Case study 14: Hacking attack on SelfCatering [2010] IEDPC 14 (2010)
Company X, as data controller, failed to implement adequate security measures for its website, resulting in a large-scale compromise of personal and credit card data, in breach of data protection obligations.
- Citation
- [2010] IEDPC 14
- Parties
- Data Controller: Company X; Regulator: Irish Data Protection Commission
- Jurisdiction
- Ireland
- Procedural Posture
- Data Protection Investigation / Final Decision
- Outcome
- Breach found; remedial measures required
- Legal Topics
- Data Breach, Website Security, PCI Compliance, Personal Data Protection
Case Brief
Summary, issues, holding and outcome
More case intelligence is available
Unlock the full research layer for this judgment.
Parties
Company X
Data Controller
Irish Data Protection Commission
Regulator
Procedural Posture
Data Protection Investigation / Final Decision
Legal Issues
- 1 Whether Company X failed to secure personal data in compliance with data protection obligations
- 2 Whether Company X's website security met PCI standards for online credit card transactions
Ratio Decidendi
Company X, as data controller, failed to implement adequate security measures for its website, resulting in a large-scale compromise of personal and credit card data, in breach of data protection obligations.
Court Disposition
Breach found; remedial measures required
Orders
- Company X to cease processing personal data via its website until certified secure by a reputable third party
- Company X to address identified security issues and obtain third party confirmation of resolution
Full Case Text
Judgment text and source record
Sign in to read
Sign in to read the full judgment text
Sign in to read the full judgment text. Downloads and additional research tools may depend on your plan.
Sign in to read the full judgment