Share on LinkedInShare on LinkedIn

ARTICLE · 03 AUGUST 2007

Financial Institutions Under Scrutiny For E.U. Data Security Breaches: Lessons To Be Learned

The European data protection authorities have been cracking down on data security breaches and the UK has recently focused its attention on financial institutions who have violated the Data Protection Act 1998 (DPA).

European UnionPrivacy
Ieuan Jolly
Ieuan Jolly

The European data protection authorities have been cracking down on data security breaches and the UK has recently focused its attention on financial institutions who have violated the Data Protection Act 1998 (DPA). Organizations that fail to process personal information in line with the principles of the DPA not only risk enforcement action, prosecution and fines by the regulators, but also losing the trust of their customers. Earlier this year, the UK data protection regulator, the Information Commissioner's Office (ICO), published a list of eleven financial institutions who breached the DPA by their improper disposal of customer information. Among the institutions publicly named were Barclays Bank, Royal Bank of Scotland, and NatWest.

The ICO's action was on the heels of an investigation by the Financial Services Authority (FSA), which regulates the financial services industry in the UK. Following the theft of a laptop computer containing sensitive data from an employee's home, the FSA fined Nationwide Building Society almost $2 million for failing to ensure it had effective systems in place to manage the risks associated with their information security.

The institutions that were singled out by both the ICO and FSA experienced a significant blow to their reputation which affected the confidence of clients and investors. Financial institutions should take heed and implement the necessary steps to ensure that they operate in compliance with the applicable data security regulations.

This Article briefly examines four key points:

  • The recent breaches of the Data Protection Act
  • The implications of the Data Protection Act for financial institutions
  • Lessons to be learned
  • Steps financial institutions can take to achieve compliance

Recent Breaches Of The Data Protection Act

The ICO and FSA have both been accused of lacking teeth and being lenient regulators, yet both have recently cited institutions for data security violations. Generally speaking, every institution that holds personal data concerning living individuals must comply with the DPA and its Eight Principles. The Seventh Principle requires that, "appropriate technical and organizational measures shall be taken against unauthorized or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data." Additionally, the majority of financial institutions in the UK are regulated by the FSA, and breach of the DPA can also infringe the FSA Principles for Businesses. In particular, Principle Three requires companies to "take reasonable care to organize and control its affairs responsibly and effectively, with adequate risk management systems."

In February 2007, the FSA took action against Nationwide for its breach of FSA Principle Three and the DPA, by issuing a financial penalty of £980,000. The breach arose due to the theft of a Nationwide employee's laptop containing confidential customer information, an event which Nationwide had failed to investigate for three weeks. The FSA found that Nationwide had failed to take reasonable care to ensure it had effective systems to manage risks, failed to ensure its information security procedures were understood by its employees and failed to implement adequate controls to mitigate information security risks.

In March 2007, the ICO named and "shamed" eleven financial institutions that had violated the DPA. The named institutions had disposed of personal data such as cut-up debit cards, PIN numbers, credit and account applications, life assurance letters, and paying-in envelopes in unlocked trash bins outside their premises. As a result of these actions, the institutions were found to have breached the Seventh Principle of the DPA because discarding data in this manner allowed the public ready access to customer information and there were no appropriate technical and organizational measures in place to safeguard the data being disposed of.

Implications Of The Data Protection Act For Financial Institutions

Financial institutions that breach the DPA can be held accountable by both the ICO and the FSA. In addition to facing regulatory fines, financial institutions not only risk civil action, but they can also face criminal prosecution if they fail to comply with the DPA. The DPA creates a number of criminal offenses, beyond the offenses of failure to comply with information or enforcement notices. While most offenses can only be committed by entities who control the purposes for which and manner in which personal data is processed ("Data Controllers"), the offense of procuring unauthorized disclosure and related offenses may be committed by anyone. Data Controllers may commit offenses if they fail to register with the ICO or keep the details of the registration current; and there are several offenses in connection with a failure to cooperate in the execution of a warrant. If an institution commits one of these offenses, a director, manager or officer can also be found personally guilty for the institution's offense if it was committed with the officer's consent or was attributable to the officer's neglect. If found guilty, a person/company may be liable for significant fines.

