Hazard

Reprimands · General business

GRS (Roadstone) Limited

No fineReprimands
Root cause Insider misuse A member of staff accessed or took personal data they had no business reason to touch. Frequently prosecuted under the Computer Misuse Act.

What happened

The Information Commissioner (the Commissioner) issues a reprimand to GRS (Roadstone) Limited in respect of infringements of Article 32 (1) (b) and Article 32 (1) (d) of the UK GDPR. The organisation did not have appropriate security measures in place, which resulted in an unauthorised Threat Actor being able to exfiltrate the individual personal data of current and former employees.

Summarised from the notice published by the ICO on 14 November 2023. Read the original notice — it is the authoritative version.