Norwich Union Life

What

  • Disclosure of personal information to fraudsters.
  • Fraudulent policy surrender

How much

  • 632 records
  • 74 records

Why

Telephone based fraudsters used publically available information (name, DoB etc) to impersonate customers and gain access to accounts.

Regulator

FSA

Regulatory action

Monetary penalty – £1,260,000

Reason for action

Aware of threat but took inadequate countermeasures except in case of Aviva group directors.

When

17 December 2007

Links

View the press release relating to Norwich Union Life on the FSA website

View PDF of the Norwich Union Life Final Notice (via FSA website)

View PDF of the Norwich Union Life Final Notice (Breachwatch archive)

The Department of Health

What
Inappropriate processing of personal data

How much
Unknown.

Why
The personal details of junior doctors held on the Medical Training Application Service (MTAS) website was readily accessible to any person accessing the website.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that sensitive personal data held on the website must be encrypted. Instructions and advice as to the use of passwords and PIN numbers be given to the data controller to those entitled to access the site. Staff will be given appropriate training and regular penetration and vulnerability testing of developing applications and systems to minimise unauthorised access.

Reason for action
The ICO had received a complaint about the data controller’s breach of the Seventh Data Protection Principle.

When
4 December 2007

Links
View PDF of the Department of Health Undertaking (Breach Watch Archive)