Reported incidents ICO fine

Reported incident: Mermaids, £25,000 fine after an email group was left publicly viewable

£25,000 fine · 8 July 2021

Organisation
Mermaids
Sector
Charity
Regulator
Information Commissioner's Office (ICO)
Announced
8 July 2021
Outcome
£25,000 fine
Law
GDPR Articles 5(1)(f) and 32(1) and (2); penalty under section 155 of the Data Protection Act 2018

This is a publicly reported regulatory case. The organisation is not, and has not been, one of our clients.

What happened

On 15 August 2016 the chief executive of Mermaids, at the time the charity's only paid member of staff, set up an email group on Groups.IO, an online service based in the USA, so that emails could be shared with the charity's 12 trustees. The group used the setting "Group listed in directory, publicly viewable messages", which the ICO's penalty notice describes as the service's default. The group was listed in the Groups.IO directory and was indexed by search engines such as Google.

The last email was sent to the group on 21 July 2017, but the group was never closed down. It stayed publicly viewable until 14 June 2019, nearly three years in total. Around 780 pages of emails were exposed, containing personal data about 550 people. For 24 of them the data was sensitive in context or related to children or vulnerable people. Of those 24, 15 had special category data exposed, including information about mental or physical health, sexual orientation and gender incongruence, and four were aged 13 or under in June 2019.

Mermaids found out on 14 June 2019, when a service user told the chief executive that a Sunday Times journalist had called her to say her personal data could be viewed online. The charity reported the breach to the ICO that day. On 18 June 2019 it learned that archived or cached copies of the emails were still online, and these were removed. The ICO could not establish whether anyone other than the journalist had accessed the exposed data.

The ICO's monetary penalty notice is dated 5 July 2021 and the fine was announced on 8 July 2021. Steve Eckersley, the ICO's director of investigations, was quoted by Civil Society as saying: "The very nature of Mermaids' work should have compelled the charity to impose stringent safeguards to protect the often-vulnerable people it works with."

What the regulator found

Lessons for small organisations

Want to know where you stand?

We assess your public web and email surface and send you a written report. No charge, no obligation.

Book a free audit

← All reported incidents