We focus on the latest news surrounding data breaches, leaks and hacks plus daily internet security articles.
Some 5 million HMRC voice ID records are to be deleted after regulators ruled that a “significant” breach of data protection law had taken place over the use of the “my voice is my password” system.
The UK’s data watchdog, the ICO (Information Commissioner’s Office), has given the government until next month to remove data collected without proper content from millions of taxpayers. Although some people have since opted in for the system, the data for those collected and retained without proper consent is to be removed.
The issue has raised concerns over the government’s own ability to adhere to important data protection laws, with the ICO critical of HMRC’s behaviour.
We’re coming up to the first anniversary of the data law changes next month. Many are still unaware as to how GDPR and compensation claims work, and what the relationship is.
As data breach compensation experts, we can answer the key questions for you.
GDPR and compensation claims can go hand-in-hand, but they can also be viewed as two separate things. The new legislation has made the reporting of data breaches a bigger burden, which has led to an influx of reports since the law changes took place. GDPR can also place a greater burden for accountability when it comes to breaking data laws, and there’s the potential for huge fines.
But compensation is usually something that’s separately pursued to any involvement from the Information Commissioner’s Office (ICO). And that’s why we’re here.
The Bristol council data breach incident that was reported last week is understood to have affected thousands of residents.
The incident was yet another case of an avoidable data breach that has been caused by what appears to be a simple error. We see these kinds of leaks all the time, and they’re not the first council to have committed a breach just like it.
One of the most severe data breach group actions we’re running stemmed from an incident that’s exactly the same as this one. The damage that can be caused from a simple email error that leads to a leak can be substantial. A large volume of the cases we deal with are for council data breach compensation claims. They really are awfully common.
We may see a Marriott GDPR fine applied after the monumental breach that was discovered last year, given the volume of people affected and the nature of the breach.
As many as 500 million people were affected, with data said to have been compromised between 2014 and 2018. An unauthorised third-party is said to have accessed the guest reservation table fore the Startword division of the company. Data exposed in the breach included a lot of personal and account data.
The breach lapses over GDPR coming into force in May 2018. That means that the ICO (Information Commissioner’s Office) could issue a fine that equates to 4% of the Marriott’s global annual turnover.
A Deliveroo data breach “incident” is said to have been reported to the ICO who have confirmed that they’re making inquiries.
Back in 2016, the food delivery company faced scrutiny after customers complained of fraudulent transactions on their accounts. In some cases, it appeared the issues were down to people’s credentials being stolen in hacks completely separate to Deliveroo. Criminals had used stolen credentials to access accounts in cases where credentials were reused.
Deliveroo were subsequently criticised over what some customers felt was a failure to spot and stop fraudulent transactions. In this latest incident, it appears that history may be repeating itself.
Greater Facebook regulation is looking imminent after a year-long inquiry that included issues over the misuse of personal data.
The inquiry, launched in-part after the Cambridge Analytica scandal, comes after a spate of recent data breach incidents involving the social medial platform. The recommendations made by the Digital, Culture, Media and Sport Committee include an independent regulator to oversee tech firms like Facebook.
It’s not been an easy process judging from the remarks of MPs and others involved with the inquiry. Facebook founder, Mark Zuckerberg, didn’t even come to the UK to answer questions himself, which has reportedly caused a stir.
There’s been another Facebook data leak, and yet again, millions of users are said to have been affected.
The fines that Facebook could now face in accordance with GDPR are mounting. This is one of many data leaks that have been revealed recently. The previous one, affecting some 29m users, was only discovered a couple of months ago.
In this latest Facebook data leak, a software bug has led to users’ photos being uploaded to websites without permission.
If you need legal advice about the Marriott data breach, we can help. This is another huge breach that has led to private and sensitive data being exposed.
This has to be 2018’s mega breach. Although we thought the British Airways one was the breach to set the bar, this one is obscene in terms of data breached and the timeframe. Some 500 million customers whose data was on Marriott’s Starwood reservation database has been comprised since 2014. Anyone with data on the system up until 10th September 2018 may be affected.
If you’ve received notification that you’re a victim of the data breach and you’re based in England or Wales, we can help.
It seems highly likely there will be some form of Facebook GDPR fine coming at some time. The recent data breaches cannot go unpunished.
As data breaches and our rights to privacy continue to grow in importance, people want to know how GDPR will be there to protect us. With the massive Facebook data breach that took place in September fresh in our minds, people want to know what kind of Facebook GDPR fine may be issued.
Facebook could find themselves as the marker in Europe for how far the new GDPR will go. Although it isn’t the first company to have been at the centre of a data breach since the rule change in May, it could be the biggest.
Earlier this month, an apology was issued over the Southwark Council data leak, and the matter was brought to the attention of regulators.
The personal information of around 20 people was accidentally leaked as part of a Freedom of Information request. The request had asked for correspondence between council officials and Delancey, an asset management company.
The personal information had not been redacted, resulting in the leak. The Information Commissioner’s office (ICO) has been informed.
EasyJet admits data of nine million hacked
British Airways data breach: How to claim up to £6,000 compensation
Are you owed £5,000 for the Virgin Media data breach?
Virgin Media faces £4.5 BILLION in compensation payouts
BA customers given final deadline to claim compensation for data breach
Shoppers slam Morrisons after loyalty points stolen
Half a million customers can sue BA over huge data breach
Lawyers accuse BA of 'swerving responsibility' for data breach
The biggest data breaches of 2020
Fill out our quick call back form below and we'll contact you when you're ready to talk to us.