Featured Article : Ofcom Fines Virgin Media £23.8 Million

Ofcom has fined Virgin Media £23.8 million after finding that the company’s move to digital landlines left thousands of vulnerable telecare customers at direct risk of harm.

What Ofcom Has Decided

On 1 December 2025, Ofcom announced that it had imposed a £23.8 million penalty on Virgin Media for serious failings during its programme to migrate customers from traditional analogue landlines to digital services.

Why?

The regulator’s investigation concluded that, between August 2022 and December 2023, Virgin Media’s handling of telecare users breached its consumer protection obligations. For example, under Ofcom’s rules, telecoms providers must have clear and effective policies to ensure the fair treatment of customers whose circumstances make them vulnerable.

In practice, Ofcom found that Virgin Media failed on two major fronts. First, it did not properly identify and record telecare customers, which created significant gaps in its screening and support processes. Second, it disconnected some known telecare users who did not respond to the company’s contact attempts about the digital switchover, despite the risks that disconnection posed.

Those disconnections prevented telecare alarm devices from reaching monitoring centres in an emergency, leaving affected users in potentially unsafe situations. Ofcom said this put thousands of vulnerable people at direct risk of harm.

Four Weeks To Pay

Virgin Media must pay the £23.8 million fine within four weeks. The amount reflects a 30 per cent reduction in recognition of the company’s decision to admit liability, cooperate with Ofcom’s investigation and enter a formal settlement process.

Why Telecare Users Were So Exposed

Telecare systems are widely used by elderly, disabled or otherwise vulnerable people who rely on an emergency pendant or wristband to call for help. When activated, the device connects via the user’s landline to an alarm monitoring centre or a designated carer. Any break in that connection, therefore, can have severe consequences for anyone experiencing a fall, sudden illness or another emergency.

Transition

The UK’s telecoms sector is currently transitioning from the ageing public switched telephone network, the copper based PSTN, to digital IP based voice services. The PSTN is now considered beyond its intended lifespan and increasingly unreliable, which is why the digital upgrade is underway across the industry.

For most households, the change is relatively straightforward. For telecare users, however, migration must be handled with greater care. Telecare devices may not work correctly if not fully tested on digital lines, and power outages can affect digital services unless appropriate backup solutions are in place. For this reason, Ofcom has repeatedly stressed that telecoms companies must identify, protect and support these users throughout any transition.

How Virgin Media’s Switchover Went Wrong

Virgin Media first alerted Ofcom to a series of “serious incidents” involving telecare customers in November and December 2023. These reports triggered a formal investigation into whether the company had systemic issues in its migration process.

Over a period of roughly sixteen months, Ofcom found that Virgin Media’s approach had exposed vulnerable users in several ways. For example, significant numbers of telecare customers were not correctly identified in Virgin’s internal systems, meaning they were not flagged for the additional support required during migration.

Ofcom also found that Virgin Media disconnected some telecare users who did not respond to letters, emails or calls about the switchover. These disconnections went ahead even though the company was aware of the risks this created for users who depended on working landlines for emergency assistance.

During its remedial work, Virgin Media contacted 42,991 identified telecare customers to support them through migration. This figure gives a sense of the scale of the telecare customer base that the company needed to re-assess once the issues came to light.

What Virgin Media Says In Its Defence

Virgin Media has accepted Ofcom’s findings and the pretty substantial fine. The company has emphasised that the majority of migrations were completed without issue, but acknowledges that it did not get everything right for telecare users.

A spokesperson said the company recognised the problems that occurred and had since addressed the issues identified by Ofcom. Virgin Media has also highlighted the broader context, stating that the move to digital phone lines is essential because analogue lines are becoming less reliable and are increasingly difficult to maintain.

Reviews And Improvements

The company says it’s carried out an end to end review of its digital migration processes and introduced a “comprehensive package of improvements”, including:

– Better targeted communications for telecare users.

– Additional in home support during the switchover.

– Extensive post migration checks.

– Manual reviews of customer records to identify additional telecare users.

– A new policy that keeps non engaging telecare customers in a continuous engagement process rather than disconnecting them.

Virgin Media also says it is working with government, Ofcom and local authorities on a national awareness campaign to help improve understanding of the digital switchover and the specific needs of telecare users.

