The Information Commissioner's Office (ICO) has today served a
monetary penalty of £130,000 to Powys County Council for a serious breach of the Data Protection Act where the details of a child protection case were sent to the wrong recipient. The penalty is the highest that the ICO has served since it received the power in April 2010 and follows a less serious, but similar incident, which was reported by the council to the ICO in June last year.
Once again it seems that a council is fined even though it put it hands up by notifying the ICO of the breach? Surrey County Council also told the ICO of its breach but were still handed a £120K fine.
There is no legal obligation to do so.
I would be interested in colleagues' views.