Information Commissioner (ICO) · 19 October 2022
Interserve Group Limited
Insufficient technical and organisational measures to ensure information security
Fine€5,033,000Fine issued
- Regulator
- Information Commissioner (ICO)
- Decided
- 19 October 2022
- Country
- United Kingdom
- Sector
- Industry and Commerce
- Regulator’s reference
- Not recorded
- Fino case number
- 2022/GB/001
What happened
The UK DPA imposed a fine of around €5,100,000 (GBP 4,400,000) on the controller for failing to implement appropriate technical and organisational measures to secure employee's personal data, which contributed to a data breach caused by a cyberattack, contrary to Articles 5(1)(f) and 32 GDPR.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(f)Read →
- Art. 32Security of processingRead →
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2022/GB/001.