Authority
ICO
Country
United Kingdom
Date Issued
December 6, 2023
Industry
Education
Summary
Finham Park Multi Academy Trust received a reprimand from the ICO for inadequate security measures that allowed an unauthorized third party to access and encrypt their systems using compromised credentials, affecting 1,843 data subjects. The organization lacked adequate account lockout and password policies in violation of UK GDPR Articles 5(1)(f) and 32(1)(b).
Violation Types
SecurityData Breach
Articles Violated
Related Enforcement Actions
Avoid enforcement risk with automated compliance
IQWorks helps organizations automate UK GDPR compliance before regulators come knocking.
Talk to an Expert