Tax Advisory Firm Fined Over Hacked Email Account Containing Personal Data

SECURITYTax Advisory Firm Fined Over Hacked Email Account Containing Personal Data
- Advertisement -Translation agency in Poland – professional language servicesTranslation agency in Poland – professional language services

Mirosław Wróblewski, President of Poland’s Personal Data Protection Office (UODO), has imposed a fine of PLN 11,594 on the controller of a tax advisory firm. The penalty was issued because the firm failed to adequately secure an email account that was accessed by an unauthorised person. The compromised mailbox contained the personal data of 111 individuals.

The case began when the tax advisory firm itself reported a personal data breach. The controller informed the President of UODO that an unauthorised party had taken control of one of its employees’ email accounts.

The mailbox contained personal data relating to the firm’s clients, their employees and children registered for health insurance. In total, the incident affected more than one hundred people.

Compromised Account Used to Send Spam

The firm explained that messages had been sent from the compromised account, but argued that there was no evidence that the unauthorised person had obtained the data stored in the mailbox. The supervisory authority did not accept this position.

The President of UODO noted that the controller was unable to establish exactly when the account had been taken over or how long the mailbox may have remained under the control of the unauthorised person. The employee used the account only occasionally, while the hosting provider blocked it after anti-spam protections were triggered.

The controller also did not have access to logs or other tools that would have allowed it to verify whether the data had been downloaded, copied or used by the unauthorised party.

Lack of Evidence Does Not Rule Out a Breach

As the President of UODO stressed, the absence of confirmation that the data had actually been obtained by a third party does not automatically mean that no personal data breach occurred.

Under the GDPR, a personal data breach is defined as a security breach leading, among other things, to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.

In this case, the unauthorised access itself to a business email account containing data relating to clients and their employees was sufficient to conclude that a personal data breach had occurred.

No Adequate Procedures in Place

During the proceedings, UODO established that before the incident the controller had not implemented separate rules governing the protection of personal data in electronic systems. No risk assessment had been carried out for the processing of personal data through email.

Security measures were not regularly tested, and their effectiveness had not been assessed. According to the authority, this meant that the tax advisory firm had failed to implement the appropriate technical and organisational measures required under the GDPR.

After discovering the breach, and during the proceedings conducted by the President of UODO, the controller took remedial action. It carried out a risk assessment, implemented an Information Security Policy and additional internal rules, and conducted an audit of its IT infrastructure.

Fine for Failing to Ensure an Appropriate Level of Security

The President of UODO reminded organisations that administrative fines are not limited to entities directly responsible for unlawful data processing. A penalty may also be imposed on a controller that fails to ensure an appropriate level of security for personal data.

As a result, the tax advisory firm was fined PLN 11,594.

The decision shows that businesses processing client data through email should not only use technical safeguards, but also regularly assess risk, test their systems and maintain procedures that allow them to quickly determine the scale of a potential incident.

Case reference: DKN.5131.34.2023.

Check out our other content
Related Articles
The Latest Articles