RSS FeedPublic Sector

Information Commissioner 'blocked' from auditing key sectors

Information Commissioner 'blocked' from auditing key sectors

NHS, local government and private sector resisting audits

Information Commissioner Christopher Graham has said his office is "being blocked" from auditing organisations in sectors that are "causing concern" over their handling of personal information.

Compulsory audit powers are needed for local government, the NHS and the private sector to ensure compliance with the law, he said at today's 10th annual data protection compliance conference in London.


Related Articles

 

Virtualisation, Big Data and BYOD

Check out our Business IT Hub for opinions and briefings. Read more


The only compulsory data protection audit powers the ICO currently has are for central government departments. For all other organisations the ICO has to win consent before an audit can take place.

Graham said data breaches in the NHS continue to be "a major problem". Of the 47 undertakings the ICO has agreed with organisations that have breached the Data Protection Act since April, over 40 percent (19) were in the healthcare sector.  

In addition, the most serious personal data breaches that have resulted in an ICO fine have occurred in the local government sector. Four of the six penalties served so far involved local authorities, said Graham.

Graham said businesses remain the sector generating the most data protection complaints though. Despite this, as reported in July, just 19 percent of companies contacted by the ICO accepted the offer of undergoing an audit.

The ICO has written to 29 banks and building societies and so far only six (20 percent) have agreed to undergo an audit. The insurance sector has also shown reluctance in this area. Of the 19 companies contacted this year by the ICO, only two agreed to an audit.

Graham said: “Something is clearly wrong when the regulator has to ask permission from the organisations causing us concern before we can audit their data protection practices.

"Helping the healthcare sector, local government and businesses to handle personal data better are top priorities, and yet we are powerless to get in there and find out what is really going on."

Graham said he was "preparing the business case" for an extension of the ICO’s Assessment Notice powers under the Coroners and Justice Act 2009 to deal "with these problematic sectors". 

Send to a friend

Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Does your company use managed print services?

Question of the day!

Does your company use managed print services?


% of Computerworld UK readers agree with you


Yes
TBC
No
TBC

What benefits do you believe managed print services offer?


123 characters remaining

Follow the conversation at @Think_Print


ComputerWorldUK Resources

ComputerworldUK
Share
x
Open
* *