EP NowStoreAcademySupportProduction LotProducts by Country
Legal & Compliance Home

ICO Warns Against Complacency as it Hands Out £4.4M GDPR Penalty

The Information Commissioner’s Office (ICO) imposes hefty penalty for failing to protect employee personal data, in breach of the UK General Data Protection Regulation (GDPR).
November 16, 2022
ICO Issues 4.4M Penalty

The Information Commissioner’s Office (ICO) has imposed a hefty penalty of £4.4M on UK-based construction company Interserve Group Ltd. for failing to protect employee personal data, in breach of the UK General Data Protection Regulation (GDPR).

Despite falling victim to a cyberattack, the ICO had little sympathy for Interserve, with Information Commissioner John Edwards stating

The biggest cyber risk businesses face is not from hackers outside of their company, but from complacency within their company. If your business doesn't regularly monitor for suspicious activity in its systems and fails to act on warnings, or doesn't update software and fails to provide training to staff, you can expect a similar fine from my office.

Clearly, the ICO is continuing to crack down on companies which don’t take data security seriously. So, what can production teams learn from this decision?

What happened?

In March 2020 a phishing email was sent to Interserve’s accounts team mailbox requesting urgent review of a document. The email wasn’t picked up by Interserve’s email system. An employee monitoring the inbox forwarded it to a colleague who was responsible for paying invoices.

The second colleague opened the email and downloaded the attached zip file. The file installed malware on their computer, giving the hacker access to their system.

Interserve’s anti-virus tool detected the malware and removed it. However, the company failed to take any further steps to investigate the incident and the hacker retained access to the employee’s computer.

The hacker subsequently gained access to Interserve’s IT system. Among other things, the hacker compromized four HR databases containing data relating to 113,000 former and current employees. This data included personal data – such as contact details, national insurance numbers, bank details and salary information – as well as special category personal data, including data relating to ethnic origin, religion, sexual orientation and disabilities.

Two months after the original attack, during a routine maintenance check, Interserve discovered a message on its server stating that it had been hacked. It subsequently reported the attack to the National Cyber Security Centre and the National Crime Agency and submitted a personal data breach notification to the ICO.

The penalty

Following an investigation, the ICO concluded that Interserve had failed to put appropriate technical and organizational measures in place to prevent the cyberattack, in breach of Articles 5(I)(f) and 32 of the UK GDPR.

In particular, the ICO found that Interserve had:

  • Failed to follow up after being alerted to suspicious activity
  • Used outdated software systems and protocols
  • Failed to provide proper staff training (at the time of the incident, only one of the employees who received the phishing email had undertaken data protection training), and
  • Failed to undertake proper risk assessments

According to the ICO, these failures had rendered Interserve vulnerable to a cyberattack.

Takeaways for production

In its decision, the ICO acknowledges that while protecting a business from cyberattacks can feel intimidating, most organizations which get it wrong make preventable mistakes.

With phishing attempts constituting the most common form of cyberattack reported by UK businesses, there are some lessons which can be learned from this decision.

Training, training, training

Because phishers prey on individuals, it’s essential that production teams undergo data protection training so that they can recognize attempted attacks (things like unusual or mis-spelled domain names, poor spelling and grammar and urgent requests to perform a task (such as making a payment) can all be signs that an email isn't what it seems). As demonstrated in this case, accounts teams may be a particular target due to the nature of their role.

Phishers are becoming increasingly sophisticated, so training should be provided on a regular basis to keep data protection top of mind.

Policies

In addition to providing regular training, it’s essential that production companies have appropriate data protection policies in place and a means to update and promote these. It’s also important to have a clear audit trail of who’s read and agreed to your policies.

Robust systems

Interserve’s outdated software systems made it vulnerable to a cyberattack. Similarly, personal email systems and devices and unsecure IT networks can leave you exposed if you’re using them to host and share personal data, such as contract and payment information. To reduce your risk, make sure you’re using a secure, cloud-based solution to manage personal data, with added security measures like multi-factor authentication.

For more information on how to secure your production data, check out our guide to information security.

Topic: Security

Related Content

Thumbnail-Master Series Panelists-UK Cultural Test

Tips for Passing the UK Cultural Test

4/11/2025
Discover how to easily qualify your film under the Cultural Test, a vital step every project must complete...

How to Manage Global Residuals: A Guide to North America, the UK and Australia

4/1/2025
Your quick-guide overview of how film and television residuals are managed in the United States, Canada,...
UK government issues 2025 Spring Statement

How Will the New Spring Statement Impact UK Film and TV Productions?

3/27/2025
Find out how Chancellor Rachel Reeves' Spring Statement 2025 will impact payroll budgets for film and TV...
Payroll accountants review year-end payroll on UK production

How to Get Your Payroll Ready for Year-End: A Guide for UK Productions

3/18/2025
Find out how UK production teams can streamline their year-end payroll and ensure a smooth transition to...

