No GDPR Penalties For UK Swann 'Spying Hack'

Author: Charles Rollet, Published on Nov 20, 2018

The UK’s data protection agency has closed its investigation into Infinova-owned Swann Security UK, the ICO confirmed to IPVM, deciding to take “no further action” after customers unintentionally received video from different users in separate incidents earlier this year.

These data breaches received substantial media attention in June/July 2018, such as:

This took place after the arrival of the GDPR - broad new European privacy regulations which include the prospect of heavy fines for such incidents.

In this note, we examine what happened, the UK’s response to IPVM, and what the GDPR implications are for manufacturers and sellers of IoT devices such as video surveillance.

*** **’* **** ********** ****** *** ****** *** ************* **** Infinova-owned***** ******** **, *** *** ********* ** ****, ******** ** **** “** further ******” ***** ********* *************** ******** ***** **** ********* ***** in ******** ********* ******* **** ****.

***** **** ******** ******** *********** ***** ********* ** ****/**** ****, such **:

**** **** ***** ***** *** ******* ** ******* - ***** *** ******** ******* **************** ******* *** ******** ** ***** ***** *** **** *********.

** **** ****, ** ******* **** ********, *** **’* ******** to ****, *** **** *** **** ************ *** *** ************* and ******* ** *** ******* **** ** ***** ************.

[***************]

What ********

** ****,*** *** ************ *** ** *** ******** *** ***** * ***** ****** started ********* ***** **** * ********’* ******* ** *** ********** app. *** *** ***** * **** ******* ********, **** **** in ***, **** * ********* ***** ******** ********** ** ******* of ********* ***** **** ** ******* ***.

***** ***** **** ********, ******* *** ***** ** * ************* error *** *** ****** ** ********* ***** *********** ***** **** for **** *******.

** * ******** ****,** *** ******* **** ***************“************ ******** ***** ***** **** *** ****** ** *******” ** Swann’s ***** *******, ********* “********* ****** ** ******’* ******.” ***** also ***** **** *****, ***** *** *** ****** ** ******'* personal *********** ***** ********.

ICO ************

** *** **, ****** *** **, * ****** ******** ****** ************** ************’* ****** ** ***- ******** *** **** ********** *******. ** ************ *** ***** security ******** ******** ** *** *** *** ******* ******, ********* IPVM **** **** **** *** **** *** **** *******:

*** **** ********* ***** ************** (******) ******* *** **** ****** with ** ******* ******. *** **** ** ********* ***** ****** to *********** *** ********** *** *** ** **** ********* *** company *** ********** *** *** ************ ********** ******** ***** ***** commencing *** *** *************

GDPR ********** *****

***** **** ******** **** ***** ***** *** ************** ** *** 25 ** *** **’* *** **** ******* *****, *** ****, which ****** *** **.

*** ********* **** ***** ********** ** **** ********** **** ********* **’* *************** “******* ******** **** *** *** **** ********** ******* *** individual’s ************ ** ** ********** ****** ** ******* *******.”

************* *** *********** ***** **** ******* ***** ****** ***** **** penalties ** **** *** ******** ** ********, ***** ********** ******** ** ** ** ** ******* ***** ** *% ** worldwide *******.

How ***** ******* **** *********

*******, *** ***’* ******** *** ** ******** ***** ***** ****, so ***, ***** ** ******** *** ***-******** **** ***** *** EU ***** ************ ********* *** *********.

*** **** ****** ***** *********** ****** ** ******** *********** **** it ***** ** ******** ******* ** *** ** ****** *********.******* ** **** ************** *** ****** *** “***********,” ******* ***** *** * “******* to **** ******** ** ******** *** ****** ***** ********,” *** whether ***** *** * “**** ** ************* **** ***********”.

