- Organisation
- Mermaids
- Sector
- Charity
- Regulator
- Information Commissioner's Office (ICO)
- Announced
- 8 July 2021
- Outcome
- £25,000 fine
- Law
- GDPR Articles 5(1)(f) and 32(1) and (2); penalty under section 155 of the Data Protection Act 2018
This is a publicly reported regulatory case. The organisation is not, and has not been, one of our clients.
What happened
On 15 August 2016 the chief executive of Mermaids, at the time the charity's only paid member of staff, set up an email group on Groups.IO, an online service based in the USA, so that emails could be shared with the charity's 12 trustees. The group used the setting "Group listed in directory, publicly viewable messages", which the ICO's penalty notice describes as the service's default. The group was listed in the Groups.IO directory and was indexed by search engines such as Google.
The last email was sent to the group on 21 July 2017, but the group was never closed down. It stayed publicly viewable until 14 June 2019, nearly three years in total. Around 780 pages of emails were exposed, containing personal data about 550 people. For 24 of them the data was sensitive in context or related to children or vulnerable people. Of those 24, 15 had special category data exposed, including information about mental or physical health, sexual orientation and gender incongruence, and four were aged 13 or under in June 2019.
Mermaids found out on 14 June 2019, when a service user told the chief executive that a Sunday Times journalist had called her to say her personal data could be viewed online. The charity reported the breach to the ICO that day. On 18 June 2019 it learned that archived or cached copies of the emails were still online, and these were removed. The ICO could not establish whether anyone other than the journalist had accessed the exposed data.
The ICO's monetary penalty notice is dated 5 July 2021 and the fine was announced on 8 July 2021. Steve Eckersley, the ICO's director of investigations, was quoted by Civil Society as saying: "The very nature of Mermaids' work should have compelled the charity to impose stringent safeguards to protect the often-vulnerable people it works with."
What the regulator found
- Between 25 May 2018, when the GDPR took effect, and 14 June 2019, Mermaids failed to use appropriate technical and organisational measures to keep personal data secure, breaching GDPR Articles 5(1)(f) and 32.
- The email group used what the ICO called "an insecure and inappropriate setting". More secure options, such as keeping messages private and the group out of the directory, were available but not used.
- No pseudonymisation or encryption was applied to the data. The ICO said either would have offered an extra layer of protection.
- The charity's data protection policies had not been updated after the GDPR came in, and there were no records of how the group was set up or which controls were considered at the time.
- Staff and volunteers had mandatory data protection training in December 2018, but nobody at Mermaids spotted the exposed group. The ICO said this showed the training was inadequate or ineffective.
- The group was left dormant but still accessible, and in the ICO's words "appears to have been forgotten".
- The ICO judged the failings negligent, not deliberate. It treated the sensitivity of the data, the involvement of children and the length of the exposure as aggravating factors. It gave credit for Mermaids reporting the breach itself, taking immediate remedial action, cooperating with the investigation and having no previous infringements.
Lessons for small organisations
- Check the sharing and privacy settings of every online tool that holds personal data, such as email groups, shared drives, forms and messaging apps. Do not rely on the default, and write down what you chose and why.
- Keep a simple list of the systems and accounts that hold personal data. When one stops being used, close it down and delete or move the data, instead of leaving it dormant and forgotten.
- Where you handle health or other sensitive information about children or vulnerable people, share only what is needed and consider extra protection such as encryption or pseudonymisation.
- Review your data protection policies when the law or your ways of working change, and make training practical so that staff and volunteers know how to spot and report data that is exposed by mistake.
- If you do find an exposure, report it to the ICO promptly, take the data down and ask search engines and archive sites to remove cached copies. The ICO credited Mermaids for its self-report and quick remedial action.
Want to know where you stand?
We assess your public web and email surface and send you a written report. No charge, no obligation.
Book a free audit