Global Production Incentives Update: March 2025

3/3/2025
Your guide to enacted and proposed legislation shaping film and television incentive programs across the...
EP Blog-image of a woman animating a character on her computer-Animation Incentives Around the World

Animation Around the World: How Incentives Drive a Growing Industry

2/27/2025
Learn how many countries, including the US, Canada and UK, are boosting global animation business with...
Master Series Thumbnail Square - Panelists discuss UK budgeting for 2025

Budgeting for 2025: What UK Productions Need to Know

2/20/2025
Learn about critical legislative changes in the UK that will impact production budgets starting April 1,...
Getting paid as a supporting artist on UK films and TV shows

How Much Are Supporting Artists Paid on UK Film and TV Productions?

2/11/2025
Find out about the basic rates of pay, supplementary fees and allowances supporting artists are entitled...

The Ultimate Career Toolkit for Self-Employed Actors in the UK Film & TV Industry

2/4/2025
Discover essential resources and expert insight to help you navigate the UK film and TV industry and build...
HMRC self-assessment tax form for UK supporting artists

The Ultimate Tax Guide for Self-Employed Workers in the UK Film & TV Industry

1/28/2025
Discover essential resources to help you simplify your UK tax obligations and stay compliant as a...
Female supporting artist in period film

How to Become a Supporting Artist on UK Film and TV Productions

1/20/2025
Want to be a part of the UK's biggest film and TV productions? Find out how to become a supporting artist...
Square image of currencies and countries on a blue map

Global Production Incentives to Watch: A Look Back at 2024 and What’s Ahead in 2025

1/14/2025
A retrospective of the major UK reforms, incentives introduced in Ireland & the broader European market,...
EP Newsroom-Thumbnail-PGGB

PGGB Talent Development Fund: Year Two Reception

11/29/2024
The Production Guild of Great Britain (PGGB) recently celebrated the wrap of the second year of its Talent...
Calculating UK tax increases

Budgeting for 2025: UK Tax Increases Impacting Film & TV Productions

11/26/2024
Learn how changes to UK payroll taxes and minimum wage rates will affect new and existing productions from...
EP Newsroom-Thumbnail-PGGB

PGGB Membership Focus: Talent Development Alumni

11/25/2024
In its latest Membership Focus, the Production Guild of Great Britain (PGGB) spoke to members who have...

What Does the UK's Enhanced VFX Rate Mean for Productions?

11/6/2024
Learn how the incoming enhancement of the UK's VFX incentive rate, including the eligibility of generative...
Self-employed crew members work on set

New UK Employment Rights Bill: Significant Reform for Film & TV's Self-Employed?

10/29/2024
The highly anticipated Employment Rights Bill makes some major changes to UK employment law. But what does...
Film crew on UK independent film tax credit production

UK Independent Film Tax Credit (IFTC) Approved: Key Updates for Producers

10/10/2024
The UK government has passed the new Independent Film Tax Credit (IFTC) into law, providing welcome...
RTS Film & TV Mini MBA students

Royal Television Society Launches Film & TV Mini MBA with Support from EP’s FLB Accountants

10/3/2024
This first-of-its-kind course is aimed at media professionals who want to broaden their skillset and...
Dark-haired woman operates a steadycam on set

The Producer’s Guide to Unions in the UK Film and TV Industry

10/1/2024
Take a whistlestop tour of the main unions governing the UK film and TV industry so that you can be...
People on set discuss incentives estimates

Incentives Estimate or Opinion Letter: Which One Is Right for My Production?

9/25/2024
Looking to obtain funding for your production? Learn whether an incentives estimate or an opinion letter...

California vs. the World: The Race to Nab Film and TV Productions

8/22/2024
Locales from Atlanta to Tokyo are steadily beefing up their tax relief programs in bids to attract...
Cameramen with professional equipment films two young people

What is an Incentives Estimate and Why Do I Need One?

8/21/2024
Find out how an incentives estimate can help you to lock down your production's finance plan and turn your...
UK Phases Out Biometric Residence Documents

More Right to Work Changes as UK Phases Out Biometric Residence Documents

8/8/2024
Find out what UK productions should do to prepare for the expiration of biometric residence permits on...
Topic: Legal
More

Payroll & Finances

PayrollResidualsSmartStartSmartTimeEP On LocationSmartAccountingEP LiveSmartPOCASHétPayPaymaster Rate GuideEP ResidencyMoneypenny

Manage Multiple Productions

AssetHubSmartHub

Additional Services

Academy
Subscribe now

Be an industry insider with EP's
newsletters and alerts

LegalPrivacy NoticeSecurity
© 2025 Entertainment Partners. All rights reserved.