WORLDLINE SA ubsidiary Payone GmbH are today accused of breaching data protection regulation after it sent sensitive employee payroll information to the wrong address by accident.
The Worldline Group hold a 60% stake in the Frankfurt based company who have a small UK market presence. In June 2021, one of Payone GmbH’s ex UK employees (the data subject) received a “potential data breach notification” from the firm advising him that his salary, National Insurance data, nationality was amongst various bits of information sent to an incorrect address.
This included personal information such as the former employees bonus salary, date of birth, name, age and address. It also included details such as the amount of annual work bonus he received in his bank account amongst other identifiable data. Payone GmbH confirmed that this document was sent out in error following an employee making a mistake when re-entering data processed by their third-party payroll provider. The error arose when the employee was fulfilling an Article 15 GDPR request. The error was spotted by the data subject when he noticed in an email version of the document that the postal address was incorrect. An attempt to notify Payone GmbH of the error went in vain as the document was already irretrievably despatched. The data subject was alarmed with the incident which exposed him to the possibility of fraudulent activity, amidst reasonable fears his data could end up on the dark web and used by criminals. Habitually resident in the UK he complained to the Information Commissioner’s Office (ICO) in June 2021. He similarly raised the concern in Germany via The Hessian Commissioner for Data Protection and Freedom of Information (HBDI).
The ICO reprimanded Payone GmbH for the error in their final decision letter. Similarly, the HBDI cited a violation of Article 5(f) of the General Data Protection Regulation (GDPR) relating to integrity and confidentiality. The ICO stated in their July 2021 findings that Payone GmbH,
“should take steps to ensure that all personal data records are accurate and up to date. Holding inaccurate information, such as addresses, does increase the risk of personal data breaches and poses risks to the security of information”. [Information Commissioner findings to Payone GmbH 2021]
The HBDI confirmed in their October 2021 findings that Payone GmbH had taken remedial action. They concluded that a monetary fine would not be imposed on Payone GmbH as they had taken technical and organisational steps in response to the data breach. Data subjects could now request their data in an autonomous portal.
The HBDI were referencing Worldline SA and Payone’s 2021 implementation of the OneTrust software which supports the use of a webform. The form is accessed via the Worldline privacy page and allows data subjects to request their data under Article 15 GDPR. Loopline media has noted however that the webform lacks capability to upload any documents. Such an upload functionality would support data subjects where they are providing verification identification such as passports and proof of address where that is required. OneTrust Technology Limited have an office nestled in the city of London, whilst their global HQ is based in Atlanta, USA.
The GDPR, which came into effect in 2018, gave the Information Commissioner’s Office greater powers to tackle data breaches. The new ‘UK GDPR’ charts its own course after Brexit whilst seeking to maintain EU GDPR adequacy. In extreme scenarios, organisations face penalties of up to £20m or 4 per cent of their global worldwide turnover, whichever is more. In the years prior to GDPR, the ICO fines were capped at £500,000.
The data subject said: “I am just glad I spotted it; Payone were going to resend the document again to another wrong address. Prior to Brexit the process would have been commenced via the ICO who in turn would liaise with the HBDI on the data subjects’ behalf; but I found myself communicating with both authorities separately which was an additional step but in the end was surprisingly effective. The authorities were great and swift in reprimanding Payone GmbH who have offered no apology or update as to the whereabouts of the lost data.
Unfortunately, Payone GmbH only 8 months after the ICO reprimand shockingly failed to take care of their data accuracy and sent my incorrect address to the Workers Pension Trust in January 2022, and documents yet again went to the wrong address. The Workers Pension Trust have been amazing and are supporting me to get to the bottom of this new issue. I am exhausted with it all and would not trust them to hold my data due to the carelessness. In my opinion they have not learned any lessons from the first time and my complaint is sitting with the ICO yet again”.
The legal representatives of Payone GmbH declined to comment on the article.