Virgin Media Customers

For most customers, the fine itself doesn’t change day to day services, since the money will go directly to the Treasury. However, the wider questions relate to whether Virgin Media’s updated processes are now strong enough to prevent a recurrence and whether customers, particularly those responsible for the care of vulnerable people, can have confidence in the company’s revised safeguards.

Businesses that rely on landlines for safety critical systems are likely to now be paying close attention to these developments. For example, telecare is the highest risk category, but many organisations still have legacy analogue dependencies, including alarm systems, lift phones, payment terminals and monitored entry systems. As the Virgin Media case shows, identifying those dependencies early is essential to ensure continuity during migration.

How Significant Is This Penalty?

The penalty sits among Ofcom’s larger fines in recent years. It is smaller than the £50 million fine issued to Royal Mail in 2018 and the £42 million penalty imposed on BT in 2017, but it is one of Ofcom’s largest decisions involving consumer protection rather than competition or technical service breaches.

What sets this case apart, however, is its focus on vulnerability and safety. Ofcom has made clear that the digital switchover cannot be treated as a purely technical exercise, particularly where safety critical devices are involved. Providers must be able to demonstrate that they have identified every customer who relies on telecare or similar services and that they have a safe, verified plan for migrating them.

Implications For Rivals And The Wider PSTN Switchover

The decision arrives during a complex national transition. Telecoms providers, government and industry bodies have agreed new charters and non voluntary migration checklists designed to strengthen protections for vulnerable customers. These include new expectations around individual risk assessments, enhanced contact attempts and safeguards before any disconnection can take place.

Other major providers have already had to revise their own migration plans in response to concerns about telecare reliability. The Virgin Media case is likely to intensify scrutiny across the sector, as Ofcom has made clear that it will not hesitate to take enforcement action if providers cannot demonstrate that vulnerable customers are being safeguarded.

Questions And Criticisms

The decision has raised several points of debate. For example, one relates to the absence of direct compensation, since the fine goes to the Treasury rather than to affected customers or local authorities who may have had to respond to incidents during the switchover. Ofcom’s role in this case is enforcement rather than redress, which means affected users will not receive direct financial support through this process.

Another issue is whether the failures identified at Virgin Media point to a broader challenge for the sector. Telecare providers, charities and parliamentary committees have continued to highlight confusion about responsibilities during migration, particularly where equipment manufacturers, care providers and telecoms companies all play different roles in keeping telecare services working.

There are also concerns that awareness among small businesses and property managers remains low. For example, even organisations not directly involved in health or social care may still rely on analogue lines for alarms, access systems or monitoring equipment without realising the implications of the switchover. The Virgin Media enforcement action is likely to prompt renewed calls for clearer guidance, more proactive industry communication and closer coordination with equipment suppliers.

What Happens Next?

Virgin Media has already paused and redesigned parts of its migration process. The company is now operating under updated policies, a revised engagement model for telecare users and closer regulatory oversight.

Ofcom is continuing to issue guidance on how providers should handle the remainder of the PSTN switch off. This includes expectations around vulnerability assessments, business continuity planning and coordination with emergency services, local authorities and telecare operators.

The case is likely to remain a reference point for months to come as organisations, regulators and telecoms companies navigate the final stages of the UK’s shift to digital landline services.

What Does This Mean For Your Business?

This enforcement decision leaves the sector with a clearer sense of what regulators expect during the remainder of the switchover. Virgin Media’s failings were specific, but the underlying challenges are shared across the industry, particularly the difficulty of mapping analogue dependencies and ensuring that every vulnerable user is identified before any change goes ahead. The scale of the fine signals that Ofcom is prepared to act when those responsibilities are not met, which will shape how major providers approach their own migration plans over the next year.

The case also demonstrates why UK businesses should pay closer attention to their remaining reliance on analogue systems. Many organisations have digitalised most of their operations but still depend on a single lift line, alarm system or monitored entry point that uses outdated infrastructure. The disruption experienced by telecare users shows how easily those hidden dependencies can be overlooked and why forward planning is essential. For sectors such as housing, healthcare, facilities management and retail, the risks are not only technical but operational and reputational.

