The managing director of Wolverhampton City Council has been ordered to sign a commitment to improve staff data-protection training after recent incidents in which sensitive employee information were inadvertently disclosed
A report from the Information Commissioner’s Office said that in November last year payroll data relating to almost 10,000 people had been wrongly disclosed to a third party because of an e-mail “oversight”.
It said that at the beginning of this year personal information about staff at 73 educational establishments had been wrongly disclosed in similar circumstances.
Related content
Councils sidelining information governance teams, says ICO official
ICO slams Wolverhampton over data security
The ICO’s report into the security lapses said investigators found the council “does not have a reliable method of monitoring the completion of refresher training” in relation to data-protection.
The joint undertaking signed by ICO head of enforcement Stephen Eckersley and Wolverhampton City Council managing director Keith Ireland commits the council to introduce mechanisms to deal with the shortcomings by the end of the year.
It says: “The data controller (Ireland) shall devise and implement a system to ensure that completion of data protection training is monitored and that procedures are in place to ensure that staff who have not completed training within the specified time period do so promptly. This should be completed within three months.
“The data controller shall ensure that all staff handling personal data receive data protection training and that this training is refreshed at regular intervals, not exceeding two years. The data controller should ensure that all staff that handle sensitive personal data regularly, receive refresher training within six months of the date of this undertaking.”
Eckersley’s report said he was satisfied that the terms of a 2014 enforcement notice handed down to Wolverhampton had been complied with.