13th June 2011

Candygram for Mongo!

Cleavon Little played the new sheriff Bart in the 1974 classic Blazing Saddles. To get an important message to ‘Mongo’ who was terrorising the townsfolk of Rock Ridge, he assumed the persona of a bellhop delivering an important message to Mongo that would result in his capture.

The purpose of this comedy classic diversion is to make the point that to get the message to the right person at the right time and for their eyes only is as vital today as it was then to the good townsfolk of Rock Ridge.

With this in mind, it comes as no surprise that the Keydata founder Stewart Ford has lodged a complaint with the FSA alleging that the regulator delivered his confidential copy of the Keydata preliminary investigation report to his ex-wife.

The complaint, reported by Money Marketing, claims that in August the FSA delivered a 5,000-page package of sensitive documents, held on unencrypted discs, to Ford’s ex-wife in Glasgow and his lawyers.

Richard Thomas, the Information Commissioner is on record as saying that

“the blunt truth is that all organisations need to take the protection of customer data with the utmost seriousness. I have made clear publicly on several occasions over the past year that organisations holding individuals’ data must in particular take steps to ensure that it is adequately protected from loss or theft. There have been several high-profile incidents of data loss in public and private sectors during that time which have highlighted that some organisations could do much better. The coverage of these incidents has also raised public awareness of how lost or stolen data can be used for crimes like identity fraud. Getting data protection wrong can bring commercial, reputational, regulatory and legal penalties. Getting it right brings rewards in terms of customer trust and confidence.

This quote came from the FSA factsheet April 2008 which also contained the following key points concerning data-

  • 1. Customer data is a high value commodity for fraudsters and securing it is your responsibility. In line with Principles 2 and 3 of the FSA’s Principles for Businesses, you should make an appropriate assessment of the financial crime risks associated with your customer data.
  • 2. SYSC 3.2.6R requires firms to take reasonable care to establish and maintain effective systems and controls for countering the risk that the firm might be used to further financial crime.
  • 3. This factsheet outlines the areas of your business that you should consider when assessing the risks to your customer data including; physical security, governance, staff recruitment and vetting, training and awareness, systems and controls, disposal of data, third parties and compliance.

I think everyone would accept that mistakes happen, but for such a mistake to be made by an organisation that has issued this guidance for firms would suggest that this is a case once again of do what I say and not what I do.

Given the huge fines handed out to big firms for failing to adequately protect data, I think that the regulator should consider how it will deal with this internally. No doubt any ‘naming and shaming’ is a no go area probably on the grounds of Data Protection or Human Rights, but at the very least it should hold it’s hands up, if true, apologise and take action against the individual responsible.

After all, an organisation whose stated aim that you should be ‘very afraid’ if you do wrong, should practice what it preaches regarding the security of data.

All data that contains sensitive information should at the very basic level be protected by encryption whether sent by post, courier or e-mail.

As for Mongo, he as we, are only a “pawn in the game of life” played out in real regulatory time!

 

FSA/FCA

Registration

Free Registration and CPD

Related Articles_


Adviser Sector Capacity Grows by 23% in 2021

Read More

FCA exploring more impactful alternatives


As reported in Bento 1262 on 7th August, we received tip-off from an FCA mole that the FCA had put into action their ‘Ethnicity Action Plan’ which focusses on refreshing Unconscious Bias training, exploring more impactful alternatives and rolling out the workshops across the organisation to support the changes they want to see.

Read More

Nightmare on Compensation Street


I sometimes awake in the middle of the night, bathed in sweat and breathing heavily. For a minute or so I’m confused and disoriented and then, after the mental turmoil subsides I realise it was only a nightmare. In my nightmare I had worked at a Claims Management company (CMC).

Read More

Comments (3)

Ref your statement

"All data that contains sensitive information should at the very basic level be protected by encryption whether sent by post, courier or e-mail."

How do you encyrpt a paper fact find and suitability report when sent to a client in the post? Should we use a cypher to encypt the cover letter, FF and report and send a seperate code book for teh client to manually decypher waht we have written?

Sending things t the right address is the important thing and intercepting the Royal Mail is a criminal offence, so correct address & Royal Mail shoudl be the end of it. Royal Mail shoudl be responsibile for their side, not firms have to take ever increasing ADDITIONAL security measures ....

As for the FSA and delivering to the wrong person.... unforgivable.

Phil Castle   14/06/2011   09:04
Am I in the Secret Services or Financial Services? This is cart before horse stuff. If there is a genuine concern then it must centre on the worry that unscrupulous people who may get their hands on the information will use it for nefarious purposes. The loser of the information may be careless, but surely not a criminal.

In which case increase the penalties. Ten years without parole should sort it - and while we’re at it what about bringing back hard labour, no TVs in cells and making a prison sentence a really unpleasant experience. Perhaps we than may have less crime all round. And accessing information that is no concern of yours is a crime.

Norwest   14/06/2011   09:13
Phil - if you send a non-encrypted Suitability Report you will clearly be in breach for failing to ensure you client's personal data is secure.

On the other hand, if you encrypt it, you will be in breach for failing to ensure it is clear, fair and not misleading

Peter Turner   14/06/2011   16:17

You need to be logged in to comment on this article