Advertisement
Promo

Security threats Toolkit

HSBC companies fined £3m over data breaches

Jo Best silicon.com

Published: 23 Jul 2009 09:11 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Three HSBC companies have been hit with fines after the financial services watchdog found they were not doing enough to protect customers' data.

The Financial Services Authority (FSA) fined HSBC Life £1,610,000, HSBC Actuaries £875,000 and HSBC Insurance Brokers £700,000 — making a total of £3m in penalties between them.

Due to the fact the three firms settled with the FSA, their fines were discounted by 30 percent — the original charges totalled £4.55m.

The FSA handed down the fines after an investigation found customer data was sent without encryption to third parties and via couriers, and left in unlocked cabinets and shelves openly.

Staff were also not given proper training over how to spot and deal with risks like identity theft, the FSA found.

Clive Bannister, group managing director of HSBC Insurance, said the company regrets falling short in dealing with customers' data.

"While this is a serious matter, no customer reported any loss from these failures and we are doing everything possible to prevent a recurrence. We have implemented even more rigorous systems, better checks and more training for our people. We believe our customers can have confidence that we are doing everything we can to protect their privacy," he said in a statement.

Two of the HSBC companies recorded losses of data: in 2007, HSBC Actuaries lost an unencrypted floppy disk in the post, containing the details of 1,917 pension-scheme members, including addresses, dates of birth and national insurance numbers; while 2008 saw HSBC Life lose an unencrypted CD containing the details of 180,000 policy holders in the post. Those affected have been alerted to the losses by the companies.

Margaret Cole, director of enforcement at the FSA, described the losses as "disappointing".

"All three firms failed their customers by being careless with personal details which could have ended up in the hands of criminals. It is also worrying that increasing awareness around the importance of keeping personal information safe and the dangers of fraud did not prompt the firms to do more to protect their customers' details," she said in a statement.

The three companies have now improved staff training and use encryption when data is being moved.

Credit: HSBC companies slapped with £3m fines over data breaches from silicon.com

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
1 out of 1 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment

Campaigners criticise '£10bn NHS IT ov...

The National Health Service's flagship IT project has been criticised by a tax campaign group for running billions of pounds over budget. The NHS National Programme for IT (NPfIT)... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters