Voters details leaked in council data breach

PA/ Dominic Lipinski Hands on a laptop keyboard.PA/ Dominic Lipinski
More than 2,900 people in the Arbury ward have been affected by the data breach at Nuneaton and Bedworth Borough Council

Personal details of almost 3,000 voters have been leaked by a council in Warwickshire.

Nuneaton and Bedworth Borough Council admitted the data breach and said an administrative error was to blame.

The authority said the issue occurred as council staff were updating the electoral roll, sending out emails to those who had registered with the council's online elections portal.

However, the email sent to voters accidentally contained a link to thousands of names, those individuals' corresponding email addresses and, alongside the information, a personalised security code allowing each recipient to log in to the council's online system. An investigation is under way.

BBC/Joan Cummins The exterior of Nuneaton and Bedworth Borough Council's headquarters.BBC/Joan Cummins
The breach occurred on the first day of the annual canvass, where councils across England start updating their local electoral roll

The council said the breach happened on 27 July as part of the annual canvass to update details of everyone registered to vote in Nuneaton and Bedworth, more than 70,000 people in total.

It is understood the rogue emails were sent to voters in the Arbury ward, with the link leading to a spreadsheet full of the sensitive data of just over 2,900 people.

Tom Shardlow, chief executive of the council, apologised for the breach and said he was confident it was an isolated case.

"This was very quickly identified by the council and my teams worked really hard to limit the impact of this and bring the information offline and also to assure and notify those resident concerned," he said.

'Unacceptable'

He said the data that was breached was considered to be low-level by the council.

However, Shardlow said he understood that people who had been affected would be concerned.

"We take out information security really seriously and though I said low-level, any information shared when it shouldn't be shared is completely unacceptable.

"If I was a resident and saw that information shared, it would be very concerning. I can see why residents are becoming concerned around that."

He also said that those whose names and email addresses leaked had been contacted and if people had not been contacted by the council, they should not worry.

Shardlow said it was important that all council staff involved learn from the mistakes that led to the breach.

"We need to build into our processes fail-safes and double-checks to make sure this doesn't happen again. And that's what we're doing."

The council said it had also informed the Information Commissioner's Office (ICO), which provided advice on how to handle the breach and what steps needed to be taken.

Follow BBC Coventry & Warwickshire on BBC Sounds, Facebook, X and Instagram.