Insufficient technical and organisational measures to ensure information security


Image of book with GDPR on cover - data protection training courses from Concrew Training

The number of fines imposed for breaches of data protection legislation, the GDPR and PECR continues to rise.  The main driver being the data controller/processor failing to implement sufficient technical and organisational measures to ensure information security.

In basic terms this means the management leadership team within the organisation receiving the fine failed to have robust policies and procedures in place or that they failed to ensure they were adhered to.

The fines imposed are usually substantial.

Recent fines include:

FineOrganisationReason
£120,000Allay Claims LtdInsufficient technical and organisational measures to ensure information security
£105,000ZMLUK LtdInsufficient technical and organisational measures to ensure information security
£1,400,000LastPass UK LtdInsufficient technical and organisational measures to ensure information security
£6,880,000CAPITA PENSION SOLUTIONS LIMITEDInsufficient technical and organisational measures to ensure information security
£9,180,000CAPITA PLCInsufficient technical and organisational measures to ensure information security
£230Unidentified Individual Police OfficerInsufficient legal basis for data processing
£20,725BirthlinkInsufficient technical and organisational measures to ensure information security
£2,700,00023andMe, Inc.Insufficient technical and organisational measures to ensure information security
£70,300DPP Law Ltd.Insufficient technical and organisational measures to ensure information security
£3,500,000Advanced Computer Software Group LtdInsufficient technical and organisational measures to ensure information security
£904,000Police Service of Northern IrelandInsufficient technical and organisational measures to ensure information security
£8,700Central Young Men’s Christian AssociationInsufficient technical and organisational measures to ensure information security

Concrew Training’s courses on data protection are designed to help those attending understand the legislation and take action to reduce the risk of breaches and fines.

They are very affordable, especially when compared to the fines for breaches.

Data Protection, GDPR, PECR Training Course