Skip to content
Enforcement · Information Commissioner (ICO) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Interserve Group Limited: Insufficient technical and organisational measures to ensure information security

The British DPA has fined the construction group Interserve Group Limited EUR 5,033,000.

€5,033,000 Fine
Interserve Group Limited
UNITED KINGDOM
Art. 5 GDPR Art. 32 GDPR

Full text 2 findings

Paragraphs carrying a topic or an applied provision show those connections inline
§

The British DPA has fined the construction group Interserve Group Limited EUR 5,033,000. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. Interserve had suffered a cyber attack in which the attackers sent a phishing mail to the mailbox of Interserve's accounting team. The mail was opened by an employee who also downloaded and opened an attached zip file. This allowed the attackers to install malware and siphon off personal data from 113,000 employees. The siphoned data contained bank account information, social security numbers, ethnicity, sexual orientation and religion of the data subjects, among other things. The DPA's investigation found that inadequate security measures allowed the attack to occur. Interservere employees, for example, had not been adequately trained on data privacy. In addition, Interserve processed personal data on unsupported operating systems that were no longer subject to security updates to address vulnerabilities in the system.

§

Also, Interserve had not conducted adequate vulnerability scans. Finally, Interserve's information security team had not sufficiently investigated the attack as antivirus software reported that the malware had been removed. GDPR Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR Industry: Industry and Commerce

How it connects

2 of 2 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-60/22 UZ v Bundesrepublik Deutschland In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik… CJEU ·Fifth Chamber May 4, 2023 Right to Restriction Right to be Forgotten Personal Data
C-182/22 JU and SO v Scalable Capital GmbH In Joined Cases C-182/22 and C-189/22, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Amtsgericht München concerning the… CJEU ·Third Chamber Jun 20, 2024 Liability Data Breaches Notification Obligation
C-667/21 ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts The CJEU (Third Chamber) ruled on a preliminary reference from the Bundesarbeitsgericht in a case where ZQ sought compensation from his employer, Medizinischer Dienst der… CJEU ·Third Chamber Dec 21, 2023 Health Data Healthcare Integrity and Confidentiality Principle
C-492/23 X v Russmedia Digital SRL and Inform Media Press SRL In Case C-492/23, the Court of Justice of the European Union (Grand Chamber) addressed a preliminary reference from the Curtea de Apel Cluj concerning whether an online… CJEU ·Grand Chamber Dec 2, 2025 Controllers Accountability Personal Data