Advertisement

We need your help now

Support from readers like you keeps The Journal open.

You are visiting us because we have something you value. Independent, unbiased news that tells the truth. Advertising revenue goes some way to support our mission, but this year it has not been enough.

If you've seen value in our reporting, please contribute what you can, so we can continue to produce accurate and meaningful journalism. For everyone who needs it.

SIPA USA/PA Images

Data Protection Commissioner concludes investigation into Yahoo over massive data breach

500 million people were affected by the breach.

THE DATA PROTECTION Commission has finished its investigation of a huge data breach by Yahoo.

The data breach was initially notified to the DPC on 22 September 2016 and the DPC began an investigation into what happened as Yahoo! EMEA Limited (Yahoo – since renamed Oath (EMEA) Limited) was a data controller.

The data breach ranks as one of the largest breaches to impact EU citizens, and affected approximately 39 million European users. It is the largest breach which has ever been notified to and investigated by the DPC.

The DPC has now established that the breach dated back to 2014. It said that a separate breach dating back to 2013 was not investigated by the DPC because, at the time the breach occurred, Yahoo was not a data controller within the meaning of the Data Protection Acts 1988 and 2003 and therefore Yahoo was not subject to the jurisdiction of the DPC.

Its investigation focused mainly on assessing the technical security and organisational measures Yahoo had in place at the time of the data breach. It also analysed Yahoo’s response to the data breach.

The investigation assessed whether there were potential areas in which Yahoo could improve its protection of individuals’ data protection rights.

The breach was reported to the DPC in September 2016 and involved the unauthorised copying and taking, by one or more third parties, of material contained in approximately 500 million user accounts from Yahoo! Inc infrastructure in 2014.

At the time, Yahoo EMEA was the data controller for the subset of the affected user accounts associated with EU citizens, with Yahoo Inc acting as its data processor.

The DPC found:

  • Yahoo’s oversight of the data processing operations performed by its data processor did not meet the standard required by EU data protection law and as given effect or further effect in Irish law
  • Yahoo relied on global policies which defined the appropriate technical security and organisational measures implemented by Yahoo. Those policies did not adequately take into account Yahoo’s obligations under data protection law
  • Yahoo did not take sufficient reasonable steps to ensure that the data processor it engaged complied with appropriate technical security and organisational measures as required by data protection law.

The DPC has now notified Yahoo that it requires it to take specified and mandatory actions within defined time periods. It says it will be closely supervising Yahoo’s timely compliance with these actions.

The actions include that Yahoo should ensure that all data protection policies which it uses and implements take account of the applicable data protection law, and that such policies are reviewed and updated at defined regular intervals.

The DPC has directed Yahoo to update its data processing contracts and procedures associated with such contracts to comply with data protection law.

It has also directed the company to monitor any data processors which it engages for compliance with data protection law on an ongoing basis.

The DPC says it will be engaging closely with Yahoo to monitor the implementation of these actions and if necessary will issue enforcement notices to secure compliance. It will also continue to actively monitor Oath EMEA’s ongoing data processing operations to ensure those operations comply with the new legal framework of the General Data Protection Regulation.

Readers like you are keeping these stories free for everyone...
A mix of advertising and supporting contributions helps keep paywalls away from valuable information like this article. Over 5,000 readers like you have already stepped up and support us with a monthly payment or a once-off donation.

Close
8 Comments
This is YOUR comments community. Stay civil, stay constructive, stay on topic. Please familiarise yourself with our comments policy here before taking part.
Leave a Comment
    Install the app to use these features.
    Mute mojitio joe
    Favourite mojitio joe
    Report
    Oct 27th 2011, 7:20 AM

    Eh McGuinness can’t vote….

    54
    Install the app to use these features.
    Mute Torpedo
    Favourite Torpedo
    Report
    Oct 27th 2011, 7:47 AM

    He knows he’s not going to win so why bother go down and vote. He is probably not planing another bank robbery with people he doesn’t know

    29
    Install the app to use these features.
    Mute conoraleckelly
    Favourite conoraleckelly
    Report
    Oct 27th 2011, 8:35 AM

    He is giving the other 6 a head start out of the goodness of his heart. That’s why he is not voting.

    14
    Install the app to use these features.
    Mute Tony Fitzpatrick
    Favourite Tony Fitzpatrick
    Report
    Oct 27th 2011, 10:19 AM

    I am so dissapointed that the standard of our presidential candidates is so low !!!!! is that what we have become ??? Where is the Statesman or woman in that lot !!!!! Martin McGuinness ???? HOW COULD THE COUNTRY EVEN CONSIDER HIM AS PRESIDENT. Sean Gallagher !!! please , who does he think he is ??? a half baked go between for shady people………. and the rest, well harmless and hopeless. Our country has lost its way for sure.

    12
    Install the app to use these features.
    Mute Paul Houston
    Favourite Paul Houston
    Report
    Oct 27th 2011, 1:36 PM

    MMG is not voting because he doesn’t have a vote. Like many 10′s of thousands of Irish citizens who live in the 6 counties we don’t have a vote. Ironically we can stand though !

    Hopefully the forthcoming constitutional convention will right this wrong.

    10
    Install the app to use these features.
    Mute Torpedo
    Favourite Torpedo
    Report
    Oct 27th 2011, 1:49 PM

    Yes that true it is wrong that you can stand to be the Irish President if your from a DIFFERENT COUNTRY. Hopefully that will be sorted soon.

    5
    Install the app to use these features.
    Mute Deirdre Farrelly
    Favourite Deirdre Farrelly
    Report
    Oct 27th 2011, 8:11 AM

    Thought there was a moretoreum till voting closes tonight

    7
    Install the app to use these features.
    Mute Michael Hegarty
    Favourite Michael Hegarty
    Report
    Oct 27th 2011, 10:33 AM

    only applies to “mandate broadcasting”…..ie Special Mary talking about her integrity and all that shite!!!

    7
    Install the app to use these features.
    Mute The Baxter
    Favourite The Baxter
    Report
    Oct 27th 2011, 12:07 PM

    df you think to much

    1
    Install the app to use these features.
    Mute avril dunne
    Favourite avril dunne
    Report
    Oct 28th 2011, 3:21 AM

    Or not!

    2
    Install the app to use these features.
    Mute Lou Brennan
    Favourite Lou Brennan
    Report
    Oct 27th 2011, 9:33 AM

    I reckon they’ll all be in the toilet.

    1
Submit a report
Please help us understand how this comment violates our community guidelines.
Thank you for the feedback
Your feedback has been sent to our team for review.

Leave a commentcancel

 
JournalTv
News in 60 seconds