News: 1595224990

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Lock down your data – or get the cheque book out: ICO privacy violation fines are rising, say lawyers

(2020/07/20)


Violating Europe's General Data Protection Regulation (GDPR) rules is a costly mistake that is only getting more expensive, according to lawyers totaling up fines from the UK's Information Commissioner's Office (ICO).

Law firm Reynolds Porter Chamberlain (RPC) today said it has been tracking ICO fines since 2016 and has found that, over the four-year period, the average amount of money taken from punished violators has tripled from £73,645 ($92,560) to £216,200 ($271,730). Most of the increase, says RPC, is the result of the GDPR.

Since the privacy regulations were [1]activated in May 2018, the ICO fined businesses an estimated £5.96m, and the average penalty went up 194 per cent, the law firm says. We note that although the ICO can fine organizations, the money [2]isn't always coughed up .

And that total is set to grow substantially over the short term, thanks to planned penalties of [3]£183m ($230m) against British Airways and [4]£99m ($124m) against Marriott for their respective data fumbling.

Facebook accused of trying to bypass GDPR, slurp domain owners' personal Whois info via an obscure process [5]READ MORE

The overall increase, say the legal eagles, is not a coincidence. The ICO is making a point of going after big business in order to send a message.

"This suggests that the ICO is being selective about its enforcement targets," said Richard Breavington, a partner at London-based RPC. "However, this new wave of blockbuster fines that the ICO has said it plans to impose shows that pressure on businesses is only likely to increase."

While this will be welcome news to everyone tired of the endless parade of careless companies spilling people's private information, it is a prospect that will keep many business owners up at night. Particularly now that so many employees find themselves working remotely due to the pandemic, far away from the security controls of their corporate networks.

Breavington reckons that the work-from-home transition is only going to mean more lapses in data security and an increase in companies running afoul of GDPR.

"Although many businesses now have robust systems in the workplace to protect against hackers, some might not have the same measures in place to protect against staff working from home," he said. "In addition, there is nobody on the ground to enforce basic protocols to protect against hacking."

That being said, the ICO has [6]also suggested [PDF] it will be easing up a little on those who leak data while short-staffed and outgunned by hackers amidst the pandemic.

The office says it will be showing some restraint in who it goes after for fines over the next few months.

"As a public authority, we must act in a manner which takes into account these circumstances," the ICO says. "The law gives us flexibility around how we carry out our regulatory role, which allows us to recognise and engage with the unique challenges the country is facing." ®

Get our [7]Tech Resources



[1] https://www.theregister.com/2018/05/25/gdprmageddon_do_you_think_its_all_over_its_not/

[2] https://www.theregister.com/2019/11/25/ico_7m_in_fines_uncollected/

[3] https://www.theregister.com/2019/07/08/ico_threatens_ba_with_huge_fine_for_huge_data_loss/

[4] https://www.theregister.com/2019/07/09/marriott_hotels_ico_fine_intention_99m_starwood_breach/

[5] https://www.theregister.com/2020/06/23/facebook_gdpr_workaround/

[6] https://ico.org.uk/media/about-the-ico/policies-and-procedures/2617613/ico-regulatory-approach-during-coronavirus.pdf

[7] https://whitepapers.theregister.com/

Maybe an increase in fines but

Whitter

As the prosecution rate is so low, one can see why a CEO may just choose to ignore it.

Observant!

Mike 137

'"This suggests that the ICO is being selective about its enforcement targets," said Richard Breavington'

You don't need a law degree to spot this. However a basic principle has escaped everyone concerned. If you don't nip abuses in the bud they become ingrained and accepted as normal practice. As data protection consultants, since the GDPR came into force we've only found a couple of privacy "policies" that actually comply with the law. Indeed, the last time I looked, the ICO's own template "policy" for SMEs didn't. It requires all the statutory information, but not in a manner that allows the data subject to exercise their rights (which is what "transparency" actually means).

Re: Observant!

Cederic

It's tricky for the ICO though. They do need to assure that SMEs aren't misbehaving but they also need to avoid killing off UK business.

There's also the challenge that individual SMEs breaching the rules are likely to impact far fewer people than large businesses, so the ICO probably feels obliged to focus resources where they'll have the greatest benefit.

Have you fed back to the ICO your thoughts on their template? That does feel a sensible thing to assure is giving SMEs a good start point for compliance.

SMEs?

Frederic Bloggs

Point taken for SMEs, but British Airways? Marriott?

It is no wonder that people are so horrible when they start life as children.
-- Kingsley Amis