News: 1638343689

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK watchdog's punishment for Blackbaud, Easyjet, other big privacy lawbreakers was slap on the wrist in private

(2021/12/01)


Blackbaud was given a private slap on the wrist by the UK's Information Commissioner's Office (ICO) after [1]paying off criminals who stole users' financial data from the cloud CRM biz's servers.

The astonishingly mild sanction was revealed in a Freedom-of-Information [2]response after senior data protection specialist Jon Baines at London law firm Mishcon de Reya asked about reprimands made under the General Data Protection Regulation (GDPR).

Reprimands are a formal expression of the ICO's disapproval, issued to organisations that have broken data protection law.

[3]

Blackbaud was one of 42 organisations given reprimands since GDPR came into force in 2018. While most of those were in the public sector, it included supermarket chains Asda and Morrisons, healthcare provider BUPA, and since-shuttered voice chat app Houseparty.

[4]

[5]

West Midlands Police was slapped on the wrist twice in three years for unspecified data protection failures. The Home Office clocked up two finger-wagging sessions during a six-month period in 2019 – while budget airline Easyjet received a telling-off in November 2019.

Six months later, "following discussions with the ICO," the orange skyfarers [6]confessed that nine million customers' travel details and email addresses had been stolen by black-hat hackers. A law firm [7]filed suit against Easyjet shortly afterwards, claiming an implausible £18bn in damages.

[8]

Other reprimands were issued to local councils, Oxford University, NHS health boards, schools – and Zoom, the videoconferencing app company. There appeared to be no small and medium-sized enterprises that were handed reprimands. The names of five organisations were withheld, potentially because they were under appeal.

An ICO spokeswoman told The Register : "The ICO's aim is to protect people from poor organisational practices that put their personal information at risk. We have a range of powers to help us do that, including issuing reprimands and warnings to ensure the right policies and practices are in place. If we find that organisations have not made changes as set out in reprimands, or if any further incidents or complaints are reported to us, we can consider further regulatory action."

[9]UK privacy watchdog may fine selfie-hoarding Clearview AI £17m... eventually, perhaps

[10]Privacy Sandbox saga continues: UK watchdog extracts more commitments from Google over ad tech

[11]Max Schrems hits Irish Data Protection Commissioner with corruption complaint

[12]Labour Party supplier ransomware attack: Who holds ex-members' data and on what legal basis?

Reprimands are issued under [13]article 58(2)(b) of UK GDPR, or alternatively under [14]clause 2(b) of Schedule 13 of the Data Protection Act 2018, itself a creation of the GDPR. They are handed down where the ICO believes a data processor has broken the law.

Strangely, reprimands are not made public by the ICO even though it publicizes fines it issues. Mishcon de Reya's Baines pointed The Register to the ICO's enforcement communications policy

[15]PDF

, which says about reprimands: "We will publicise these if it will help promote good practice or deter non-compliance."

It appears this policy allows the ICO to issue slaps on the wrist in private mainly to public-sector organisations and big business. Meanwhile, SMEs' data protection law infringements earn them well-publicized fines and directorial disqualifications in some cases.

[16]

Blackbaud itself revealed the existence of its reprimand in a 10-K filing

[17]PDF

with America's SEC, although it did not say it had been administered in private. It stated in the filing: "The ICO did not impose a penalty related to the security incident, nor did it impose any requirements for further action by us."

Some large data lawbreakers are fined by the ICO, we note: these include [18]Ticketmaster , [19]British Airways , and hotel chain [20]Marriott .

