EP NowStoreAcademySupportProduction LotProducts by Country
Legal & Compliance Home

ICO issues £98,000 penalty following ransomware attack

Information Commissioner’s Office (ICO) imposed penalty on a leading UK law firm for breaching the UK General Data Protection Regulation (GDPR).
July 13, 2022
Blue graphic with map of UK and title ICO penalty following ransomware attack

On March 10, 2022 the Information Commissioner’s Office (ICO) imposed a £98,000 penalty on a leading UK law firm for breaching the UK General Data Protection Regulation (GDPR).

This decision has a number of useful takeaways for studios and production companies which operate in the UK.

What happened?

In August 2020 the law firm learned that its IT systems had been the subject of a ransomware attack, which had resulted in a personal data breach.

The attacker infiltrated the law firm’s network and encrypted 972,191 individual files, 60 of which were later released onto underground data marketplaces. The encrypted files included both personal data and special category data, including:

  • Basic identifiers
  • Health data
  • Economic and financial data
  • Criminal convictions
  • Data revealing racial or ethnic origin

The law firm commissioned a third party to investigate the incident, but it was unable to determine conclusively how the attacker had been able to access the network. However, it did find evidence of a known system vulnerability that could have been used to either access the network or further exploit the law firm once inside the network.

The Decision

The ICO found that the law firm had breached Article 5(1)(f) of the UK GDPR (“Integrity and Confidentiality”). Under Article 5(1)(f), personal data must be: "Processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures."

The ICO acknowledged that the attacker was primarily responsible for the data breach. However, the law firm had contravened the UK GDPR by, among other things, having a vulnerable network which could be exploited.

In particular, the ICO stated that the law firm had failed to:

  • Implement multi-factor authentication (MFA) for its remote access solution (despite two-factor authentication being required under its GDPR and Data Protection Policy).
  • Encrypt its data when it was at rest (ie, when stored), despite ICO guidance from 2018 recommending this.
  • Apply a high-risk security patch until four months after it was released.
  • Delete stored court bundles after the seven-year retention period, some of which were exfiltrated through this attack. 

The Penalty

Based on the nature, gravity and duration of the infringement – including the number of data subjects affected and the level of damage they suffered – the ICO imposed a penalty of £98,000 on the law firm.

Key takeaways for productions

This decision has a number of key takeaways for studios and production companies operating in the UK.

Protect your data with MFA

The National Cyber Security Centre recommends the use of MFA to mitigate against password guessing and theft, including brute force attacks. According to the ICO, had MFA been used in this case, the likelihood of the attack would have been substantially reduced.  

Encrypt your data

Should an attacker obtain access to your data, effective encryption can prevent them from reading it, helping you to maintain the principle of data confidentiality under the UK GDPR.  

Delete data once you no longer need it

Article 5(1)(e) of the UK GDPR requires personal data to be "kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.”

Keep information security at the forefront of your mind

This decision follows a number of recent ICO penalty decisions, including its decisions to fine the Home Office £500,000 and a charity £10,000 for breaches of the UK GDPR. Coupled with the recent announcement that the ICO is now able to keep up to £7.5 million of funds paid as a result of its civil monetary penalties – which it will use to “hold those who don't comply to account” – it’s clear that the ICO is continuing to crack down on organisations which breach the UK GDPR. As such, it’s essential to have sufficient safeguards in place to protect your crew data, and to maintain a record of those safeguards in case of a dispute.

For more information on how the Production Portal helps you to secure your production data, see our guide to information security.

Topic: UK

Related Content

Cameraman filming outside in a field

HMRC Announces Changes to Claiming UK Creative Sector Tax Incentives

4/26/2024
What productions should know about the increased disclosure requirements under the UK's Audio-Visual...
More
MAMA Youth Project Team Photo

Celebrating (Almost) 20 Years of MAMA Youth Project

4/17/2024
UK charity’s founder, Bob Clarke, shares how this unique initiative is breaking down barriers to...
Producer and actor standing on a film set

How to Prepare for an Audit: Tips for UK Productions

4/16/2024
Discover key strategies UK film and TV production companies can use to effectively prepare for an audit.
Topic: UK
More
Camera man and production crew on a film set

Curious About Co-productions? What Producers Need to Know.

