying "Under new GDPR laws, the ICO could fine Facebook £479m" 
The ICO has fined 54 organisations so far this year.  Looking at these fines in more detail many relate to failings in common business activities that may have been prevented with better staff training and awareness on the importance of privacy and data protection. 
For example:
  • inappropriate CCTV signage - £2000
  • multiple addresses in the email "to" field - £80000
  • data breach due to weak passwords - £100000
  • sensitive data left insecure - £35000
  • secondary web site left insecure - £120000 
  • lost unencrypted DVDs that contained sensitive information - £325000
  • Inappropriate information released through a FOI request - £120000
It will be interesting to see what levels of fines are issued for GDPR breaches - but one thing is for sure, all organisations and businesses need to make #dataprotection training an annual occurrence and make sure their staff are fully aware of the companies data protection, privacy and #eprivacy rules, the #GDPR, the #PECR and Privacy Impact Assessments (#PIA)

Concrew trainings one day workshops on data protection are designed to meet this need.



Image: Modification to the Image: Tafel  by  Oliver Tacke  used under CC BY


Comments

Popular posts from this blog

Employee Rep Training - Great Feedback

Working with Volunteers - 10 Tips for Success

Using Social Media at Work - Staff rights and responsibilities