Home Knowledge More Data Security Breaches: GAA and Fine Gael in the Spot Light

More Data Security Breaches: GAA and Fine Gael in the Spot Light

January 12, 2011

The recent cyber attack on the Fine Gael website, along with the theft of data relating to over 500,000 GAA members, has firmly placed the issue of data protection back in the spotlight.

The hacking of the Fine Gael website, allegedly by the ‘Anonymous’ group, resulted in the personal details of nearly 4,000 people being compromised. The Anonymous group has gained notoriety in the past couple of months following a number of high profile cyber attacks against companies such as Amazon, Paypal, Mastercard and Visa in retaliation for those companies withdrawing their support from Wikileaks following the publication of confidential US Government communications.

The GAA members’ data, which was stolen following a security breach at a Belfast company, included names and addresses, dates of birth, mobile phone numbers, email addresses and, in around 500 instances, medical information. The breach also affected over 150,000 members who are under the age of 18. The Office of the Data Protection Commissioner is currently investigating both data security breaches and has a number of powers available to them to deal with such breaches including potential civil and criminal sanctions.

More and more companies are having to face the challenges raised by a data security breach (see our previous article on a cyber attack against a UK law firm ) and these incidents highlight the importance of ensuring that adequate plans are in place to deal with these types of issues. In the case of cyber attacks, this should include appropriate staff training, encryption of sensitive data and firewalls designed to cope with an attack of this nature. It is also advisable to create a staff policy so that potential data security breaches are recognised and that the appropriate steps, as outlined in the recently published Data Security Breach Code of Practice (which is discussed here ), are taken.

In addition companies should examine the nature and purpose of the data they are gathering. In the case of the Fine Gael website the data was gathered from individuals who wished to leave a comment on the website. Companies should review their policies relating to data gathering and storage so as to ensure that they have adequate protection in place depending on the nature of the data they are gathering and storing.

For further information or if you have any queries please contact either Leo Moore or John Magee of our Data Protection department.