United Kingdom United Kingdom

Tuckers Solicitors LLP

115,000 €

GDPR enforcement action by Information Commissioner (ICO) on 2022-03-10.

Rank · Sector
#85
of 322 in Finance, Insurance and Consulting
Rank · United Kingdom
#20
of 28
Rank · All fines
#445
of 3,042

Case details

Authority
Information Commissioner (ICO)
Date
2022-03-10
Controller / Processor
Tuckers Solicitors LLP
Sector
Finance, Insurance and Consulting
Quoted Articles
Art. 5 (1) a) f) GDPR
Type of violation
Non-compliance with general data processing principles

Summary

The UK DPA (ICO) has fined law firm Tuckers Solicitors LLP EUR 115,000. Tuckers suffered a ransomware attack on its systems, which resulted in a personal data breach. As part of its investigation, the DPA determined that Tuckers had failed to take appropriate technical and organizational measures to protect personal data. This failure left its systems vulnerable to malicious attacks. The attackers managed to encrypt 972,191 individual files of which 24,712 were related to court proceedings and to siphon off 60 files and publish them in underground data marketplaces. The files contained both personal and special category data, such as medical records, witness statements, names and addresses of witnesses and victims, and the alleged crimes of data subjects.

Open original source Links to the regulator's original publication or another source.

Related fines