Southend-on-Sea City Council has referred itself to the Information Commissioner’s Office (ICO) following a serious data breach in which the personal information of over two thousand people currently or recently employed by the council, as well as current councillors, was mistakenly disclosed.
Very poor handling of the data breach
The first reports of the breach appeared on the website of the Echo newspaper during the evening of 2 November and included a quote from the leader of the council, Conservative Councillor Toby Cox, and this was followed swiftly by the BBC. However, nothing about the breach was posted at the time on the council’s ‘X’ (formerly Twitter) account or on their own website to give any indication whether the story was true.
An official press release, which contained the same Cox quote, was eventually uploaded to the ‘latest news’ section of the council website during the morning of Friday 3 November. This meant that for some 12 hours after the story broke, those potentially affected could only learn of the breach by reading a news alert, rather than hearing directly from the council.
Why the gap between the news breaking and it being acknowledged on the council website? If the news articles published on Thursday evening were the result of a press release from the council, why was it not uploaded sooner on their own site, or referenced on social media? If the news came not from a press release, but from an internal email or update to the staff, then this should raise further concerns over how Southend Council manages and controls its data.
What was disclosed in the data breach?
The breach disclosed the full names, home addresses, national insurance numbers, pension details, salaries and equal opportunities information of the current 1,854 permanent, part-time or casual staff, 276 former members of staff, and 169 agency staff, canvassers, office holders, councillors and co-opted staff.
A former member of staff who wishes to remain anonymous summed up the ramifications of the breach:
“Errors like that should not have happened. I do not know if I have been affected by this and, due to their proven inability to do things right, I cannot trust that they would have contacted me by now.”
How did the data breach happen?
The information about the members of staff was contained on a spreadsheet created in response to a Freedom of Information Act (FOI) request. The spreadsheet was uploaded to a Freedom of Information website on 17 May.
To be clear, this was not an email to an individual, it was on a website that any member of the public could view. The spreadsheet was originally anonymised and related only to one department, but on 27 October 2023 the council became aware that private and personal information could be accessed by those with a knowledge of how spreadsheets work.
East Anglia Bylines has had experience of dealing with the FOI team at Southend City Council throughout this year and has had to endure ignored requests and late responses. Information has been supplied that is inaccurate to the point of almost being intentionally misleading. Their handling of FOIs has been generally sub-optimal.
This breach is emblematic of wider failures within the organisation and comes as the council is still attempting to move on from accusations of bullying and fraud. It is difficult to see how this recent calamity will aid that effort.
Consequences of a data breach
Having received the referral from the council, the ICO will begin an investigation into what actually happened and what lessons can be learned. They can also issue fines, sometimes in the range of hundreds of thousands of pounds, depending on the severity, in relation to the breach. Such an outcome will be problematic for the council which is already feeling the widespread pressure on local authority finances due to government cuts. It is currently £14m in debt and is seeking to cut services.
Southend City Council has confirmed it will no longer be providing spreadsheets as part of its FOI responses.