For telecare users, charities and local authorities, the decision provides reassurance that regulators are watching and treating these risks seriously. It also highlights how fragmented responsibilities have made safe migration more complicated. Telecoms providers can update their own processes, but the safety of vulnerable customers also depends on the readiness of equipment manufacturers, monitoring centres and care providers. The outcome may drive more coordinated planning across these groups, which has often been missing.

The broader lesson for the sector is that the digital switchover is not simply a matter of replacing one network with another. It is an exercise in risk management that requires precise data, careful customer engagement and a full understanding of how different services interact with the telecoms network. Virgin Media has now rebuilt much of its process, but the scrutiny it faced is likely to set new expectations for every provider involved in the transition.

As the migration continues, the focus will shift to whether the safeguards now put in place are strong enough to prevent a repeat of the problems uncovered here. The coming months will show whether the industry can maintain the pace of digital upgrade while keeping vulnerable customers protected and giving businesses and public sector bodies the certainty they need to manage their own critical systems.

Company Check – New UK Law Could Hit IT Firms With £100K-a-Day Fines

The UK government has unveiled sweeping new cyber legislation that could see organisations hit with fines of up to £100,000 (per day!) if they fail to respond to threats in time – a move that dramatically raises the stakes for IT providers, critical service operators, plus their supply chains.

Tough New Rules Aimed at Critical Infrastructure and the Tech Supply Chain

The draft Cyber Security and Resilience (CSR) Bill, formally outlined this week by technology secretary Peter Kyle, seems to be setting out a more aggressive approach to cyber regulation in response to what ministers describe as “unprecedented threats” to the UK’s digital and physical infrastructure.

Crucially, the bill expands the scope of current regulations and will bring managed service providers (MSPs), IT suppliers, and potentially datacentre operators into the same regulatory framework as public utilities and emergency services. This means that for the first time, commercial tech firms (up to 1,000 of them by current estimates) could be legally obliged to meet strict cybersecurity standards or face financial penalties.

“Economic growth is the cornerstone of our Plan for Change,” said Kyle, “And ensuring the security of the vital services which will deliver that growth is non-negotiable.”

Three Core Pillars – and a Sharp Set of Teeth!

The new bill is built on three pillars. First, widening the scope of the UK’s existing Network and Information Systems (NIS) regulations to include more types of organisations. Second, giving regulators stronger powers to enforce those rules and third, allowing government to rapidly update the rules in response to new and emerging cyber threats.

What’s new (and raising a few eyebrows) is the addition of discretionary government powers to issue binding cyber directives in real-time. For example, if an in-scope organisation receives a formal order to patch a vulnerability or improve cyber defences in response to an active threat and fails to comply, it could face daily fines of up to £100,000, or 10% of turnover, whichever is higher.

The message, therefore, appears to be that falling short isn’t just risky but could be ruinously expensive.

Why Supply Chain Security Is Now Front and Centre

The bill changes how cyber risk is perceived at the national level. For example, instead of focusing solely on headline-grabbing ransomware events or attacks on high-profile utilities, the government now appears to be turning its attention to the digital supply chain, i.e. the vast network of IT support firms, software providers, and cloud service operators that underpin the UK economy.

For example, the Cloud Hopper espionage campaign, which targeted MSPs to indirectly infiltrate governments and corporations, is a cautionary tale of how supply chain vulnerabilities can be weaponised at scale. Likewise, the recent breach of the Ministry of Defence’s payroll system showed how even indirect routes into sensitive data can have real-world consequences.

The UK’s National Cyber Security Centre (NCSC) is backing the approach, and as NCSC CEO Richard Horne says: “The Cyber Security and Resilience Bill is a landmark moment,” adding that “It will improve the cyber defences of the critical services on which we rely every day, such as water, power and healthcare.”

Datacentres and the Next Phase of CNI Regulation

The government is also strongly considering bringing datacentre operators into the bill’s remit, a step it hinted at last year when these facilities were designated as critical national infrastructure (CNI).

If passed, this could affect more than 180 UK-based datacentres and over 60 operators, according to industry figures. While exact compliance requirements haven’t yet been defined, it’s expected that these facilities will be subject to the same incident reporting rules and real-time intervention powers as other in-scope entities.

What’s more, ministers are exploring the use of AI tools to help detect and respond to threats inside these physical and virtual infrastructure hubs.

