The UK's Information Commissioner's Office (ICO) is set to fine the Police Service of Northern Ireland (PSNI) £750,000 ($954,000) for a breach of staff data after the service accidentally published a spreadsheet containing personal details of employees online

The ICO is a regulatory body responsible for enforcing UK data protection laws. This mistake by the PSNI is a clear breach of those laws
See also: Western Sydney University: Thousands of students' data breach
The police revealed the incident on August 8, 2023, stating that an error occurred while responding to a Freedom of Information (FOI) Request (FOI). The result of this error was the leak of the following data:
- Surnames
- Initials of name
- Grades
- Clock
- Locations
The data breach affects 9,483 active duty officers and staff of the Police Service of Northern Ireland.
According to the ICO's assessment, the incident placed the exposed individuals at serious physical risk, while it was an incident that could have been completely avoided.
"We have announced that we intend to impose a fine of £750,000 on the Police Service of Northern Ireland (PSNI) for failing to protect the personal data of its entire workforce," the statement reads.
"Our investigation provisionally found that the PSNI's internal procedures and signing protocols for the secure disclosure of information were inadequate," the Commissioner said.
See also: OmniVision reveals data breach
The research revealed that many were forced to move to new physical addresses, cut off communication and relationships with family members to protect them from potential harm, and were generally forced to completely change their daily lives.
The Commissioner noted that the proposed fine for the Police Service of Northern Ireland for the data breach is far lower than it should be. It simply takes into account that the PSNI is a public body operating on a limited budget, providing critical services to the community.
By order of the Commissioner, the police are required to implement improved data protection measures in the process of handling FOI requests.
The police accepted the sentence and pledged to take steps to implement all the proposed changes.
The force said it has been supporting its staff with crime prevention advice, online tools and home visits throughout this time. At the same time, 90% of exposed offices and staff also received a £500 ($635) refund in December 2023.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The investigation into who owns the leaked data continues!

This incident highlights the importance of proper data handling and security protocols within organizations. The fine also serves as a reminder of the consequences of non-compliance with data protection laws.
See also: Australia: MediSecure suffers data breach
Organizations should have robust systems in place to prevent accidental exposure of personal data. This includes implementing appropriate training and procedures for handling sensitive information, regular security , and having a designated Data Protection Officer responsible for ensuring compliance with data protection regulations.
In addition to fines, failure to comply with laws can also lead to serious damage to an organization's reputation. Data breaches can lead to identity theft, financial loss, and other negative consequences for individuals whose personal data is exposed.
Source: www.bleepingcomputer.com
