Zurich in breach of Data Protection Act

| March 25, 2010 | 0 Comments
Zurich in breach of Data Protection Act

Zurich Insurance has been obliged to sign an undertaking with the Information Commissioner’s Office (ICO) agreeing to improve security.

The insurer lost an unencrypted back-up tape containing personal financial information belonging to over 46,000 of its policyholders, and has been found breach of the Data Protection Act.

Customers of Zurich Private Client, Zurich Special Risk and Zurich Business Client were affected by the slip-up.

The tape, which also held details of 1,800 third parties, was lost by Zurich Insurance Company South Africa in 2008, during a routine transfer to a data storage centre.

However, parent company Zurich Insurance plc was not informed of events for over a year.

Subsequent internal investigations in South Africa revealed failings in the management of security procedures and under the terms of the Undertaking, future movement of the group’s back-up tapes will require various data security measures, including the use of encryption.

In addition, potential or actual data loss will need to be reported promptly.

Earlier this month, Royal London was rapped over the knuckles by the ICO after eight of the mutual’s laptops, two of which contained details of 2,135 people who had sought pension scheme illustrations, were stolen from its Edinburgh offices.

The data were password protected but unencrypted.

Tags: , , , , , , , , ,

Category: Insurance News, Legal News, Zurich News

Comments (0)

Trackback URL | Comments RSS Feed

There are no comments yet. Why not be the first to speak your mind.

Leave a Reply

You must be logged in to post a comment.


Visited 3636 times, 2 so far today