Information Commissioner's Office delivers damning verdict after RSA personal data loss

Oliver Gill
Follow Oliver
Royal and Sun Alliance
RSA has over nine million customers and employs 13,500 staff globally (Source: Getty)

Regulators have fined insurance giant RSA for losing the personal information of almost 60,000 customers.

The owners of the More Than brand were handed a £150,000 penalty by the Information Commissioner's Office (ICO) after the theft of a hard drive device containing thousands of customers' personal data and the credit card details of 20,000 people.

The ICO can impose fines of up to £500,000 for breaches of data security. Last year, it slapped broadband firm TalkTalk with a £400,000 penalty after it was subject to a cyber attack in 2015.

Read more: Stephen Hester sees positives from Brexit vote for RSA

“When we looked at this case we discovered an organisation that simply didn’t take adequate precautions to protect customer information. Its failure to do so has caused anxiety for its customers not to mention potential fraud issues," said ICO head of enforcement Steve Eckersley.

There are simple steps companies should take when using this type of equipment including using encryption, making sure the device is secure and routine monitoring of equipment.

RSA did not do any of this and that’s why we’ve issued this fine.

No economic loss

The ICO said expiry dates and CVC numbers of the credit cards were not contained on the hard drive. An RSA spokesperson stressed there was "no evidence to suggest that the stolen storage device has resulted in any economic loss for the customers involved".

Read more: RSA raises bonuses by 66 per cent, chief takes home £2.5m

The spokesperson continued: “The ICO fined us for not foreseeing the risk that the theft of a storage device could cause and for not protecting it adequately.

"We recognise that this should have never have happened and we would like to say sorry once again to those of our customers and partners who were impacted.

"We have reviewed and reinforced our data protection procedures to mitigate the risk of this happening again – the substantive work that has been undertaken since then to improve date protection in our company has been acknowledged by the ICO.”

Related articles