No GDPR Penalties For UK Swann 'Spying Hack'

Published Nov 20, 2018 12:11 PM

The UK’s data protection agency has closed its investigation into Infinova-owned Swann Security UK, the ICO confirmed to IPVM, deciding to take “no further action” after customers unintentionally received video from different users in separate incidents earlier this year.

IPVM Image

These data breaches received substantial media attention in June/July 2018, such as:

This took place after the arrival of the GDPR - broad new European privacy regulations which include the prospect of heavy fines for such incidents.

In this note, we examine what happened, the UK’s response to IPVM, and what the GDPR implications are for manufacturers and sellers of IoT devices such as video surveillance.

What ********

** ****,*** *** ************ *** ** *** ******** *** owned * ***** ****** ******* ********* video **** * ********’* ******* ** her ********** ***. *** *** ***** a **** ******* ********, **** **** in ***, **** * ********* ***** customer ********** ** ******* ** ********* video **** ** ******* ***.

***** ***** **** ********, ******* *** first ** * ************* ***** *** the ****** ** ********* ***** *********** being **** *** **** *******.

** * ******** ****,** *** ******* **** ***************“************ ******** ***** ***** **** *** camera ** *******” ** *****’* ***** service, ********* “********* ****** ** ******’* camera.” ***** **** ***** **** *****, which *** *** ****** ** ******'* personal *********** ***** ********.

ICO ************

** *** **, ****** *** **, a ****** ******** ****** – ************** ************’* ****** ** ***- ******** *** **** ********** *******. It ************ *** ***** ******** ******** reported ** *** *** *** ******* months, ********* **** **** **** **** the **** *** **** *******:

*** **** ********* ***** ************** (******) Limited *** **** ****** **** ** further ******. *** **** ** ********* being ****** ** *********** *** ********** low *** ** **** ********* *** company *** ********** *** *** ************ sufficient ******** ***** ***** ********** *** own *************

GDPR ********** *****

***** **** ******** **** ***** ***** the ************** ** *** ** ** the **’* *** **** ******* *****, the ****, ***** ****** *** **.

*** ********* **** ***** ********** ** GDPR ********** **** ********* **’* *************** “******* ******** **** *** *** made ********** ******* *** **********’* ************ to ** ********** ****** ** ******* persons.”

************* *** *********** ***** **** ******* about ****** ***** **** ********* ** they *** ******** ** ********, ***** the******* ******** ** ** ** ** ******* euros ** *% ** ********* *******.

How ***** ******* **** *********

*******, *** ***’* ******** *** ** sanction ***** ***** ****, ** ***, fears ** ******** *** ***-******** **** fines *** ** ***** ************ ********* are *********.

*** **** ****** ***** *********** ****** to ******** *********** **** ** ***** to ******** ******* ** *** ** punish *********.******* ** **** ************** *** ****** *** “***********,” ******* there *** * “******* ** **** measures ** ******** *** ****** ***** occurred,” *** ******* ***** *** * “lack ** ************* **** ***********”.

** ****** *** ***** *** *********** with ***********, ***** *** **** ** avoid ********* **********.

GDPR ************

************* ****** *** **** **** **** as ******** **** *** **** ** toothless. ***-**** ********* ****** ********, ***** a *** ****** **** ****** ** Swann’s ***** *** **** *** ****** only ******** * *** ******, **** of **** ***** *** ********** *** compensation ** ******* ************ **.

************, *** ***** **** **** **** establish * ********* ********* ** ************* and *********** **** ** ***** ** data ********. ** **** ***** *** importance ** ***** ********** *** *********** with *********** ** **** ** * breach.

IPVM’s *** ********* ***** *** ********

*** *** ** ****************** ****’* **** ********* ***** ****** recognition***** **** ********** ** ***** ** London.

*** ******-**** ************* ** ***** ******** and ***** *** ** ** ********** of ******* ******* ****** ** * ***** in **** *************** ** ******** **** ********** ******** ******* ****** ****** ******* **** manufacturers *** ***********’ *****.

Comments (7)
U
Undisclosed #1
Nov 20, 2018

* ** ********* ** **** ********** are ***** ** ******* ** ********** like **** ******** *******.

(2)
Avatar
Jon Dillabaugh
Nov 21, 2018
Pro Focus LLC

*’** *** *** **** ********** **** a ******* ******** **. 

(1)
U
Undisclosed #2
Nov 21, 2018
IPVMU Certified

*** ******** *** ***** *** ***** persons ****?

Avatar
Jon Dillabaugh
Nov 21, 2018
Pro Focus LLC

** **** * **** *** *** I *** ******* ****’* ****

U
Undisclosed #2
Nov 21, 2018
IPVMU Certified

****** **** * ****** *** :)

(3)
U
Undisclosed #2
Nov 21, 2018
IPVMU Certified

** **** * **** *** *** I *** ******* ****’* ****

***** * ***** ******!

(1)
UI
Undisclosed Integrator #3
Nov 23, 2018

** ****** **** *** ********** ***, *** *** GDPR, **** **** **** ** ** surprise *** ***** ** **** **** a ******** ****-****. **** *** *** first **** ** **** ** *** 80's, * ******** ** "*******" ******* setting ** ********* *** ******** ****** of ****** **** ****** *** ****** on *** ********** ***** **** ** huge ***** ** *** ******* ** use ***** ********. *** **** *** was ** ******* *********** **** *** ****** available ** *** ******, **** ****** created *** **** ** ******** ***** and ************ **** ***** ***** **** been ******** ** ***** ******. **** were ***** ** * ********* ** be **** **** ** *********** ***** of ****** ****** *** ******** ******.

*** **** *** *** ** ****** with ****, ** ** ***** **** case **** **** **********. *** ***** concept ** **** *** *** ** a ******** ******** ** * **** breach. ** **********  *** *****, ****** and ****** ** ****** * ******** and ******** ** ** ****. ***** clear ****** ** **********, ******* **** deliberate ******** ******* *** **** ******** abuse ** *** **** ********* - this ***** **** ** * ******** toward *** ****** *** *********. *** to *** ******** ***** *** * ******** minor ****** ***** ***** ** **** likely ** ****** *** ** **** damage ** ******** **** ********* ** reasonable.

*** ** *** * ****** ********* ******* on ***** ******* - ** ******* it *** **** ** *** *******, but ****** ******** **** ** ********** of ********* *** *** *** **** for **** *****. ******** - **** was ***** *** ** *********** *** CCTV, *** *** ******* ** **** is *** **** ****** ******** ** it. ***** **** ******* ************* **** ******** ** *** ******** data ********* **** ****** **** ***** Facebook, *****, ******* *** **** ********** **** ******** ****** ******* *****, livelihood's *** ******** ** * *********** effect *** *** *** * ****** idea ** **** **** *** *** up ** **.

*** ********** ** **** ***** ********* will ** ******** - **** ****** given *** ******* ** ***** *** "issue" **** ***** - * **** exhibition ************* *** ******** ***** **********. I ****** **'* * **** *********, but ** ** ****** **** ***** fry **** *** **** ** *** appalling ******* *** ***** ** **** taking ***** *********. **'* **** ********** considering **** ****** *** *** *** GDPR *** ** ********** ** ****, its * ***** **** ****** **** anything ** ***** ******* ** *** EU ***** *** **** ****** ** data ********** *** ***** ** *** only ***** *********** - *** **** enabled ** *** ** **** ****** where * ****** *********** ******** ***** **************'* **** ***** ** ******* ******* in *** **** ** *** *** of ********* *****.