Mandatory Incident Reporting Tightens Timelines

Another key change is a tightening of mandatory reporting timelines. Organisations in scope of the CSR Bill will need to notify regulators and the NCSC of significant incidents within 24 hours – faster than the 72-hour window required by both the EU’s NIS2 directive and the US’s CIRCIA.

A full report must follow within 72 hours, creating a dual-stage reporting process that places UK organisations under one of the most stringent regulatory regimes in the world.

As technology secretary Peter Kyle says: “This is not just red tape,” but rather “It’s about making sure we know, quickly, when something serious is happening – and being able to act fast.”

Why This Isn’t a ‘One and Done’ Job

Legal experts and cyber risk consultants are warning that the scale of the challenge posed by the new rules is significant, i.e. not just in terms of cost, but also the time and effort required. For example, even well-resourced organisations could find the process of aligning legacy infrastructure with modern cyber resilience standards a long and complex task.

The key point that many are making is that cyber security is not something that can be addressed once and then forgotten. With threats constantly evolving, businesses will need to build ongoing investment and regular system upgrades into their operations. The burden, therefore, isn’t going to be just technical, but will also demand sustained leadership focus and cultural change across entire workforces. In other words, achieving compliance in this case is going to be a continuous journey.

Statutory Powers and Strategic Priorities

As well as giving regulators sharper enforcement tools, the bill proposes that the government publish a unified Statement of Strategic Priorities (updated every three to five years) to guide the approach of different regulators. This aims to bring consistency and clarity to enforcement across sectors, ensuring that energy, healthcare, and IT providers all face comparable expectations.

The government would also be granted the power to issue emergency directions to organisations where needed. This could prove vital in responding to fast-moving attacks, such as zero-day exploits or geopolitical cyber events.

Rising Threats, Rising Costs

The need for faster, tougher intervention isn’t theoretical. In 2023, attacks on UK utility firms surged by 586 per cent, according to reinsurance firm Chaucer. The NCSC dealt with 89 nationally significant incidents (up from 62 the previous year) including 12 so serious they required COBR (Cabinet Office Briefing Rooms) meetings.

Notably, one of the most damaging incidents of last year (i.e. the ransomware attack on NHS blood testing partner Synnovis) cost the NHS an estimated £32 million! Analysts have suggested that a well-coordinated attack on the energy grid in southeast England could cost the UK economy up to £49 billion!

In light of this, the CSR Bill is not just about compliance, but is also about protecting national prosperity.

What Does This Mean For Your Business?

The details of the Cyber Security and Resilience Bill seem to show that the intention is to move things from reactive firefighting to proactive, enforceable standards. For UK businesses, particularly those in the technology supply chain, the message is that cybersecurity isn’t simply optional, nor is it simply an IT issue. It is now a board-level priority with legal and financial consequences attached.

While some organisations, especially larger providers, may already have mature systems in place, many will find that aligning with the new expectations demands more than just a policy refresh. Compliance will mean revisiting internal processes, investing in tools and training, and developing the ability to respond quickly and transparently to incidents. Smaller IT firms, regional MSPs, and niche datacentre operators, who may not have considered themselves part of critical national infrastructure until now, are likely to face the steepest learning curve.

The government’s aim appears to be to ensure the resilience of the UK’s digital backbone, and it is using both carrot and stick to get there. On one hand, businesses are being offered access to NCSC resources and support frameworks like Cyber Essentials. On the other, they face heavy penalties if they fail to take action when directed. Regulators, too, will be expected to step up, with clearer powers and more tools to enforce consistent, effective oversight across all sectors.

For regulators, IT service providers, and businesses that rely on outsourced digital infrastructure, the implications are far-reaching. In the short term, there may be uncertainty over exactly how these rules will be applied and interpreted, especially as the list of in-scope organisations grows. But in the long term, the bill signals a new era in which resilience and responsiveness are the benchmark for doing business in a connected economy.

The stakes are high but, looking on the positive side, so is the opportunity to build a more secure, digitally confident UK. With attacks becoming more frequent, more sophisticated, and more costly, the government is hoping that strong, enforceable rules are the best way to safeguard both national infrastructure and future economic growth. For those now falling under the scope of this legislation, the clock has started ticking.

Tech News : Google Fined All The Money In The World!

