Case study 15: Compromise of a GAA database [2010] IEDPC 15 (2010)
Centralised databases are vulnerable to inappropriate access; full cooperation and mitigation measures are required following a breach; no evidence of illegal use or identity theft, but affected members must remain vigilant.
- Citation
- [2010] IEDPC 15
- Parties
- Data Controller: GAA (member organisation); Data Processor: Company X; Regulator: Irish Data Protection Commission
- Jurisdiction
- Ireland
- Procedural Posture
- Data Breach Investigation / Investigation Report
- Outcome
- investigation concluded; ongoing criminal investigation
- Legal Topics
- Database Compromise, Personal Data Breach, Cross Border Data Transfer, Medical Data Exposure
Case Brief
Summary, issues, holding and outcome
More case intelligence is available
Unlock the full research layer for this judgment.
Parties
GAA (member organisation)
Data Controller
Company X
Data Processor
Irish Data Protection Commission
Regulator
Procedural Posture
Data Breach Investigation / Investigation Report
Legal Issues
- 1 unauthorised access to personal data
- 2 adequacy of security measures
- 3 notification and mitigation obligations
Ratio Decidendi
Centralised databases are vulnerable to inappropriate access; full cooperation and mitigation measures are required following a breach; no evidence of illegal use or identity theft, but affected members must remain vigilant.
Court Disposition
investigation concluded; ongoing criminal investigation
Orders
- Organisation must continue to liaise with authorities and inform affected members.
- Members advised to remain vigilant against unsolicited contacts.
Full Case Text
Judgment text and source record
Sign in to read
Sign in to read the full judgment text
Sign in to read the full judgment text. Downloads and additional research tools may depend on your plan.
Sign in to read the full judgment