Mermaids
- Country
- United Kingdom
- Fine
- 25,000 GBP
- Date
- 2021-07-08
- Sector
- General business
- Articles
- Art 5(1)(f), 32 GDPR
Monetary fine for failure to provide adequate physical security arrangements to protects its customers' personal data as per Art 32 GDPR. The company also failed to prevent fraudulent activities on its customers' bank cards as per Art 5(1)(f).
The ICO conducted an investigation after it received a report of a data breach from an internal email group. The ICO found that the group was created with sufficiently secure settings, resulting in approximately 780 pages of confidential emails being viewable online for nearly 3 years. The ICO subsequently fined the organisation £25,000 for breaches of Arts. 5(1)(f) and 32 GDPR.
Source: https://ico.org.uk/media/action-weve-taken/mpns/2620171/mermaids-mpn-20210705.pdf
Reported by: Pinsent Masons (UK)