A Russian court has fined Google over two undecillion rubles (a 36-digit figure, i.e. a sum that’s greater than the world’s total GDP) for removing Russia’s state media channels from YouTube.

Two Undecillion Rubles… And Growing! 

As if being initially fined more money than there is in the world isn’t enough, Russian state-owned news agency TASS reports the state’s lawyer in this case, Ivan Morozov, as saying, “This number is growing daily because of penalties incurred due to non-payment.” 

Actually, It Could Be a Limitless Fine 

It’s also been reported that Morozov has said that if the fine is not paid within nine months, it doubles every day after that, and there is no limit on this number!

How and Why? 

The fine originated from Google’s decision to restrict access to several Russian state-affiliated media channels on YouTube, a move the Russian government has interpreted as politically motivated censorship. Google initially began blocking Russian media, including Tsargrad TV and RIA FAN, in 2020. Following the sanctions imposed on Russia in 2014 after its annexation of Crimea, Google faced mounting pressure to comply with Western sanction policies, which restricted content from entities associated with individuals or organisations under these sanctions.

Escalation 

The situation escalated dramatically after February 2022, when Google expanded its restrictions, this time blocking prominent Russian state channels like RT, Sputnik, NTV, and Russia 24. This expanded set of bans came in the wake of Russia’s invasion of Ukraine and was largely in line with sanctions imposed by Western governments on Russian state-controlled media. Google argued that these removals were consistent with both sanctions and YouTube’s own content policies.

The Legal Battle That Followed 

In response to these actions, Russian media channels filed lawsuits against Google in Russian courts, demanding reinstatement on YouTube and hefty fines for Google’s continued defiance. Perhaps not surprisingly, the Moscow Arbitration Court ruled in favour of the plaintiffs (the Russian state) and ordered Google to restore the channels. This led to a ruling where Google would face progressively severe fines until it complied with the court order.

These fines were set to increase exponentially, with an initial penalty of 100,000 rubles (£794) per day. When Google failed to reinstate the channels, the daily fines began to double at a rapid pace. By September 2023, reports indicated the total fine had surged to 13 decillion rubles (33 zeros) – the equivalent of £103.2 nonillion – and by October, it had reached the unprecedented two undecillion mark.

Google’s Response – Bankruptcy in Russia and International Legal Measures 

Facing these overwhelming financial demands, Google’s Russian subsidiary, Google LLC, declared bankruptcy in June 2022. According to company representatives, the subsidiary’s debts had exceeded 19 billion rubles, while its assets were estimated to be only 3.5 billion rubles. Google’s bankruptcy declaration marked the company’s official exit from Russia, yet the fine continued to grow, as Google’s decision to pull out did not halt the penalties.

To limit further exposure, Google has launched defensive legal actions in other jurisdictions, filing cases in US and UK courts against Russian state channels RT, Tsargrad, and Spas. Through these cases, Google is seeking rulings to prevent these media channels from initiating similar lawsuits outside Russia. Google’s reasoning is that Russian court decisions should not carry legal weight internationally, especially when they pertain to companies acting in compliance with sanctions on state-owned media.

Trying to Seize Google’s Assets 

However, it seems that Russia has attempted to pursue Google’s assets outside its borders in a bid to actually enforce its court rulings. In June 2023, the High Court of South Africa granted Russian authorities permission to seize Google’s assets within South Africa after the company did not comply with a Moscow court order to restore Spas’s YouTube account. This ruling marked one of the few instances where a Russian court decision was enforced internationally, though the scale of assets seized was minuscule compared to the multi-undecillion fine imposed in Moscow.

While seizing assets within Russian territory might once have been feasible, Google’s withdrawal from the country has made enforcement nearly impossible. However, Russian authorities have continued trying to explore asset seizure in other regions, including Turkey, Hungary, and Spain, though these international pursuits have yet to yield substantial recoveries.

The Consequences for Google 

While the fine’s actual collection is, as you may expect from the ludicrously large figure, almost impossible, the political pressure from Russia could create a long-lasting effect on Google’s operations and reputation. The enormous fine highlights Russia’s determination to exercise control over foreign tech companies operating within its jurisdiction and represents a broader, international standoff over information control.

Could It Set a Precedent for Other States? 

