Warning of scant regard for data protection
The warning came in the latest annual report issued by the data protection commissioner Billy Hawkes, in which he revealed that there was a record number of investigations opened by his office last year following complaints from people who were blocked from accessing personal data held by organisations.
It also revealed that the activities of domestic data controllers — both in the private and public sectors — attracted most of the enquiries and complaints dealt with by the office last year.
Writing in the foreword, Mr Hawkes said: “Our audits of state organisations have, in too many cases, shown scant regard by senior management to their duty to safeguard the personal data entrusted to them — a duty that is all the greater because of the legal obligation to provide such personal data to the State.
“Failure to treat personal data with respect can only lessen the trust that should exist between the individual and the State. It will also lead inevitably to more formal enforcement action by my office unless system- wide action is taken to improve current practice.”
An audit of the gardaí found “disturbing instances” of improper access by individual gardaí and that scheduled audits of accesses to the Pulse system, as provided for in the force’s Data Protection Code of Practice, had not been carried out.
As for commercial entities, Mr Hawkes said many complaints received by his office were due to “poor standards of customer service” and that “repeat failures in this area is a source of concern”. The report also noted a growing issue of “staff moving from one employer to another and taking client data to their new employer”.
Overall, the office opened 910 complaints, down from 1,349 complaints in 2012, but complaints concerning access requests accounted for 56.8% of the total. The 517 complaints in relation to access requests was an annual record for the office.
Unsolicited direct marketing, text messages, phone calls, faxes, and emails accounted for almost a quarter of complaints, with prosecutions brought against major telecommunications firms.
The vast majority of complaints concluded last year were “resolved amicably”.
Read the full report at www.dataprotection.ie
- A doctor passed on a patient’s personal data to an insurance company without consent. The GP received a request seeking medical records relating to a knee injury. It was alleged the GP disclosed sensitive medical information — including cervical smear test results, a colposcopy, correspondence over lesions, and records relating to carpel tunnel syndrome — none of which related to the knee injury.
Following contact from the Data Protection Commissioner, the doctor said copies of a patient’s records were “inadvertently” supplied to the insurance company with some details which were not relevant to her knee injury, and that this was an oversight and that he was deeply sorry.
- The office received a complaint in May 2012 against the Department of Social Protection, in which a complainant alleged there had been unauthorised access within the department to his records by an employee. The Data Protection Commissioner found 12 instances of unauthorised access of the complainant’s records.
According to the report: “This case highlights the unacceptable practice by some individuals of snooping through official records for personal reasons unconnected with their official duties.”
- Carphone Warehouse apologised to a woman after a member of staff provided her contact details to two people understood to have stolen the phone from her.
Following the initial theft of the phone, two people arrived at the woman’s isolated home with the stolen phone and sought a reward for finding it. The woman handed over €50 and the phone was returned to her, albeit damaged.
- Spar said it was “regrettable and completely in contravention of the ethos of the business” that CCTV footage showing a staff member tripping and falling had been accessed, copied to a mobile phone by another staff member in the company of a manager, and circulated to third parties.
Data Protection Commissioner’s Annual Report:
- 1,577 data security breach notifications received;
- 910 complaints opened for investigation;
- 517 complaints — almost 57% of the total number — opened for investigation related to people having difficulty securing access to their personal data held by organisations;
- 204 investigations related to unsolicited marketing communications;
- 44 audits and inspections were carried out — up 10% on 2012’s figure;
- Three audits of major holders of personal data — the Department of Social Protection, the Revenue Commissioners and An Garda Síochána;
- 12,000 queries dealt with via info@dataprotection.ie, up 2,500.