4/9/2024
Learn how international collaborators and countries come together to create captivating content for global...
National Film and Television School

Entertainment Partners To Provide Funding For Future Assistant Directors And Floor Managers

3/28/2024
Two new scholarship opportunities are now available for those looking to train in the field of assistant...

What Does the UK’s New Independent Film Tax Credit (IFTC) Mean for Productions?

3/7/2024
As the UK government strengthens its support for productions, find out what the latest changes to the...
Four panelists discuss co-production-square

Unlocking the Myths and Benefits of Co-Production

2/15/2024
Learn the difference between an official co-production and PSA, and how to leverage these opportunities to...
EP Newsroom-Thumbnail-PGGB

Million Youth Media Wins The Duke of Edinburgh Film & TV Inclusion Award 2024 at PGGB Talent Showcase

2/14/2024
The Duke of Edinburgh Film & TV Inclusion Award presented to Million Youth Media, an organisation offering...
Blue square with white letters and UK flag: Changes to UK Paternity Leave Regulations

Changes to UK Paternity Leave Regulations

1/19/2024
Effective March 8th, modified paternity leave to provide more flexibility for UK fathers.
Topic: Alerts
More
Big Ben, London

5 Things to Consider Before Transitioning to the UK’s New AVEC Regime

1/16/2024
A comprehensive overview to help determine if you should use the UK’s new incentive regime to fund your...
Blue tile stating UK announces minimum wage updates

UK Government Announces Minimum Wage Updates

12/5/2023
National Living Wage and National Minimum Wage rates increase for 2024.
Master Series Thumbnail Square UK Productions

UK Production: Sites, Services and Studios

10/20/2023
Learn about UK incentives, infrastructure and production innovation spanning from London to Wales,...

Entertainment Partners Makes Commitment to UK Production with Film & TV Partnership Programme

10/12/2023
Find out how EP is partnering with the leading UK training organisations to close the skills gap, increase...
Entertainment Partners Logo Thumbnail-square

NFTS and Entertainment Partners (EP) Establish Partnership to Support the Future of Film and Television Production

10/5/2023
By supporting the National Film and Television School through this new partnership, Entertainment Partners...
Newsroom-Advanced-Television-Logo-Thumbnail

NFTS, Entertainment Partners establish partnership

10/5/2023
EP the entertainment payroll and production technology company joins as a prominent new Patron of the...
British-Cinematographer-Logo-Thumbnail

NFTS and Entertainment Partners (EP) establish partnership

10/5/2023
The National Film and Television School (NFTS) announces a new partnership with Entertainment Partners...
UK Right to Work Penalties to Triple in 2024

UK Right to Work Penalties to Triple in 2024

9/26/2023
Find out how your production can prepare for the increased penalties for employing a worker who doesn't...
Topic: Legal
More
EP Blog_SQUARE_Spread of UK Production

Outside of London: How the UK Production Industry Spread Beyond the Capital

9/21/2023
Film and TV production outside of London (OOL) is now an integral part of the UK, with world-class media...
Topic: UK
More
Expert Advice_Sam Collett

Spotlight: Sam Collett, UK Production Accounting and Incentives Expert

9/19/2023
Meet the Senior Partner at FLB Accountants, an Entertainment Partners company specializing in UK media and...
Master Series_UK Incentives Panel_Square

What's Changing in UK Production Incentives

9/15/2023
Learn about the recent changes to the UK Creative Sector Tax Credits and how they might impact your next...
EP Blog_SQUARE_UK cultural test

Understanding the UK Cultural Test

9/12/2023
Find out whether your film or TV show will pass the UK’s Cultural Test, a key step in qualifying for the...

Payroll & Finances

PayrollResidualsSmartStartSmartTimeProduction PortalEP On LocationSmartAccountingEP LiveSmartPOCASHétPayPaymaster Rate GuideEP Residency

Manage Multiple Productions

AssetHubSmartHub

Additional Services

Academy
Subscribe now

Be an industry insider with EP's
newsletters and alerts

LegalPrivacy NoticeSecurity
© 2024 Entertainment Partners. All rights reserved.