Notice
Determination - ODPA sanctions Fresh Dental for phishing attack breach (2025-12-11)
Issued 2025-12-11View on ODPA's website Source document
Summary
This is a formal Breach Determination Notice and enforcement order issued by Guernsey's Office of the Data Protection Authority (ODPA) against Fresh Dental following a phishing attack that compromised a staff Microsoft 365 account and led to a personal data breach. The Authority found Fresh Dental breached section 34 (duties of controllers in relation to processors) and section 41 (duty to take reasonable steps to ensure security) of the Data Protection (Bailiwick of Guernsey) Law, 2017, and has imposed a formal enforcement order under section 73 requiring specific remedial actions within set timeframes.
- Section 34 breach: Fresh Dental had no legally binding processing agreement with its IT provider (a processor) despite an eight-year relationship, contrary to its own stated policies.
- Section 41 breach: Fresh Dental failed to implement adequate technical and organisational security measures given it processes special category health data, including insufficient employee cyber security training, inadequate phishing detection measures, and limited penetration testing scope.
- Investigation failures: Fresh Dental retained insufficient records of its breach investigation, could not demonstrate root-cause analysis, and did not follow its own incident response plan.
- Enforcement order terms: The Authority ordered Fresh Dental to implement security measures for Microsoft 365 and related systems, put in place a compliant processor agreement with its IT provider, undertake penetration testing, act on reasonable recommendations, and retain related records for six years.
While this determination is specific to Fresh Dental, it signals ODPA's expectations for all controllers and processors handling personal data, particularly special category data, regarding processor contracts, phishing resilience, staff training, penetration testing, and breach investigation record-keeping.
Key obligations
- Fresh Dental must implement reasonable and appropriate technical and organisational measures for its Microsoft 365 accounts and related systems to prevent, detect, investigate, and remediate unauthorised access, within 3 months of the section 73 notice.
- Fresh Dental must implement training for all relevant staff on cyber security risks, including identifying phishing attacks, as part of the required security measures within 3 months.
- Fresh Dental must implement a legally binding processing agreement with its current or an alternative IT provider addressing personal data processing, within 3 months.
- Fresh Dental must provide written confirmation to the Authority within 3 months that terms 1 and 2 have been complied with, including a written overview of measures implemented.
- Fresh Dental must undertake a penetration test of its computer systems, including at minimum the authentication security of its Microsoft 365 tenant, within 6 months, and provide a written overview of results to the Authority within the same period.
- Within 9 months, Fresh Dental must consider all penetration test recommendations, implement those determined reasonable under section 41, and provide written confirmation of implementation to the Authority.
- Any records created as a result of the enforcement order must be retained for a minimum of six years and provided to the Authority upon request.
Applies to
data controllers, data processors, Fresh Dental (dental practice controller processing special category health data)
Deadlines
- 3 months from issuance of notice under section 73: Fresh Dental must implement required security measures and a compliant processor agreement, and provide written confirmation of compliance to the Authority.
- 6 months from issuance of enforcement order under section 73: Fresh Dental must undertake a penetration test of its computer systems and provide a written overview of results to the Authority.
- 9 months from issuance of enforcement order under section 73: Fresh Dental must implement reasonable recommendations from the penetration test and confirm implementation in writing to the Authority.
- minimum of six years: Records created as a result of the enforcement order must be retained and made available to the Authority upon request.