** ****** *** ***** *** *********** **** ***********, ***** *** able ** ***** ********* **********.

GDPR ************

************* ****** *** **** **** **** ** ******** **** *** GDPR ** *********. ***-**** ********* ****** ********, ***** * *** factor **** ****** ** *****’* ***** *** **** *** ****** only ******** * *** ******, **** ** **** ***** *** complaints *** ************ ** ******* ************ **.

************, *** ***** **** **** **** ********* * ********* ********* to ************* *** *********** **** ** ***** ** **** ********. It **** ***** *** ********** ** ***** ********** *** *********** with *********** ** **** ** * ******.

IPVM’s *** ********* ***** *** ********

*** *** ** ****************** ****’* **** ********* ***** ****** **************** **** ********** ** ***** ** ******.

*** ******-**** ************* ** ***** ******** *** ***** *** ** an ********** ** ******* ******* ****** ** * ***** ** **** *************** ** ******** **** ********** ******** – ******* ****** ****** playing **** ************* *** ***********’ *****.

Comments (7)

* ** ********* ** **** ********** *** ***** ** ******* be ********** **** **** ******** *******.

*’** *** *** **** ********** **** * ******* ******** **.

*** ******** *** ***** *** ***** ******* ****?

** **** * **** *** *** * *** ******* ****’* door

****** **** * ****** *** :)

** **** * **** *** *** * *** ******* ****’* door

***** * ***** ******!

** ****** **** *** ********** ***, *** *** ****, **** will **** ** ** ******** *** ***** ** **** **** a ******** ****-****. **** *** *** ***** **** ** **** in *** **'*, * ******** ** "*******" ******* ******* ** companies *** ******** ****** ** ****** **** ****** *** ****** on *** ********** ***** **** ** **** ***** ** *** impetus ** *** ***** ********. *** **** *** *** ** provide *********** **** *** ****** ********* ** *** ******, **** simply ******* *** **** ** ******** ***** *** ************ **** would ***** **** **** ******** ** ***** ******. **** **** there ** * ********* ** ** **** **** ** *********** cases ** ****** ****** *** ******** ******.

*** **** *** *** ** ****** **** ****, ** ** early **** **** **** **** **********. *** ***** ******* ** GDPR *** *** ** * ******** ******** ** * **** breach. ** ********** *** *****, ****** *** ****** ** ****** a ******** *** ******** ** ** ****. ***** ***** ****** is **********, ******* **** ********** ******** ******* *** **** ******** abuse ** *** **** ********* - **** ***** **** ** a ******** ****** *** ****** *** *********. *** ** *** sanction ***** *** * ******** ***** ****** ***** ***** ** most ****** ** ****** *** ** **** ****** ** ******** data ********* ** **********.

*** ** *** * ****** ********* ******* ** ***** ******* - ** ******* ** *** **** ** *** *******, *** wholly ******** **** ** ********** ** ********* *** *** *** GDPR *** **** *****. ******** - **** *** ***** *** up *********** *** ****, *** *** ******* ** **** ** has **** ****** ******** ** **. ***** **** ******* ************* **** ******** ** *** ******** **** ********* **** ****** from ***** ********, *****, ******* *** **** ********** **** ******** ****** ******* *****, **********'* *** ******** ** a *********** ****** *** *** *** * ****** **** ** what **** *** *** ** ** **.

*** ********** ** **** ***** ********* **** ** ******** - most ****** ***** *** ******* ** ***** *** "*****" **** place - * **** ********** ************* *** ******** ***** **********. I ****** **'* * **** *********, *** ** ** ****** well ***** *** **** *** **** ** *** ********* ******* and ***** ** **** ****** ***** *********. **'* **** ********** considering **** ****** *** *** *** **** *** ** ********** by ****, *** * ***** **** ****** **** ******** ** place ******* ** *** ** ***** *** **** ****** ** data ********** *** ***** ** *** **** ***** *********** - but **** ******* ** *** ** **** ****** ***** * figure *********** ******** ***** **************'* **** ***** ** ******* ******* ** *** **** ** the *** ** ********* *****.