In fact, although the level of the fine may sound ridiculous, Russia’s approach could set a precedent for other states with similar grievances to pursue legal action against tech giants, especially where national sovereignty and content censorship intersect. Tech companies like Google, with operations in politically diverse regions, therefore face the complex challenge of balancing platform neutrality with compliance with local legal and political pressures.

What Has Google Said About It All? 

Google has responded to Russia’s escalating fines with a mix of official statements and legal actions, designed to illustrate its stance on the matter without directly engaging with the colossal monetary demands. For example, in its Q2 2024 report, Google’s parent company, Alphabet, briefly acknowledged the ongoing disputes with Russian authorities, noting:

“Google has ongoing legal matters related to Russia. For example, some of the disputes involve account closures, including for sanctioned individuals. The company has also been assessed progressive fines in connection with account suspension disputes, including for sanctioned individuals. We do not believe these legal matters will have a material adverse effect on Google’s business.” 

This statement suggests that Google views the legal claims and fines as largely unenforceable outside Russia and unlikely to impact its core financial operations globally. Google has consistently argued that its actions (e.g. blocking channels tied to Russian state media) are in line with Western sanctions and YouTube’s policies against disinformation, which it aims to uphold across all regions.

Russia Not the Only One Restricted 

It’s worth noting here that Russia is not the only state that appears to have had its official YouTube channels blocked by Google. Other states that have faced similar restrictions include:

– Iran, where various channels have been blocked due to US sanctions policies affecting Iranian state entities.

– Syria and Sudan, whose channels were blocked due to content critical of the government or politically sensitive material during conflicts.

– South Korea. Google has restricted thousands of pieces of content at the South Korean government’s request, i.e. restricting material that has criticised the government there.

What Does This Mean for Your Business? 

The dispute between Google and Russia highlights the increasingly complex terrain that global tech giants face in balancing platform policies with the demands of local authorities. For Google, the sheer scale of the fine (two undecillion rubles and rising!) represents more than just a financial threat. In fact, it appears to highlight the lengths to which some governments are willing to go to enforce compliance from international companies, particularly in the realm of media and information control. Although Google’s exit from Russia has effectively rendered asset seizure within the country impossible, Russia’s ongoing attempts to pursue Google’s assets globally may serve as a warning to other companies operating in volatile geopolitical environments.

This case may set a new precedent, not only for Russia but for other governments seeking to impose their own rules on tech companies that manage information flows across borders. With YouTube’s global reach and influence, the stakes are high, as Russia’s actions signal a challenge to the control tech companies wield over content in international spaces. For other states observing this case, Russia’s persistence could inspire similar approaches, especially where media content is tightly regulated or where governments view certain narratives as critical to their sovereignty. Google’s stance that compliance with Western sanctions justifies its content decisions will, therefore, likely be tested further, particularly as other governments seek ways to enforce their authority over powerful global platforms.

Ultimately, this saga reflects the tension between state sovereignty and the global nature of digital information. As Google continues its legal battles to contain Russia’s claims within Russian borders, the case raises questions about the future of global digital governance. For now, Google’s strategy of defending its policies within Western legal frameworks suggests a focus on protecting its broader operations rather than bending to state-specific demands. However, as technology giants grapple with a patchwork of international laws and political expectations, the question remains – how sustainable is it for global platforms to uphold uniform policies in a world increasingly divided by political and cultural boundaries?

Tech News : Hacked MSP Fined £6m (Provisionally)

A provisional £6m fine has been imposed on an NHS software provider Advanced Computer Software Group following a 2022 data breach that affected more than 80,000 people.

Advanced Software Group 

Founded in 2008, Advanced Computer Software Group, often referred to as “Advanced,” is a UK-based software and IT services company that provides a range of digital solutions primarily to the public sector, healthcare, and private sector organisations. As an IT and software services provider to organisations including the NHS and other healthcare providers, in the eyes of the law, it handles people’s personal information on behalf of these organisations as their ‘data processor’.

What Happened? 

In 2022, hackers accessed a number of Advanced’s health and care systems via a customer account that did not have multi-factor authentication. The personal information belonging to 82,946 people was stolen following the attack. This information included phone numbers and the medical records, as well as details of how to gain entry to the homes of 890 people who were receiving care at home.

