Tuckers Solicitors LLP
Issued by Information Commissioner's Office (ICO) on 2022-03-10
What happened
The ICO fined Tuckers Solicitors LLP, a criminal defence law firm, £98,000 after a ransomware attack compromised the personal data of 60 court bundles containing sensitive information relating to criminal proceedings. The attack encrypted 972,191 files, of which 24,712 related to court bundles. The compromised data included sensitive legal documents covering criminal cases, witness statements, and other highly confidential legal materials. The ICO found that Tuckers had failed to implement appropriate security measures: the firm did not use multi-factor authentication, patch management was inadequate, and there was no adequate encryption of personal data at rest. As a small law firm handling extremely sensitive criminal case data, the security obligations were particularly high.
Articles violated
Lessons learned
Law firms handling sensitive criminal case data must implement security measures proportionate to the extreme sensitivity of the information. Multi-factor authentication is a baseline requirement, not an optional enhancement. Small professional services firms are not exempt from GDPR security obligations — indeed, the sensitivity of their data may require higher standards. Regular patching and encryption of data at rest are fundamental security controls. This case demonstrates that even modest fines carry significant reputational damage for professional services firms.
Source
View original decisionDisclaimer: This summary is for informational purposes only and does not constitute legal advice. Refer to the original decision for complete details.
Get enforcement alerts for Other
We track GDPR fines across Europe. Enter your email to get notified about new enforcement actions.
Related enforcement actions
Department of Justice and Constitutional Development
Information Regulator of South Africa · Security Measures
Read caseMinistry of Defence
Information Commissioner's Office (ICO) · Data Breach
Read caseInterserve Group
Information Commissioner's Office (ICO) · Security Measures
Read case