GDPR Fines

A public record of GDPR enforcement across Europe — compiled by INPLP members

Mermaids

Country
United Kingdom
Fine
25,000 GBP
Date
2021-07-08
Sector
General business
Articles
Art 5(1)(f), 32 GDPR

Monetary fine for failure to provide adequate physical security arrangements to protects its customers' personal data as per Art 32 GDPR. The company also failed to prevent fraudulent activities on its customers' bank cards as per Art 5(1)(f).

The ICO conducted an investigation after it received a report of a data breach from an internal email group. The ICO found that the group was created with sufficiently secure settings, resulting in approximately 780 pages of confidential emails being viewable online for nearly 3 years. The ICO subsequently fined the organisation £25,000 for breaches of Arts. 5(1)(f) and 32 GDPR.