2020-02-17
Legal Articles

Data protection - Sony fined £250,000 for data security breach

Home / Knowledge base / Data protection - Sony fined £250,000 for data security breach

Posted by Claire Halle-Smith on 08 March 2013

Claire Halle Smith - Data Protection Lawyer
Claire Halle-Smith Senior Associate

The UK Information Commissioner’s Office (the “ICO”) has fined Sony £250,000 following a breach of security of its PlayStation Network Platform.

In April 2011, a group of hackers attacked part of the PlayStation Platform compromising the personal information of millions of Sony customers, including their names, addresses, email addresses, dates of birth, account passwords and in some cases, credit card details.

ICO’s findings

The ICO determined that Sony had committed a serious breach of the Data Protection Act 1998. It had failed to ensure that appropriate technical measures were taken against unauthorised or unlawful processing of personal data stored on its servers (breaching the seventh data protection principle). 

The ICO considered a number of aggravating and mitigating factors, including the nature and effect of the breach, Sony’s behaviour and the impact on Sony. 

Aggravating factors:

  • The nature and vast amount of personal data placed at risk meant that the contravention was considered particularly serious.
  • Sony should have been aware of the software vulnerability, acted sooner and had sufficient resources to address the security issues.
  • Sony has sufficient financial resources to pay a monetary penalty up to the maximum without causing undue financial hardship.

Mitigating factors:

  • Sony was subject to “a focused and determined criminal attack”.
  • Sony had taken steps to secure some aspects of the PlayStation Platform and there had been no similar security breach in the past.
  • The compromised personal data was unlikely to have been used for fraudulent purposes and the ICO had not received any complaints.
  • Sony voluntarily reported the contravention to the ICO and had subsequently been fully cooperative with the ICO investigations. 
  • Sony had taken substantial remedial action, which included informing the affected data subjects and offering reparation in the form of a “welcome back” package where appropriate.
  • The security breach had had a significant impact on Sony’s reputation.

Comment

Although the maximum fine that can be levied is £500,000, this is the largest penalty awarded by the ICO against a private company to date. 

The case highlights that organisations that process consumers’ personal data need to remain vigilant to data security and ensure that they have appropriate, effective and up to date security measures in place to protect all personal data stored and processed on their computer systems. 

In the event of a breach occurring, data controllers should consider making a voluntary notification to the ICO and co-operating fully with the ICO’s investigations, as this may be taken into account by the ICO to reduce the level of the penalty.

About the author

Claire Halle-Smith

Senior Associate

Claire’s experience in-house coupled with her ten plus years’ advising on data privacy matters enables her to identify those key issues facing an organisation and to provide practical, solutions-based advice.

Claire Halle-Smith

Claire’s experience in-house coupled with her ten plus years’ advising on data privacy matters enables her to identify those key issues facing an organisation and to provide practical, solutions-based advice.

Recent articles

07 August 2020 Protecting your chances of getting paid; retention of title clauses

A retention of title clause is a term within a contract for the sale of goods which states that the seller retains ownership of the goods until specified obligations are fulfilled by the buyer.

Read article
05 August 2020 Privilege: Protecting your business communications

Privilege can entitle a party involved in court proceedings to withhold a document from their opponent or to deny access to regulators and enforcement agencies.

Read article
30 July 2020 Rethinking the landlord / tenant relationship

We have been following the travails of the high street for over 12 months where changing shopping habits, business rates and rent increases have been contributing to a growing strain on many landlord / tenant relationships.

Read article
Contact
How can we help?
01926 732512
CALL BACK