ICO Data Security: The Milestone Case and Fine

By: Ben Fielding | Estimated Reading Time: 2 minutes

On 7th August 2024, the UK’s Information Commissioner’s Office (ICO) issued a landmark provisional fine of £6.09 million against Advanced Computer Software Group Ltd (“Advanced”) for failing to implement adequate security measures. This decision marks the ICO’s first enforcement action against a data processor under the UK GDPR, signifying a shift in regulatory scrutiny and responsibilities in the realm of data protection. The ICO data security mission was already clear, and now this bell has been rung, it’s even clearer.

ICO: What Happened?

Advanced, a UK-based IT services provider, suffered a ransomware attack in August 2022, compromising the personal data of 82,946 individuals. As a processor handling sensitive data for the NHS and other major social care bodies, Advanced’s security lapse led to significant disruptions, including an outage of the NHS’s 111 service and the exposure of medical records and private information.

The ICO’s action underscores that processors, not just data controllers, bear direct regulatory responsibilities under the UK GDPR. This move parallels a trend in the EU, where processors have increasingly faced penalties for data protection failings.

Data Security Implications for Processors

This case serves as a clear reminder: processors are no longer shielded from enforcement actions. Processors are required to:

  • Implement robust security measures to prevent breaches.
  • Notify controllers of any data breaches without delay.
  • Ensure compliance with GDPR obligations, such as using secure systems and documenting compliance efforts.

Processors handling sensitive data must now adopt a proactive stance, ensuring they meet the same level of accountability as controllers.

Lessons for SMEs: Data Security

This decision has broad implications, particularly for SMEs that rely on third-party processors to handle their data. Here are key takeaways:

1. Reassess Processor Contracts

SMEs should review their agreements with processors to ensure data protection clauses (as outlined in Article 28 of the UK GDPR) are not just present but also actionable.

2. Due Diligence on Data Security

Controllers must vet processors thoroughly, evaluating their security frameworks and ability to safeguard sensitive information.

3. Multi-Factor Authentication (MFA) Is Essential

The ICO highlighted MFA as a critical defence against cyberattacks. Businesses should enforce MFA as part of their security measures for both processors and controllers.

4. Prepare for Shared Responsibility

Data breaches often involve both controllers and processors. Controllers must ensure they aren’t solely liable by clearly defining shared responsibilities and liabilities in contracts.

The Road Ahead

The core ICO data security mission finally bears it’s teeth to a layer previously untouched. The Advanced fine sets a precedent that could lead to more frequent enforcement actions against processors. Both controllers and processors must adapt to this heightened regulatory environment by prioritising compliance and collaboration.

Nxt Steps

At Nxt Gen IT, we help businesses navigate the complex world of data protection and cybersecurity. From securing systems with advanced technical solutions to ensuring compliance with the latest regulatory requirements, our team is here to support you.

Let’s work together to protect your business and the data you manage. Contact us today to discuss how we can bolster your security measures and GDPR compliance strategy