Business & Technology
Council data breaches rise 53% in five years, study finds
Recorded data breaches across 78 of England’s largest local councils rose 53% over five years, according to research by password management company Passpack. Referrals to the Information Commissioner’s Office (ICO) for the most serious incidents increased 41% over the same period.
The study drew on Freedom of Information responses from 78 of 100 councils contacted, covering 2021 to 2025. In the most recent reporting year supplied by each authority, the councils logged 16,902 incidents on internal breach registers and made 305 referrals to the ICO.
The figures cover a wide range of incidents, from emails sent to the wrong recipient to breaches serious enough to require notification to the regulator. Under UK GDPR, organisations must report a breach to the ICO within 72 hours if it is likely to pose a risk to individuals’ rights and freedoms.
Across the dataset, the ratio of internal incidents to ICO referrals was about 50 to one. This suggests most logged events were minor, but the rise in referrals points to an increase in incidents councils judged serious enough to have potential consequences for residents.
Largest rises
Among authorities with data for the full period, Wiltshire Council recorded the sharpest increase in internally logged incidents, up 601% from 341 in 2021 to 2,391 in 2025. Gateshead Council followed with a 302% increase, while the London Borough of Greenwich rose 215% and Salford City Council 191%.
Wiltshire also recorded the highest total number of incidents in the latest year covered, ahead of Bristol City Council with 721, Wakefield Council with 607, Sheffield City Council with 574 and Manchester City Council with 533.
Bristol recorded the highest number of ICO referrals in its latest reporting year, with 21. Cumberland Council and Cornwall Council each recorded 16, followed by Shropshire Council with 15 and the London Borough of Enfield with 14.
Council responses
Several councils said the figures reflected stronger internal reporting rather than a direct rise in damaging breaches or cyber attacks. Some also stressed the distinction between data-handling incidents and cyber security events.
A Manchester City Council spokesperson said the FOI data covered all types of potential data incidents, including near misses, cases where no data was lost and incidents flagged by other organisations that may have affected the council.
They said such incidents would not necessarily qualify as data breaches, and many did not involve personal data breaches. Many were low-level data-handling issues and did not involve unauthorised system access, malware or external threat actors, but were still reported internally as good practice.
The spokesperson added that annual mandatory GDPR training had improved staff understanding of good data practice and reporting responsibilities. Greater awareness, clearer reporting routes and better detection mechanisms meant issues that might previously have gone unreported were now being logged and managed appropriately.
Manchester also said cyber security and data protection were treated as separate risk areas, and that combining the two would give a misleading impression of its cyber security position. It said there had been no material cyber security incidents affecting core systems or resulting in the loss of personal data, and that a higher number of reported data protection incidents reflected stronger organisational maturity and a more open reporting culture, rather than weaker cyber security controls.
Bristol, which recorded the most ICO referrals, said it encouraged staff to report all suspected incidents, however minor, so they could be investigated and used to improve controls.
Wakefield Council, one of the authorities with the highest internal incident totals, said the figures included minor, non-reportable events and that no cyber attacks had resulted in a personal data breach during the period covered.
Wiltshire Council said its high totals reflected a broad reporting culture that included near misses and incidents identified through data loss prevention tools introduced through Microsoft 365. It added that none of the breaches it had reported to the ICO over the past five years had resulted in enforcement action.
Broader pressure
The findings come as local government faces sustained scrutiny over cyber resilience and data protection practices. Councils hold large volumes of residents’ personal information, including housing, social care, education and benefits data, while many operate under financial pressure.
Several major incidents have affected councils in recent years. Leicester City Council suffered a ransomware attack that disrupted IT systems and phone lines for weeks, while an attack on housing software supplier Locata affected housing websites used by Manchester, Salford and Bolton councils. Following a 2020 ransomware attack, Hackney Council spent more than GBP £12 million in a single financial year on recovery.
The research also noted the lack of a consistent national approach to how local authorities detect, classify and record data incidents. That makes direct comparisons difficult, particularly when one authority logs near misses and another records only confirmed breaches.
The London Borough of Bexley said the increase in reported data breaches should be seen in the context of a more open and mature reporting culture. It said staff had been encouraged to report all actual and potential data breaches, however minor, so they could be investigated, lessons learned and controls improved.
Bexley added that while the overall number of internally reported breaches had increased, the number requiring notification to the ICO had remained broadly consistent. In its view, that suggests the rise was driven mainly by better internal reporting of lower-level incidents rather than an increase in serious breaches, and reflected greater awareness of the importance of data protection across the organisation.
