Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Organizations
  • Organizations
    • FCC Moves to Expel Hong Kong Telco From U.S. Networks Over Security Concerns
    • Efforts to ‘Decimate’ CISA’s Cyber Workforce Must End, Rep. Swalwell Says
    • Federal Agencies Ordered to Address ‘Imminent’ Cyber Threat
    • Louisiana State Agencies Barred From Using DeepSeek Over Concerns About Chinese Spying
    • Roku Accused of Children’s Privacy Violations in Florida AG’s Lawsuit
    • Sen. Grassley Seeks Records From Telecom Carriers on Arctic Frost Subpoenas
    • U.K. Firm to Pay $18.7M to Settle Data Breach Case
  • Articles
  • Articles
  • Organizations
  • Organizations

    Cybersecurity Policy Report, U.K. Firm to Pay $18.7M to Settle Data Breach Case, (Oct 15, 2025)

    By R. Jason Howard, J.D.

    A London-based professional services firm will pay 14 million pounds sterling ($18.7 million) to end an investigation by the United Kingdom’s Information Commissioner's Office (ICO) into a 2023 data breach that exposed the personal information ...

    By R. Jason Howard, J.D.

    A London-based professional services firm will pay 14 million pounds sterling ($18.7 million) to end an investigation by the United Kingdom’s Information Commissioner's Office (ICO) into a 2023 data breach that exposed the personal information of 6.6 million people.

    The ICO accused Capita plc of violating the U.K.’s General Data Protection Regulation by failing to protect the personal data in its possession. The information stolen in the 2023 breach included pension records, staff records, and personal data from customers of organizations Capita supports, the ICO said in a news release.

    For some of the individuals, the personal data included sensitive information such as details of criminal records, financial data, or special category data, the office noted.

    ICO’s investigation found that Capita failed to implement appropriate technical and organizational measures to safeguard the data it held, including the failure to prevent privilege escalation and unauthorized lateral movement, and the failure to respond appropriately to security alerts.

    Under the voluntary settlement, Capita admits liability and agrees to pay the penalty without appealing.

    News: InternationalLegislation DataPrivacy DataSecurity DataBreach LitigationEnforcement GCNNews

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use