Reprimands · General business
GRS (Roadstone) Limited
No fineReprimands
Root cause
Insider misuse
A member of staff accessed or took personal data they had no business reason to touch. Frequently prosecuted under the Computer Misuse Act.
What happened
The Information Commissioner (the Commissioner) issues a reprimand to GRS (Roadstone) Limited in respect of infringements of Article 32 (1) (b) and Article 32 (1) (d) of the UK GDPR. The organisation did not have appropriate security measures in place, which resulted in an unauthorised Threat Actor being able to exfiltrate the individual personal data of current and former employees.
Summarised from the notice published by the ICO on 14 November 2023. Read the original notice — it is the authoritative version.