A recent report has proven that even judges are not immune from GDPR requirements after a member of the judiciary was involved in an accidental breach that meant their emails were automatically forwarded to a malicious account in Nigeria.

 

The slip-up was revealed in an annual report from HM Courts and Tribunals Service (HMCTS) to the Information Commissioner’s Office, alongside four other personal data-related incidents.

 

According to the report from HMCTS, the breach was uncovered on 20th September 2018, after a judge’s email account had been accidentally set up to forward all of the emails received to a malicious account with a Nigerian IP address.

 

A spokesperson for the Ministry of Justice confirmed that the incident was an isolated one pertaining to a single email address, and likely resulted from a scam. He went on to add that the body’s security systems and processes are under constant review and that steps had immediately been taken to make sure that the mistake was not repeated.

 

The incident serves as a stark reminder to all that no one is exempt from GDPR requirements or data compliance laws, not even the judiciary, but it is not the only mistake on record for HMCTS.

 

Four further incidents also occurred in 2018, including the disclosure of sensitive information to someone requesting information on an associate’s prior convictions. The incident, which pertained to a junior member of staff, took place on the 13th March.

 

In May, another breach was recorded when an application for an adoption hearing was unwittingly disclosed to the child’s biological mother. The mistake was assigned to human error, with no further action being taken as a result.

 

In June and July of the same year, two additional incidents were reported, the first relating to two court notices issued to an incorrect address, and the second to a bag of driving licences and paperwork that was lost in transit and delivered to the wrong business unit.

 

What each of these incidences does is serve as a reminder of the importance of understanding and abiding by data protection laws, no matter how big or small a venture you might be. Need some advice yourself? Then contact Nalders Solicitors – one of the largest law firms in Cornwall – for expert business advice today.

Truro | Farley House

Tel: 01872 241414, Fax: (01872) 242424

St Austell 

Tel: 01726 879333, Fax: (01726) 67401

Falmouth 

Tel: 01326 313441, Fax: (01326) 315971

Falmouth Berkeley Vale 

Tel: 01326 316655, Fax: (01326) 315971

Newquay 

Tel: 01637 871414, Fax: (01637) 879414

Camborne 

Tel: 01209 714278, Fax: (01209) 710437

Helston 

Tel: 01326 574001, Fax: (01326) 564547

Penzance 

Tel: 01736 364014, Fax: (01736) 364054

Nalders Solicitors is a trading name of Nalders LLP and is a Limited Liability Partnership registered in England and Wales (LLP No. OC354499). We use the term partner to refer to a member of Nalders LLP. A list of the members may be inspected at our registered office: Farley House, Falmouth Road, Truro, Cornwall. TR1 2HX. Nalders LLP is authorised and regulated by the Solicitors Regulation Authority No. 538003. Resolution Accredited Specialist. We will not accept service by electronic mail. VAT Registration No. 131 8555 74

postmaster@nalders.co.uk

Nalders Solicitors