Birthlink
€20,725
Insufficient technical and organisational measures to ensure information security
Decision Date
June 24, 2025
Authority
Information Commissioner (ICO)
GB
Sector
Individuals and Private Associations
Country
GB
Law
GDPRStatus
FINALDescription
The UK DPA has imposed a fine of £ 18,000 (EUR 20,725) on Birthlink. The controller, a scottish registered charity, failed to implement sufficient technical and organisational measures to ensure data security, resulting in the loss of irreplaceable personal records.
Legal Citations
Art. 5 (1)Art. 32 (1)Art. 33
Issues & Violations
Insufficient technical and organisational measures to ensure information security