Home
 » ISP News » 
Sponsored Links

ICO Upholds £1,000 Fine Against TalkTalk for Personal Data Breach

Friday, Sep 2nd, 2016 (3:04 pm) - Score 1,093

The Information Commissioner’s Office (ICO) has upheld a £1,000 fine against UK phone and broadband provider TalkTalk after the ISP failed to inform the watchdog that a personal data breach had occurred on its system (the provider should have done this within 24 hours of becoming aware).

The breach, which is not related to last year’s cyber-attack on the ISP, occurred on 16th November 2015 when one of TalkTalk’s customers “accidentally obtained unauthorised access to the personal data of another customer” and was able to see the other users name, address, telephone numbers, email addresses and date of birth.

Apparently the situation occurred due to a problem with one of TalkTalk’s mechanisms for keeping its customers’ personal data secure – specifically, the password mechanism by which customers access their TalkTalk accounts online. The customer promptly notified both the ISP and ICO on the same day and two days after that they also followed it up again with a detailed letter.

The ICO then raised the issue with TalkTalk on 20th November and the ISP confirmed reception of that letter. However it then took until 27th November before TalkTalk’s Information Security Officer, Mike Rabbitt, was able to confirm that an investigation had been started, although they didn’t officially confirm that a data breach had occurred until 1st December.

TalkTalk claims that the delay in reporting the breach was because “the incident had not been reported to either [TalkTalk’s] Information Security or Fraud team.” In February 2016 the ICO informed TalkTalk that they intended to impose a fine for the reporting failure, which TalkTalk opposed and ultimately the case went to appeal.

Suffice to say that the Tribunal was unanimous in dismissing TalkTalk’s appeal.

HM Courts & Tribunals Service Ruling

The Tribunal consequently concluded that TalkTalk had sufficient awareness of the breach and that a personal data breach had been detected upon receipt of the customer’s letter of 18th November. The Tribunal strongly suspected that TalkTalk in fact had sufficient awareness of the breach when the customer telephoned on 16th November but were hampered in reaching any conclusion on this point by the failure of TalkTalk to provide any details of that initial complaint.

As part of their counter-argument TalkTalk revealed that the complaints they received about potential personal data breaches amounted to around 50 per month. However the Tribunal was apparently unimpressed by “the contention that holding that ‘sufficient awareness’ in this case arose from the customer’s letter would place an unreasonable burden on service providers“.

Mark-Jackson
By Mark Jackson
Mark is a professional technology writer, IT consultant and computer engineer from Dorset (England), he also founded ISPreview in 1999 and enjoys analysing the latest telecoms and broadband developments. Find me on X (Twitter), Mastodon, Facebook and .
Search ISP News
Search ISP Listings
Search ISP Reviews

Comments are closed

Cheap BIG ISPs for 100Mbps+
Community Fibre UK ISP Logo
150Mbps
Gift: None
Virgin Media UK ISP Logo
Virgin Media £26.00
132Mbps
Gift: None
Shell Energy UK ISP Logo
Shell Energy £26.99
109Mbps
Gift: None
Sky Broadband UK ISP Logo
100Mbps
Gift: None
Plusnet UK ISP Logo
Plusnet £27.99
145Mbps
Gift: None
Large Availability | View All
Cheapest ISPs for 100Mbps+
Gigaclear UK ISP Logo
Gigaclear £17.00
200Mbps
Gift: None
YouFibre UK ISP Logo
YouFibre £19.99
150Mbps
Gift: None
Community Fibre UK ISP Logo
150Mbps
Gift: None
BeFibre UK ISP Logo
BeFibre £21.00
150Mbps
Gift: £25 Love2Shop Card
Hey! Broadband UK ISP Logo
150Mbps
Gift: None
Large Availability | View All
The Top 15 Category Tags
  1. FTTP (5532)
  2. BT (3518)
  3. Politics (2542)
  4. Openreach (2298)
  5. Business (2266)
  6. Building Digital UK (2247)
  7. FTTC (2045)
  8. Mobile Broadband (1977)
  9. Statistics (1790)
  10. 4G (1668)
  11. Virgin Media (1621)
  12. Ofcom Regulation (1465)
  13. Fibre Optic (1396)
  14. Wireless Internet (1391)
  15. FTTH (1382)

Helpful ISP Guides and Tips

Promotion
Sponsored

Copyright © 1999 to Present - ISPreview.co.uk - All Rights Reserved - Terms , Privacy and Cookie Policy , Links , Website Rules , Contact
Mastodon