Illegal Ads, Hacked Sites: You're Still Liable
— Law, Business & Power Correspondent, News Beast --- Scottish Borders Council didn't buy the ads.
By Harvey Specter Jr. — Law, Business & Power Correspondent, News Beast
---
Scottish Borders Council didn't buy the ads. Didn't approve them. Didn't know they were there. An outdated backlog system — some forgotten corner of their web infrastructure — got exploited, and for a period that nobody can quite agree on, their official government website was serving illegal gambling advertisements to the public. The BBC reported it. The Council apologised. And then everyone moved on, because that's what institutions do when the embarrassment is technical rather than intentional.
Here's what nobody explained: the apology doesn't close the legal exposure. The "we didn't know" defence is one of the most misunderstood concepts in European regulatory law, and the organisations that rely on it most are usually the ones that end up paying the most when it fails.
Under the General Data Protection Regulation — the full name is Regulation (EU) 2016/679 — data controllers are responsible for what happens on their systems regardless of how it happened. Under the UK Gambling Act 2005 and the relevant CAP/BCAP codes that govern advertising standards, a website owner is the publisher of what appears on their pages. The intent behind how it got there is a mitigating factor. It is not a defence. There is a significant difference between those two things, and the distance between them is measured in regulatory fines.
The Scottish Borders Council case is one story. But the real story is the pattern it represents, and that pattern reaches directly into Maltese law, into every business operating a website, and into every organisation — public or private — that has digital infrastructure they haven't audited recently.
I spent years before I picked up a law book watching people get into trouble not because they did something wrong, but because they failed to do something right. The law doesn't grade on effort. It grades on outcome. A landlord who "didn't know" the flat had an unsafe gas installation is still liable when the tenant is harmed. A business that "didn't know" its website plugin was collecting user data beyond consent is still in breach of GDPR. And a public authority that "didn't know" its website was displaying illegal advertising content is still the publisher of that content until proven otherwise.
In Malta, this sits at the intersection of the Data Protection Act (Chapter 586 of the Laws of Malta) — which mirrors the GDPR framework — and the Broadcasting Act, as well as MGA enforcement jurisdiction where gambling advertising is involved. The Malta Gaming Authority's advertising guidelines are explicit: operators and platforms serving Maltese audiences must comply with responsible advertising standards, and the accountability chain does not terminate just because the technical failure was three vendors removed from the decision-maker.
The Candle Lake situation with Evolution Gaming tells a parallel story from a corporate governance angle. Evolution's board moved immediately to recommend shareholders reject the takeover offer. That speed is not instinct — it's legal strategy. When a mandatory offer lands, the board's fiduciary duty crystallises into a very narrow window of action. Move fast, document the reasoning, protect the recommendation with independent valuation evidence, and get it in front of shareholders before the offer narrative takes hold. The boards that lose these fights are the ones that hesitate, because hesitation looks like ambivalence, and ambivalence looks like the offer might be reasonable after all.
The common thread across both stories — a hacked council website and a hostile takeover recommendation — is the same principle: the organisation that controls the narrative controls the outcome, but only if it moves before the story moves without it. Legal exposure doesn't wait for you to finish your internal review. It accumulates while you're reviewing.
The "we didn't know" defence, properly constructed, sounds like this: documented evidence of reasonable technical safeguards, a demonstrable audit trail showing when the breach occurred and when it was identified, immediate remediation steps recorded in writing, proactive disclosure to the relevant authority before they come to you, and a remediation plan that addresses the root cause rather than the symptom. That's not a defence — that's mitigation. And mitigation is what keeps a regulatory investigation from becoming a regulatory fine.
The organisations that get this wrong are the ones that treat the discovery of a problem as the beginning of a crisis. The ones that get it right treat the discovery as the beginning of a solution — and they document every step of that solution with the understanding that the documentation is itself a legal instrument.
A pro b