United National Bank Limited

What
Loss of personal data

How much
A number of records.

Why
Items of personal information were recovered from refuse bins used by the Manchester branch of the data controller, including a copy of a fax showing business and personal account details, a remittance form, a copy of an internal email and other miscellaneous paperwork.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that clear policies and procedures are in place to cover the disposal of waste containing personal information. Adequate and relevant data protection training must be given to all staff.

Reason for action
The ICO had received a complaint about the data controller’s breach of the Seventh Data Protection Principle.

When
13 February 2007

Links
View PDF of the United National Bank Limited Undertaking (Breach Watch Archive)

Immigration Advisory Service

What
Loss of personal data

How much
A number of records.

Why
Items of personal information relating to a case before the Asylum and Immigration Tribunal were recovered from refuse bins used by the Birmingham office the data controller.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that clear policies and procedures are in place to cover the disposal of waste containing personal information. Adequate and relevant data protection training must be given to all staff. A review of the processing of personal information is to undertaken to ensure that it is carried out in line with the data protection principles.

Reason for action
The ICO had received a complaint about the data controller’s breach of the Seventh Data Protection Principle.

When
9 February 2007

Links
View PDF of the Immigration Advisory Service Undertaking (Breach Watch Archive)

Scarborough Building Society

What
Loss of personal data

How much
A number of records.

Why
Items of personal information were recovered from refuse bins used by the York branch of the data controller, including a customer’s mortgage application form and copies of supporting bank statements, customer account details, standing order details and other miscellaneous paperwork.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that clear policies and procedures are in place to cover the disposal of waste containing personal information. All paper waste generating in branches must be treated as confidential and be shredded. Adequate and relevant data protection training must be given to all staff.

Reason for action
The ICO had received a complaint about the data controller’s breach of the Seventh Data Protection Principle.

When
9 February 2007

Links
View PDF of the Scarborough Building Society (Breach Watch Archive)

Clydesdale Bank plc

What
Loss of personal data

How much
29 records.

Why
A telephone banking form containing a customers name and contact details, six cash deposit bags showing customer names and account numbers, 22 computerised print outs showing direct debits and bank giro credits to customer accounts and other miscellaneous papers were all recovered from refuse bins outside the bank’s Glasgow branch.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that all data protection procedures are updated and strictly adhered to, especially relating to the disposal of confidential waste. Appropriate data protection training must be given to relevant staff.

Reason for action
Policies for secure disposal of confidential waste were insufficient.

When
5 February 2007

Links
View PDF of the Clydesdale Bank plc Undertaking (Breach Watch Archive)

Barclays Bank plc

What
Loss of personal data

How much
6 records.

Why
A Barclaycard was found cut up into four pieces in a refuse bin outside the Park Gate Branch and four cut up debit/visa cards were found along with a deposit envelop in a refuse bin outside the Bristol branch.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that all data protection procedures are updated and strictly adhered to, especially relating to the disposal of confidential waste. Appropriate data protection training must be given to relevant staff and all third parties and sub-contractors comply with the data controller’s data protection principles.

Reason for action
Policies for secure disposal of confidential waste were insufficient.

When
2 February 2007

Links
View PDF of the Barclays Bank PLC Undertaking (Breach Watch Archive)