Payments

Nexi and orderbird Collaborate to Launch New Payment Platform for German ISVs

Nexi, a leading European payments company, and its subsidiary Orderbird, a provider of Point of Sale (POS) systems, have announced the launch of the Nexi Partner Portal (NPP) in Germany, according to Fintech Finance News. This new platform is designed to streamline payment processing for Independent Software Vendors (ISVs) across various industries, including retail and […]

Nexi and orderbird Collaborate to Launch New Payment Platform for German ISVs Read More »

A 30% Jump in Visa & Mastercard Fees, who takes the hit?

The Payment Systems Regulator (PSR) published an interim report on their market review of card scheme and processing fees, particularly focusing on the dominance of Mastercard and Visa. This report, a comprehensive examination of the complex financial network that underpins everyday transactions, laid bare the substantial impact these fees have on businesses and consumers alike.

A 30% Jump in Visa & Mastercard Fees, who takes the hit? Read More »

Peace of Mind for Developers: Apple’s Secure Platform Empowers Innovation

The allure of smartphones and tablets is undeniable, but the vast ecosystem of apps that fuel them can be a breeding ground for fraudsters. Apple, however, has emerged as a champion for user safety, implementing a robust multi-layered defense system that has thwarted a staggering $7 billion in potentially fraudulent transactions on the App Store

Peace of Mind for Developers: Apple’s Secure Platform Empowers Innovation Read More »

Verifone & Logos Join Forces to Transform Self-Service Payments

The landscape of self-service payments is poised for a significant transformation. Industry leaders Verifone, a titan in FinTech solutions, and Logos Payment Solutions, a pioneer in unattended payment technology, have announced a strategic partnership. This collaboration aims to revolutionize the way businesses and consumers interact in a variety of unattended payment scenarios. What are Unattended

Verifone & Logos Join Forces to Transform Self-Service Payments Read More »

How Unified Ledgers Offer Efficiency and Flexibility

What are unified ledgers? Imagine your financial life as a house. You might have a room where you store cash and coins, another secure vault for precious metals and jewelry, and perhaps a digital safe for storing cryptocurrency. While these rooms serve their purposes, keeping everything separate creates inefficiencies. Moving assets between them can be

How Unified Ledgers Offer Efficiency and Flexibility Read More »

FinTech Frontrunner SumUp Circles Up $1.6 Billion Loan

SumUp, a pioneer in the FinTech space for small businesses, has secured a significant financial boost with a $1.6 billion loan deal. This financing, led by Goldman Sachs Asset Management, serves a dual purpose: refinancing existing debt and fueling the company’s ambitious international expansion plans. The deal marks a strategic shift in SumUp’s capital acquisition

FinTech Frontrunner SumUp Circles Up $1.6 Billion Loan Read More »

Bridging the Gap: M-Pesa’s Role in Financial Inclusion

Smartphone apps and contactless payments are commonplace and it’s easy to take for granted the convenience and security of modern financial transactions. However, for millions of people in developing nations, access to traditional banking systems remains elusive. Brick-and-mortar banks might be inaccessible, leaving cash as the only option – a risky and limiting proposition. This

Bridging the Gap: M-Pesa’s Role in Financial Inclusion Read More »

Open Banking Poised to Gain Momentum in Wake of LVMH, Visa, Mastercard Lawsuit

The recently publicised legal battle between luxury giant LVMH and payment network Visa and Mastercard might seem like a squabble amongst titans, a mere financial tug-of-war with little bearing on the average consumer. However, beneath the surface lies a psychological undercurrent, a potential shift in the way we perceive and interact with money, particularly for

Open Banking Poised to Gain Momentum in Wake of LVMH, Visa, Mastercard Lawsuit Read More »

A Fingerprinted Future for Retail Payments – Are You Ready to Join?

Mutual Trust Bank (MTB), a leading private commercial bank headquartered in Dhaka, Bangladesh, has forged a strategic partnership with Norway’s IDEX Biometrics to introduce cutting-edge biometric payment cards to the Bangladeshi market. This collaboration aims to revolutionize payment security by integrating fingerprint authentication technology directly into physical payment cards, enhancing both convenience and security for

A Fingerprinted Future for Retail Payments – Are You Ready to Join? Read More »

Fiserv’s Clover Ignites Growth with New Offerings in the Point-of-Sale Market

The Fiserv Inc nearly five-year-old acquisition of First Data Corp for $22 billion is proving to be a linchpin in its growth strategy. The deal introduced Clover, a sophisticated suite of point-of-sale technologies, which is now driving substantial revenue growth for the Milwaukee-based firm. Clover’s innovative products and broad market applications are swiftly making it

Fiserv’s Clover Ignites Growth with New Offerings in the Point-of-Sale Market Read More »

We use cookies to improve user experience and analyse website traffic. By clicking ‘Accept’, you agree to our website’s cookie use as described in our Privacy Policy.

Post-Brexit: data protection
Card processor sends sensitive data to wrong address
24 August 2022

Worldline SA subsidiary Payone GmbH has been accused of breaching data protection rules after it sent sensitive employee payroll information to the wrong address by accident. The Worldline Group holdS a 60% stake in the Frankfurt based company who have a small UK market presence.

In June 2021, one of Payone GmbH’s ex UK employees (the data subject) received a “potential data breach notification” from the firm advising him that his salary, National Insurance data, nationality (Special Category Data) was amongst various bits of information sent to an incorrect home address.

This included personal information such as the former employees name, age and address.  It also included details such as the date of birth and the amount of annual work bonus he received in his bank account amongst other identifiable data.

Payone GmbH confirmed that this document was sent out in error following an employee making a mistake when re-entering data processed by their third-party payroll provider.  The error arose when the employee was fulfilling an Article 15 GDPR request. The error was spotted by the data subject when he noticed in an email version of the document that the postal address was incorrect. An attempt to notify Payone GmbH of the error went in vain as the document was already irretrievably despatched.

The data subject was alarmed with the incident which exposed him to the possibility of fraudulent activity, amidst reasonable fears his data could end up on the dark web and used by criminals.  Habitually resident in the UK he complained to the Information Commissioner’s Office (ICO) in June 2021. He similarly raised the concern in Germany via The Hessian Commissioner for Data Protection and Freedom of Information (HBDI).

The ICO reprimanded Payone GmbH for the error in their final decision letter.
Similarly, the HBDI cited a violation of Article 5(f) of the General Data Protection Regulation (GDPR) relating to integrity and confidentiality.

The ICO stated in their July 2021 findings that Payone GmbH, “should take steps to ensure that all personal data records are accurate and up to date. Holding inaccurate information, such as addresses, does increase the risk of personal data breaches and poses risks to the security of information”.

The HBDI confirmed in their October 2021 findings that Payone GmbH had taken remedial action. They concluded that a monetary fine would not be imposed on Payone GmbH as they had taken technical and organisational steps in response to the data breach. Data subjects could now request their data in an autonomous portal.

The GDPR, which came into effect in 2018, gave the Information Commissioner’s Office greater powers to tackle data breaches. The new ‘UK GDPR’ charts its own course after Brexit whilst seeking to maintain EU GDPR adequacy.  In extreme scenarios, organisations face penalties of up to £20m or 4 per cent of their global worldwide turnover, whichever is more.

In the years prior to GDPR, the ICO fines were capped at £500,000.

The data subject said: “I am just glad I spotted it; they were going to resend the document again to another wrong address. Prior to Brexit the process would have been commenced via the ICO who in turn would liaise with the HBDI on the data subjects’ behalf; but I found myself communicating with both authorities separately which was an additional step but in the end was surprisingly
effective. Unfortunately, Payone GmbH again sent my incorrect address to the
Workers Pension Trust in January 2022, and documents yet again went to the wrong address. In my opinion they have not learned from the first time and my complaint is sitting with the ICO yet again”.

The former employee is pursuing a remedy under Article 82 UK GDPR via
the Court’s of England & Wales.

Extraordinary Experiences

Click edit button to change this text. Lorem ipsum dolor sit amet, consectetur adipiscing elit.

Click edit button to change this text. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

Our Core Values

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.