Business & Technology
‘WH Smith’ chain rescue comes with ‘considerable risks’
“This has all the hallmarks of an adventurous equity play,” wrote Mr Justice Hildyard in his judgment published yesterday after he last month approved the restructuring, which involves the closure of 150 of the books-to-paperclips retailer’s 450 stores.
He added that the group’s turnaround plans “might strike the sceptic as more in the nature of generic aspirations than concrete grounds for confidence in a successful outcome”.
The chain includes numerous former WH Smith branches across Oxfordshire.
These include stores in Cornmarket, Oxford, and in Witney, Abingdon, Chipping Norton, Didcot, Wantage and Banbury. The takeover came into effect a year ago.
READ MORE: Major high street retailer could collapse
“The execution risk is very considerable,” Mr Justice Hildyard said, indicating the £3m valuation of the company – compared with its acquisition value of about £40m only a year before – reflected the potential for high losses as well as high profits.
The retailer, which until recently employed about 5,000 staff, was bought last year by Modella Capital, the private equity firm which is also behind Hobbycraft and owned the UK arm of jewellery retailer Claire’s and The Original Factory Shop until they collapsed earlier this year.
It recently bought Flying Tiger, the Danish retailer known for its cut-price homewares, craft kits and notebooks, which operates about 1,000 stores worldwide.
TG Jones in Oxford (Image: Google Maps)
The original owner of WH Smith continues to operate stores in airports, hospitals and railway stations, so Modella quickly rebranded the high street stores as TG Jones.
Sales quickly fell back after the deal, and Modella had warned it could have to call in administrators if the restructuring plan, which involves writing off debts to suppliers and cutting rent for many landlords, was not approved.
The judge approved the plan despite his scepticism about potential success, because Modella had put up new investment to turn it around.
Alex Willson, the chief executive of TG Jones, said last month that approval of the plan “allows us to move ahead with our turnaround strategy”.
“The plan protects the substantial core of the store estate and makes TG Jones a stronger, more sustainable business,” he said.
Court approval was needed for what is known as a “cram down” scheme, as many classes of creditor who would lose money under the scheme rejected it. The model allows courts, in certain circumstances, to impose a restructuring on dissenting classes of creditors.
Fewer than a third of general creditors, who include card makers and pen brands, agreed to the plan and no landlords owning unwanted stores – where rent will be cut to zero or closed – backed the plan.
Small suppliers, such as toy makers, were set to lose at least half the money owed to them by the former WH Smith high street chain under the restructure.
Business & Technology
B&Q issues urgent recall for popular heatwave item amid 'electric shock' warning
B&Q has issued an urgent recall for one of its popular heatwave items after warning of ‘electric shock and fire’.
Source link
Business & Technology
Evri approved after Oxford Botley Road shop wins extension appeal
Nisa Local, which first opened in Botley Road in November, can now be extended after a Planning Inspector overturned Oxford City Council’s rejection.
The proposal is for a steel security shutter and a single-storey rear extension, which would provide more space for new services such as an Evri and two more Cook frozen meal freezers.
The Costa Coffee self-service machine is hoped to be on the front of the shop and will provide more floor space for Bake & Bite and the Oxford-based Natural Bread Company.
Oxford City Council refused permission in March arguing the extension would harm the character and appearance of the property.
Aejal Patel, Nisa manager (Image: Ben Hardy)
However, planning inspector Alexander O’Doherty concluded the impact on the wider area would be limited because the extension would be largely hidden at the rear from public view.
In his decision issued on July 23, the inspector acknowledged that the extension would have some harmful effect on the appearance of the building itself, but said the benefits outweighed that harm.
The inspector noted the shop is “clearly lacking in storage space” and said the additional floor area would help it better serve local residents.
The decision also referenced numerous representations from supporters, with the inspector saying these lent “considerable credence” to the benefits of the scheme.
He added that providing these services within a residential area would encourage walking, cycling and the use of public transport by reducing the need for residents to travel elsewhere by car.
-
Business & Technology3 weeks agoHSBC UK & Visa test AI shopping with live payments
-
Business & Technology4 weeks agoMouser warns against viral hacks to cool overheating phones
-
Business & Technology3 weeks agoValarian lands USD $50 million backing for sovereign AI
-
Business & Technology4 weeks agoKane tops England influencer rankings after Mexico win
-
Business & Technology4 weeks agoSNP & Palantir launch AI tools for SAP transformations
-
Oxford News4 weeks agoDWP now checking bank accounts for Universal Credit and Pension Credit
-
Oxford Events4 weeks agoHenley Festival 2026 highlights: Five nights of unforgettable performances and festival moments
-
Business & Technology4 weeks agoOde launches free AI voice service for poem recommendations
