- Organisation
- DPP Law Ltd
- Sector
- Legal services (law firm)
- Regulator
- Information Commissioner's Office (ICO)
- Announced
- 16 April 2025
- Outcome
- £60,000 fine
- Law
- UK GDPR Articles 5(1)(f), 32(1), 32(2) and 33(1)
This is a publicly reported regulatory case. The organisation is not, and has not been, one of our clients.
What happened
DPP Law Ltd is a law firm headquartered in Bootle, Merseyside, with offices in Birmingham, Liverpool, London and Tolworth. It specialises in crime, military, family, fraud and sexual offences work and actions against the police. It employs fewer than 250 staff.
A later review of log files by a third-party firm found brute-force attempts on DPP's network from as early as 19 February 2022, with 400 attempts in total. On 3 June 2022 an administrator account called sqluser logged on to the network. DPP used MFA for connecting to its network through a VPN, but sqluser had none because it was a service account. The account had been set up in 2001 for a legacy case management system. DPP replaced that system in 2019 but kept it running because of its six-year data retention policy. Despite its limited role, the account had full administrator rights across the network.
On 4 June 2022 the attacker disabled Windows Defender, deployed ransomware and installed file transfer tools (MegaSync and Rclone). DPP's email server stopped working and staff lost access to the network. Systems did not work properly for around a week, and staff could not use the case management software for eight days. DPP recovered its data from off-site backups. Its firewall logs did not record outgoing data, and on the logs it had, DPP concluded that no data had been taken. It did not report the incident to the ICO.
On 15 July 2022 the National Crime Agency told DPP that three folders of its data, totalling 32.4GB, had been published on the dark web. They included court bundles, documents, photos and video, including police body camera footage. DPP reported the breach to the ICO on 17 July 2022, 43 days after the attack. The breach affected 791 people: 306 crime clients, 225 family clients, 14 matrimonial clients, 137 actions against the police clients and 109 expert witnesses. DPP told them by letter, email and phone, most of them by the end of August 2022.
The ICO's penalty notice is dated 14 April 2025, and the ICO announced the £60,000 fine on 16 April 2025. In the ICO's news release, Andy Curry, Director of Enforcement and Investigations (Interim), said: "Data protection is not optional. It is a legal obligation, and this penalty should serve as a clear message: failure to protect the information people entrust to you carries serious monetary and reputational consequences."
What the regulator found
- DPP breached Articles 5(1)(f), 32(1) and 32(2) of the UK GDPR by failing to keep personal data secure. The ICO's enforcement page gives the period as 25 May 2018 to 17 July 2022.
- DPP did not audit or properly manage the accounts on its servers, including password administration and access privileges. It had no measures to audit accounts, limit their privileges or disable them.
- The sqluser account had rights across the whole network even though it had a narrow role and was not needed day to day after the 2019 system change. DPP did not apply the principle of least privilege and did not risk assess the account.
- DPP did not carry out asset management. The ICO said an asset audit would have shown that sqluser had a narrow purpose but privileges giving full network access.
- DPP also breached Article 33(1) by not reporting the breach to the ICO within 72 hours. It focused on getting its systems back online, did not assess the risks to people, and did not realise that losing access to personal data is itself a personal data breach. The ICO said the 43-day delay also delayed its own investigation.
- The ICO rated the infringements as medium seriousness. DPP processes highly sensitive data, including special category data, DNA data and legally privileged information, and some of its clients are vulnerable, including children and victims of sexual offences.
- The ICO's penalty calculation produced £23,800. It decided that figure would be neither effective nor dissuasive and set the fine at £60,000. Telling the people affected and improving security were not treated as mitigation because they were legal requirements, and DPP's cooperation was treated as neutral.
Lessons for small organisations
- Keep a list of every account on your systems, including service accounts that a software supplier set up years ago. Disable any account you no longer need and give the rest only the access their job requires.
- Use MFA on every account that can reach personal data, not just on remote access. Where a service account cannot use MFA, limit what it can reach and where it can log in from, and ask your IT provider to watch it for unusual use.
- If you keep an old system running to meet retention rules, include it in your security reviews. A replaced system is easy to forget and can still give an attacker a way in.
- Treat a ransomware attack, or any loss of access to personal data, as a possible personal data breach. Assess the risk straight away and, if it is reportable, tell the ICO within 72 hours. You can send more details later.
- Ask your IT provider whether your logs record data leaving your network. Without them you cannot tell whether data was stolen, so do not assume it was not.
Want to know where you stand?
We assess your public web and email surface and send you a written report. No charge, no obligation.
Book a free audit