The Daily Telegraph

Child abuse inquiry fined for ‘reply all’ email data breach

- social affairs Correspond­ent By Olivia Rudgard

THE independen­t child abuse inquiry has been fined £200,000 by the Informatio­n Commission­er (ICO) after identifyin­g dozens of possible sex abuse victims.

The Independen­t Inquiry into Child Sexual Abuse sent a blind carbon copy (BCC) email to 90 participan­ts on Feb 27 2017, informing them of a public hearing, but a correction was then sent with the email addresses in the “to” field instead, the ICO said.

This allowed recipients to identify others as possible victims of child sexual abuse.

Steve Eckersley, the ICO’S investigat­ions director, said the incident “placed vulnerable people at risk”, adding that more “should and could have been done to ensure this did not happen”.

He said: “People’s email addresses can be searched via social networks and search engines, so the risk that they could be identified was significan­t.”

One respondent said he was “very distressed” by the data breach, and in total the ICO received 22 complaints about it. Of the 90 email addresses, 52 contained the recipient’s full name or a label with their full name.

The ICO said the inquiry had failed to give staff proper training about the importance of the “BCC” field.

Several months later, in July 2017, a further incident arose when a recipient clicked on “Reply To All” in response to an email from the inquiry, sent via the mailing list, and revealed their email to the entire list.

The inquiry had also breached its own privacy notice by sharing participan­ts’ email addresses without consent.

In a statement the inquiry said: “After a wide-ranging review by external experts, we have amended our handling processes for personal data to ensure they are robust and the risk of a further breach is minimised.”

The Prime Minister’s official spokesman said Theresa May continued to have confidence in the inquiry.

“The inquiry has apologised for this incident and referred itself to the ICO immediatel­y, and has introduced a number of measures to improve its data management,” the spokesman added.

Newspapers in English

Newspapers from United Kingdom