This article is from the source 'rtcom' and was first published or seen on . It last changed over 40 days ago and won't be checked again for changes.

You can find the current article at its original source at https://www.rt.com/uk/528705-transgender-charity-mermaids-fined/

The article has changed 3 times. There is an RSS feed of changes available.

Version 1 Version 2
Transgender youth charity Mermaids fined £25K for exposing personal info of trans children & parents online Transgender youth charity Mermaids fined £25K for exposing personal info of trans children & parents online
(about 2 months later)
Mermaids, a controversial UK charity which helps transgender youth, has been fined £25,000 after it unknowingly exposed nearly 800 pages of personal emails containing the private information of trans children and their parents.Mermaids, a controversial UK charity which helps transgender youth, has been fined £25,000 after it unknowingly exposed nearly 800 pages of personal emails containing the private information of trans children and their parents.
The Information Commissioner’s Office (ICO) fined Mermaids £25,000 (nearly $35,000) for failing to “implement an appropriate level of organisational and technical security to its internal email systems.” The failure, it said, led to emails and documents containing personal information about children and other vulnerable people “being searchable and viewable online by third parties through internet search engine results” – a violation of GDPR laws.The Information Commissioner’s Office (ICO) fined Mermaids £25,000 (nearly $35,000) for failing to “implement an appropriate level of organisational and technical security to its internal email systems.” The failure, it said, led to emails and documents containing personal information about children and other vulnerable people “being searchable and viewable online by third parties through internet search engine results” – a violation of GDPR laws.
According to the ICO’s penalty notice, the security flaw was discovered in 2019 after a Sunday Times journalist informed one of the parents who had been in contact with Mermaids that their child's current name, birth name, date of birth, and health details, along with the child’s mother's name, telephone number, and employer’s address were freely available online.According to the ICO’s penalty notice, the security flaw was discovered in 2019 after a Sunday Times journalist informed one of the parents who had been in contact with Mermaids that their child's current name, birth name, date of birth, and health details, along with the child’s mother's name, telephone number, and employer’s address were freely available online.
Four exposed emails contained details about transgender children under the age of 13 at the time.Four exposed emails contained details about transgender children under the age of 13 at the time.
The ICO claimed that the leaked data was particularly “sensitive in its context” as “groups supporting transgender rights and people experiencing gender incongruence may be at a higher risk of experiencing prejudice, harassment, physical abuse or hate crime.”The ICO claimed that the leaked data was particularly “sensitive in its context” as “groups supporting transgender rights and people experiencing gender incongruence may be at a higher risk of experiencing prejudice, harassment, physical abuse or hate crime.”
“If someone had accessed the email group online there would have been sufficient available identifying data to potentially ‘out’ the data subject, removing any choice and infringing their privacy,” the penalty notice explained.“If someone had accessed the email group online there would have been sufficient available identifying data to potentially ‘out’ the data subject, removing any choice and infringing their privacy,” the penalty notice explained.
The ICO admitted that it was unsure whether any third parties had accessed the data other than the Sunday Times journalist who broke the story.The ICO admitted that it was unsure whether any third parties had accessed the data other than the Sunday Times journalist who broke the story.
ICO Director of Investigations Steve Eckersley said in a statement that the “very nature of Mermaids’ work should have compelled the charity to impose stringent safeguards to protect the often vulnerable people it works with,” and that “its failure to do so subjected the very people it was trying to help to potential damage and distress.”ICO Director of Investigations Steve Eckersley said in a statement that the “very nature of Mermaids’ work should have compelled the charity to impose stringent safeguards to protect the often vulnerable people it works with,” and that “its failure to do so subjected the very people it was trying to help to potential damage and distress.”
He added that, though charities like Mermaids do “important work,” they should know the importance of safeguarding personal information and “cannot be exempt from the law.”He added that, though charities like Mermaids do “important work,” they should know the importance of safeguarding personal information and “cannot be exempt from the law.”
Responding to the fine, Mermaids said it took “full responsibility” for the data breach and thanked the ICO for “balancing the size of its fine against our need to continue supporting service users.” The charity’s chair of trustees Dr. Belinda Bell said in a statement that it fully accepts “that an honest but significant mistake was made” and that the privacy of its service users is “paramount.”Responding to the fine, Mermaids said it took “full responsibility” for the data breach and thanked the ICO for “balancing the size of its fine against our need to continue supporting service users.” The charity’s chair of trustees Dr. Belinda Bell said in a statement that it fully accepts “that an honest but significant mistake was made” and that the privacy of its service users is “paramount.”
“We are determined to ensure that Mermaids continues to fulfil its obligations regarding safe data management with the utmost diligence,” Bell said.“We are determined to ensure that Mermaids continues to fulfil its obligations regarding safe data management with the utmost diligence,” Bell said.
Think your friends would be interested? Share this story!Think your friends would be interested? Share this story!
Dear readers and commenters,
We have implemented a new engine for our comment section. We hope the transition goes smoothly for all of you. Unfortunately, the comments made before the change have been lost due to a technical problem. We are working on restoring them, and hoping to see you fill up the comment section with new ones. You should still be able to log in to comment using your social-media profiles, but if you signed up under an RT profile before, you are invited to create a new profile with the new commenting system.
Sorry for the inconvenience, and looking forward to your future comments,
RT Team.