The Police Service of Northern Ireland (PSNI) is facing a £750,000 fine for failing to protect the personal information of its workforce following an unprecedented data breach.
Announcing its intention to issue the proposed fine on Thursday, the UK Information Commissionerâs Office (ICO) said last Augustâs leak â involving more than 9,000 serving officers and staff â caused âtangible fear of threat to lifeâ.
The controversy led in part to the resignation of the then PSNI Chief Constable Simon Byrne, who described the breach as âindustrial scaleâ after the surname, initials, rank and role of every PSNI and civilian staff member accidentally appeared online in response to a Freedom of Information request.
In some instances, this detail was highly sensitive, particularly for individuals working in intelligence or covert operations.
Police later confirmed that the information was in the hands of dissident republicans.
ICO investigators said they had heard âharrowing storiesâ about the impact of the âavoidable errorâ on peopleâs lives, with some forced to move house or cut themselves off from family members.
They provisionally found the PSNIâs internal procedures and sign-off protocols for the safe disclosure of information were inadequate.
A total of 9,483 serving PSNI officers and staff were affected.
John Edwards, UK Information Commissioner, said that the sensitivities in Northern Ireland and unprecedented nature of the breach created a âperfect storm of risk and harmâ.
Some individuals had âcompletely altered their daily routines because of the tangible fear of threat to lifeâ, he said.
âIt shows how damaging poor data security can be,â he said.
âAnd whatâs particularly troubling to note is that simple and practical-to-implement policies and procedures would have ensured this potentially life-threatening incident, which has caused untold anxiety and distress to those directly affected as well as their families, friends and loved ones, did not happen in the first place.
âI am publicising this potential action today to once again highlight the need for all organisations to check, challenge and, where necessary, change disclosure procedures to ensure they have robust measures in place to protect the personal information people entrust to them.â
The Commissioner stressed that the findings and fine are provisional, adding he had used his discretion to apply the so-called public sector approach when calculating the £750,000 fine.
âThe aim of the approach is to ensure public money is not diverted away from where it is needed most, while maintaining the right to issue fines in the most serious of cases,â he said.
Had this approach not been applied, the fine would have been set at £5.6 million.
The PSNI and Northern Ireland Policing Board commissioned an independent review in the wake of the incident last year.
Carried out by Pete OâDoherty, temporary commissioner of the City of London Police, it made 37 recommendations for improving information security within the PSNI and said the breach should act as a âwake up callâ for forces across the UK.
PSNI Deputy Chief Constable Chris Todd described the ICO fine as âregrettableâ given the forceâs financial constraints, challenges and current deficit.
The senior officer said the PSNI accepted the Commissionerâs findings and will now take steps to implement the changes recommended.
âWe will make representations to the ICO regarding the level of the fine before they make their final decision on the amount and the requirements in their enforcement notice,â he said.
âThe reports highlight once again the lasting impact this data loss has had on our officers and staff and I know this announcement today will bring those to the fore again.
âSince the data loss occurred in August, the police service has worked tirelessly to devalue the compromised data set by introducing a number of measures for officers and staff. We provided significant crime prevention advice to our officers and staff and their families via online tools, advice clinics and home visits.â
The Police Federation for Northern Ireland (PFNI), which represents rank and file officers, said the ICO confirmed there were âdangerous failingsâ in the protection of personal information.
âItâs clear from this damning report that there was no holding back or minimising what officers and staff were confronted with as a result of personal information reaching the public domain,â Liam Kelly, federation chair, said.
âThis kind of egregious error can never be allowed to happen again and that must mean the organisation ensures watertight data defences are in place and that they operate the most stringent possible processes and protocols in the future.â