We'd like to remind Forumites to please avoid political debate on the Forum... Read More »
Massive GDPR breach at work, what should I do

welcometomynightmare
Posts: 2 Newbie


I didn't really know where to put this so if admins want to move it somewhere more appropriate that's fine.
Hello,
This month everybody, (I think it's about 95 people) who work where I do had their payslips sent in a none password protected email to a single employee who was somehow cc'd on the emails. Then a rather pathetic and very self serving apology was sent, by email, which again contained the payslip in none password protected format. Furthermore it said that in future if payslips are sent out in emails they will be done through the Brightpay App, "Your password is your date of birth" so now 95 people can easily find out each others passwords to the wages app,, the last thing it said was that if you want your password changing email your new password to the accounts guy and he will change it for you.
It is the most insane example of gross incompetence I think I've ever seen. The ordinary workers in this company do a GDPR training course, I don't think the same can be said for "The accounts team" which is who the apology email said was responsible, All the staff know "The accounts team" Is a guy called Simon who as far as I can tell is not trained in accounts but is the partner of the "Operations Director". As a snapshot of the competence of "The Accounts Team" my wages were missing a day this month and someone else of the 10 or so people I work with had 3 days pay sent to someone else's account because they share the same forename, they're both called Wendy, this type of thing happens regularly.
I can see 4 huge CDPR breaches there.
Any suggestions or advice would be greatly appreciated.
Thank you in advance.
b
Hello,
This month everybody, (I think it's about 95 people) who work where I do had their payslips sent in a none password protected email to a single employee who was somehow cc'd on the emails. Then a rather pathetic and very self serving apology was sent, by email, which again contained the payslip in none password protected format. Furthermore it said that in future if payslips are sent out in emails they will be done through the Brightpay App, "Your password is your date of birth" so now 95 people can easily find out each others passwords to the wages app,, the last thing it said was that if you want your password changing email your new password to the accounts guy and he will change it for you.
It is the most insane example of gross incompetence I think I've ever seen. The ordinary workers in this company do a GDPR training course, I don't think the same can be said for "The accounts team" which is who the apology email said was responsible, All the staff know "The accounts team" Is a guy called Simon who as far as I can tell is not trained in accounts but is the partner of the "Operations Director". As a snapshot of the competence of "The Accounts Team" my wages were missing a day this month and someone else of the 10 or so people I work with had 3 days pay sent to someone else's account because they share the same forename, they're both called Wendy, this type of thing happens regularly.
I can see 4 huge CDPR breaches there.
Any suggestions or advice would be greatly appreciated.
Thank you in advance.
b
0
Comments
-
I mean GDPR not CDPR0
-
My commiserations.
Looks like there’s a big round of well informed wage negotiations coming up. Employers as well as employees hate this kind of disclosure.What are you looking for?
compensation?
And at the least correction of the process going forward?
I’d be surprised if none of the 95 take this to the ICO so your room for individual negotiation may be limited.0 -
The organisation has a duty to report the data breach to the ICO, they have a duty to mitigate the impact of the breach, and HR should have a protocol in place to deal with the employee who breaches the GDPR. I would think disclosure to other employees of payslip information would constitute a serious breach and should not be allowed to be brushed under the carpet. Your employers may need reminding of this!
1 -
So 95 people had their payslip to themselves and also another person... was this the same additional person? Presumably they are an employee too? What role do they have?
Having a standard initial password isn't uncommon, we had 5 new starters this week and I know what all 5 of their passwords are because everyone who started this year has the same one and everyone last year you just had to change the 2024 to 2023. Arguably using DoB is more secure than that.
Have you actually looked at the BrightPay app and if you can self manage the change in password? Looking at their site it seems like you can do it yourself if you are worried about the accounts guy knowing your choice. In almost, if not all, employers there will be people in certain departments that can bypass whatever security is in place as it's necessary for them to do their role.
No requirement for someone in "accounts" to have any particular training. Sounds like more issues are driving the issue than simply what's just happened and this is just the straw thats broke the camels back.1 -
welcometomynightmare said:I didn't really know where to put this so if admins want to move it somewhere more appropriate that's fine.
