Warning this blog post contains spoilers!
I appreciate that this might sound a bit sad. Very sad actually. I recently went to see the latest Bond movie, Skyfall, and whilst the rest of the audience were caught up in the action and adventure, my mind started drifting off to the exciting world of the Data Protection Act 1998.
Let me explain.
The plot of Skyfall revolves around the theft of a laptop’s hard drive containing personal details of undercover agents placed in terrorist organisations by NATO states. Bond travels around the world killing people in order to hunt down the thief, while back in London, ‘M’ has to take the flak for the appalling breach of security.
Although ‘M’ is subject to a great deal of criticism, not once (not once!) is there mention of the Data Protection Act 1998.
Schedule 1 of the Data Protection Act sets out eight Data Protection principles. The 7th principle is that “appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data”.
Some might say that the fact MI6 were happy that a database of highly sensitive personal data should be stored on a laptop and taken outside MI6′s headquarters was a flagrant breach of this principle. The encryption system used on the hard drive also appears to be substandard, as these names started popping up in the public domain almost before Bond had managed to bag himself his first kill.
Breaches of this principle are not however confined to the silver screen.
In October 2007, HM Revenue & Customs lost two computer discs containing the personal details of all families in the UK claiming child benefit. The data was reported to concern approximately 25 million people, and include details of names, addresses, national insurance numbers and bank details.
In 2008, a laptop belonging to a company retained by Marks & Spencer was stolen during a burglary at the home of its managing director. The laptop contained the unencrypted personal pension details of around 26,000 M&S employees.
In an age of remote working, laptops, mobile phones and other hand-held devices, compliance with the 7th Data Protection Principle is difficult, but all the more important. The Information Commissioner’s Office has recommended that all portable and mobile devices used to store and transmit personal information should be protected using approved encryption software. The ICO will take enforcement action in cases where encryption has not been used to protect data and losses occur. It is no defence that a device was stolen rather than simply lost. If personal data is being processed by contractors, it is important to ensure that those contractors adopt the same standards, and that full risk assessments are undertaken before data is provided to those contractors.
If you have any queries regarding your obligations under the Data Protection Act, or are subject to an ICO investigation then Buckles is happy to assist. If any writers of the next Bond movie are reading this, we are also of course happy to provide our input to ensure the script properly references all relevant legislation.