In addition, any person who causes the disclosure of personal data without the authority of the Data Controller may be guilty of an offense, including related offenses involving offering or selling such data. Institutions should ensure that staff members are made aware of these provisions as violations can result in individual criminal liability. Moreover, institutions and their employees may be targets of persons seeking to obtain information illicitly. Staff should be trained to be alert for such potential attacks on security.

The FSA also has the power to take disciplinary action to penalize financial institutions for breach of the DPA by imposing financial penalties as well as issuing public statements and censures of misconduct.

Financial institutions should also keep in mind that as Data Controllers, they remain liable for all infringements of the DPA, even if they outsource their data processing. This means that even though a financial institution may obtain an indemnity from a vendor who processes personal data on its behalf, it still remains liable and runs the risk of being listed as an infringer. When a financial institution outsources any processing, the outsourcing contract must require the processor to comply with the DPA (and in particular, the Seventh Principle). Further, financial institutions should be aware of the new powers the ICO has recently requested from the British Government which include the right to inspect and audit an institution without their consent and the power to impose more stringent penalties.

Lessons To Be Learned

The Nationwide case illustrates certain key lessons that financial institutions can learn from in order to avoid data security breaches:

  • Nationwide's failure to implement robust systems and controls regarding the storage and use of customer information on portable storage devices put customers at an increased risk of being victims of financial crimes if the data was lost or misused. Financial institutions should consider on which mediums their information is stored and what the associated information risks are, including external or internal sources, human error, accidental loss or deliberate theft of information, and thereafter, establish and maintain controls to mitigate those risks.
  • Nationwide failed to respond quickly and appropriately in the first three weeks following the theft, thus increasing the opportunity for the information to be used fraudulently. Financial institutions should have incident management procedures that are commensurate with the size of their operation. This case also highlights the need for institutions to update their procedures in line with developments in technology, particularly with an eye toward the increasing use of portable storage devices (e.g. laptops, PDAs) that have the capacity to hold large amounts of data.
  • Nationwide employees were merely required to self-certify that they had read and understood Nationwide's procedures for information security. The staff received generic training on the application of information security procedures; however, no job specific training was provided and no controls existed to ensure employees were adhering to the procedures. Reliance on such lax procedures was dangerous and ineffective due to the company's size. Financial institutions should implement appropriate monitoring controls to ensure information security protocols are being followed, including monitoring compliance with procedures, implementing physical and electronic barriers to copying and transmitting information to portable storage devices, and conducting random and targeted monitoring to ensure only necessary data is stored on portable storage devices.
  • Nationwide's information security procedures were contained in an unmanageable electronic format on an internal Web site and were not located in one single document. The information was not organized such that employees could easily identify which procedures applied to their specific role, and use a search function to locate applicable procedures. Financial institutions should house their information security procedures in one location in a user friendly format so that employees can readily access the procedures they need.
  • Nationwide's policies lacked prioritization and contained numerous inconsistencies. There was no distinction between mandatory critical requirements and lesser issues. Financial institutions should outline their procedures in a coherent format that includes a clear distinction and prioritization of critical steps, as well as information on lesser issues and best practices.

Steps Financial Institutions Can Take To Achieve Compliance

All Financial institutions can and should take steps to ensure they have the proper safeguards in place to protect personal data. Although no amount of security can eliminate the risk that electronic storage devices, such as laptops, will be lost or stolen, steps can be taken to ensure that loss of physical equipment does not compromise customer information. Failure to take these steps can result in large fines, criminal prosecution, civil sanctions and unfavorable publicity. To avoid such consequences, Financial institutions should consider taking the following steps, in addition to those described in the "Lessons to be Learned" section, above:

  • Assess current technical and organizational measures in order to guarantee that there are proper safeguards to protect the customer's personal data and information;
  • Hold training programs for employees who regularly process or handle customers' personal data and information, and implement appropriate monitoring and controls to ensure the employees are compliant with such procedures;
  • Implement systems and controls concerning the use and storage of customer information on portable storage devices, such as laptops, that put customers at risk of the loss or misuse of their personal data;
  • Respond promptly in the event of a theft or loss of storage device to decrease the opportunity for the information to be misused, ideally following a previously-drafted data breach response plan; and
  • Seek legal advice to ensure that your company is in compliance with data protection requirements.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

See more popular content from