On 7th August 2024, the UK’s Information Commissioner’s Office (ICO) issued a landmark provisional fine of £6.09 million against Advanced Computer Software Group Ltd (“Advanced”) for failing to implement adequate security measures. This decision marks the ICO’s first enforcement action against a data processor under the UK GDPR, signifying a shift in regulatory scrutiny and responsibilities in the realm of data protection. The ICO data security mission was already clear, and now this bell has been rung, it’s even clearer.
ICO: What Happened?
Advanced, a UK-based IT services provider, suffered a ransomware attack in August 2022, compromising the personal data of 82,946 individuals. As a processor handling sensitive data for the NHS and other major social care bodies, Advanced’s security lapse led to significant disruptions, including an outage of the NHS’s 111 service and the exposure of medical records and private information.
The ICO’s action underscores that processors, not just data controllers, bear direct regulatory responsibilities under the UK GDPR. This move parallels a trend in the EU, where processors have increasingly faced penalties for data protection failings.
Data Security Implications for Processors
This case serves as a clear reminder: processors are no longer shielded from enforcement actions. Processors are required to:
- Implement robust security measures to prevent breaches.
- Notify controllers of any data breaches without delay.
- Ensure compliance with GDPR obligations, such as using secure systems and documenting compliance efforts.
Processors handling sensitive data must now adopt a proactive stance, ensuring they meet the same level of accountability as controllers.
Lessons for SMEs: Data Security
This decision has broad implications, particularly for SMEs that rely on third-party processors to handle their data. Here are key takeaways:
1. Reassess Processor Contracts
SMEs should review their agreements with processors to ensure data protection clauses (as outlined in Article 28 of the UK GDPR) are not just present but also actionable.
2. Due Diligence on Data Security
Controllers must vet processors thoroughly, evaluating their security frameworks and ability to safeguard sensitive information.
3. Multi-Factor Authentication (MFA) Is Essential
The ICO highlighted MFA as a critical defence against cyberattacks. Businesses should enforce MFA as part of their security measures for both processors and controllers.
4. Prepare for Shared Responsibility
Data breaches often involve both controllers and processors. Controllers must ensure they aren’t solely liable by clearly defining shared responsibilities and liabilities in contracts.
The Road Ahead
The core ICO data security mission finally bears it’s teeth to a layer previously untouched. The Advanced fine sets a precedent that could lead to more frequent enforcement actions against processors. Both controllers and processors must adapt to this heightened regulatory environment by prioritising compliance and collaboration.
Nxt Steps
At Nxt Gen IT, we help businesses navigate the complex world of data protection and cybersecurity. From securing systems with advanced technical solutions to ensuring compliance with the latest regulatory requirements, our team is here to support you.
Let’s work together to protect your business and the data you manage. Contact us today to discuss how we can bolster your security measures and GDPR compliance strategy
Ben helps growing businesses turn technology into a driver of performance instead of a barrier. At Nxt Gen IT he works with SME leaders, recruiters, and fast-scaling teams to design solutions that improve reliability, strengthen security, and unlock growth.
With a background in email deliverability and cloud systems, Ben specialises in making sure businesses communicate effectively, keep data safe, and get the most from Microsoft 365. His experience spans solution design, managed IT services, and virtual CIO support, always with a focus on practical outcomes that reduce headaches for business owners.
Ben has supported organisations across the UK, from recruitment agencies struggling with inbox placement to SaaS firms scaling fast, and SMEs needing a trusted partner for their IT. He believes tech is never the end goal: growth is. His role is to make sure technology never gets in the way of it.
