Security and Encryption Solutions Development Company

Three companies of the world banking giant HSBC have been fined nearly ₤3.2 m for failing to ensure proper protection of their customers’ personal data.

open safe

The Federal Services Authority (the FSA) reported repeated cases of HSBC’s sending “large amounts“ of unencrypted confidential customer data by post or courier with some information left on open shelves or in unlocked cabinets. The FSA qualified keeping and transmitting data on unencrypted media as a careless treatment of personal information of customers and absence of a due identity protection system.

As the FSA reports, the first case (April 2007) involved a lost floppy disk with unencrypted personal data of 1,917 pension scheme members including their addresses, dates of birth and national insurance numbers. The second case was a lost CD that contained personal details of 180,000 policyholders. In both instances the confidential data were found stored on unencrypted media.

The three companies immediately responded to the raised concern, expressed their strong regret of the case and promised to take all the necessary corrective and preventive actions to tackle the issue. Although HSBC stated there had been no complaints coming from the customers associated with losses due to this failure, the FSA believes this could have brought out much more adverse consequences if the information got into the wrong hands.

The FSA describes such cases as a disturbing lack of the companies’ awareness of the importance to ensure adequate safekeeping and protection of personal information. This case is illustrative of the necessity to assure information security not only at the level of human responsibility but also at that of technology.


World News

November 15, 2009 - NHS Trust patient records repeatedly exposed over the last month
Several patient data theft cases were brought to the attention of the Information Commissioner’s Office (ICO) over the last month. Those involved eight desktop computers and four laptops containing sensitive patient details stolen from different hospitals. In most cases, the computer equipment was neither protected with any of encryption means, nor kept physically secure in locked premises, thus, carelessly exposing patients’ mental and physical health details to the risk of unauthorized access or theft.
September 16, 2009 - Border search of laptops is challenged by ACLU
The American Civil Liberties Union has brought a legal action against unjustified confiscation and searches of corporate laptops by border police. The objective of the lawsuit is to provide the ACLU with the records of faultless searches and checks of travelers’ laptops executed by the US customs.
August 28, 2009 - Global banking giant fined for losing personal customer data
Three companies of the world banking giant HSBC have been fined nearly ₤3.2 m for failing to ensure proper protection of their customers’ personal data.
August 28, 2009 - Cost of a Lost Corporate Laptop
An independent research conducted by the request of the Intel company on 22 April 2009 revealed the degree of financial damage associated with a loss of a corporate laptop.
Russian