Digital

A Fingerprinted Future for Retail Payments – Are You Ready to Join?

Mutual Trust Bank (MTB), a leading private commercial bank headquartered in Dhaka, Bangladesh, has forged a strategic partnership with Norway’s IDEX Biometrics to introduce cutting-edge biometric payment cards to the Bangladeshi market. This collaboration aims to revolutionize payment security by integrating fingerprint authentication technology directly into physical payment cards, enhancing both convenience and security for […]

A Fingerprinted Future for Retail Payments – Are You Ready to Join? Read More »

Standard Chartered Unveils New Open Banking Marketplace to Boost API Integration

In a significant development for digital banking, Standard Chartered today announced the launch of its Open Banking Marketplace, a robust platform designed to empower clients to explore and integrate application programming interfaces (APIs) more efficiently. This initiative marks a pivotal step in enhancing business-to-bank collaboration, offering both existing and prospective clients a user-friendly environment to

Standard Chartered Unveils New Open Banking Marketplace to Boost API Integration Read More »

Fintech in China: Integrating Payment Apps with Blockchain Growth

Navigating the digital landscape of payments in China is an exciting journey given the plethora of options available to consumers and businesses alike. Here’s a quick rundown of the top 5 Chinese payment apps that are reshaping how transactions are conducted in the world’s most populous country: Alipay: Alipay is the kingpin of mobile payment

Fintech in China: Integrating Payment Apps with Blockchain Growth Read More »

startup, business, people-849804.jpg

How Contract Lifecycle Management Transforms Legal, Procurement, and Finance Departments

Contract Lifecycle Management (CLM) has emerged as a pivotal process for managing, analyzing, and executing contract creation. The adoption of CLM practices gained momentum in 2018, and its significance has only amplified in the post-pandemic world. As businesses increasingly invest in contract management, it lays the foundation for growth and drives operational efficiency across various

How Contract Lifecycle Management Transforms Legal, Procurement, and Finance Departments Read More »

WhatsApp Workplace Dynamics and Communication Challenges

Where social media platforms reign supreme, communication in the workplace has undergone a significant transformation. Among the myriad of platforms available, WhatsApp has emerged as a popular choice for employees to stay connected, share information, and collaborate on various projects. However, the informal nature of WhatsApp communication, particularly when used in unofficial groups, poses a

WhatsApp Workplace Dynamics and Communication Challenges Read More »

Worldline Subsidiary, Payone, 2024 Court Dates and Legal Proceedings Announced

Worldline’s German-based entity, Payone GmbH, finds itself entangled in various legal proceedings spanning from regulatory-related matters to matters related to Equality Act proceedings. The scheduled court dates for these cases are as follows: 23 February 2024: County Court Hearing in London Payone is the Defendant in this matter Nature of the Matter: Relating to a

Worldline Subsidiary, Payone, 2024 Court Dates and Legal Proceedings Announced Read More »

credit card, bank card, theft-1591492.jpg

On Track to Financial Inclusion: Bridging the Gap for Individuals with Disabilities

Embarking on a journey through the intricate web of financial exclusion, we delve into the overlooked challenges faced by vulnerable groups. With a fresh perspective and our unique spin, we embark on an exploration of the impact on older individuals, those grappling with mental health issues, and the disabled community. As we embark on a

On Track to Financial Inclusion: Bridging the Gap for Individuals with Disabilities Read More »

city of london, bank, london-4481399.jpg

Advantages and Challenges in 2024 for Traditional Banks

The financial services landscape has undergone a profound transformation in recent years, propelled by the rise of fintech disruptors challenging traditional banking norms. This article explores the dynamic interplay between fintech innovators and traditional banks, highlighting their respective advantages and challenges in a rapidly evolving industry. As the fintech sector faces a challenging funding landscape,

Advantages and Challenges in 2024 for Traditional Banks Read More »

Ever Wondered? What’s Really Happening When You Tap Your Card at the Store?

