The case of TalkTalk v ICO UK: Service Providers must comply with the 24 hour notification rule when a customer provides detailed complaint of a personal data breach On August 30, 2016, the Information Rights Tribunal (the "Tribunal") dismissed an appeal from TalkTalk Telecom Group Plc ("TalkTalk") challenging a £1,000 monetary penalty which had been imposed on the company by the ICO for a delay in issuing a personal breach notification back in in March 2016. Whilst a small amount of money, at stake was an important principle as to the point at which the time limits for notification of a security breach commence. The Tribunal held that the ICO did have legal basis for imposing the monetary penalty notice.  TalkTalk should have notified the data breach within 24 hours after the detection of the breach, and it was feasible for the company to have done so. Whilst this specific to the … Continue Reading ››