Equifax Ltd fined GBP 500k

Essentials

Date of enforcement action:
20/Sep/2018
Jurisdiction: Fine imposed:
United Kingdom Flag for United Kingdom, which is the jurisdiction taking enforcement action GBP 500,000
Defendant company or entity: Industry segment:
Equifax Ltd

Case summary

The Information Commissioner’s Office has issued Equifax Ltd with a £500,000 fine for failing to protect the personal information of up to 15 million UK citizens during a cyber attack in 2017.

The ICO investigation found that, although the information systems in the US were compromised, Equifax Ltd was responsible for the personal information of its UK customers. The UK arm of the company failed to take appropriate steps to ensure its American parent Equifax Inc, which was processing the data on its behalf, was protecting the information.

The incident, which happened between 13 May and 30 July 2017 in the US, affected 146 million customers globally.

The ICO investigation found that, although the information systems in the US were compromised, Equifax Ltd was responsible for the personal information of its UK customers. The UK arm of the company failed to take appropriate steps to ensure its American parent Equifax Inc, which was processing the data on its behalf, was protecting the information.

The ICO’s probe, carried out in parallel with the Financial Conduct Authority, revealed multiple failures at the credit reference agency which led to personal information being retained for longer than necessary and vulnerable to unauthorised access.

The investigation was carried out under the Data Protection Act 1998, rather than the current GDPR, as the failings occurred before stricter laws came into force in May of this year. Today’s fine is the maximum allowed under the previous legislation.

The company contravened five out of eight data protection principles of the Data Protection Act 1998 including, failure to secure personal data, poor retention practices, and lack of legal basis for international transfers of UK citizens’ data.

(ICO Official Release)

Applicable legal provisions

Enforcement information

Enforcement authority: Type of enforcement action:
Information Commissioner's Office Flag for United Kingdom, which is the jurisdiction taking enforcement action Penalty notice
Subject to appeal?
Yes

Cite this fine in your work

Data Privacy Fines Index. (2018-09-20 12:21) Equifax Ltd fined GBP 500k. dataprivacyfines.com. Retrieved from https://dataprivacyfines.com/fine/equifax-ltd-fined/

Entry last updated: 2020-01-12 11:31 GMT.