This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies.  > Find out more here

 

All the latest UK technology news, reviews and analysis

ICO fines Prudential £50,000 for database mix up

by Dan Worth

06 Nov 2012

View Comments

  • Tweet this
Prudential logo

The Information Commissioner's Office (ICO) has fined insurance and pensions giant Prudential £50,000 after a database mix up.

The incident saw two separate customers with the same first name, surname and same date of birth mixed up in its database, a situation that caused thousands of pounds from one of the individual's retirement funds to be placed in the others.

This was despite a warning from one of the customers that he had not changed address in 15 years after he received a letter from the firm confirming his supposed change of address.

The ICO said the firm failed to investigate properly and it took some three years for the situation to be finally resolved in 2010 after the problem was first in the system in 2007.

Stephen Eckersley, ICO head of enforcement, said the case should serve as a warning that firms holding personal data must keep records accurate and up-to-date in order to comply with the Data Protection Act.

"In this case two customer files were consistently confused and the company failed to remedy the situation despite being alerted to the problem on more than one occasion before it was finally resolved," he said.

"This case would be considered farcical were it not for the serious sums of money involved."

Prudential apologised for the mistake and said it had compensated the customers affected but accepted the ICO's findings.

"The problem was rectified in 2010 to the satisfaction of the ICO. We co-operated openly and fully with the review and we accept the fine imposed," it said.

"When this issue came to light we reviewed our procedures and staff training and made changes to minimise the chances of a similar error occurring again."

The fine could be reduced to £40,000 if the firm pays up by 29 November.

The fine is notable as not only is it one of the rarer occasions when the private sector has been fined by the ICO but it relates to data handling practices, rather than data loss - the usual cause of hefty fines from the data watchdog.

"Inaccurate information on a customer's record, particularly when the record relates to an individual's financial affairs, can have a significant impact on someone's life," warned Eckersley.

"We hope this penalty sends a message to all organisations, but particularly those in the financial sector, that adequate checks must be in place to ensure people's records are accurate."

The fine comes after the ICO confirmed to V3 that fines levied against the public sector for data breaches have passed £2m, a notable waste of public funds at a time when front line services are already facing limited budgets.

Do you agree

blog comments powered by Disqus

Poll

Business security poll

How concerned are you by the rising tide of cyber threats?

16%

56%

10%

9%

9%

Popular Threads

Powered by Disqus
BlackBerry Q5

BlackBerry Q5 video demo

BlackBerry's latest smartphone is a mid-tier handset that will cost less than the Q10 and Z10

Updating your subscription status Loading

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

newsletter sign-up button

mcafee

7 requirements for hybrid web delivery

It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model

navisite

BYOD: the implications for the IT team

BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs

IT Support Analyst

A Support Analyst with good commercial experience and...

SEPA Business Analyst - General Insurance

A Business Analyst is required by a leading international...

Oracle DBA 11g - Weblogic / Middleware Stack / SQL Server

An Oracle DBA is required by one of the UK's leading...

IT Senior Support Analyst

A Senior Support Analyst with good commercial experience...

To send to more than one email address, simply separate each address with a comma.