Print

Print


Chris's point is a good one in circumstances where you do not actually know what has been lost - steps should be taken in such cases to retrieve the material so that you can properly assess what remedial action to take. In other cases it is surely for the data controller to keep proper records of the breach. Failure to do so would in my view be a further breach of P7 and could be a serious aggravating factor when sanctions were considered. Asking the recipient to keep the 'evidence' should be unnecessary in such cases. 
----- Original Message -----
From: Chris Tinsley
Sent: 09/07/12 10:05 AM
To: [log in to unmask]
Subject: Re: [data-protection] Data breach and responsibilities of the recipient

 I wonder if by asking the unintended recipient of the data to destroy it that you may be asking them to destroy evidence of your misdemenour(perhaps in the hope that it will go away), which may be a good thing for you but not for justice. Perhaps you should be telling them to inform ICO and see what ICO want them to do with it. Imagine the senario, "I've just been sent sent loads of really sensitive data from an NHS trust by mistake" "What was it". "Can't tell you cause I've destroyed it". "Who else was it sent to". "Don't know cause Ive destroyed it". "Who sent it to you". "I don't know who but it came from the hospital". Chris Chris Tinsley | Information Management Officer, GreenSquare Group tel: 01249 466112 | [log in to unmask] | Methuen Park, Chippenham SN14 0GU GreenSquare incorporates Oakus, OCHA, Sparrow, Tidestone, and Westlea Housing housing people, building communities www.greensquaregroup.com

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
     All archives of messages are stored permanently and are
      available to the world wide web community at large at
      http://www.jiscmail.ac.uk/lists/data-protection.html
     If you wish to leave this list please send the command
       leave data-protection to [log in to unmask]
All user commands can be found at http://www.jiscmail.ac.uk/help/commandref.htm
 Any queries about sending or receiving messages please send to the list owner
              [log in to unmask]
  Full help Desk - please email [log in to unmask] describing your needs
        To receive these emails in HTML format send the command:
         SET data-protection HTML to [log in to unmask]
   (all commands go to [log in to unmask] not the list please)
    ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^