Council fined $384k for negligent outsourcing

Digitisation project ends in dumpster privacy disaster.
  • Liam Tung (CSO Online (Australia))
  • — 12 September, 2012 13:50

The UK’s Information Commissioner’s Office (ICO) has fined a council £250,000 (AU$384,000) after its document scanning contractor dumped a load of employee pension records in a shopping market’s recycling bin.

In 2011, a member of the public discovered eight boxes overflowing from a paper recycling bin that were later found to contain income, insurance, address and other personal details of over 600 former Scottish Borders Council employees.

The discovery was reported to police and the council later discovered the documents were dumped by the scanning outfit it had contracted in 2005 to digitise its pension records.

While hundreds of documents were found in that recycling bin, the ICO’s investigation found the contractor’s standard practice was to dump the original pension documents in recycling bins. The contractor also returned the scanned files to the council on unencrypted discs in standard post.

As many as 8000 pension records were handled in similar fashion during the contract’s duration, according to the ICO’s penalty notice.

The council was fined primarily for failing to require its contractor to securely handle sensitive employee documents.

“This is a classic case of an organisation taking its eye off the ball when it came to outsourcing. When the Council decided to contract out the digitising of these records, they handed large volumes of confidential information to an outside company without performing sufficient checks on how securely the information would be kept, and without even putting a contract in place,” said Ken Macdonald, ICO Assistant Commissioner for Scotland.

Follow @CSO_Australia and sign up to the CSO Australia newsletter.

Comments are now closed.
CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Trend Micro Mobile Security

Comprehensive enterprise protection for mobile devices

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.