Cabinet Office

€585,000

Insufficient technical and organisational measures to ensure information security

Дата прийняття рішення

25 листопада 2021 р.

Влада

Information Commissioner (ICO)

GB

Сектор

Public Sector and Education

Країна

GB

Право

GDPR

Статус

FINAL

Опис

The UK DPA (ICO) has fined the Cabinet Office EUR 585,000. On December 27, 2019, the Cabinet Office published a file on GOV.UK containing the names and uncensored addresses of more than 1,000 individuals who had received New Year's honors. Individuals from a wide range of professions across the United Kingdom were affected, including individuals with a high public profile. After learning of the data breach, the Cabinet Office removed the web link to the file. However, the file was still in the cache and was accessible online to people who had the exact website address. The disclosed personal data was available online for two hours and 21 minutes and had been accessed 3,872 times. The breach occurred due to an error in the setup of the Cabinet Office's new IT system. The ICO found that the Cabinet Office failed to take appropriate technical and organizational measures to ensure a level of protection appropriate with the risk to data subjects.

Юридичні посилання

Art. 5 (1)Art. 32

Проблеми та порушення

Insufficient technical and organisational measures to ensure information security

Залишайтеся в курсі подій щодо захисту конфіденційності

Ми поважаємо вашу конфіденційність. Один лист на місяць, без спаму, відпишіться в будь-який час.