Hello,
This month everybody, (I think it's about 95 people) who work where I do had their payslips sent in a none password protected email to a single employee who was somehow cc'd on the emails. Then a rather pathetic and very self serving apology was sent, by email, which again contained the payslip in none password protected format. Furthermore it said that in future if payslips are sent out in emails they will be done through the Brightpay App, "Your password is your date of birth" so now 95 people can easily find out each others passwords to the wages app,, the last thing it said was that if you want your password changing email your new password to the accounts guy and he will change it for you.
It is the most insane example of gross incompetence I think I've ever seen. The ordinary workers in this company do a GDPR training course, I don't think the same can be said for "The accounts team" which is who the apology email said was responsible, All the staff know "The accounts team" Is a guy called Simon who as far as I can tell is not trained in accounts but is the partner of the "Operations Director". As a snapshot of the competence of "The Accounts Team" my wages were missing a day this month and someone else of the 10 or so people I work with had 3 days pay sent to someone else's account because they share the same forename, they're both called Wendy, this type of thing happens regularly.
I can see 4 huge CDPR breaches there.
Any suggestions or advice would be greatly appreciated.
Thank you in advance.
b
If wages are being paid inaccurately as you suggest, then maybe the information is of limited value anyway.
Beware over-reacting to something which might actually have done little, if any, damage to anyone - BUT certainly check what actions the employer has taken, especially in relation to reporting to the ICO.Googling on your question might have been both quicker and easier, if you're only after simple facts rather than opinions!0 -
Sounds like utter incompetence from the accounts person0
-
welcometomynightmare said:I didn't really know where to put this so if admins want to move it somewhere more appropriate that's fine.
Hello,
This month everybody, (I think it's about 95 people) who work where I do had their payslips sent in a none password protected email to a single employee who was somehow cc'd on the emails.welcometomynightmare said:Then a rather pathetic and very self serving apology was sent, by email, which again contained the payslip in none password protected format.welcometomynightmare said:Furthermore it said that in future if payslips are sent out in emails they will be done through the Brightpay App, "Your password is your date of birth" so now 95 people can easily find out each others passwords to the wages app,, the last thing it said was that if you want your password changing email your new password to the accounts guy and he will change it for you.welcometomynightmare said:It is the most insane example of gross incompetence I think I've ever seen.welcometomynightmare said:The ordinary workers in this company do a GDPR training course, I don't think the same can be said for "The accounts team" which is who the apology email said was responsible, All the staff know "The accounts team" Is a guy called Simon who as far as I can tell is not trained in accounts but is the partner of the "Operations Director".welcometomynightmare said:As a snapshot of the competence of "The Accounts Team" my wages were missing a day this month and someone else of the 10 or so people I work with had 3 days pay sent to someone else's account because they share the same forename, they're both called Wendy, this type of thing happens regularly.welcometomynightmare said:I can see 4 huge CDPR breaches there.welcometomynightmare said:I mean GDPR not CDPR
I can only see one, the initial emails.welcometomynightmare said:Any suggestions or advice would be greatly appreciated.
Thank you in advance.
b
If you are feeling vindictive you could report it to the ICO, as a small business and the breach being minor they would likely get a letter though the post and be required to fill in an online form.0 -
What Matt(x3) has said above.
You could report it to the ICO if you really wanted, all that will happen (if the ICO choose to investigate at all) is they will email the company in about 3+ months time to ask what happened. The company will probably reply to say it was an administrative mistake and payslips will be sent out in future via a dedicated app. The ICO will probably then close the case.
Worth remembering that even when the ICO determines a serious breach has take place, they have the power to fine a company or reprimand them but they do not (and do not have the power) to award compensation.
I would just move on.0
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 350K Banking & Borrowing
- 252.7K Reduce Debt & Boost Income
- 453.1K Spending & Discounts
- 242.9K Work, Benefits & Business
- 619.8K Mortgages, Homes & Bills
- 176.4K Life & Family
- 255.9K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.1K Discuss & Feedback
- 15.1K Coronavirus Support Boards