• Welcome to the LegalBeagles Consumer and Legal Forum.
    Please Register to get the most out of the forum. Registration is free and only needs a username and email address.
    REGISTER
    Please do not post your full name, reference numbers or any identifiable details on the forum.

FSA Fines Zurich Insurance £2.275 000 over loss of policy holder details

Collapse
Loading...
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • FSA Fines Zurich Insurance £2.275 000 over loss of policy holder details

    FSA fines Zurich Insurance £2,275,000 following the loss of 46,000 policy holders' personal details


    Margaret Cole

    Zurich UK let its customers down badly. It failed to oversee the outsourcing arrangement effectively and did not have full control over the data being processed by Zurich SA.




    FSA/PN/134/2010
    24 August 2010
    The Financial Services Authority (FSA) has fined the UK branch of Zurich Insurance Plc (Zurich UK) £2,275,000 for failing to have adequate systems and controls in place to prevent the loss of customers’ confidential information. The fine is the highest levied to date on a single firm for data security failings.
    The failings came to light following the loss of 46,000 customers’ personal details, including identity details, and in some cases bank account and credit card information, details about insured assets and security arrangements. The loss could have led to serious financial detriment for customers and even exposed them to the risk of burglary.
    Zurich UK has seen no evidence to suggest that the personal data was compromised or misused.
    Zurich UK outsourced the processing of some of its general insurance customer data to Zurich Insurance Company South Africa Limited (Zurich SA). In August 2008, Zurich SA lost an unencrypted back-up tape during a routine transfer to a data storage centre. As there were no proper reporting lines in place Zurich UK did not learn of the incident until a year later.
    Zurich UK failed to take reasonable care to ensure it had effective systems and controls to manage the risks relating to the security of customer data resulting from the outsourcing arrangement.
    The firm also failed to ensure that it had effective systems and controls to prevent the lost data being used for financial crime.
    Margaret Cole, the FSA’s director of enforcement and financial crime, commented:
    "Zurich UK let its customers down badly. It failed to oversee the outsourcing arrangement effectively and did not have full control over the data being processed by Zurich SA. To make matters worse, Zurich UK was oblivious to the data loss incident until a year later.
    "Firms across the financial sector would do well to look at the details of this case and learn from the mistakes that Zurich UK made."
    As Zurich UK agreed to settle at an early stage of the investigation the firm qualified for a 30 per cent discount. Without this discount the firm would have been fined £3.25 million.
    Notes for editors

    1. The Final Notice for Zurich Insurance Plc can be found on the FSA website.
    2. Zurich’s failings were in breach of Principle of Business 3 (management and control) and the FSA’s System and Controls rules.
    3. The FSA has previously fined HSBC, Nationwide and Norwich Union for data loss.
    4. The FSA regulates the financial services industry and has five objectives under the Financial Services and Markets Act 2000: maintaining market confidence; promoting public understanding of the financial system; securing the appropriate degree of protection for consumers; fighting financial crime; and contributing to the protection and enhancement of the stability of the UK financial system.


    Source: Latest publications
    "Family means that no one gets forgotten or left behind"
    (quote from David Ogden Stiers)

  • #2
    Re: FSA Fines Zurich Insurance £2.275 000 over loss of policy holder details

    Hmmm really dont get this...

    Back in January I received a letter from MBNA stating that their "partner" RMA/NCO had lost a laptop with "customer account information" on it and to safeguard me and everyone else affected they would a) Put CIFAS markers on our credit history for 3 months and b) Gave me 12months creditexpert to keep track of my credit file.

    Why no involvment from FSA/FOS/ICO in that case then? bizarre!

    S.
    I thought I knew something, but now I know nothing

    Comment

    View our Terms and Conditions

    LegalBeagles Group uses cookies to enhance your browsing experience and to create a secure and effective website. By using this website, you are consenting to such use.To find out more and learn how to manage cookies please read our Cookie and Privacy Policy.

    If you would like to opt in, or out, of receiving news and marketing from LegalBeagles Group Ltd you can amend your settings at any time here.


    If you would like to cancel your registration please Contact Us. We will delete your user details on request, however, any previously posted user content will remain on the site with your username removed and 'Guest' inserted.
    Working...
    X