British Pregnancy Advice Service slammed over £200K data breach fine
Abortion service blasted over poor data handling in wake of £200,000 data breach fine from the ICO.

The information security industry has blasted the British Pregnancy Advice Service (BPAS) after it was fined 200,000 for a serious breach of the Data Protection Act.
News of the fine broke last Friday, when it was revealed that almost 10,000 people who contacted the abortion charity had their names, address and contact details exposed to a hacker.
The affected individuals were people who entered their name, address, data of birth and telephone number into the BPAS website to request a call back from one of its advisors.
This data was then stored by the website unbeknown to the charity in an unsecure way and a flaw in the website's code allowed a hacker to access the system and dig out the information.
This fine seems out of proportion when compared with those levelled against other organisations who were not themselves the victims of a crime.
The hacker later threatened to publish the names of people who contacted the service, an act that was later prevented by the police and an injunction obtained by the BPAS.
The individual behind the attack later received a 32 month jail sentence.
The service was fined 200,000 in total after an investigation by the Information Commissioner's Office (ICO), which confirmed the BPAS had breached the Data Protection Act twice.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The first time when the hacker got hold of the information, and for a second time by retaining the call back data for five years longer than needed.
David Smith, deputy commissioner and director of data protection at the ICO, said the BPAS could not use ignorance as an excuse in this case.
"It is especially unforgiveable when the organisation is handing information as sensitive as that held by the BPAS. Data controllers must take active steps to ensure that the personal data they are responsible for is kept safe," said Smith. "There's a simple message here: treat the personal information you are holding with respect. This includes making sure you know just what information you are holding and that it's subject to up-to-date and effective security measures."
In response, BPAS chief executive Ann Furedi said the organisation accepts hackers should not have been able to steal its data, before hitting out at the unjust size of fine it received.
"We accept that no hacker should have been able to steal our data but are horrified by the scale of the fine, which does not reflect the fact that BPAS was a victim of a serious crime by someone opposed to what we do," she said.
"BPAS is a charity which spends any proceeds on the care of women who need our help and on improving public education and knowledge on contraception, fertility and unplanned pregnancy.
"This fine seems out of proportion when compared with those levelled against other organisations who were not themselves the victims of a crime," she concluded.
Since news of the data breach broke, the information security industry has roundly condemned the BPAS and its approach to data handling.
Tim Erlin, director of security and risk at vendor Tripwire, said: "They must have known they were a target and should have been more diligent about securing this data."
Brendan Rizzo, technical director for EMEA at Voltage Security, was equally damning in his response to the news.
"Companies must ensure that, if the data does need to be collected, that it is protected with strong encryption," said Rizzo.
"Often this is seen as a stumbling block because it has traditionally required extensive customisations to accommodate the use of this encrypted data at every step along the way."
-
The Race Is On for Higher Ed to Adapt: Equity in Hyflex Learning
By ITPro
-
Google faces 'first of its kind' class action for search ads overcharging in UK
News Google faces a "first of its kind" £5 billion lawsuit in the UK over accusations it has a monopoly in digital advertising that allows it to overcharge customers.
By Nicole Kobie
-
AI recruitment tools are still a privacy nightmare – here's how the ICO plans to crack down on misuse
News The ICO has issued guidance for recruiters and AI developers after finding that many are mishandling data
By Emma Woollacott
-
“You must do better”: Information Commissioner John Edwards calls on firms to beef up support for data breach victims
News Companies need to treat victims with swift, practical action, according to the ICO
By Emma Woollacott
-
LinkedIn backtracks on AI training rules after user backlash
News UK-based LinkedIn users will now get the same protections as those elsewhere in Europe
By Emma Woollacott
-
UK's data protection watchdog deepens cooperation with National Crime Agency
News The two bodies want to improve the support given to organizations experiencing cyber attacks and ransomware recovery
By Emma Woollacott
-
ICO slams Electoral Commission over security failures
News The Electoral Commission has been reprimanded for poor security practices, including a failure to install security updates and weak password policies
By Emma Woollacott
-
Disgruntled ex-employees are using ‘weaponized’ data subject access requests to pester firms
News Some disgruntled staff are using DSARs as a means to pressure former employers into a financial settlement
By Emma Woollacott
-
ICO reprimands Coventry school over repeated data protection failures
News The ICO said the academy trust failed to follow previous guidance, which caused a serious data breach
By Emma Woollacott
-
ICO dishes out fine to HelloFresh for marketing spam campaign
News HelloFresh failed to offer proper opt-outs, the ICO said, and customers weren’t warned their data would be used for months after they cancelled
By Emma Woollacott