IMPORTANT: Please make sure your posts do not contain any personally identifiable information (both your own and that of others). When uploading images, please take care that you have redacted all personal information including number plates, reference numbers and QR codes (which may reveal vehicle information when scanned).
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Huge Data Protection Breach?

Good evening

Earlier today I discovered that my car, its number plate and the ticket I was issued have been placed online by a parking company and can be viewed by anyone.

I then discovered that I could access hundreds of other car registrations, tickets, and other personal information from the parking providers website by changing numbers in the url.

I know that we all walk past thousands of cars every day and can see their number plates but am I right in thinking this is a little bit dodgy?

I did my research on the company and due to the expertise of their director, it cannot be an accident that they are so easily accessible.

Should I take any action or am I overthinking this?
«1

Comments

  • KeithP
    KeithP Posts: 41,296 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    Report your findings to the Information Commissioner's Office.
    Let them investigate.
  • The_Slithy_Tove
    The_Slithy_Tove Posts: 4,100 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    This has happened before, can't remember which PPC. They got into quite a bit of trouble for it.
  • The_Deep
    The_Deep Posts: 16,830 Forumite

    I did my research on the company and due to the expertise of their director, it cannot be an accident that they are so easily accessible.


    I am not sure I understand, do you mean the Companies House information? Which Company?
    You never know how far you can go until you go too far.
  • The ICO investigation was into Islington Council and resulted in a £70,000.00 fine.

    The parking company I am dealing with have done the same as Islington Council.

    The evidence I have has been passed to the ICO who are taking the breach seriously.

    Due to the large number of people affected by the breach and who's data can be easily accessed by anyone, it would be inappropriate to name the parking company.

    I'll update the thread once the ICO investigation has been completed.
  • Half_way
    Half_way Posts: 7,491 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    Apart from the.reg numbers, is there anything else linked to the numbers, such as times in car park, overstays/ lengths of stay, or more serious payment method, or names, and addresses?
    From the Plain Language Commission:

    "The BPA has surely become one of the most socially dangerous organisations in the UK"
  • In the worst case some customers had placed notices in their car windows giving names. contact numbers and jobs. This was clearly to try and make the parking company act with some compassion. Photos have been taken of these signs and put online along with the car registrations. All can be easily accessed.
  • Johno100
    Johno100 Posts: 5,259 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    This has happened before, can't remember which PPC. They got into quite a bit of trouble for it.

    Yes, I remember all the various time stamped photos of the vehicles were available. I can't remember if it was just by altering (going up or down) on a number in the URL or they'd left a directory on their computer system open.
  • Coupon-mad
    Coupon-mad Posts: 153,255 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    LOL!
    Exclusive Britain's privacy watchdog will investigate a major car-parking contractor after its website allegedly leaked drivers' personal information.

    Readers will be relieved to know, however, that representatives of chesty TV princess Katie Price say she has avoided having any sensitive private information revealed during the affair.
    What a relief!

    In all seriousness, maybe the Director of this current company thinks he's some sort of DPA expert and internet engineer but turns out to be clueless. Seen that before.
    PRIVATE 'PCN'? DON'T PAY BUT DON'T IGNORE IT (except N.Ireland).
    CLICK at the top or bottom of any page where it says:
    Home»Motoring»Parking Tickets Fines & Parking - read the NEWBIES THREAD
  • fisherjim
    fisherjim Posts: 7,111 Forumite
    Part of the Furniture 1,000 Posts Photogenic Name Dropper
    This was the best one from those lowlife ding-bat muppets at UKPC who are still in business despite all their misdemeanours:


    http://nutsville.com/2013/03/31/british-parking-association-member-ukpc-in-epic-data-protection-failure/


    If it's them again they should be put out of business.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.4K Banking & Borrowing
  • 253.2K Reduce Debt & Boost Income
  • 453.8K Spending & Discounts
  • 244.3K Work, Benefits & Business
  • 599.6K Mortgages, Homes & Bills
  • 177.1K Life & Family
  • 257.9K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.