ICO fine enforcement slowed last year, as [21]its latest figures showed. ®

Get our [22]Tech Resources



[1] https://www.theregister.com/2021/08/17/ccpa_blackbaud/

[2] https://ico.org.uk/about-the-ico/our-information/disclosure-log/ic-132478-h6k7/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YadV8Gphi1FEuAe-PvCsiQAAAEA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YadV8Gphi1FEuAe-PvCsiQAAAEA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YadV8Gphi1FEuAe-PvCsiQAAAEA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2020/05/19/easyjet_hack_9million_2000_credit_cards/

[7] https://www.theregister.com/2020/05/26/easyjet_sued_9m_data_breach/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YadV8Gphi1FEuAe-PvCsiQAAAEA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2021/11/30/uk_clearview_fine/

[10] https://www.theregister.com/2021/11/26/cma_google/

[11] https://www.theregister.com/2021/11/24/max_schrems_files_corruption_complaint/

[12] https://www.theregister.com/2021/11/05/labour_party_ransomware_data_breach_questions/

[13] https://ukgdpr.fieldfisher.com/chapter-6/article-58-gdpr/

[14] https://www.legislation.gov.uk/ukpga/2018/12/schedule/13/paragraph/2/enacted

[15] https://ico.org.uk/media/1890/ico_enforcement_communications_policy.pdf

[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YadV8Gphi1FEuAe-PvCsiQAAAEA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[17] https://investor.blackbaud.com/static-files/8d45af58-ea5a-4414-8c60-609c775b2dec

[18] https://www.theregister.com/2020/11/13/ticketmaster_fined_1_25m_magecart_breach/

[19] https://www.theregister.com/2020/10/16/british_airways_ico_fine_20m/

[20] https://www.theregister.com/2020/10/30/marriott_starwood_hack_fine_just_18_4bn/

[21] https://www.theregister.com/2021/11/03/ico_fines_5m_pounds_outstanding/

[22] https://whitepapers.theregister.com/



an implausible £18bn in damages

Neil Barnes

But that's the problem: the damages are unknown and unknowable, particularly with future risks of, for example, identity theft.

The restitution should not be damages except where they can be explicitly shown and proven; they should be punitive to persuade companies that, hey, guess what, it's not a cost of doing business, it's a good idea to get some better security organised.

Re: an implausible £18bn in damages

SsiethAnabuki

Yes - this was very much the reason behind linking maximum fines to company turnover, so that they culd be effectively punitive.

Re: an implausible £18bn in damages

tiggity

And it was likely to be top grade ID data for travel - passport number, genuine DOB, address etc. So those damages not that far fetched - really needs a proper punishment instead of minor fines or "reprimands" (I'm assuming SMEs don't have the right contacts to know the special approaches needed to get a reprimand instead of a fine)

Maybe I'm odd but very few sites have my full real details, especially DOB, huge difference in info a site gets from me when its a legal requirement for them to be accurate (e.g. travel out of UK), compared to what they get when accurate data is not legally mandatory.

... Amazing how many sites are happy with a DOB that would make me the worlds oldest person by quite a few years.

Further regulatory action

Tromos

Such as being sent to bed early or no pudding?

Re: Further regulatory action

Winkypop

No pudding?!

That’s inhuman sir!

Phones Sheridan

Prior to GDPR the ICO openly wasn't interested in pursuing companies that were involved in data leaks. When pushed excessively it's fines typically never went over a few thousand pounds, and they were rare. Then the GDPR came along and all that changed. It was power hungry, huge fines being thrown out all over the place. But then the fines (mostly) went unpaid. Now Brexit has been and gone, the ICO seems to have reverted to it's pre GDPR behaviour. It's political masters don't want to be rocking the boat when there's trade deals to be done with the very people who don't give two hoots about data protection.

Chris G

"We will publicise these if it will help promote good practice or deter non-compliance."

This should apply particularly to all public bodies who, in theory, are or should be answerable to the public.

Obviously fining them means the fines being paid from the public purse so the minimum ought to be to shame them publicly.

"The ICO did not impose a penalty, nor did it impose any requirements for further action"

Howard Sway

Whilst the effectiveness and appropriate size of fines is a reasonable matter for debate, the fact that there was no requirement to toughen up their security after the incident is appalling. It only leaves the suspicion that the government has turned the ICO into a paper tiger that lets companies get away with stuff, due to some blind ideology about regulation being "bad for business".

What's really bad for business is sending the message that UK companies are allowed to have poor security in the name of not "burdening" them with the cost of implementing it. Why do business with them if they're allowed to play fast and loose with your data?

Record additional transactions on back of previous stub.