Tuckers Solicitors LLP

€115,000

Non-compliance with general data processing principles

Data della decisione

10 marzo 2022

Autorità

Information Commissioner (ICO)

GB

Settore

Finance, Insurance and Consulting

Paese

GB

Legge

GDPR

Stato

FINAL

Descrizione

The UK DPA (ICO) has fined law firm Tuckers Solicitors LLP EUR 115,000. Tuckers suffered a ransomware attack on its systems, which resulted in a personal data breach. As part of its investigation, the DPA determined that Tuckers had failed to take appropriate technical and organizational measures to protect personal data. This failure left its systems vulnerable to malicious attacks. The attackers managed to encrypt 972,191 individual files of which 24,712 were related to court proceedings and to siphon off 60 files and publish them in underground data marketplaces. The files contained both personal and special category data, such as medical records, witness statements, names and addresses of witnesses and victims, and the alleged crimes of data subjects.

Citazioni legali

Art. 5 (1)

Problemi e violazioni

Non-compliance with general data processing principles

Rimanete aggiornati sull'applicazione della privacy

Rispettiamo la vostra privacy. Un'email al mese, niente spam, cancellazione in qualsiasi momento.