Reprimands · Legal
Swinburne, Snowball and Jackson
No fineReprimands
Root cause
Cyber attack
An external attacker got in and took data. Where the ICO's notice names the specific failure that let them, the case is filed under that instead.
What happened
The Information Commissioner (the Commissioner) issues a reprimand to Swinburne, Snowball and Jackson in respect of infringements of Article 5(1)(f), which requires personal data is processed securely, and Article 32(1)(b) of the UK GDPR, which requires appropriate measures are in place to ensure a level of security appropriate to the risk and ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services.
Summarised from the notice published by the ICO on 12 August 2023. Read the original notice — it is the authoritative version.