Reprimands · General business
Gap Personnel Holdings Limited
No fineReprimands
Root cause
Cyber attack
An external attacker got in and took data. Where the ICO's notice names the specific failure that let them, the case is filed under that instead.
What happened
The Information Commissioner (the Commissioner) issues a reprimand to Gap Personnel Holdings Limited in respect of infringements of Article 32 (1), Article 32 (1) (b) and Article 32 (1) (d) of the UK GDPR. The organisation did not have appropriate security measures in place, which resulted in an unauthorised threat actor being able to access individuals personal data twice within a 12-month period.
Summarised from the notice published by the ICO on 19 October 2023. Read the original notice — it is the authoritative version.