Massive Data Breach Exposes 9,500 PSNI Officers and Staff
A critical data breach involving the police service in Northern Ireland has resulted in the accidental publication of personal details of nearly 9,500 officers and staff. The breach occurred in August 2023, when a Freedom of Information request led to the upload of sensitive information onto a website. Counsel for the affected individuals has claimed that at least four people failed to spot the sensitive data, highlighting gross negligence and systemic failure.
Key Takeaways:
- The data breach occurred in August 2023, when a Freedom of Information request led to the upload of sensitive information onto a website.
- Nearly 9,500 PSNI officers and staff had their names, ranks, and roles inadvertently published.
- At least four individuals allegedly failed to spot the sensitive data, highlighting gross negligence and systemic failure.
- Up to 8,500 affected individuals are seeking damages, with group actions being pursued and six test cases identified.
- Claims have been brought for negligence and breaches of data protection and privacy.
- The PSNI has accepted liability but does not have the funding to settle the actions, with the UK Treasury rejecting a request for financial help.
- Counsel for the affected individuals has argued that the breach was so serious that it would have warranted a penalty of over £5m in the private sector.
Statistics:
- 9,500 PSNI officers and staff had their personal details inadvertently published.
- Up to 8,500 affected individuals are seeking damages.
- The estimated cost of the data breach is £120m.
- The PSNI has already been fined £750,000 by the Information Commissioner's Office for the data breach.
- Counsel has argued that a private sector organization would have faced a penalty of over £5m for the same breach.
Sources:
- The Times
- Reuters
- Information Commissioner's Office (ICO)