Southend on Sea City Council – Violation Found (United Kingdom, 2024)

Violation Found
Information Commissioner's Office17 October 2024United Kingdom
final
Violation Found

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Southend on Sea City Council in the UK faced a reprimand for accidentally revealing hidden personal data in a public document. This incident matters because it shows how easily sensitive information can be exposed due to lack of training. Companies should prioritize staff training on data handling to prevent similar mistakes.

What happened

The Council accidentally published a spreadsheet containing hidden personal data of employees and associated individuals.

Who was affected

Council employees, former employees, and associated individuals whose personal details were exposed.

What the authority found

The Information Commissioner's Office reprimanded the Council for failing to protect sensitive data due to inadequate training on Excel.

Why this matters

This case underscores the need for proper training in data management practices. Organizations must ensure their staff are equipped to handle personal data securely to avoid breaches.

GDPR Articles Cited

AI-verified

Art. 5(1)(f) GDPR
View original scraped data
Art. 5(1)(f) GDPR

Original data from scraper before AI verification against source document.

Source verified 23 March 2026
national law identified
Full Legal Summary
Detailed

On May 17, 2023, the Southend-on-Sea City Council, in Essex, responded to an freedom of information (FOI) request posted on the What Do They Know (WDTK) website (a public platform which allows individuals to submit requests to public bodies within the UK and all the request and the responses from the public bodies are published on the website, making them publicly accessible). The response included a spreadsheet that contained hidden personal data of Council employees, former employees, and associated individuals, such as agency workers. This data included contact details, employment information, salary, health data, gender, and ethnicity. The breach was only identified on October 27, 2023, five months later, when WDTK notified the Council. At the same time, the Council notified ICO about the data breach. The Council’s lack of awareness and preparedness for handling hidden data in Excel spreadsheets was highlighted as the primary cause. Staff had not been adequately trained in using Excel’s “Inspect Document” feature, which would have allowed them to check for hidden data before releasing the document. The ICO acknowledged the Council’s cooperation and transparency during the investigation, as well as the steps taken to mitigate the breach’s impact. However, due to the initial failure to ensure secure data processing, the ICO issued a reprimand, since the Council's failing to adequately protect sensitive employee data due to insufficient Excel training and awareness, emphasizing the need for improved data handling practices to comply with Article 5(1)(f) UK GDPR. In the reprimand, ICO recommended the implementation of all remedial actions to ensure future compliance and to provide training to all relevant staff on using Excel’s “Inspect Document” feature to prevent similar breaches.

Outcome

Violation Found

The DPA found a violation but did not impose a fine.

Related Enforcement Actions (0)

No other enforcement actions found for Southend on Sea City Council in UK

This is the only recorded action for this entity in this jurisdiction.

Details

Decision Date

17 October 2024

Authority

Information Commissioner's Office

GDPRhub ID

gdprhub-8568

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Southend on Sea City Council - United Kingdom (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: