PSNI Data Breach: Causes and Consequences

PSNI Data Breach

Due to human error the Police Service of Northern Ireland (PSNI) recently experienced a data breach. The breach involved the release of personal information accidentally, in response to a freedom of information request.

The data shared included the names of serving officers and staff, where they were based and their roles.

Although later removed the spreadsheet containing the information was published online.

Clearly this data breach presents risks given the political situation in Northern Ireland. Many if not all of the people affected will be distressed by this event.

Unfortunately data breaches like this happen all too often. The details of this particular incident will become clear once an investigation into is is complete and at that point regulators like the Information Commissioner will decide what further action, if any, is necessary. It is important to understand that the areas of concern this breach raised are still only being looked at in an initial way and more details will be forthcoming as an urgent enquiry moves forward.

You can learn more about the offences and penalties that can arise from breaching GDPR here.

________________________________________________________________________________________________

About the Author
Michael is an expert in governance and information governance, with many years’ experience developing and improving freedom of information systems and processes. He has worked in this field across the public sector including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five star rated Freedom of Information course.

________________________________________________________________________________________________

The Impact on PSNI Staff

In the meantime police officers and police staff working in the police service will be taking steps to mitigate the risk of harm arising from the data breach. At worst this security breach could lead to consequences of monumental proportions. Police services could be disrupted and the people whose data have been breached could be the subject of criminal activity ranging from coercion and blackmail to serious personal harm arising from violent attacks or even terrorism.

More widely the friends and family of many officers will be worried and all affected will want to know what safeguards will be put in place to protect them from the threat this data breach has potentially caused. Individuals will a concern about the level of safety they can be sure of, perhaps for years to come.

When Freedom of Information and GDPR Meet

We have seen data breaches like this before. They often arise from human error and most of the time they occur either because data was not checked before being shared, or because the task of handling the data was delegated to an employee who is too junior to have the data skills necessary to recognise and prevent the potential breach.

Sharing Personal Data

What many people realise is that under the Freedom of Information Act it is legal to share the personal data of other people. The data of the requestor is exempt because they can make a subject access request under the Data Protection Act. However, third party data can be released in a limited number of circumstances.

Primarily the release of information about individuals has to be GDPR compliant. That means, principally, it has to be lawful fair and transparent. You could, for example, seek the consent of those whose data have been requested.

On the other hand it may be reasonable to share some limited personal data without consent because, for example, it relates to someone very senior like (in this instance) the Chief Constable. This is because their names, career histories, and remuneration are often in the public domain already. The same is not true of lower ranks.

Conversely, in relation to the PSNI data breach, uniformed PSNI officers wear badges with their name and rank while on duty. But again there is a difference between sharing information in relation to their police duties, and publishing information for the world to see.

However, because Freedom of Information disclosures are considered to be to the world at large, rather than the individuals requesting information, it is important to think about what is fair to data subjects in that context when considering whether or not to release information about them.

Find out more about Freedom of Information here.

Human Error Data Breaches are Avoidable

The key thing to remember here is that the information that was shared should never have been released. Breaches can occur in a number of ways – cyber attacks, for example. However, this accidental data breach was reportedly down to human error. How does an error like this happen? Well, in our experience there are typically three root causes:

A Lack of Understanding

In many instances people simply do not know that there are additional protections around personal data, or what to do to comply with the GDPR. This is more often the case for more junior colleagues, who will do what they are instructed to do and may not have a concern about a breach involving personal data.

Most organisations will typically provide some form of basic training. However, this is more often than not inadequate if a role involves collating, processing, sharing or publishing information about people.

A Lack of Time

In a fast paced work environment where there are a lot of demands on people’s time people can easily make mistakes. This is especially true if responding to a freedom of information request is not a regular or core part of someone’s functions. Unless people have support to handle personal data there is likely to be an issue from time to time.

Support can come in may forms, from a Data Protection Officer or FOI Officer, relevant policies, and clear procedures. Again, effective training will help people understand they they need to be mindful of data protection and the need to avoid a data breach.

A Lack of Ownership

This issue manifests itself in two ways.

Firstly, in a process like handling freedom of information requests a lot of people can be involved. From the person processing the information request to the people who have the requested data, a number of individuals have different roles to play. However, it may be that none of them focus on the data aspects of their role. As such data protection and information governance can slip between the cracks.

Alternatively people can work in a culture where the threat of a data breach is not treated as a potential issue. Data protection is given lip-service and senior leadership do not give GDPR compliance a priority. No-one treats the risk of a data breach seriously.

The outcome is the same either way. Human error happens because there was no process in place, culturally or operationally, to prevent it.

PSNI Data Breach: The Expert View

Michael Wuestefeld-Gray, our GDPR and Freedom of information expert said “too often events like this PSNI data breach occur because people do not recognise the sensitivity of personal data or give due regard to the risksof sharing it. Because data protection and information security are not treated as a priority they do not get the attention from senior leadership that they deserve. When delivering training I always encourage participants to compare information management to their management of money. In many instances organisations would never dream of managing their money the way they handle personal data. That is why things like the GDPR are needed. Members of a police service are now distracted from their duties and likely mistrustful of their organisation”

________________________________________________________________________________________________

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won’t use your data for anything else.

Sign Up Here:

________________________________________________________________________________________________

Data Breaches: Damage and Distress

There are different types of data breach. The most serious are the ones that are likely to cause damage or distress to the people affected. The GDPR describes this as impacting on the rights and freedoms of data subjects.

The most significant breaches are those that, according the the Information Commissioner, could lead to:

  • result in discrimination;

  • damage to reputation;

  • financial loss; or

  • loss of confidentiality or any other significant economic or social disadvantage.

Mitigating Action

Clearly the PSNI data breach staff have experienced could lead to at least one of these and mitigating action should be taken.

There are a number of actions the police service could take to support police officers and staff:

  • provide them with information about the breach so they can proactively take action to protect themselves from harm.

  • give them a route to raise any concern they have and discuss their safety and that of members of their family

  • increase the level of surveillance in order to pick up on any increased threat.

  • put in place other safeguards depending on the circumstances of any individual officer or employee.

Things that Make a Data Breach More Serious

A data breach becomes more serious if it involves:

  • the data of a large number of people

  • any delay to realising a data breach has occurred

  • the details of a vulnerable group such as children

  • sensitive personal data such as anything relating to health, gender, race, sexual orientation or political beliefs

  • anything that could lead to someone being the victim of a crime.

Anything that involves one or more of the above should inform your response to a data breach. It should make you consider what you should do in order to make the threat to people affected smaller.

You can learn more about how to handle a data breach here.

________________________________________________________________________________________________

Learn About the Freedom of Information

Gain the practical skills you need work with Freedom of Information and GDPR with these five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

 

Five star training testimonial

________________________________________________________________________________________________

Conclusion

The recent data breach that affected the PSNI is the latest in a series of human error based GDPR breaches. More details will be made public. However, over the years one thing has become clear. Almost every organisation would benefit from establishing the cultural and informational systems and processes that would reduce the risk of a data breach – and the threat to both them and data subjects if a data breach occurred.