Every time you tap your card or insert it into the terminal, you’re embarking on a fascinating journey through the digital realm. The seemingly mundane act unfolds a series of intricate processes, involving technology, security measures, and a dash of magic. Let’s take a vivid journey through what happens behind the scenes when your card

Ever Wondered? What’s Really Happening When You Tap Your Card at the Store? Read More »

Is This More Than Just a Gift? Ethical Uncertainty in Business Holiday Season

A Festive Dilemma in the Corporate World The holiday season, with its spirit of giving, often extends into the workplace. But in the corporate world, this tradition of exchanging gifts can lead to a complex situation. Imagine you’re a corporate account manager or an IT manager, and a client or a team member sends you

Is This More Than Just a Gift? Ethical Uncertainty in Business Holiday Season Read More »

We use cookies to improve user experience and analyse website traffic. By clicking ‘Accept’, you agree to our website’s cookie use as described in our Privacy Policy.

Post-Brexit: data protection
Card processor sends sensitive data to wrong address
24 August 2022

Worldline SA subsidiary Payone GmbH has been accused of breaching data protection rules after it sent sensitive employee payroll information to the wrong address by accident. The Worldline Group holdS a 60% stake in the Frankfurt based company who have a small UK market presence.

In June 2021, one of Payone GmbH’s ex UK employees (the data subject) received a “potential data breach notification” from the firm advising him that his salary, National Insurance data, nationality (Special Category Data) was amongst various bits of information sent to an incorrect home address.

This included personal information such as the former employees name, age and address.  It also included details such as the date of birth and the amount of annual work bonus he received in his bank account amongst other identifiable data.

Payone GmbH confirmed that this document was sent out in error following an employee making a mistake when re-entering data processed by their third-party payroll provider.  The error arose when the employee was fulfilling an Article 15 GDPR request. The error was spotted by the data subject when he noticed in an email version of the document that the postal address was incorrect. An attempt to notify Payone GmbH of the error went in vain as the document was already irretrievably despatched.

The data subject was alarmed with the incident which exposed him to the possibility of fraudulent activity, amidst reasonable fears his data could end up on the dark web and used by criminals.  Habitually resident in the UK he complained to the Information Commissioner’s Office (ICO) in June 2021. He similarly raised the concern in Germany via The Hessian Commissioner for Data Protection and Freedom of Information (HBDI).

The ICO reprimanded Payone GmbH for the error in their final decision letter.
Similarly, the HBDI cited a violation of Article 5(f) of the General Data Protection Regulation (GDPR) relating to integrity and confidentiality.

The ICO stated in their July 2021 findings that Payone GmbH, “should take steps to ensure that all personal data records are accurate and up to date. Holding inaccurate information, such as addresses, does increase the risk of personal data breaches and poses risks to the security of information”.

The HBDI confirmed in their October 2021 findings that Payone GmbH had taken remedial action. They concluded that a monetary fine would not be imposed on Payone GmbH as they had taken technical and organisational steps in response to the data breach. Data subjects could now request their data in an autonomous portal.

The GDPR, which came into effect in 2018, gave the Information Commissioner’s Office greater powers to tackle data breaches. The new ‘UK GDPR’ charts its own course after Brexit whilst seeking to maintain EU GDPR adequacy.  In extreme scenarios, organisations face penalties of up to £20m or 4 per cent of their global worldwide turnover, whichever is more.

In the years prior to GDPR, the ICO fines were capped at £500,000.

The data subject said: “I am just glad I spotted it; they were going to resend the document again to another wrong address. Prior to Brexit the process would have been commenced via the ICO who in turn would liaise with the HBDI on the data subjects’ behalf; but I found myself communicating with both authorities separately which was an additional step but in the end was surprisingly
effective. Unfortunately, Payone GmbH again sent my incorrect address to the
Workers Pension Trust in January 2022, and documents yet again went to the wrong address. In my opinion they have not learned from the first time and my complaint is sitting with the ICO yet again”.

The former employee is pursuing a remedy under Article 82 UK GDPR via
the Court’s of England & Wales.

Extraordinary Experiences

Click edit button to change this text. Lorem ipsum dolor sit amet, consectetur adipiscing elit.

Click edit button to change this text. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

Our Core Values

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.