News & Analysis as of

Data Breach United Kingdom Corporate Counsel

Womble Bond Dickinson

The ICO’s Penalty Against 23andMe Brings New Emphasis on Cybersecurity Risks - Key Takeaways for U.S. Companies

Womble Bond Dickinson on

The dramatic increase in global reach that the internet provides U.S.-based companies comes as a double edge sword. While it significantly increases a company’s potential customer pool, it also subjects companies to...more

Jones Day

English High Court Confirms Narrow Approach to Assessment of Data Breach Liability

Jones Day on

On 31 January 2022, the English High Court delivered its judgment in Stadler v Currys Group Limited (EWHC 160 (QB)); the latest in a series of rulings which appear set to constrain the relatively nascent UK data breach claims...more

A&O Shearman

Lloyd v Google a sigh of relief for data controllers

A&O Shearman on

In unanimously refusing to allow a representative action to proceed, the UK Supreme Court may have sounded the death knell for opt-out class actions in England for data breaches: Lloyd v Google [2021] UKSC 50....more

Proskauer on Privacy

English High Court Clarifies Appropriate Causes of Action in Data Claim Where Defendant Was a Victim of Third-Party Cyber-Attack

Proskauer on Privacy on

In the recent and significant Warren v DSG Retail Ltd [2021] EWHC 2168 (QB) decision the High Court in England clarified the limited circumstances in which claims for breach of confidence, misuse of private information and...more

Faegre Drinker Biddle & Reath LLP

Significant Changes Proposed to UK GDPR

On September 10, the U.K. government launched a consultation “Data: A New Direction” (Consultation), which proposes significant changes to the U.K.’s data protection framework. The U.K. government has signalled its...more

Orrick, Herrington & Sutcliffe LLP

Warren v DSG Retail Ltd – Shifting the Liability Landscape in Post‐Cyberattack Litigation

Since the General Data Protection Regulations ("GDPR") came into force in 2018, companies in the United Kingdom (UK) that have suffered cybersecurity attacks often face civil claims from individuals whose data has been...more

Orrick, Herrington & Sutcliffe LLP

Marriott Secures 80% Reduction in ICO Fine, but Here’s What You Missed…

Hot on the heels of the £20 million fine issued to British Airways, the Information Commissioner’s Office (“ICO“) has issued Marriott International Inc. (“Marriott“) with a long-awaited penalty notice for its failure to...more

A&O Shearman

What Might The BA And Marriott Fines Tell Us About The ICO’s Approach To Penalties?

A&O Shearman on

Few will have been surprised that, when the ICO eventually published details of the BA and Marriott fines, the final penalties were very much lower than the £183+ million and £99+ million proposed in the original notices of...more

Faegre Drinker Biddle & Reath LLP

Marriott Cyberattack Fine Reduced as ICO Shifts Penalty Policy

On 30 October 2020, the UK’s data privacy regulator, the Information Commissioner’s Office (ICO) issued a final penalty notice (Penalty Notice) to fine the hotel chain Marriott International, Inc. (Marriott) for a GDPR data...more

Morgan Lewis - Tech & Sourcing

ICO GDPR Fines Reduced to £20m and £18.4m to Reflect British Airways and Marriott Mitigating Factors

The UK Information Commissioner’s Office (ICO) has recently handed down two of the largest fines relating to a data breach in UK history. In August 2018, British Airways (BA) was subject to a cyberattack which breached the...more

Hogan Lovells

Five conclusions from the UK ICO's British Airways fine

Hogan Lovells on

On 16 October the UK Information Commissioner (ICO) confirmed that it had imposed a fine of £20m on British Airways (BA) for infringing the GDPR by failing to protect the personal data of approximately 400,000 of its...more

Skadden, Arps, Slate, Meagher & Flom LLP

Privacy & Cybersecurity Update - July 2020

In this month's edition, we examine the Court of Justice of the European Union's decision invalidating the EU-U.S. Privacy Shield framework, as well as the U.S. government's response to the decision. We also examine two...more

