The Cabinet Office has been reprimanded by the Information Commissioner for a data breach that affected thousands of residents.
Every household across the Isle of Man was contacted in January ahead of the September general election to verify and update electoral registration details.
Letters were addressed to ‘The Occupier’ and contained a form with the personal details of the last people to register to vote at the address.
But some of the information was out of date.
Members of the public complained to the Information Commissioner’s Office (ICO) that they had received personal details about other people.
An estimated 3,215 individuals were affected.
The ICO alerted Cabinet Office which took steps to stop the rest of the letters from being delivered - but it was too late.
On January 7, a data breach was reported to the ICO by the Cabinet Office.
The Information Commission investigated and concluded that a reprimand should issued.
Information Commissioner Dr Alexandra Delaney-Bhattacharya said: ‘Taking into account all the circumstances of this case, including the aggravating and mitigating factors, and remedial steps, I have decided to issue a reprimand to Cabinet Office in relation to the infringements of the Applied GDPR.
‘Cabinet Office holds some of the island’s most sensitive personal data. For people to have trust in government institutions – particularly for something as important as people’s right to vote, it is essential their information is respected and protected.
‘I am pleased to note Cabinet Office is committed to applying the learning from this incident and is strengthening its approach to data protection compliance.’
Under an original plan, letters were to be addressed either to a previously confirmed ‘head of household’ or, where no head of household had been nominated, to ‘The Occupier’.
For households with a confirmed head of household, the enclosed form would include the personal details of registered occupants so they could be checked and updated if necessary. Where no head of household was recorded, the form was intended to be left blank.
However, in preparing for the canvass, Cabinet Office found that 53 percent of households did not have a nominated head of household.
A decision was taken to address all correspondence to ‘The Occupier’ and to pre-populate forms with the personal data of those last registered to vote at each address.
Dates of birth, which do not appear on the public electoral register, were also included.
The Information Commissioner acknowledged that the Cabinet Office had reported the breach promptly and this was taken into account when deciding on what level of regulatory action to take.
Outlining the lessons to be learned, she said it had been recognised at the risk assessment stage that the proposed processing would result in a personal data breach.
Where this is the case, organisations should take measures to mitigate the risk - even if this means that the preferred method of processing must be altered to accommodate the additional protections, she said.
Data protection should be considered from the outset and in this case, time-pressured reviews and late-stage changes led to risks not being fully mitigated.





