Tuckers Solicitors LLP

€115,000

Non-compliance with general data processing principles

Datum odločitve

10. marec 2022

Organ

Information Commissioner (ICO)

GB

Sektor

Finance, Insurance and Consulting

Država

GB

Zakon

GDPR

Status

FINAL

Opis

The UK DPA (ICO) has fined law firm Tuckers Solicitors LLP EUR 115,000. Tuckers suffered a ransomware attack on its systems, which resulted in a personal data breach. As part of its investigation, the DPA determined that Tuckers had failed to take appropriate technical and organizational measures to protect personal data. This failure left its systems vulnerable to malicious attacks. The attackers managed to encrypt 972,191 individual files of which 24,712 were related to court proceedings and to siphon off 60 files and publish them in underground data marketplaces. The files contained both personal and special category data, such as medical records, witness statements, names and addresses of witnesses and victims, and the alleged crimes of data subjects.

Pravne navedbe

Art. 5 (1)

Vprašanja in kršitve

Non-compliance with general data processing principles

Spremljajte novice o uveljavljanju zasebnosti

Spoštujemo vašo zasebnost. Eno e-poštno sporočilo na mesec, brez neželene pošte, odjava kadar koli.