Hazard

Reprimands · General business

Gap Personnel Holdings Limited

No fineReprimands
Root cause Cyber attack An external attacker got in and took data. Where the ICO's notice names the specific failure that let them, the case is filed under that instead.

What happened

The Information Commissioner (the Commissioner) issues a reprimand to Gap Personnel Holdings Limited in respect of infringements of Article 32 (1), Article 32 (1) (b) and Article 32 (1) (d) of the UK GDPR. The organisation did not have appropriate security measures in place, which resulted in an unauthorised threat actor being able to access individuals personal data twice within a 12-month period.

Summarised from the notice published by the ICO on 19 October 2023. Read the original notice — it is the authoritative version.