ICO fine Liverpool law firm for data breach

Picture of Ed Austin

Ed Austin

Solicitor & Director

It’s not often that we write about ICO enforcements against law firms. The last was in August/September 2023.

That’s probably because law firms generally have good information security protocols. However, a recent case concerning DPP Law (a Liverpool-based firm dealing with criminal, military and family law) highlights the need for ongoing vigilance and the absolute need for law firms to be on top of this.

In a lengthy (55 page) Penalty Notice, the firm was fined £60,000 for various information security lapses which allowed a hacker to access the firm’s systems and to post highly confidential and sensitive data relating to 791 (a mixture of clients and experts) on the dark web. The firm knew that its systems had been hacked but only became aware of the theft of data on contact from the National Crime Agency.

The problem appeared to be the hacking of a user laptop that then enabled access to a legacy system administrator account that automated communications between DPP’s servers.  Although the account had a limited role, it had full access to data. You can read more about the issues here. The ICO identified several aggravating factors, including a 43-day delay in notifying the ICO of the breach. The Penalty Notice makes for rather painful reading with multiple references to ‘negligence’ ‘failings’ ‘should have’ and similar epithets. For example:

‘The nature, gravity and duration as well as the clearly negligent character of the infringements coupled with the impact on sensitive information militates towards a high degree of seriousness.‘

The ICO considered that most of the mitigations advanced did not withstand scrutiny, resulting in a high level of culpability, and an eye-watering fine:

‘The Commissioner considers that these actions (notifying affected data subjects and improving the DPP security system) do not amount to a mitigating factor in his decision on whether to impose a penalty. These actions were all legal requirements and include what would reasonably be expected of an organisation in response to a personal data breach.’

Takeaways for COLPs and DPOs

It is absolutely critical to understand your IT system and in particular to carry out risk assessments on the security of your data. It is insufficient to say ‘our external IT people do that’ as the data controller (i.e. the law firm) bears responsibility. Please be sure that you understand who does what, and that you are familiar with the limits of your retainer with any external supplier.