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Related Reports

Massive Leak Of Chinese VMS Provider Exposes Xinjiang Surveillance on Feb 20, 2019
A subsidiary of China’s claimed largest VMS provider is tracking the precise location and ethnicity of millions in China’s Xinjiang region,...
Ubiquiti Favorability Results 2019 on Feb 18, 2019
Ubiquiti has quietly grown into a $1+ billion annual revenue company, with offerings across wireless, wireline network and video surveillance (see...
Casino Surveillance Pro Interview: James Lathrop on Feb 15, 2019
James Lathrop has been working in casinos for almost 25 years. During that time, he says he has held "just about every job you can do in the...
Uniview / UNV Favorability Results 2019 on Feb 12, 2019
Uniview / UNV, the self-proclaimed #3 China manufacturer, while starting late, has been working to make inroads internationally. In IPVM's 2019...
Barnes Buchanan 2019: Despite 'Strange Narrative' Great Time To Be In Security on Feb 11, 2019
A "strange narrative" is being spun, said Michael Barnes at the 2019 Barnes Buchanan Conference. However, despite that narrative, it is a "great...
FLIR Favorability Results 2019 on Feb 08, 2019
FLIR has had a challenging past few years including FLIR Security business struggling, FLIR restructuring their security division and FLIR selling...
Sony Favorability Results 2019 on Feb 06, 2019
Sony Favorability amongst integrators improved moderately compared to their 2017 favorability results, with a modest net positive...
Hanwha Techwin Favorability Results 2019 on Jan 31, 2019
Hanwha Techwin's favorability results surged, in IPVM's 2019 study, going from barely neutral in 2016 to strongly net positive, as the results...
Vivotek Favorability Report 2019 on Jan 29, 2019
Taiwanese video surveillance manufacturers, even relatively large ones like Vivotek, have lost ground in the PRC-China-driven race to the bottom....
Austria’s First GDPR Fine Is For Video Surveillance on Jan 29, 2019
Should EU businesses be concerned if police see a business' surveillance cameras filming public areas? This is what happened with Austria’s first...

Most Recent Industry Reports

Outdoor Camera Mounting Hardware Guide on Feb 21, 2019
Mounting cameras outdoors can be challenging, requiring understanding different types of equipment and methods. In this guide, we teach this...
HID Favorability Results 2019 on Feb 21, 2019
HID favorability results were strong, in the 2019 IPVM integrator study of 200+ integrators, with a net +62% and low negativity as the table below...
First US State, Vermont, Bans Dahua and Hikvision on Feb 21, 2019
The first US state, Vermont, has issued a ban on a number of Chinese and Russian manufacturers including the world's 2 largest video surveillance...
ADI 'SAVE BIG' On FLIR And Hikvision Examined on Feb 20, 2019
One is a major US defense supplier. The other is owned by the Chinese government. But you can "SAVE BIG" on both at ADI. In this note, we...
BluB0x Company Profile on Feb 20, 2019
BluB0x has doubled in revenue every year since its founding in 2013, according to CEO Patrick Barry. We originally reported on them in 2015. At the...
Security Installation Tools Guide - 22 Tools Listed on Feb 19, 2019
In this guide, we cover 22 tools that security installers frequently use. This is one part of our upcoming Video Surveillance...
Sales Cuts At Rasilient on Feb 19, 2019
Over the past 2 years, video surveillance storage specialist Rasilient has expanded its workforce significantly, aiming to build its own branded...
Exacq Raises VMS Software Pricing Twice in Less Than a Year on Feb 18, 2019
Most VMSes regularly release new features, but rarely increase their prices. For the 3rd time in 4 years, and 2nd time in 8 months, since being...
Axis IR Multi Imager Camera Tested (P3717-PLE) on Feb 18, 2019
Axis has released their first IR multi imager, the P3717-PLE, a repositionable model listing 360° IR illumination and flexible positioning,...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact