"sensitive" documents found in street, GDPR?

Soldato
Joined
3 Oct 2009
Posts
19,892
Location
Wales
It could happen to anyone!
That sort of thing (well not quite) is what the regs are supposed to stop. At my old place we had a right crack down on papers/files being left out on desks, confidential waste disposal etc etc. Thankfully now I'm paperless my biggest worry is putting the wrong recipient on an email...
 
Soldato
Joined
22 Nov 2006
Posts
23,362
Could have blown away in the wind, an accident... Can't class everything with a pointing finger really if the facts aren't known.

You can accidentally leave a USB stick on a train too. You are still required to keep the data safe and are liable if you lose it, in any format.

The fines are ridiculously high now. Up to 2 million per customer or something like that. If you lose a whole database worth of stuff and it wasn't encrypted, your business is ******.
 
Last edited:
Don
OP
Joined
18 Oct 2002
Posts
41,744
Location
Notts
Once you have lodged a disclosure to the ICO they will start their investigation. The data controller will then be given a window in which they must provide the ICO with policies and procedures, evidence of how these have been brought to the attention of employees and included in the day to day running of the business, evidence of staff training and whatever else the ICO see fit to request.

Based on the evidence provided they will either take enforcement action upon the data controller or they will require steps be taken in order to ensure compliance.

.


That's pretty much what the ICO and Data protection officer told me
 

Deleted member 651465

D

Deleted member 651465

Plot twist: Rotty tries to send copies of the data to the ICO and the branch, only for the data to be intercepted by another party!

:eek:
 
Soldato
Joined
8 Dec 2002
Posts
20,118
Location
North Yorkshire
Back when I was at infotech expo the ICO were presenting there and they adamant they much prefer carrot and stick approach. So I would imagine they will enforce education on them and then follow up for proof this is happening.
 
Don
OP
Joined
18 Oct 2002
Posts
41,744
Location
Notts
Back when I was at infotech expo the ICO were presenting there and they adamant they much prefer carrot and stick approach. So I would imagine they will enforce education on them and then follow up for proof this is happening.


I think so too, get them to put proper process in place while simultaneously puting the fear of god in them
 
Soldato
Joined
13 Jan 2003
Posts
23,661
In town tonight and found a number of personal tenancy agreements / applications from a lettings agency blowing around the street

these have names/addresses/phone numbers/ rent amounts on them

don't want to be a **** but IMO this is out of order

any idea where to report or what to do?

To your title question - yes. Any leak of personal informal is covered by GDPR.

The company concerned only has a short period of time to inform those affected.
 
Back
Top Bottom