Learnings about data security from an £80k ICO fine for an estate agent

Digital Compliance News and Blog

Share This Post

Share on facebook
Share on linkedin
Share on twitter
Share on email

The ICO have fined estate agent, Life at Parliament View Limited (LPV), £80,000 for security failings relating to tenant information.

The breach occurred in 2015 (which is why this was dealt with under “old” data protection and not GDPR). It occurred when an insecure FTP (file transfer service) server was used to transfer just over 18,600 tenant records to a third party. Only problem was the FTP server was not secure and allowed “anonymous” access to the server and therefore the data was accessible to unauthorised parties, and in fact was left “live” on the server in this state for a couple of years. The issue here is one of taking appropriate organisational and technical measures to ensure the security of personal data, with the ICO finding:

  • The “anonymous” access allowed unauthorised parties to access and download the data
  • Whilst there was some encryption in place it didn’t encrypt transfers of the data to non-registered users
  • The types of personal data included names, addresses, dates of birth, income, employment details (including salary, payroll numbers, etc.) and also contained images of passports and bank statements, etc.

The lack of security wasn’t noticed for 2 years – once it had LPV remedied the issue but noticed over 500,000 anonymous login events (1,213 unique IP addresses) indicating that anonymous access had been used and then in October 2017 a hacker contacted LPV (with evidence) that they possessed the information and they would release it publicly unless a ransom was paid.

So all in all, the fine reflects the lack of security and exposure of extensive personal data for a significant number of data subjects, but actually we can learn much more from the ICO’s enforcement notice about what their thinking is with regards to what constitutes appropriate organisational and technical measures:

  • Make sure systems are configured correctly and there are no “general” unauthenticated means of access (even if specific users are given login/passwords)
  • Monitoring of systems and access logs should be carried out, once set up, to keep an eye on any unusual or unexpected behaviour
  • Penetration testing or other checks should be carried out to alert to vulnerabilities
  • Make sure employees fully understand the consequences and therefore need to ensure security of personal data at all time, whether those employees are configuring the systems or using them

As mentioned, the above enforcement was taken under Data Protection Act 1998 and not GDPR, with the ICO able to fine up to 4% of global turnover or €20m, we wonder what the GDPR equivalent fine would have been…

More To Explore

Eat. Sleep. GDPR. Repeat.

We live and breathe GDPR and ePrivacy compliance, so you don’t have too. Our GDPR UNLIMITED helpline is all about offering you help and support, whenever you need it most. As well as the unlimited helpline, you get up to 4 hours “hands-on” help each month, which we can configure to help you in anyway you need such as a GDPR review, or acting as your DPO.

As well as the unlimited helpline and hands-on help you get GDPR and privacy updates, access to our GDPR knowledge centre and webinars.

Unlimited email & phone support

Unlimited email and phone support. Email or organise a voice call as often as you need each month.​

Up to 4 hours "hands-on" help per month

We use these "hands-on" hours to do the GDPR work for you, such as reviews, acting as your DPO, checking DPIA, dealing with breaches, training your staff, etc. (Additional hours: £100+VAT per hour)

Online resources

Our Knowledge Centre gives you access to information, guidance, topic related guides and other tools to support your GDPR and PECR compliance

Updates, alerts & briefings

We provide updates and alerts and a monthly compliance briefing. You can either sign into the Knowledge Centre or sign up via email to receive an email every time we add a new update or alert

DPO services

Whether mandated or not we can act as your Data Protection Officer (DPO) and manage your day to day compliance

Webinars, workshops & training

Whether updates on the latest issue, workshops or team training, it's all included in your monthly retainer.

LIKE WHAT YOU'RE READING? join our email list

Sign up for monthly briefings and the occasional emails about our webinars and services

Want to know more about how we use your data? Check out our privacy policy