
Taxman says records lost by external courier
By Tom Espiner
Published: 7 November 2007 09:35 GMT
A lost compact disc containing the personal pension details of 15,000 people was not encrypted.
The CD was lost in transit between Her Majesty's Revenue and Customs Service (HMRC) and financial services company Standard Life, and was unencrypted, HMRC revealed on Monday.
An HMRC statement said: "HMRC take the security of customer information very seriously. The data, which contained the records of around 15,000 people, was lost in transit by HMRC's external courier."
"Customers have been written to and precautionary measures have been put in place to check customers' records for any fraudulent activity. We have also reviewed our arrangements and introduced safeguards to prevent this happening in future."
One form of pension payment is an Age Related Rebate (ARR). Funds are paid into the accounts of individuals' pension providers by HMRC electronically, depending on the level of the National Insurance contributions people have made. The pension details of the individuals are then sent separately to pension providers, to enable their records to be updated.
In this instance 15,000 pension details of customers of Standard Life were sent to the pension provider by HMRC via an unnamed third-party courier, at the end of September. However, the courier lost the disc, which was not encrypted, an HMRC spokesperson silicon.com siter publication ZDNet.co.uk.
"HMRC very much regrets that this has happened and are committed to working with the institutions to ensure that those customers affected receive the advice and support they require," said the HMRC statement. "We have asked customers to remain vigilant and have set up a number of dedicated HMRC telephone hotlines."
The data contained on the disk included the surnames and initials of the individuals, as well as their National Insurance numbers, dates of birth and pension plan numbers. That the disc was not encrypted means the details can be read more easily.
Tom Espiner writes for ZDNet.co.uk
<Deep sigh> - and these are the people who reckon ...
Dave Brown
Could we please have a mandatory fine or jail sent...
Graham Coles
and the government expect us to have confidence in...
Christopher Hubbard
Was the last sentence [" That the disc was not enc...
Anonymous
To be able to read, write, work with numbers and use a computer Keep records and paperwork up to date and accurate Role: Support Worker Location: ...
Data Protection You should adhere to best practice when dealing with data protection and be willing to undergo a security check should a client ...
This is a new team within the organisation to assist in the growth and scalability of the IS security operation.Key Responsibilities/Duties 1st and ...
Agenda Setters 2008
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Naked CIO Naked CIO: Should you monitor staff? Somebody's watching you
Elinor Mills Why 1970s hackers had 'whiz kid' status Q&A: Kevin Mitnick - blackhat hacker turned good guy