Earlier this week, Justice Minister Michael Wills laid a statutory instrument before Parliament setting a £500,000 fine for companies that fail to protect sensitive personal data. Under the legislation, the Information Commissioner's Office (ICO) can fine companies if "the data breach resulted from a deliberate act or negligence and is likely to cause damage or distress to an individual."
Between 2007 and 2009, 209 NHS health trusts and bodies suffered data security breaches. At present, the ICO only has the power to serve companies with an enforcement notice requiring them to improve data security or face legal action. Unless Parliament objects to the proposal, the legislation will come into effect from the 6th April, and companies failing to comply will be forced to pay the £500k fine.
To read the story in full on Silicon.com, please click here