The cost of getting Data Protection wrong

The cost of getting Data Protection wrong

Data Protection is an essential part of any modern business and it is much more than antivirus software and password protection. Training and understanding across the organisation is necessary to ensure compliance. Get it wrong and the consequences can be severe.

Uber fined €290M in 2024

Uber transferred the personal data of its European drivers to US servers without the use of approved safeguards. They failed to understand the importance of ensuring privacy controls are in place before transferring personal data to a "third country".

Police Service of Northern Ireland fined £750K

Failed to implement adequate security measures and as a result, the names, addresses and other details of police officers were published on their public facing website. Officers had to be relocated with their families for their safety.

The Labour Party reprimanded

Failed to respond to subject access requests. "Why they were not prosecuted and fined is beyond me," says Strident Compliance Specialist, Rebecca Richards. "This is one of the most serious offences under the GDPR and every other organisation who have been prosecuted for this, have had the hammer come down hard. Labour Party pretty much got away with it."

The Central YMCA reprimanded

Failed to use the BCC option when emailing 166 individuals about a program for people living with HIV – thus exposing the HIV diagnosis of everyone within the email.

Clearview put out of business through fines

Clearview was developing facial recognition AI software. To train the AI, they used faces of people on social media, organisational websites etc and had governments and police forces across the world queueing up to buy the software.

However, Clearview had no consent from people they had used the photos of to train the AI, had applied no lawful basis for the processing, failed to be ‘transparent’ with how they used the data, had not assigned data retention periods and failed to answer subject access requests.

Clearview were fined €20M in France, Greece and Italy, a further €8M by the UK. Clearview were also ordered to delete all of the personal data they had collected and were banned from operating in the countries that fined them. They are no longer operational.

These issues could have been avoided

In each case, appropriate training and procedures - costing far less than the damage incurred - would have prevented these issues occurring. To find out more about how Strident can help your business become more secure and compliant, then please get in touch here.

Get the latest news from Strident

6 Steps for Sorted IT

ISO & Data Protection