ICO Fines a Data Processor For The First Time Following Ransomware Attack
8th April 2025
For the first time since the UK GDPR came into force after Brexit, the ICO has fined a processor rather than a controller. The processor, Advanced Computer Software Group Ltd, failed to implement suitable security measures, leading to a data breach in August 2022. The original fine was set at £6.09 million but was reduced to the final amount of £3.07 million. Fines and other penalties for breaking data protection laws, often resulting in data breaches, are often levied against controllers, rather than processors, but processors still accept a level of responsibility when handling personal data.
Who are Advanced Computer Software Group Ltd?
Advanced Computer Software Group Ltd, henceforth known as Advanced, are a software company that provides IT and software solutions to several organisations, including the NHS. They provide digital services such as patient check-in and the NHS non-emergency service 111.
Details of the Data Breach
In August 2022, the NHS software managed by Advanced was subject to a personal data breach. They discovered that it was a ransomware attack aimed at the NHS referral system, including ambulance dispatch, out-of-hours appointments, patient history and emergency prescriptions. This affected the whole of the UK, including 111 calls for several days until the systems were restored. They worked to restore services as quickly as possible but would not say if any patient’s data had been accessed. It was later revealed that hackers did gain access to the personal information of 79,404 people, including details of how to access the homes of 890 people receiving in-home care.
The ICO Investigation
Upon investigation, the ICO found that the hackers were able to access this information thanks to a lack of sufficient protection, including multi-factor authentication (MFA) as well as a lack of vulnerability scanning and inadequate patch management. While access to some systems was controlled by multi-factor authentication, this coverage was incomplete. In August 2024, 2 years after the incident, the ICO announced plans to fine Advanced £6.09 million, which later was reduced due to the proactive engagement of Advanced with the police, cyber security services and the NHS.
“The security measures of Advanced’s subsidiary fell seriously short of what we would expect from an organisation processing such a large volume of sensitive information” – Information Commissioner John Edwards
The Key Differences Between Controllers and Processors
It’s worth looking at the differences between controllers and processors, and how it affects their level of responsibility for handling personal data. A controller, in this case, the NHS, decides how and why data is processed (the purpose and the means in GDPR language). A processor processes this data on behalf of the controller according to their instructions. The controller has the most responsibility for protecting the privacy of individuals and the rights of data subjects.
While a processor processes the data given to them by the data controller, they do not own it or have any control over the purpose for which it is used. However, they have obligations under data protection legislation to process the data lawfully and ensure that it is processed in line with all GDPR obligations. Whilst the processor should follow the processing instructions from the controller, a processor decides ‘how’ data is processed. They are usually specialists in their field and use that technical knowledge to decide how to achieve the processing aims of the controller. In this case, the NHS set the aim of delivering services to patients, Advanced built the software to achieve this aim.
The decision by the ICO to fine the processor rather than the controller was clearly justified in this case, as it was obvious that Advanced’s failings led to the data breach. The impact that this data breach had and the number of individuals whose data was affected made it all the more serious. This case is a reminder for controllers to do their due diligence when selecting a processor to handle their processing needs, as any sub-standard processor could have a direct impact on their own data security. Data processing agreements should also be robust and have some clauses regarding indemnities.
Lessons in Cybersecurity
Firstly, before commissioning any new service, a data protection impact assessment (DPIA) must always be performed. Always ensure that two-factor or multi-factor authentication or similarly strong access controls are implemented to secure any systems or databases that contain personal data. Apply software patches and updates as swiftly as possible, although in service-critical environments, a test update may be appropriate to assess any impact on service delivery.
Regular audits and security assessments, such as penetration testing, can help to identify vulnerabilities before cyberattackers can exploit them. Train all members of staff in malware and ransomware attacks and other examples of data breaches so they can identify any weaknesses in your security measures and spot evidence of data breaches quickly. You should also have a data breach policy and a plan in place for what to do in the event of a data breach, including what short-term and long-term measures to take. You can see more guidance on ransomware attacks and other data security issues from the ICO here. If you are concerned that your organisation is not prepared for a potential data breach or another cybersecurity issue, then get in touch with us for confidential support and tailored advice – see our contact page here, or call us for a chat on 01673 885533.
Author: Mike Martin LLM
Mike is the lead information governance specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.
Sources