What is a serious breach of data protection law?
The ICO has produced statutory guidance on how it will apply the new penalties – click here to view a copy. The ICO guidance suggests that the Information Commissioner, in determining whether he has the power to impose a monetary penalty, will consider whether: • there has been a serious contravention of data protection law; • the contravention was of a type that was likely to cause substantial damage or distress; and either • the contravention was deliberate; or • the data controller knew or ought to have known there was a risk and failed to take reasonable steps to prevent the contravention.