Original Article Text

Click to Toggle View

Northern Ireland police faces £750k fine after exposing staff info. The United Kingdom's Information Commissioner Office (ICO) intends to impose a fine of £750,000 ($954,000) on the Police Service of Northern Ireland (PSNI) for exposing the entire workforce's personal details by mistakenly publishing a spreadsheet online. PSNI disclosed the incident on August 8, 2023, when the police force warned that a mistake occurred during a response to a Freedom of Information (FOI) Request, exposing the following data about 9,483 active officers and staff: According to the ICO's assessment, the incident put exposed individuals at grave physical risk, resulted from poor data security from PSNI, and was deemed entirely preventable. "We have announced we intend to fine the Police Service of Northern Ireland (PSNI) £750,000 for failing to protect the personal information of its entire workforce." reads the announcement. "The proposed fine relates to an incident where personal information – including surname, initials, rank, and role of all 9,483 serving PSNI officers and staff – was included in a "hidden" tab of a spreadsheet published online in response to a freedom of information request." "Our investigation has provisionally found the PSNI's internal procedures and sign-off protocols for the safe disclosure of information were inadequate." ICO's investigation into the incident revealed that many were forced to move to new physical addresses, cut off communication and relations with family members to protect them from potential harm, and completely alter their daily routines. The Commissioner noted that the proposed fine on PSNI is set much lower than the nominal provisional figure, which is £5.6 million ($7.1 million), taking into consideration that PSNI is a public organization that operates on a finite budget, providing crucial services to the community. The ICO has also served PSNI a preliminary enforcement notice requiring the implementation of data security improvements in the handling process of FOI requests. PSNI's response to ICO's action was positive, accepting the penalty and assuring that they are taking steps to implement all of the recommended changes. The police force noted that throughout this time, they have supported their staff with crime prevention advice, online tools, and home visits. At the same time, 90% of the exposed offices and staff also accepted a reimbursement of £500 ($635) in December 2023. The investigation into who holds the leaked data continues, with detectives conducting numerous searches and arrests related to the unlawful dissemination of the stolen data set.

Daily Brief Summary

DATA BREACH // £750K Fine for Northern Ireland Police After Data Leak

The Police Service of Northern Ireland (PSNI) is set to be fined £750,000 by the UK's Information Commissioner Office (ICO) for a significant data breach.

A spreadsheet containing personal details of 9,483 PSNI officers and staff was mistakenly published online following a Freedom of Information request.

Exposed information included surnames, initials, ranks, and roles, which posed a severe safety risk to the individuals affected.

Many affected staff were forced to change addresses, sever family contacts, and alter daily routines to ensure safety.

ICO criticized PSNI for inadequate internal procedures and protocols for safely disclosing information.

The proposed fine is much lower than the initial provisional figure of £5.6 million, considering PSNI's status as a public entity with limited budget.

PSNI has responded positively to the enforcement notice and penalty, committing to implementing the required data security improvements.

Ongoing investigations and efforts are in place to determine possession of the leaked data, including multiple searches and arrests.