Bennett Jones LLP

Data Breach and Vicarious Liability for Employee Misconduct

Bennett Jones LLP on

It is not only hackers who pose a risk to an organization's information security; hostile insiders do as well. According to Verizon, an estimated 34 percent of data breaches involve internal actors. Hostile insiders may be...more

Akin Gump Strauss Hauer & Feld LLP

U.K.’s Data Protection Regulator’s Updated Guidance on “Empathetic and Pragmatic” Approach

On April 15, 2020, the Information Commissioner’s Office (ICO), the U.K.’s data protection authority, issued further guidance on its regulatory approach during the global COVID-19 pandemic. Following its March note that we...more

Morrison & Foerster LLP

Case Update: Morrisons Not Vicariously Liable For Data Breach By Rogue Employee

In Various Claimants v. WM Morrison Supermarkets [2020] UKSC 12, the Supreme Court has reversed the Court of Appeal decision and held that Morrisons supermarket is not liable for the serious (intentional) data breach by its...more

Skadden, Arps, Slate, Meagher & Flom LLP

UK Employment Flash - August 2019

In this issue of UK Employment Flash, we examine the latest employment law developments, news and insights from the UK, including the Court of Appeal's ruling regarding pay for fathers or other caregivers taking shared...more

Skadden, Arps, Slate, Meagher & Flom LLP

GDPR Collective Civil Claims Present Potential for Reputational Risk and ‘Ruinous’ Damages

While much attention has been paid to the maximum level of administrative fines under the General Data Protection Regulation (GDPR) — up to 4 percent of total worldwide annual turnover — the regulation also provides for...more

Littler

Data Breach in the UK: Can a Rogue Employee Leave You on the Hook?

Littler on

A supermarket chain in the United Kingdom has been all over the press after it was held liable for a data breach by a rogue employee. This article analyzes the appellate court’s judgment to set out what it means for employers...more

Morgan Lewis

UK High Court: Employers Are Liable for Employee Data Breaches

Morgan Lewis on

The UK Court of Appeal recently upheld a decision by the UK High Court ruling that employers can be vicariously liable for an employee’s misuse of personal data under the control of the employer. Employers should also be...more

Skadden, Arps, Slate, Meagher & Flom LLP

Privacy & Cybersecurity Update - March 2018

In this month's edition of our Privacy & Cybersecurity Update, we discuss all 50 states now having data breach notification laws, state attorneys general and their opposition to a federal data breach notification law, the FBI...more

Morgan Lewis

European Data Privacy: Beware and Prepare

Morgan Lewis on

The General Data Protection Regulation, which will be in force later this year, requires organisations that process European personal data to have a comprehensive compliance programme. Additionally, the UK will implement the...more

Skadden, Arps, Slate, Meagher & Flom LLP

Privacy & Cybersecurity Update - January 2018

In this month's edition of our Privacy & Cybersecurity Update, we discuss Poland's potential exemptions from the new EU data law and the Office of the Comptroller of the Currency's recommendations for U.S. banks faced with...more

Skadden, Arps, Slate, Meagher & Flom LLP

Privacy & Cybersecurity Update - November 2017

In this month's edition of our Privacy & Cybersecurity Update, we discuss a Washington state court decision allowing a data breach lawsuit to move forward on a negligence claim, a Ninth Circuit ruling regarding releasing...more

Foley & Lardner LLP

Equifax Breach Affects 143M: If GDPR Were in Effect, What Would Be the Impact?

Foley & Lardner LLP on

The security breach announced by Equifax Inc. on September 7, 2017, grabbed headlines around the world as Equifax revealed that personal data of roughly 143 million consumers in the United States and certain UK and Canadian...more

Proskauer on Privacy

TalkTalk handed record fine in data protection breach in the UK

Proskauer on Privacy on

TalkTalk, a major UK telecoms company, has been fined £400,000 for a data breach after they were hacked. This is a record fine given by the ICO (the UK’s data protection authority). Significantly the fine was imposed after a...more

26 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide