We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Starling bank gave details of my finances in an unsecure email

2»

Comments

  • leshoopers11
    leshoopers11 Posts: 22 Forumite
    Seventh Anniversary 10 Posts Name Dropper

    I have received a final response to my complaint from Starling. Having checked with their Privacy team they have concluded that the email to me containing details of my bank accounts (the account numbers and totals of transactions) did not "meet the principles" of a privacy breach.

    They have offered me £75 to compensate me for the distress and inconvenience caused.

    I may exercise my right to file a complaint with the Financial Ombudsman.

  • flaneurs_lobster
    flaneurs_lobster Posts: 10,525 Forumite
    10,000 Posts Seventh Anniversary Photogenic Name Dropper

    They have offered me £75 to compensate me for the distress and inconvenience caused.

    I may exercise my right to file a complaint with the Financial Ombudsman.

    Point of principle or hoping for more cash?

  • leshoopers11
    leshoopers11 Posts: 22 Forumite
    Seventh Anniversary 10 Posts Name Dropper

    The offer of compensation might still stand as it relates to how they treated me, not for the breach of privacy. But yes there is a point of principle too, given that if they don't think that they did anything wrong, then they will be doing it to other customers too.

  • flaneurs_lobster
    flaneurs_lobster Posts: 10,525 Forumite
    10,000 Posts Seventh Anniversary Photogenic Name Dropper
    edited 5 March at 12:30PM

    Would have thought it's quite hard to quantify your losses due to Starling putting some transaction totals in an email, unless you've already worked out a number?

    The regulator might impose punitive fines against Starling for their lapses (wouldn't be the first time) but you won't be seeing any of that.

  • leshoopers11
    leshoopers11 Posts: 22 Forumite
    Seventh Anniversary 10 Posts Name Dropper

    if Starling learn a lesson as a result of my complaint that will be good enough for me.

  • eskbanker
    eskbanker Posts: 41,010 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic

    As well as, or perhaps instead of, escalating a complaint to the Financial Ombudsman Service, you have the option of complaining to the Information Commissioner's Office, responsible for data protection matters. They won't get involved in any financial compensation for you, but if you're wanting Starling's conduct to be scrutinised by the relevant authority (and potentially added to similar complaints from others) then this avenue is available to you…

  • leshoopers11
    leshoopers11 Posts: 22 Forumite
    Seventh Anniversary 10 Posts Name Dropper

    I have just consulted the ICO and they replied that organisations are only responsible for setting appropriate security measures to their data protection processes. Apparently it is the individual's responsibility to keep their email information secure. So no help there!

  • eskbanker
    eskbanker Posts: 41,010 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic

    Not sure the person you dealt with really understood the key point about the inherent lack of security of unencrypted email during transmission, as opposed to internal processes at each end, but ultimately if the ICO doesn't consider the matter to constitute a privacy breach then it's unlikely that anyone else will.

    A quick look at their site shows more concern about inadequate CC/BCC practices and protection of genuinely sensitive personal data, rather than any specific guidance about good practice for email content - it does seem to have become standard within most financial institutions to avoid transmission of account-specific data by standard email, but perhaps this is independent of any ICO input.

  • leshoopers11
    leshoopers11 Posts: 22 Forumite
    Seventh Anniversary 10 Posts Name Dropper

    The ICO response put the responsibility on me for the bank sending me an unsecure email. So they effectively agreed with Starling who denied any wrong doing as I had given them the right to send me emails when I initially opened my account. It was a rather disappointing response.

  • masonic
    masonic Posts: 29,863 Forumite
    Part of the Furniture 10,000 Posts Photogenic Name Dropper
    edited 5 March at 5:00PM

    Well that's clearly nonsense. You have no control over what a third party sends you. I suggest you forward the ICO the emails and then report them for a data breach as the responsible party. ;)

    In all seriousness, I would make use of https://ico.org.uk/make-a-complaint/complaints-and-compliments-about-us/

    In your complaint, ask them if they are aware of Article 5(1)(f) of UK GDPR.

Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 354.6K Banking & Borrowing
  • 254.5K Reduce Debt & Boost Income
  • 455.5K Spending & Discounts
  • 247.5K Work, Benefits & Business
  • 604.4K Mortgages, Homes & Bills
  • 178.6K Life & Family
  • 261.9K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.