Connect with us

Politics

Reprimands Issued Over Breach

The investigation was launched after a senior figure in the Cabinet Office accessed islanders’ personal data on more than 1,200 separate occasions.

Published

on

The Information Commissioner has issued a reprimand to each of the 20 public authorities impacted by the unauthorised access to personal data.

The investigation was launched after a senior figure in the Cabinet Office accessed islanders’ personal data on more than 1,200 separate occasions.

Whilst the investigation into those 20 public authorities is complete (apart from confirmation of completion of actions), an investigation into other matters remains ongoing.

The Commissioner said: ‘It is not the usual practice of the Commissioner to publish, or publicise, Reprimands. In this case, however, the Commissioner considers that there is a clear public interest in doing so, noting, in particular:

  • the extent of the access;
  • the breadth of public authorities affected, including bodies distinct from government; and
  • the purpose for the processing of that personal data, i.e. the fundamental right to request access to information under the Freedom of Information Act 2015.’

Deputy Commissioner Nicola Whiting said in a letter that the Commissioner has formed the opinion that that have been infringements of the legislation and a reprimand has been issued.

The reprimands will remain in place for two years from the issue date (June 28) and may be taken into account if other regulatory action is necessary during that period.

Report

In April 2022, Cabinet Office appears to have transferred ‘administration’ of iCasework to Isle of Man Constabulary (IOMC) (i.e. subsumed into the function performed by OCSIA) and IOMC, therefore, became the processor.

On May 22 2023, the function performed by OCSIA, including ‘administration’ of iCasework, was transferred to the Department of Home Affairs (DHA) and DHA became the processor.

However, as of June 27 2023, no contract existed between the (redacted) new admin and the DHA.

The report said: ‘(redacted) therefore infringed, and is continuing to infringe, Article 28 and its responsibility as a controller under Article 24, in addition to its failure to demonstrate compliance with the principles, pursuant to Article 5(2).’

It adds: ‘Whilst there may have been an ‘arrangement’ for the person in Cabinet Office to provide ‘administrative assistance’ to in respect of iCasework (the FoI system), the administration of iCasework was transferred from Cabinet Office to IOMC in April 2022.

‘After the date of transfer, there was no lawful purpose for that person to access personal data in iCasework, and any such access was incompatible with the purpose for which the personal data had been obtained by i.e. responding to FOIA Requests.’

You can read the full report here.