Breaking NewsUpdated as information becomes available
News·Breach Analysis·16 September 2026·Breaking

Southampton council reported seven serious data breaches in a year, including a lost notebook with 224 residents' details

Southampton City Council referred seven incidents to the Information Commissioner's Office in 2025/26, including a social worker's lost notebook containing the names, addresses and key safe numbers of 224 people. Mark Fermor on what a notebook, a miscatalogued archive and a curious officer tell us about the data organisations still cannot control.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
5 min read
Share
A paper notebook of handwritten names dissolving into cyan data streams above a dark desk, with a civic building in the background and a single magenta thread highlighting one leaked line
A paper notebook of handwritten names dissolving into cyan data streams above a dark desk, with a civic building in the background and a single magenta thread highlighting one leaked line

Why it matters

What this means for organisations holding critical data

Southampton City Council referred seven incidents to the Information Commissioner's Office in 2025/26, including a social worker's lost notebook containing the names, addresses and key safe numbers of 224 people. Mark Fermor on what a notebook, a miscatalogued archive and a curious officer tell us about the data organisations still cannot control.

Southampton City Council reported seven data breaches to the Information Commissioner''s Office in the past year, each deemed serious enough to require notification to the regulator, according to a report by the Daily Echo.

The incidents, set out in a report to the council''s governance committee by data protection officer Christ Thornton, paint a picture of risk spread across every format the council touches. In one case, a social worker lost a notebook containing the names, addresses and key safe numbers of 224 individuals. In another, inaccurate information about a person was shared with police. A council officer accessed information relating to a tenant and shared it with a family member, a case referred to the ICO as a potential criminal offence, though the regulator decided against opening a criminal investigation.

Other incidents included 167 children''s social care records being destroyed prematurely, 75 asbestos reporting forms going missing, the compromise of a financial assessment provider''s system and the miscataloguing of around 80,000 social care files.

Across 2025/26, 179 data security incidents were reported to the council''s governance and information team, down from 198 the previous year. Investigations found 72 per cent of reported incidents were confirmed data breaches, with information sent electronically to the wrong recipient the most common cause.

Mr Thornton told the committee the ICO was satisfied with the council''s remediation measures and had invited the authority to support its Better Care Records campaign. No questions were asked about the breaches at the meeting.

A lost notebook is a data breach

It is tempting to read a list like this and separate the serious incidents from the mundane. That instinct is wrong. A notebook containing names, home addresses and key safe numbers is not stationery. It is a structured extract of some of the most sensitive information a council holds, travelling in a bag, readable by anyone who picks it up, with no access log, no encryption and no way to revoke it.

Key safe numbers in particular deserve attention. They are, in effect, physical access credentials to the homes of people who often receive care. Their loss is not an administrative embarrassment. It is a safeguarding event.

The fact that a notebook appears on the same incident register as a compromised supplier system and an 80,000-file cataloguing failure is itself the lesson. Sensitive data does not respect the boundary between digital and physical. Wherever it is copied, carried or written down, it becomes breachable in exactly the same way.

The insider problem, again

Two of the seven incidents involve people, not systems: an officer accessing a tenant''s record and sharing it with a family member, and inaccurate information passed to police. This is the same failure mode seen in the Southport court files case and the ambulance service record access before it: legitimate credentials used for an illegitimate purpose.

No perimeter defence addresses this, because there is no perimeter crossing. The only effective responses are least-privilege access scoped to role and need, complete audit logging, proactive review of that logging, and consequences understood in advance. It is to the council''s credit that these incidents were identified and reported. The harder question is how long they went unnoticed before review found them.

Eighty thousand miscatalogued files

The miscataloguing of around 80,000 social care files may prove the most consequential item on the list. Miscataloguing is a silent breach multiplier: records that cannot be found cannot be protected, retention rules cannot be enforced on them, subject access requests cannot be answered fully, and destruction schedules either fail or, as the premature destruction of 167 children''s records shows, execute against the wrong information.

This is the unglamorous core of data governance. An archive that nobody can accurately index is an archive nobody can honestly claim to control.

What organisations should take from this

First, treat paper as an endpoint. If staff need information in the field, control the extract: minimum necessary data, no physical access credentials, tracked issue and return, and prompt destruction.

Second, measure your wrong-recipient rate. It was the most common cause here and it is the most common cause almost everywhere. Verification steps at send time are cheap. Breach notifications are not.

Third, audit your archive before someone else does. Records you cannot locate are records you cannot protect, and retention you cannot enforce is risk you are carrying unknowingly.

Fourth, disconnect what does not need to be connected. Historical care records, closed case files and legacy archives have no requirement to sit on live, reachable systems. Data that is not online cannot be casually browsed, wrongly emailed or quietly copied. Offline Secure Storage is built for exactly this class of data: the records an organisation must keep but does not need connected.

Sources

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

CustodyNamed, access-controlled hardware in a Firevault Bunker
EvidenceAccess windows and retrieval events are recorded
SeparationPhysical isolation that satisfies offline copy requirements
JurisdictionStored where your regulatory position requires