Serious Failings 

John Edwards, UK Information Commissioner, has highlighted how the ICO, which has investigated the incident, provisionally found “serious failings” in Advanced’s “approach to information security prior to this incident”. Mr Edwards noted how Advanced “failed to keep its healthcare systems secure” when it should have been taking steps to secure its systems, such as “regularly checking for vulnerabilities, implementing multi-factor authentication and keeping systems up to date with the latest security patches.” 

The Obligations of Data Processors 

In his online statement, Mr Edwards noted that although data processors act on the instructions of their clients, the data controllers, data processors, such as Advanced, “still have their own obligations to implement appropriate technical and organisational measures to ensure personal information is kept secure” and this includes “taking steps to assess and mitigate risks”. 

Health Service Disruption Also Caused 

In his online statement, Mr Edwards also noted that in addition to the theft of personal information, the hack caused disruption to some health services, i.e. disrupting their ability to deliver patient care. Mr Edwards said this meant that “a sector already under pressure was put under further strain due to this incident”. 

Provisional Fine 

The ICO has stated that on the grounds that Advanced failed to implement measures to protect the personal (and some sensitive) information of the 80,000+ people, it has “provisionally decided” to impose a £6.09m fine on Advanced.

However, despite choosing to issue the statement about it, the ICO’s findings and fine are “provisional”. This means that conclusions shouldn’t be drawn at this stage about whether there’s actually been any breach of data protection law or that a financial penalty will ultimately be imposed.

The Commissioner says that any representations from Advanced will now be carefully considered before any final decision is made “with the fine amount also subject to change.” 

Illustrates The Importance of Prioritising Information Security 

UK Information Commissioner, said in his statement about the provisional fine: “This incident shows just how important it is to prioritise information security. Losing control of sensitive personal information will have been distressing for people who had no choice but to put their trust in health and care organisations.” 

What Does This Mean For Your Business? 

The provisional £6 million fine imposed on Advanced Computer Software Group serves as a stark reminder of the critical importance of businesses and organisations prioritising information security. This incident highlights how even well-established companies with significant responsibilities (such as handling sensitive healthcare data) are not immune to severe consequences when security measures are insufficient. The breach at Advanced not only compromised the personal and medical information of over 80,000 individuals but also disrupted essential health services, demonstrating the far-reaching impact of inadequate data protection.

For your business, this underscores the need to rigorously assess and enhance your cybersecurity practices, particularly if you are a data processor or handle sensitive information on behalf of clients. The ICO’s findings point to specific failings, such as the lack of multi-factor authentication and the failure to regularly update systems, which could have prevented the breach. Implementing robust security protocols, including regular vulnerability assessments, system updates, and comprehensive risk mitigation strategies, is not just a legal obligation but a business imperative.

Also, the incident shows how the failure to prioritise information security can lead to significant financial and reputational damage. While the ICO’s decision and fine are currently provisional, the potential for such penalties should serve as a wake-up call for businesses and organisations to take proactive steps in safeguarding personal data. As the Information Commissioner noted, this case demonstrates the distress caused to individuals who trust organisations with their sensitive information, making it clear that maintaining this trust should be a top priority.

Tech News : Amazon Fined Over “Dark Patterns”

Amazon’s (Luxembourg-based) Polish e-commerce site, Amazon.pl (Amazon EU SARL) has been fined by Poland’s competition and consumer protection watchdog following customer complaints that their orders were being mysteriously cancelled.

Massive Fine 

Following an investigation about the complaints, the President of Poland’s UOKiK consumer protection watchdog found Amazon EU SARL guilty of infringement of collective consumer interests and imposed a fine of more than 31 million zlotys / £6,342,000.

What Happened? 

In short, the Polish watchdog found that customers shopping on Amazon’s Polish website had clicked on the “Buy Now” and “Proceed to Checkout” options (paying for products such as popular e-book readers), assuming that this constituted a sale, and then waited for delivery. However, the delivery didn’t happen due to Amazon repeatedly cancelling the orders because it allegedly thought the sales contract and delivery obligations to the customer were only active after an item has been shipped, rather than when the customer purchases it.

The complaints from disappointed customers who had been waiting for cancelled orders then led to the investigation, ultimately resulting in Amazon within Poland being fined.

