Friday 17 May 2024
Select a region
News

Thousands of people’s information shared by accident in large government data breach

Thousands of people’s information shared by accident in large government data breach

Monday 29 April 2024

Thousands of people’s information shared by accident in large government data breach

Monday 29 April 2024


The health debt information of 5,059 people was shared by accident, after a member of the States of Guernsey Corporate Debt Management Team emailed it all to a customer.

The incident happened on Thursday 18 April.

The island’s Chief Resources Officer, Bethan Haines, has since apologised for the mistake: 

“I know that this incident will cause frustration and distress and I want to unreservedly apologise for the lapse in security of customer data.  

“The States of Guernsey has strict internal training requirements specific to confidentiality and data safeguarding, with refresher training for the Corporate Debt Management Team occurring at least annually.  

“We take matters of data security extremely seriously and have taken immediate steps to strengthen our security measures, whilst we continue to carry out an investigation into the incident in order to capture the lessons learnt.” 

A Public Notification has now been published in accordance with the Data Protection Law (see excerpt below).

 Screenshot_2024-04-29_at_10.30.17.png

The information shared included the full names of customers and details of money owed to the States. 

It did not include medical records and the States say that “insufficient data was shared that would enable someone to utilise that data for the purposes of identity fraud”. 

The incident has been reported to the Office of the Data Protection Authority and the full Public Notification can be read ONLINE.

It has also published a statement on the breach: 

"The Data Protection Authority (‘the Authority’) has opened an inquiry into a data breach at the Director of the Revenue Service, alleged to involve a significant volume of personal information.

"The decision to initiate this inquiry under section 69 of The Data Protection (Bailiwick of Guernsey) Law, 2017 has been made following consideration of a breach notification submitted to the Authority by the Director of the Revenue Service and seeks to establish whether the Director of the Revenue Service has breached an operative provision of the Law. Not all breach notifications result in investigations or inquiry. They are assessed on their particular fact and risk situations.

"The outcome of the Authority’s inquiry should not be speculated on, or its conclusion pre-judged. No further comment will be made at this time."

Sign up to newsletter

 

Comments

Comments on this story express the views of the commentator only, not Bailiwick Publishing. We are unable to guarantee the accuracy of any of those comments.

You have landed on the Bailiwick Express website, however it appears you are based in . Would you like to stay on the site, or visit the site?