Case study 14: Hacking attack on SelfCatering [2010] IEDPC 14 (2010)

Case study 14: Hacking attack on SelfCatering [2010] IEDPC 14 (2010)

Company X, as data controller, failed to implement adequate security measures for its website, resulting in a large-scale compromise of personal and credit card data, in breach of data protection obligations.

Citation
[2010] IEDPC 14
Parties
Data Controller: Company X; Regulator: Irish Data Protection Commission
Jurisdiction
Ireland
Procedural Posture
Data Protection Investigation / Final Decision
Outcome
Breach found; remedial measures required
Legal Topics
Data Breach, Website Security, PCI Compliance, Personal Data Protection

Case Brief

Summary, issues, holding and outcome

More case intelligence is available

Unlock the full research layer for this judgment.

Full judgment text Downloadable case file Legal principles 1 Authorities cited 2 Party arguments 2 Amounts and remedies 3
Sign in to unlock

Parties

Company X

Data Controller

Irish Data Protection Commission

Regulator

Procedural Posture

Data Protection Investigation / Final Decision

  1. 1 Whether Company X failed to secure personal data in compliance with data protection obligations
  2. 2 Whether Company X's website security met PCI standards for online credit card transactions

Ratio Decidendi

Company X, as data controller, failed to implement adequate security measures for its website, resulting in a large-scale compromise of personal and credit card data, in breach of data protection obligations.

Court Disposition

Breach found; remedial measures required

Orders

  • Company X to cease processing personal data via its website until certified secure by a reputable third party
  • Company X to address identified security issues and obtain third party confirmation of resolution