Skip to content
Enforcement · Datatilsynet (Denmark) ·2022-63-0003 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Danish DPA fines Sirius Lawyers DKK 500,000 for inadequate security after hacker attack

A law firm was exposed to a hacker attack.

Original title: Datatilsynet (Denmark) - 2022-63-0003

Holding

The Danish DPA held that the law firm lacked basic security measures, especially considering the fact that its processing involved special categories of personal data. The DPA emphasized that in such cases a data breach would almost certainly entail a high risk to the data subjects' rights. Therefore, the controller must have especially strict security measures in place to avoid unauthorised accesses. Hence, when creating remote access to such IT systems, the controller could, for instance, implement multifactor authentication. Consequently, the DPA reported the firm to the police. The DPA assessed the appropriate sanctions in accordance with Article 83(2) GDPR and suggested a fine of approximately €67,000 (DKK 500,000).

From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓

Summary

Thereby, hackers received access to the firm's servers that contained personal data and encrypted them. This posed a serious risk that the personal data was accessed by unauthorized persons, with a potential for harm to the data subjects. In March 2020, the law firm notified the Danish DPA of the data breach.

Full text 3 findings

Machine translation of the decision, via GDPRhub — not the official text. Read the original

Paragraphs carrying a topic or an applied provision show those connections inline
§

SIRIUS lawyers are fined Particularly protected personal data was compromised when SIRIUS lawyers were subjected to a hacker attack. Due to lack of security measures, the Danish Data Protection Agency has reported the company to the police and recommended a fine of DKK 500,000. SIRIUS lawyers have been fined DKK 500,000 for not implementing very basic security measures when setting up remote access to the company's IT systems with personal data of a particularly protected nature. In March 2020, SIRIUS lawyers reported a breach of personal data security to the Danish Data Protection Agency, after they were subjected to a hacker attack. During the attack, hackers gained access to and encrypted the law firm's servers, which contained information about the company's clients and counterparts. This created a serious risk that the information about the persons came into the hands of unauthorized persons with potential damage to the persons in question as a result.

§

Lack of basic safety precautions “Law firms naturally process a lot of information that requires special protection. In this case, SIRIUS lawyers have lacked basic security measures, and this unfortunately meant that i.a. clients' information was compromised. You can not protect yourself 100% against hacker attacks, but the rules in the GDPR require that you make an effort to avoid what is equivalent to the risk, "says Betty Husted, clerk in the Danish Data Protection Agency. In systems with a large number of personal data of a particularly protected nature, where compromise will involve a high risk to the data subjects' rights, the data controller must have specially qualified security measures to ensure that unauthorized access to personal data does not occur. Thus, when creating remote access to such IT systems, one must have implemented verification measures, such as. multifactor login.

§

Why police report? The Danish Data Protection Agency always makes a concrete assessment of the seriousness of the case pursuant to Article 83 (1) of the Data Protection Regulation. 2, in assessing which sanction is, in the opinion of the Authority, the correct one. In assessing that a fine should be imposed, the Danish Data Protection Agency has emphasized that SIRIUS lawyers had not implemented the security measures that are at least expected when using remote access to systems that, if compromised, would involve a high risk for the data subjects' rights. In its recommendation on the size of the fine, the Danish Data Protection Agency has, among other things, emphasized the nature and seriousness of the infringement and the regulation's requirement that a fine in each individual case must be effective, proportionate to the infringement and have a deterrent effect. Furthermore, it has been concluded, among other things, that SIRIUS lawyers were in the process of implementing a multifactor authentication solution at the time of the breach. At the same time, the Danish Data Protection Agency has emphasized that SIRIUS lawyers have acted extremely cooperatively in relation to the information in the case.

How it connects

De Deense toezichthouder (SA) heeft een boete van ongeveer 67.000 euro opgelegd aan een advocatenkantoor dat getroffen was door ransomware, vanwege ontoereikende beveiligingsmaatregelen. De Deense autoriteit voor gegevensbescherming (DPA) heeft geconstateerd dat het advocatenkantoor niet beschikte over de noodzakelijke beveiligingsmaatregelen, vooral gezien het… in Dutch Oct 28, 2022
3 of 3 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-687/21 BL v MediaMarktSaturn Hagen-Iserlohn GmbH In Case C-687/21, the Court of Justice of the European Union interpreted Articles 5, 24, 32, and 82 of the GDPR in response to a preliminary ruling request from the Amtsgericht… CJEU ·Third Chamber Jan 25, 2024 Liability Integrity and Confidentiality Principle Data Breaches
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… CJEU ·Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision
C-77/21 Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság In this preliminary ruling, the CJEU interpreted Articles 5(1)(b) and 5(1)(e) GDPR in proceedings between Digi Távközlési és Szolgáltató Kft. and the Hungarian National Authority… CJEU ·First Chamber Oct 20, 2022 Retention Period Storage Limitation Personal Data
S 5 SF 65/24 DS SG Nürnberg: MOVEit zero-day cyberattack via processor did not breach Art. 32 GDPR The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus… Social Court Nuremberg Jun 10, 2026 Processors Controllers Integrity and Confidentiality Principle