Notice
ODPA sanctions Fresh Dental for phishing attack breach (2025-12-11)
Issued 2025-12-11View on ODPA's website Source document
Summary
This is a public enforcement notice from the Guernsey Office of the Data Protection Authority (ODPA) detailing sanctions against Fresh Dental, a dental practice, following a personal data breach caused by a phishing attack on a staff email account in October 2024. The Authority found Fresh Dental in breach of the Data Protection (Bailiwick of Guernsey) Law, 2017, for inadequate security measures and for lacking a legally binding data processing agreement with its IT provider.
- Findings against Fresh Dental: No legally binding agreement was in place with its IT processor (its IT provider), and it failed to take reasonable steps to ensure an appropriate level of security for the personal data it processed.
- Contributing failings: Lack of appropriate cyber security staff training, no penetration testing prior to the breach, and an inadequate internal breach investigation with insufficient records.
- Enforcement order requirements: Fresh Dental must implement technical and organisational measures to reduce phishing risk, undertake a penetration test of its systems, and put in place a legally binding processing agreement with its IT provider.
The notice also restates general obligations under the Law applicable to all controllers and processors: written agreements must be in place before sharing personal data with processors, and reasonable security measures must be maintained proportionate to the sensitivity of data processed, particularly special category data such as health records. The Authority emphasises that outsourcing processing does not transfer responsibility for protecting personal data, and that data protection obligations continue after a breach occurs.
Key obligations
- Fresh Dental must implement technical and organisational measures to reduce the risk of phishing attacks and similar threats
- Fresh Dental must undertake a penetration test of its systems to ensure they are appropriately secure
- Fresh Dental must implement a legally binding written agreement with its IT provider addressing the processing of personal data
- Controllers generally must have a legally binding written agreement in place with processors before sharing personal data, as required by the Law
- Controllers and processors generally must take reasonable steps to ensure a level of security appropriate to the personal data being processed
Applies to
data controllers, data processors, dental practices, organisations processing special category (health) data