Please ensure Javascript is enabled for purposes of website accessibility

People

Big things are happening at Ogier. Change is embedded in everything we do. It is redefining our talent, our ways of working, our platforms of delivery, our culture.

Expertise

Services

We have the expertise to handle the most demanding transactions. Our commercial understanding and experience of working with leading financial institutions, professional advisers and regulatory bodies means we add real value to clients’ businesses.

View all services

Business Services Team

View all Business Services Team

Sectors

Our sector approach relies on smart collaboration between teams who have a deep understanding of related businesses and industry dynamics. The specific combination of our highly informed experts helps our clients to see around corners.

View all sectors

Locations

Ogier provides practical advice on BVI, Cayman Islands, Guernsey, Irish, Jersey and Luxembourg law through our global network of offices across the Asian, Caribbean and European timezones. Ogier is the only firm to advise on this unique combination of laws.

News and insights

Keep up to date with industry insights, analysis and reviews. Find out about the work of our expert teams and subscribe to receive our newsletters straight to your inbox.

Fresh thinking, sharper opinion.

About us

We get straight to the point, managing complexity to get to the essentials. Our global network of offices covers every time zone. 

No Content Set
Exception:
Website.Models.ViewModels.Components.General.Banners.BannerComponentVm

New anti-hacking law: first person charged in Ireland

Insight

08 March 2021

4 min read

ON THIS PAGE

The Criminal Justice (Offences Relating to Information Systems) Act 2017 came into force on 12 June 2017, yet David Young is the first person to be charged under the legislation.

He is 28 years old and from Cork. He is charged of committing nine offences. It is important to remember that Mr Young has just been charged at this point so we will need to wait to see if he is prosecuted. 

He was charged by the Garda National Cyber Crime Bureau of: 

  • hacking into a computer parking system in September 2018

  • interrupting the functioning of an information system at the Vodafone Data Centre between May 2018 and September 2018

  • operating a computer with the intention of making a gain for himself and others and causing a loss to others between May 2018 and September 2018

  • making a demand by threatening to release information from 12,000 accounts of ParkMagic Mobile Solutions customers in September 2019

With the ever-increasing numbers of cyber breaches and data breaches, it is to be hoped that we will see more charges brought by the Garda National Cyber Crime Bureau. 

Legislation 

The Criminal Justice (Offences Relating to Information Systems) Act 2017 (the Act) was implemented to give effect to the EU Cybercrime Directive and help prosecute cybercrime by creating specific offences. It was designed to update Irish legislation with respect to such crimes. Previous legislation referred to "unlawful use of a computer" which did not provide adequate address for cybercrime. 

Sections 2 and 3 of the Act provide: 

"2. A person who, without lawful authority or reasonable excuse, intentionally accesses an information system by infringing a security measure shall be guilty of an offence. 

  1. A person who, without lawful authority, intentionally hinders or interrupts the functioning of an information system by—

(a) inputting data on the system, 

(b) transmitting, damaging, deleting, altering or suppressing, or causing the deterioration of, data on the system, or 

(c) rendering data on the system inaccessible, 

shall be guilty of an offence." 

Impact

What is not apparent from first view of the alleged actions of Mr Young are the ramifications of these breaches: 

  • It is not clear whether, in each situation, personal data was accessed or breached

  • If so, were data subjects affected? 

  • If they were, what was the risk to those data subjects? 

  • Were notifications required to the Data Protection Commission and / or data subjects? 

  • Were funds stolen and needed to be traced? 

  • Were funds stolen from third parties? 

  • What costs were incurred by the organisations impacted for legal, PR, IT forensics or otherwise? 

  • Did these organisations face claims for the cyber or data breaches? 

  • Did these organisations have a cause of action against any of its providers with respect to the breaches? 

What is important to remember is that data and cyber breaches can result in a myriad of issues, all of which need to be considered immediately. It is critical that organisations have cyber breach, data breach and disaster recovery protocols and policies in place to follow in such situations. 

Cyber and data breaches are consistently increasing. If an organisation suffers a cyber or data breach, it should notify its cyber insurers immediately if they have cyber insurance. If it does not, it should contact a solicitor with experience of dealing with cyber and data breaches. 

Ogier provides advice with respect to cyber matters including pre-event management, incident response and post event matters. If you have any queries, please get in touch with our Technology and Web3 team.

About Ogier

Ogier is a professional services firm with the knowledge and expertise to handle the most demanding and complex transactions and provide expert, efficient and cost-effective services to all our clients. We regularly win awards for the quality of our client service, our work and our people.

Disclaimer

This client briefing has been prepared for clients and professional associates of Ogier. The information and expressions of opinion which it contains are not intended to be a comprehensive study or to provide legal advice and should not be treated as a substitute for specific advice concerning individual situations.

Regulatory information can be found under Legal Notice

No Content Set
Exception:
Website.Models.ViewModels.Blocks.SiteBlocks.CookiePolicySiteBlockVm