Foreign Office breached Data Protection Act
- 14 November, 2007 11:31
- Comments
The UK Foreign Office has been slammed for breaching the Data Protection Act after a probe by the Information Commissioner into a security flaw on a website used by people applying for UK visas.
The Information Commissioner's Office launched an investigation after being alerted in May to the security error on the UKvisas website provided by VFS Global, a commercial partner of the joint Foreign Office and Home Office agency, UKVisas.
The security hole meant that the personal data of people applying for visas to enter the UK was visible to other website users.
Independent investigators, led by Linda Costelloe Baker, have also probed the security breach, painting a damning picture of "organizational failures" by both the government agency and its contractor.
The investigation strongly criticized UKVisas' outsourcing of the online service to a firm that is not an IT specialist, the contractor's performance and the failure to respond adequately when the security hole was first revealed in December 2005.
The ICO based its ruling on the findings of the Costelloe Baker report.
But the watchdog body stopped short of slapping an enforcement notice on the Foreign Office, opting instead to require the department to sign a formal undertaking to comply with Data Protection Act principles in future.
Failure to meet the terms of the undertaking was likely to lead to further enforcement action, the ICO said.
Mick Gorrill, assistant commissioner at the ICO, said: "Organizations have a duty under the Data Protection Act to keep our personal information secure. If organizations fail to take this responsibility seriously, they not only leave individuals vulnerable to identity theft but risk losing individuals' confidence and trust. We investigate any organization in breach of the Act and will not hesitate to take appropriate action."
The undertaking commits the Foreign Office to scrapping the VFS online application website and replacing it with the visa4UK online application service -- a commitment already made by foreign secretary David Miliband.
UKvisas must also carry out a strategic review of data processing and a detailed audit of its data security procedures, regularly monitor the security of the visa4UK website and provide continuing data protection training to UKvisas staff, the document stipulates.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
-
Australia's first 4G smartphone is the HTC Velocity 4G
-
Swedish e-commerce startup's execs linked to NYC sex crime
-
Face Time - Interview with John Brennan and Robert DiStefano
-
How to implement next-generation storage infrastructure for Big Data
-
Pfizer's Future Depends on IT Transformation
-
Oracle x86 Rack Servers Optimized for Rapid Deployments and Operational Efficiency
Business-critical and mission-critical workloads demanding applications and databases require stable and secure environments. When these types of workloads are deployed on x86 servers, the need to ensure business continuity, maximum uptime, and consistent processing means that IT managers and business unit managers are looking at enterprise x86 servers in a new way: They realize that the business depends on these servers and that x86 server platforms for the enterprise are no longer expendable, as they might have been when servers were dedicated to a single application or when they were deployed as small Web servers that could be easily taken offline and replaced. -
Protecting Against the Leading Causes of Data Breach
This whitepaper was written for the organisation that wants to focus on prevention of data loss and doesn’t have millions to spend, but needs affordable solutions that can be implemented today to protect millions of sensitive records and dollars worth of intellectual property. This whitepaper addresses: - What organisations can do to prevent the four leading causes of data breaches - Why dedicated (pure-play) DLP solutions may not protect you from all four leading causes of data breaches - How to get prevent sensitive data leaving your organisation -
Pathways Advanced ICT Leadership Development Program Brochure and Course Outline 2012
Developed by the CIO executive Council in conjunction with Rob Livingstone Advisory, Pathways Advanced is a 12-month CIO delivered, small group, mentor based professional leadership development program. Pathways Advanced brings together best practice, thought leadership and business insights for today’s most promising ICT professionals
-
Professional Microsoft SQL Server 2008 Integration Services
-
Software Measurement and Estimation
-
Adobe Acrobat 8 PDF Bible
-
Mastering VBA for Microsoft Office 2007
-
Word 2003 All-In-One Desk Reference for Dummies
-
Mobility, Security and Web Services - Technologies and Service-oriented Architectures for a New Era of It Solutions
-
Coldfusion MX for Dummies
-
PHP & Mysql
-
Symbian OS Communications Programming








Comments
Post new comment