Reevesey's recommended reading

Showing posts with label ICO. Show all posts
Showing posts with label ICO. Show all posts

Saturday, 21 November 2009

T-Mobile personal data sale scandal update

As it is a few days since my original post about this I thought I would check the T-Mobile website again since they haven't had the decency to respond to my email asking whether my data was compromised.

This update is now available on their website;

"Update

T-Mobile takes the protection of customer information seriously. When it became apparent that contract renewal information was allegedly being passed on by an employee to third parties without our knowledge, we alerted the Information Commissioner’s Office. Working together with the ICO, they conducted an extensive investigation which we believe will lead to a prosecution.

We believe that this breach happened between July 2007 and November 2008 and that it was only contract renewal data that was passed on. While it is deeply regrettable that customer information has been misappropriated in this way, it should be noted that the stolen data did not include call records, financial data, password details or any other information that would enable someone else to access customers’ personal details.

Since the breach of information occurred more than a year ago, we believe that the current impact on customers will be minimal. We continue to support the ICO to help stamp out what is a problem for the whole industry.

T-Mobile Forum team"

What annoys me is that they are being so dismissive, "we believe....that it was only contract renewal data...was passed on", so, they don't actually know what data their own staff were accessing to sell on.

I hope the Information Commissioner fines T-Mobile as well as jailing the person who actually did the deed as it were, plus the brokers, because they clearly knew they were breaching data protection legislation.

Wednesday, 18 November 2009

T-Mobile claim no personal financial data has been compromised

Over on T-Mobile's website, once you go to the home page and find the small pink button "Information on T-Mobile data being sold to third parties", which is dwarfed by the latest deals from T-Mobile there are three statements from T-Mobile.

The first, including typo's (four in one statement) is here "T-Mobile takes the protection of customer information seriously. When it became apparent that contract renewal information was being passed on to third parties without our knowledge, we alerted the Information Commssioner's Office. Working together, we identified the source of the breach which led to the ICO conducting an extensive investigation which we believe will lead to a prosecution. Whilst it is deeply regrettable that customer information has been misapproriated in this way, we have proactively supported the ICO to help stamp out what is a problem for the whole industry.

We had been asked before today to keep all information on this case stricly confidential so as to avoid prejudice to the investigation and prosecution. We were therefore surprised at the way in which these statements were made to the BBC today.'

As soon as we have any further information available it will be posted in this thread. Please do not call customer services if you have read this thread as they are unable to provide any information beyond the statement above. As soon as we have any more information it will be pblished here.

T-Mobile Forum Team"

Then there is a much smaller one posted an hour after the original.

"T-Mobile is able to confirm that NO financial data has been passed on to any third parties.

T-Mobile Forum Team"

Although I am sure this is supposed to stop customers worrying, I am not sure it will work.

Anyway, statement number three also went out last night.

"T-Mobile takes the protection of customer information seriously. When it became apparent that contract renewal information was being passed on to third parties without our knowledge, we alerted the Information Commissioner's Office (ICO). It should be noted that the records were restricted to historical information on customers whose contracts were coming up for renewal in a 15-month period up to December 2008. The customer information that was compromised contained no personal financial or security-related information whatsoever.

We were proactive in engaging with the ICO to identify the source of the breach. The ICO is conducting an ongoing investigation which we believe will lead to a prosecution. While it is deeply regrettable that customer information has been misappropriated in this way, information passed on to third parties was restricted to the customer name, address and contractual renewal information. We continue to work with the IC to help stamp out what is a problem for the whole industry.

T-Mobile Forum Team"

So, apparently T-Mobile takes all of this data protection stuff quite seriously, although my question is this, if they have now secured the breach and identified the source of the leak, they must also know which customers data was compromised?

How about contacting them and worrying about them rather than worrying about statements made to the BBC?

Care about your customers not about your image and they may well do the image repair work for you.

Just a thought.

If you want to see the latest statements from T-Mobile, visit their forum page.
Related Posts with Thumbnails