Brian Sims
Editor |
Home> | Security | >IT Security | >Estate agency fined for failing to protect data |
Estate agency fined for failing to protect data
23 July 2019
THE INFORMATION Commissioner’s Office (ICO) has fined a London estate agency £80,000 for leaving 18,610 customers' personal data exposed for almost two years.
The security breach happened when Life at Parliament View Ltd (LPVL) transferred personal data from its server to a partner organisation and failed to switch off an ‘Anonymous Authentication’ function. This failure meant access restrictions were not implemented and allowed anyone going online to have full access to all the data stored between March 2015 and February 2017.
The exposed details included personal data such as bank statements, salary details, copies of passports, dates of birth and addresses of both tenants and landlords.
During its investigation, the ICO uncovered a catalogue of security errors and found that LPVL had failed to take appropriate technical and organisational measures against the unlawful processing of personal data. In addition, LPVL only alerted the ICO to the breach when it was contacted by a hacker. The ICO concluded this was a serious contravention of the 1998 data protection laws which have since been replaced by the GDPR and the Data Protection Act 2018.
Steve Eckersley, Director of Investigations at the ICO said, “Customers have the right to expect that the personal information they provide to companies will remain safe and secure. That simply wasn’t the case here.
“As we uncovered the facts, we found LPVL had failed to adequately train its staff, who misconfigured and used an insecure file transfer system and then failed to monitor it. These shortcomings have left its customers exposed to the potential risk of identity fraud.
“Companies must accept that they have a legal obligation to both protect and keep secure the personal data they are entrusted with. Where this does not happen, we will investigate and take action.”
- Government U-Turn on Grenfell Inquiry panel
- Carry on camping with alarms says Brigade
- Fire and Rescue Service-focused Community Risk Management Plan launched in Oxfordshire
- Unsprinklered East Yorkshire plastics factory destroyed by huge blaze
- NHS must defend against hackers
- Letitia Emeana elected to chair ASIS International’s UK Chapter at 2020 AGM
- Radical measures to increase competence proposed
- Grenfell fraudster jailed for five years over £32,000 con
- “Businesses must harness neurodiversity to fill cyber skills gap” urges CREST report
- Service leads on road safety campaign
- From the editor
- Blog for FSM website
- Information Commissioner makes key appointments
- BSIA forges closer American links ahead of Brexit
- Fire and Security Association names new chair
- Government wants mergers regime update to protect national security
- Chain wrestling
- Intersec 2018 preview
- Leading brands supporting new Security Event at NEC
- Leading security companies support launch of new security event at the NEC