• Welcome to the LegalBeagles Consumer and Legal Forum.
    Please Register to get the most out of the forum. Registration is free and only needs a username and email address.
    REGISTER
    Please do not post your full name, reference numbers or any identifiable details on the forum.

Next/ACI Data Breach? ICO Ruling on Post-Sale Data Sharing & SAR Failures

Collapse
Loading...
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • Next/ACI Data Breach? ICO Ruling on Post-Sale Data Sharing & SAR Failures

    Hi all,
    I wanted to share something that might be relevant to anyone dealing with Next, ACI, or Perch Capital (or other debt purchasers).

    I raised a complaint with the ICO after discovering that Next shared my personal data with ACI/Perch AFTER selling the debt. Their justification for doing this kept changing — first “performance of a contract,” then FCA DISP rules, then finally FCA CONC guidance.

    The ICO has now issued a decision that Next had not complied with their data protection obligations, and that their shifting reliance on different lawful bases was unlikely to comply with GDPR.

    What’s more, when I submitted a Subject Access Request (SAR) to Next, they refused to disclose key information such as internal notes and communications with ACI. The ICO, however, when I did a SAR to them, did disclose equivalent categories — showing that this kind of information can and should be provided.

    This raises big questions:

    How many people’s data is still being shared post-sale, months or years after debts were assigned?

    If DCAs are relying on documents obtained this way, are they using unlawfully obtained data to enforce debts?

    If SARs are incomplete, how can anyone fairly defend themselves in court?


    For me, this has been stressful, time-consuming, and has raised serious concerns about industry-wide practices. I’ll be pursuing this further, but I think it’s important that others are aware — because if your data was shared unlawfully, it could directly impact the enforceability of the debt.

    Has anyone else had similar experiences with incomplete SARs, or found DCAs going back to the original creditor to fish for documents long after a sale?

    Happy to share more detail if useful, and I’d be interested to hear if anyone else is challenging this.

    Tags: None

  • #2
    For anyone interested, the ICO has already investigated this and found that:
    > “…Next had not complied with their data protection obligations and their approach of using multiple lawful bases was unlikely to comply with data protection legislation.”



    Next actually appealed that decision, but when a different ICO officer reviewed the case, the finding was upheld in full

    Comment

    View our Terms and Conditions

    LegalBeagles Group uses cookies to enhance your browsing experience and to create a secure and effective website. By using this website, you are consenting to such use.To find out more and learn how to manage cookies please read our Cookie and Privacy Policy.

    If you would like to opt in, or out, of receiving news and marketing from LegalBeagles Group Ltd you can amend your settings at any time here.


    If you would like to cancel your registration please Contact Us. We will delete your user details on request, however, any previously posted user content will remain on the site with your username removed and 'Guest' inserted.
    Working...
    X