Disclosure Log
Freedom of Information request - Request for information surrounding data loss (FOI/5577)
Message from Nottinghamshire County Council - 26 March 2025
Dear ***** *****,
FREEDOM OF INFORMATION ACT 2000 – REQUEST FOR INFORMATION REFERENCE FOI/5577
Thank you for your request for information relating to Freedom of Information request - Request for information surrounding data loss.
We are now able to provide the following information:
I would like to know to what extent you have implemented data encryption and cyber insurance policies and losses that you have incurred specifically covering the following.
1. How many laptops, mobile, tablet or USB devices have been lost or stolen from your organisation in the past year (Jan 2024-Dec 2024)
X 2 laptops and x20 Mobile Phones and x0 USB
1.a Please specify numbers of each device type.
See above
2. How many of these devices were encrypted.
All
2.a Please specify numbers of each device type.
See above
3. Have you had to disclose or inform the ICO of any devices being lost or stolen in the past year (Jan 2024-Dec 2024)
No.
4. Have you had to disclose or inform the ICO of a data breach for any other reason e.g., insider/employee/user error, cloud breach or supply chain breach in the same period. Please state reason for disclosure.
We have notified the ICO of one breach in the past year. This was due to a failure to redact personal data from a report.
5. How many data breaches (information has been lost, stolen or taken from a system without the knowledge or authorisation of the department/organisation) have you experienced within your organisation (department) within the past year (Jan 2024-Dec 2024)
This information is exempt from disclosure pursuant to S31(1)(a) of the Freedom of Information Act 2000: "Information ... is exempt information if its disclosure under this Act would, or would be likely to prejudice ... the prevention or detection of crime."
Any information that could be used by hackers, scammers and other malicious actors to compromise the Councils ICT systems and cyber security should not be disclosed to external organisations, partners or members of the public. Examples of this include the number of incidents/breaches and the type/nature of such incidents/breaches. Information relating to the Councils ICT systems and technical and operational security measures, if provided to the public at large, could pose a risk to the operations and assets of the Council via exposure to malicious actors.
S31 attracts the public interest test and the Council asserts that the public interest in transparency, scrutiny and accountability of the Council is outweighed by the public interest in ensuring the risks to operations and assets are not exposed to malicious actors.
6. Do you have an existing cyber insurance policy in place, and how long have you had it.
No
6.a If not, do you plan to invest in cyber insurance in the coming year.
No
7. Have you had to claim on an existing cyber insurance policy in the past year (Jan 2024-Dec 2024)
N/A
7.a if so, what was the reason for this i.e. ransomware attack, phishing scam...
N/A
8. Other than GDPR, have new and updated compliance regulations such as the proposed ransomware ban;
DORA and NIS 2, changed how you store and secure data within your department/organisation over the past year (Jan 2024-Dec 2024)
No
8. a If so are you encrypting more data as a result.
No, we have always encrypted.
We trust this now satisfies your request and that you find this information to be helpful, however if you are unhappy with the way in which your request has been handled, then please email us at [email protected] quoting the reference FOI/5577 and we will be happy to review your request
For future reference, Nottinghamshire County Council regularly publishes previous FOI requests and answers on its website, under Disclosure logs, that may provide details relating to your query. (see link) Your privacy: we use your personal information such as name and address so that we can comply with our legal obligations to respond to FOI requests. For further details about the use of information about you, please see the information handling privacy notice on our website at https://www.nottinghamshire.gov.uk/media/4323566/informationgovernanceandinformationrightsprivacynotice.pdf
If you are dissatisfied with the handling of your request, you have the right to ask for an internal review. Requests should be submitted within 40 working days of the date of receipt of the response to your original request and should be addressed to: Complaints and Information Team, Nottinghamshire County Council, County Hall, Loughborough Road, West Bridgford, NOTTINGHAM, NG2 7QP or [email protected].
Please remember to quote the reference number above in any future communications.
If you are not content with the outcome of the internal review, you have the right to apply directly to the Information Commissioner for a decision. The Information Commissioner can be contacted at: Information Commissioner’s Office, Wycliffe House, Water Lane, WILMSLOW, SK9 5AF or Yours sincerely
Complaints and Information Team
Nottinghamshire County Council
The Council is committed to protecting your privacy and ensuring all personal information is kept confidential and safe. For more details see our general and service specific privacy notices at: https://www.nottinghamshire.gov.uk/global-content/privacy