05/11/2025
Not every data breach comes from a hacker, sometimes, it’s just a mistake.
South Gloucestershire Council recently shared the personal details of over 600 residents online by accident. The data stayed up for three days before being removed.
Patrick Conroy, the council’s Strategic Planning Policy Manager, offered his “unreserved apologies” and said “the council takes matters of data protection extremely seriously.”
The council confirmed that “data protection incident policy and protocols are being followed, including referring the matter to the ICO,” and that all measures will be taken to avoid a repeat.
It’s a reminder that most breaches come down to human error, not malicious intent. Even with training, proper authorisation steps, sign-offs, and management oversight are crucial.
What did they do after the breach?
Removed the data immediately.
Reported the breach to the ICO
Carried out an internal assessment.
The real lesson here is prevention. Proper approval, training, and oversight could’ve stopped this before it ever reached the public.
At QLine, we help businesses with Cyber Essentials certification and GDPR guidance and staff awareness training.
Feel free to speak to one of the team!
0113 8000 192