Lock down your data – or get the cheque book out: ICO privacy violation fines are rising, say lawyers
- Reference: 1595224990
- News link: https://www.theregister.co.uk/2020/07/20/gdpr_fines_triple/
- Source link:
Law firm Reynolds Porter Chamberlain (RPC) today said it has been tracking ICO fines since 2016 and has found that, over the four-year period, the average amount of money taken from punished violators has tripled from £73,645 ($92,560) to £216,200 ($271,730). Most of the increase, says RPC, is the result of the GDPR.
Since the privacy regulations were [1]activated in May 2018, the ICO fined businesses an estimated £5.96m, and the average penalty went up 194 per cent, the law firm says. We note that although the ICO can fine organizations, the money [2]isn't always coughed up .
And that total is set to grow substantially over the short term, thanks to planned penalties of [3]£183m ($230m) against British Airways and [4]£99m ($124m) against Marriott for their respective data fumbling.
Facebook accused of trying to bypass GDPR, slurp domain owners' personal Whois info via an obscure process [5]READ MORE
The overall increase, say the legal eagles, is not a coincidence. The ICO is making a point of going after big business in order to send a message.
"This suggests that the ICO is being selective about its enforcement targets," said Richard Breavington, a partner at London-based RPC. "However, this new wave of blockbuster fines that the ICO has said it plans to impose shows that pressure on businesses is only likely to increase."
While this will be welcome news to everyone tired of the endless parade of careless companies spilling people's private information, it is a prospect that will keep many business owners up at night. Particularly now that so many employees find themselves working remotely due to the pandemic, far away from the security controls of their corporate networks.
Breavington reckons that the work-from-home transition is only going to mean more lapses in data security and an increase in companies running afoul of GDPR.
"Although many businesses now have robust systems in the workplace to protect against hackers, some might not have the same measures in place to protect against staff working from home," he said. "In addition, there is nobody on the ground to enforce basic protocols to protect against hacking."
That being said, the ICO has [6]also suggested [PDF] it will be easing up a little on those who leak data while short-staffed and outgunned by hackers amidst the pandemic.
The office says it will be showing some restraint in who it goes after for fines over the next few months.
"As a public authority, we must act in a manner which takes into account these circumstances," the ICO says. "The law gives us flexibility around how we carry out our regulatory role, which allows us to recognise and engage with the unique challenges the country is facing." ®
Get our [7]Tech Resources
[1] https://www.theregister.com/2018/05/25/gdprmageddon_do_you_think_its_all_over_its_not/
[2] https://www.theregister.com/2019/11/25/ico_7m_in_fines_uncollected/
[3] https://www.theregister.com/2019/07/08/ico_threatens_ba_with_huge_fine_for_huge_data_loss/
[4] https://www.theregister.com/2019/07/09/marriott_hotels_ico_fine_intention_99m_starwood_breach/
[5] https://www.theregister.com/2020/06/23/facebook_gdpr_workaround/
[6] https://ico.org.uk/media/about-the-ico/policies-and-procedures/2617613/ico-regulatory-approach-during-coronavirus.pdf
[7] https://whitepapers.theregister.com/
Observant!
'"This suggests that the ICO is being selective about its enforcement targets," said Richard Breavington'
You don't need a law degree to spot this. However a basic principle has escaped everyone concerned. If you don't nip abuses in the bud they become ingrained and accepted as normal practice. As data protection consultants, since the GDPR came into force we've only found a couple of privacy "policies" that actually comply with the law. Indeed, the last time I looked, the ICO's own template "policy" for SMEs didn't. It requires all the statutory information, but not in a manner that allows the data subject to exercise their rights (which is what "transparency" actually means).
Re: Observant!
It's tricky for the ICO though. They do need to assure that SMEs aren't misbehaving but they also need to avoid killing off UK business.
There's also the challenge that individual SMEs breaching the rules are likely to impact far fewer people than large businesses, so the ICO probably feels obliged to focus resources where they'll have the greatest benefit.
Have you fed back to the ICO your thoughts on their template? That does feel a sensible thing to assure is giving SMEs a good start point for compliance.
SMEs?
Point taken for SMEs, but British Airways? Marriott?
Maybe an increase in fines but
As the prosecution rate is so low, one can see why a CEO may just choose to ignore it.