14th June 2011

Candygram for Mongo!

Cleavon Little played the new sheriff Bart in the 1974 classic Blazing Saddles. To get an important message to ‘Mongo’ who was terrorising the townsfolk of Rock Ridge, he assumed the persona of a bellhop delivering an important message to Mongo that would result in his capture.

The purpose of this comedy classic diversion is to make the point that to get the message to the right person at the right time and for their eyes only is as vital today as it was then to the good townsfolk of Rock Ridge.

With this in mind, it comes as no surprise that the Keydata founder Stewart Ford has lodged a complaint with the FSA alleging that the regulator delivered his confidential copy of the Keydata preliminary investigation report to his ex-wife.

The complaint, reported by Money Marketing, claims that in August the FSA delivered a 5,000-page package of sensitive documents, held on unencrypted discs, to Ford’s ex-wife in Glasgow and his lawyers.

Richard Thomas, the Information Commissioner is on record as saying that

“the blunt truth is that all organisations need to take the protection of customer data with the utmost seriousness. I have made clear publicly on several occasions over the past year that organisations holding individuals’ data must in particular take steps to ensure that it is adequately protected from loss or theft. There have been several high-profile incidents of data loss in public and private sectors during that time which have highlighted that some organisations could do much better. The coverage of these incidents has also raised public awareness of how lost or stolen data can be used for crimes like identity fraud. Getting data protection wrong can bring commercial, reputational, regulatory and legal penalties. Getting it right brings rewards in terms of customer trust and confidence.

This quote came from the FSA factsheet April 2008 which also contained the following key points concerning data-

  • 1. Customer data is a high value commodity for fraudsters and securing it is your responsibility. In line with Principles 2 and 3 of the FSA’s Principles for Businesses, you should make an appropriate assessment of the financial crime risks associated with your customer data.
  • 2. SYSC 3.2.6R requires firms to take reasonable care to establish and maintain effective systems and controls for countering the risk that the firm might be used to further financial crime.
  • 3. This factsheet outlines the areas of your business that you should consider when assessing the risks to your customer data including; physical security, governance, staff recruitment and vetting, training and awareness, systems and controls, disposal of data, third parties and compliance.

I think everyone would accept that mistakes happen, but for such a mistake to be made by an organisation that has issued this guidance for firms would suggest that this is a case once again of do what I say and not what I do.

Given the huge fines handed out to big firms for failing to adequately protect data, I think that the regulator should consider how it will deal with this internally. No doubt any ‘naming and shaming’ is a no go area probably on the grounds of Data Protection or Human Rights, but at the very least it should hold it’s hands up, if true, apologise and take action against the individual responsible.

After all, an organisation whose stated aim that you should be ‘very afraid’ if you do wrong, should practice what it preaches regarding the security of data.

All data that contains sensitive information should at the very basic level be protected by encryption whether sent by post, courier or e-mail.

As for Mongo, he as we, are only a “pawn in the game of life” played out in real regulatory time!

Panacea Comment

Registration

Free Registration and CPD

Related Articles_

When vulnerability policies go wrong


I have never considered myself to fit such definition but since passing 75 I am beginning to wonder if lip service is being paid by regulated firms or they have just made it more difficult for their customers?

Read More

The Golden Rule of AI for Financial Advisers: Protect Your Client Data


Artificial intelligence has the potential to transform the way advice firms work, helping to reduce administration, improve efficiency and free up more time for clients. But before embracing AI, there is one principle that should never be overlooked

Read More

Getting Better Results from AI: The RTCC Framework


Artificial intelligence is only as good as the instructions you give it. If you’ve ever asked AI a question and received an answer that felt generic, vague or simply not quite right, don’t be too quick to blame the technology.

Read More

You need to be logged in to comment on this article