R E L A T E D   C O N T E N T
ADVERTISEMENT

UK government guilty of DPA breach

Website farce exposes details of 50,000 applicants

Iain Thomson, vnunet.com 15 Nov 2007
ADVERTISEMENT

The Foreign and Commonwealth Office (FCO) has been found guilty of breaking data protection laws after a security lapse on a visa application website.

The breach occurred on a site set up by the FCO and the Home Office to handle visa applications from overseas.

An investigation by the Information Commissioner's Office (ICO) found that a flaw in the site meant that users could see as many as 50,000 other applicants' details when they logged in.

Mick Gorrill, assistant commissioner at the ICO, said: "Organisations have a duty under the Data Protection Act to keep our personal information secure.

"If organisations fail to take this responsibility seriously they leave individuals vulnerable to identity theft and risk losing individuals' confidence and trust.

"We investigate any organisation in breach of the Act and will not hesitate to take appropriate action."

The running of the site was outsourced to Indian company VFS, and a customer alerted the FCO to the problem in December 2005. The flaw remained in place, however, and the FCO only admitted to a problem earlier this year.

Following the Information Commissioner's report, the FCO has admitted responsibility for the breach, corrected the fault and ended its relationship with VFS.

"The VFS online application websites will not be reopened and will be replaced by visa4UK, the UKvisas online application facility which will be the only online application system used by UKvisas," said the FCO in a statement (PDF).

"A strategic review of data processing will be undertaken by UKvisas in order to strengthen Data Protection Act risk management processes, and a detailed audit carried out of the data processor's data security procedures.

"Regular monitoring of the visa4UK website will be undertaken to ensure that the systems in place to provide effective protection."

See also:

Courier leaves 15,000 accounts at risk  05 Nov 2007
Dealing with Nigerian 419ers first hand  24 Oct 2007
Little encryption and poor disaster recovery plans  12 Oct 2007
Survey identifies key concerns among consumers  11 Oct 2007
Dr Tanya ByronDr Tanya Byron heads review of internet and video games influence  10 Oct 2007

All Privacy & Data

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Senior C# Agile Web Developer, Online Gaming, London My Client provides adult customers with high quality gambling and gaming services in an environment that is convenient, entertaining, fair, regulated and secure. My Client is one ... more >
| Aston Carter
EMC, NetApps, West London, Media • NetApps FAS ... more >
| Abraxas
Data Analyst / MI Analyst – Leading Online Gaming Company A Data Analyst / Trafficker is sought by a leading online gaming company. The role encompasses all aspects of online advertising including data handling, communicating ... more >
| JAM Recruitment
Field Applications Engineer Power Electronics/Supplies Europe/Based Surrey Permanent Position £35-45k Basic+Bonus 10-15%+Car/Car allowance A global organisation involved with the design and development of power supplies actively requires a Field Applications Engineer to strengthen it existing ... more >
More job opportunities