The Crown Prosecution Service has become the latest government organisation to feel the wrath of the data regulator after bungling officials allowed laptops containing scores of police interview videos with victims of crime to fall into criminal hands.
The Information Commissioner’s Office has slapped the CPS with a £200,000 fine after the computers were stolen from a private studio.
The videos contained interviews with 43 victims and witnesses, and involved 31 investigations, nearly all of which were ongoing and of a violent or sexual nature. Some of the interviews related to historical allegations against a high-profile individual.
They were being edited by a Manchester-based film company so that they could be used in criminal proceedings but an ICO investigation found the videos were not being kept secure.
The film company used a residential flat as a studio. The studio was burgled on 11 September 2014 and two laptops containing the videos were stolen. The laptops, which were left on a desk, were password protected but not encrypted and the studio had no alarm and insufficient security.
The police recovered the laptops eight days later and apprehended the burglar. As far as the ICO is aware, the laptops had not been accessed by anyone else.
The ICO ruled that the CPS was negligent when it failed to ensure the videos were kept safe and did not take into account the substantial distress that would be caused if the videos were lost.
ICO head of enforcement Stephen Eckersley said: “Handling videos of police interviews containing highly sensitive personal data is central to what the CPS does. The CPS was aware of the graphic and distressing nature of the personal data contained in the videos, but was complacent in protecting that information.
“The consequences of failing to keep that data safe should have been obvious to them.”
Many of the victims were vulnerable and had already endured distressing interviews with police. In the videos, they talked openly and referred to the names of the offenders.
Eckersley added: “If this information had been misused or disclosed to others then the consequences could have resulted in acts of reprisal.”
The CPS reported the incident to the ICO and informed the victims and witnesses involved. The ICO received complaints from three affected people.
As part its investigation, the ICO learned that the CPS had been using the same film company since 2002. The CPS delivered unencrypted DVDs to the studios using a national courier firm. If the case was urgent, the sole proprietor would collect the unencrypted DVD from the CPS personally and take it to the studio using public transport.
The ICO found that this constituted an ongoing contravention of the Data Protection Act until the CPS took remedial action following the security breach on 11 September 2014.
SFO cock-up triggers £185k fine
Lawyers in the dock over data leaks
Treasury lawyers escape ICO fine
Govt fined £185k for IRA data gaffe
Red faces at MoJ for £140k data fine
Pitiful data fine triggers MoJ review