Mermaids charity fined £25,000 for data breach

UK – The Information Commissioner’s Office (ICO) has fined transgender charity Mermaids £25,000 over a data breach that exposed the personal information of over 500 people.

Privacy abstract image

The ICO launched an investigation in 2019 after the charity reported a data breach in relation to an internal email group it set up and used from August 2016 until July 2017 when it was decommissioned. Mermaids only became aware of the breach in 2019.

The regulator found that insecure settings meant that around 780 pages of confidential emails were viewable online for almost three years, including personal information such as names of 550 people.

Of those people, the personal data of 24 was found to be sensitive as it revealed how the person was coping and feeling, with a further 15 classified as special category data, as it included information on mental and physical health and sexual orientation.

Mermaids should have applied restricted access to its email group and considered more rigorous security, the ICO concluded.

The regulator has issued the charity with a penalty notice under section 155 of the Data Protection Act 2018, which imposes an administrative fine on Mermaids, in accordance with Article 83 of the General Data Protection Regulation. 

Steve Eckersley, director of investigations, ICO, said: "The very nature of Mermaids’ work should have compelled the charity to impose stringent safeguards to protect the often vulnerable people it works with. Its failure to do so subjected the very people it was trying to help to potential damage and distress and possible prejudice, harassment or abuse.

"As an established charity, Mermaids should have known the importance of keeping personal data secure and, while we acknowledge the important work that charities undertake, they cannot be exempt from the law."

The ICO said that Mermaids had inadequate policies and a lack of staff training with regards to data protection, but that it had cooperated with the investigation and has since improved its processes.

Belinda Bell, chair of trustees, Mermaids, said in a statement: "We are grateful to the ICO for taking into account our prompt remedial action and for balancing the size of its fine against our need to continue supporting service users, while protecting charitable donations made by our many generous supporters. The safety and security of our service users is paramount and we fully accept that an honest but significant mistake was made a number of years ago, and we are determined to ensure that Mermaids continues to fulfil its obligations regarding safe data management with the utmost diligence."

We hope you enjoyed this article.
Research Live is published by MRS.

The Market Research Society (MRS) exists to promote and protect the research sector, showcasing how research delivers impact for businesses and government.

Members of MRS enjoy many benefits including tailoured policy guidance, discounts on training and conferences, and access to member-only content.

For example, there's an archive of winning case studies from over a decade of MRS Awards.

Find out more about the benefits of joining MRS here.

0 Comments


Display name

Email

Join the discussion

Newsletter
Stay connected with the latest insights and trends...
Sign Up
Latest From MRS

Our latest training courses

Our new 2025 training programme is now launched as part of the development offered within the MRS Global Insight Academy

See all training

Specialist conferences

Our one-day conferences cover topics including CX and UX, Semiotics, B2B, Finance, AI and Leaders' Forums.

See all conferences

MRS reports on AI

MRS has published a three-part series on how generative AI is impacting the research sector, including synthetic respondents and challenges to adoption.

See the reports

Progress faster...
with MRS 
membership

Mentoring

CPD/recognition

Webinars

Codeline

Discounts