Three HSBC Holding subsidiaries has been fined a total £3 million (US$4.9 million) for failing to protect their customers’ confidential information.
The fines, imposed by the UK’s Financial Services Authority on Jully 22, constituted the highest ever handed out the regulator for data security breaches.
They consisted of £1.6 million for HSBC Life UK, £875,000 to HSBC Actuaries and Consultants, and £700,000 to HSBC Insurance Brokers.
In imposing the fines, the FSA said that the three wholly owned HSBC Subsidiaries had sent out customer information that was unencrypted through the mail or courier services to third parties. On two separate occasion, the data never arrived at its intended destination.
The authority said one of the firms, HSBC Acturaries, had posted two floppy disks on two separate occasions contain customers’ information, and which was lost. The bank was then warned that it would have to strengthen its security procedure to avoid similar incidents, but further losses occurred despite the warning – including an unencrypted CD with details of 180,000 policy holders including their names, ages, sex, dates of birth, and policy numbers.
In December 2006, HSBC Insurance Brokers began disposing of customer data, such as bank account details, as regular waste paper. They were left in open sacks in its head office’s reception area before being collected as rubbish.
Margaret Cole, FSA’s enforcement director, said that all three firms had failed their customers by being careless with personal details which could have landed in the hands of criminals. “It is also worrying that increasing awareness around the importance of keeping personal information safe and the dangers of fraud didn’t prompt the firms to do more to protect their customer’s details.”
HSBC Insurance group managing director Clive Bannister said that it “sincerely regretted” the incidents, and that it has implemented more rigorous system, better checks, and more training to improve data protection. Staff will now be trained to make sure all confidential data is encrypted, he added. The banking group also in the process of contacting all the customers whose personal information may have been leaked, he said. He said that no affected customers have reported any losses from the lapse.