Reasons 

The President of Poland’s Office of Competition and Consumer Protection (UOKiK) imposed the 31 million zloty fine on Amazon EU SARL for reasons related to infringing collective consumer interests, which were:

– Misleading sales and delivery practices. Amazon’s Polish website was deemed to have misled consumers about the timing of sales contract conclusions, product availability, delivery times, and consumer rights. For example, with regards to Amazon offering “Guaranteed Delivery” (i.e. the product should reach the consumer within a certain period of time), if this doesn’t happen, the consumer can request a refund of the delivery fee. However, it was found in the case of Amazon Poland that consumers didn’t receive information about the rules of this service before placing an order – the information was only made available at the order summary stage (if the consumer had decided to go through several steps defining the delivery details). This meant that if they hadn’t, they wouldn’t have been aware of their rights and may not have requested a refund or received it (when shipping was delayed). Also, information about the “Guaranteed Delivery” was found not to have been included within the order confirmations customers received.

– “Dark pattern” design tricks. This refers to Amazon being judged to have used deceptive design elements that could inject a false sense of urgency into the purchasing process, misleading shoppers about elements like product availability and delivery dates. As outlined by UOKiK’s  President, Tomasz Chróstny,  “Information about the availability of a product and its fast shipping is very valuable for consumers and for many people it can be the main reason why they make a purchase decision. However, such information must not be a decoy. If a trader gives a specific delivery date, they must meet it. This practice by Amazon is categorised as ‘dark patterns,’ as it uses pressure to make the consumer order the product as soon as possible.” 

– Cancellation of customers’ orders after payment. The practice of Amazon treating orders as non-binding until the shipment/delivery was confirmed, allowing the company to cancel them even after consumers had paid was found to be misleading as consumers believed they were concluding a sales contract upon payment.

– A lack of clarity in communication. Information crucial to understanding Amazon’s sales contract and delivery guarantee terms were found not to have been made easily accessible to consumers, and to (often) have been presented in a way that was hard to find or read (such as using a grey font on a white background, at the bottom of the page).

– The use of deceptive countdown clocks. Amazon also faces criticism in this case for having displayed countdown timers and stock availability claims that suggested imminent deadlines for order placement or implied limited product availability, without guaranteeing timely delivery.

Amazon’s practices in this case were therefore deemed to potentially mislead customers as regards the nature of their transactions on the platform, affecting their consumer rights and trust.

What Does Amazon Say? 

In its defence, Amazon Poland highlighted how it prioritises fast and reliable delivery across a wide selection of products and that Amazon.pl offers millions of items with fast and free Prime delivery. Amazon also emphasised its continuous investment and effort to provide customers with a clear and reliable delivery promise at checkout. However, it acknowledged that while most of their deliveries arrive on time, they are committed to rectifying situations promptly whenever delays or order cancellations occur.

Amazon also mentioned its collaboration with the UOKiK, proposing multiple voluntary amendments to further improve the customer experience on Amazon.pl, but stated that it strongly disagreed with the UOKiK’s assessment and penalty. Amazon also says it intends to appeal the decision.

What Does This Mean For Your Business? 

This story illustrates how any practices that could mislead customers regarding the nature of their online transactions (thereby affecting their consumer rights and trust) can lead to some painful consequences for retailers.

Although Amazon doesn’t agree with the decision and plans to appeal, the accusation and details of “dark patterns” outlined by the UOKiK in this case could be potentially quite damaging for Amazon’s reputation and could lead to them being scrutinised even more closely in the future.

While being potentially beneficial for Amazon in terms of operational flexibility, sales, and competitive positioning, the practices outlined by the UOKiK clearly backfired in a spectacularly expensive way for Amazon with a £6,342,000 fine which may be powerful enough to make Amazon more careful in future.

This case also underscores the critical importance of transparency and honesty in online retail operations. Businesses, large and small, must recognise that the digital consumer experience is not just a pathway to transactions but can have an effect on brand reputation and customer loyalty. The regulatory action taken against Amazon by Poland’s UOKiK should, therefore, serve as a potent reminder that misleading practices (intentional or not) can have severe legal and financial repercussions. It highlights the necessity for all e-commerce entities to meticulously review and possibly revamp their online sales practices, ensuring they are not only legally compliant but also aligned with ethical standards that prioritise consumer rights and transparency.