All the latest UK technology news, reviews and analysis

ICO raps Zurich Insurance for data breach

by Sharon Brennan

24 Mar 2010

Comment: 1

  • Tweet this
Security padlock
Zurich Insurance has promised to tighten data security procedures

Zurich Insurance has been found in breach of the Data Protection Act after losing an unencrypted backup tape containing personal financial data on 46,000 policy holders, and personal details on a further 1,800 third parties.

The data was lost by sister company Zurich Insurance Company South Africa during a routine transfer to a data storage centre in South Africa in August 2008. The incident was not reported to Zurich Insurance for over a year, according to the Information Commissioner's office (ICO).

An internal investigation revealed failings in the management of security procedures in South Africa, and Stephen Lewis, UK branch manger of Zurich Insurance, signed an undertaking with the ICO today.

Lewis has pledged that Zurich Insurance will ensure that data security procedures, including the use of encryption, are in place before the movement of data.

The company must also monitor and promptly report any data security weaknesses or breaches, and ensure that staff and external contractors are fully aware of security procedures.

Sally-anne Poole, head of enforcement and investigations at the ICO, urged all organisations to report any serious data breaches.

"It is vital that organisations ensure that effective safeguards are in place to protect personal information," she added.

"Failure to adequately protect personal details could lead to information falling into the wrong hands and ultimately the loss of customers' trust and confidence."

Chris McIntosh, chief executive of data encryption firm Stonewood, welcomed the ICO's hardline stance on those contravening data breach laws.

"Waiting a year, as Zurich's sister company did on this occasion, is quite frankly beyond unacceptable," he said. "As well as securing data, organisations have to ensure that they report and react to any incidents swiftly."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

31%

1%

12%

56%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Project Manager - Credit Risk - Finance IT - Investment Bank

Project Manager - Credit Risk - Finance IT - Investment...

Infrastructure Configuration Manager/Analyst/Data Modeler/IB

Infrastructure Configuration Manager/Analyst/Data Modeler...

Lead Perl Developer, Apache, SQL, Unix/Linux, INVESMENT BANK

Lead Perl Developer, Apache, SQL, Unix/Linux, Shell Scripting...

Perl Developer, Web and JEE App Servers, INVESTMENT BANK

**Perl /Java Developer, Web/ JEE application servers...

To send to more than one email address, simply separate each address with a comma.