We reported back in November that the ICO had issued draft guidance on monetary penalties for serious breaches of the Data Protection Act. The guidance was approved earlier this week by the Secretary of State for Justice, Jack Straw MP, and is expected to come into force on 6 April 2010.
It means that the ICO will have the power to impose penalties of up to £500,000 on organisations for losses of personal data. The level of penalty will depend on the gravity of the breach and whether the breach was accidental or deliberate, as well as other factors, including the size of the organisation and its financial resources.
The Commissioner has said that he "will not hesitate to use these tough new sanctions for the most serious cases where organisations disregard the law". A warning for companies to comply with the data protection principles, or be prepared to pay a hefty monetary sacrifice.
Comments