retail

ZEPZ Secures $267 Million to Bolster Expansion in African Markets

Zepz, the parent company of money transfer service Sendwave, has successfully raised $267 million in a fresh round of funding, aimed at fueling its expansion efforts across key African regions and beyond. This latest capital infusion came from a blend of both new and existing investors, underscoring the company’s robust appeal and growth potential in […]

ZEPZ Secures $267 Million to Bolster Expansion in African Markets Read More »

Hibbett Elevates API and Bot Security with Cequence’s Unified Protection Platform

Hibbett, the prominent athletic-inspired fashion retailer, has taken a significant step to bolster its digital security by adopting the Cequence Unified API Protection (UAP) platform. This strategic move aims to strengthen API security and bot management across Hibbett’s extensive online and in-store operations. In response to a critical SaaS migration to Oracle Cloud and Azure

Hibbett Elevates API and Bot Security with Cequence’s Unified Protection Platform Read More »

Stripe Strengthens Merchant of Record Capabilities with Lemon Squeezy Acquisition

Global payments powerhouse Stripe has acquired Lemon Squeezy, a rising star in the digital sales platform arena. The acquisition, announced on Friday, signifies a significant step in Stripe’s ongoing mission to simplify online payments and expand its services for businesses of all sizes. Founded in 2020 amidst the global pandemic, Lemon Squeezy quickly gained traction

Stripe Strengthens Merchant of Record Capabilities with Lemon Squeezy Acquisition Read More »

Laings Introduces Exclusive Patek Philippe Section in Glasgow Boutique

The Luxury Jeweller Celebrates a Long-standing Partnership with the Swiss Watchmaker Laings, the esteemed family-owned jeweller, has revealed a newly dedicated Patek Philippe section within its flagship store in Glasgow, Scotland reflecting the luxury and sophistication synonymous with the Swiss watch brand. Situated on the ground floor of the store, this new space epitomises the

Laings Introduces Exclusive Patek Philippe Section in Glasgow Boutique Read More »

Wero – The Future of European Payments

Wero, a cutting-edge European payment platform developed by the European Payments Initiative (EPI), is poised to revolutionize digital transactions. With a focus on speed, security, and user-friendliness, Wero aims to become the go-to choice for both consumers and businesses across Europe. What is Wero? Wero is an innovative mobile payment solution designed to simplify and

Wero – The Future of European Payments Read More »

AC Milan Debuts New Flagship Store in Milan’s Bustling Center

AC Milan proudly announces the grand opening of its latest flagship store on Via Dante, a lively street in Milan’s vibrant core. This flagship store promises to be a prime destination for AC Milan supporters and a key attraction for tourists, merging the club’s iconic red and black spirit with the city’s unique style and

AC Milan Debuts New Flagship Store in Milan’s Bustling Center Read More »

Nexi and orderbird Collaborate to Launch New Payment Platform for German ISVs

Nexi, a leading European payments company, and its subsidiary Orderbird, a provider of Point of Sale (POS) systems, have announced the launch of the Nexi Partner Portal (NPP) in Germany, according to Fintech Finance News. This new platform is designed to streamline payment processing for Independent Software Vendors (ISVs) across various industries, including retail and

Nexi and orderbird Collaborate to Launch New Payment Platform for German ISVs Read More »

gucci, brand, sunset-4883607.jpg

Challenges as Gucci Sales Decline: How Card Processing Firms Might Step Up with Better Value

Kering, a titan in the industry, faces significant financial headwinds as it reports a projected 40-45% decrease in operating profit for the first half of 2024. This downturn is notably reflected in a pronounced revenue slump at Gucci, one of its flagship brands, which has seen an 18% drop in organic revenues in the first

Challenges as Gucci Sales Decline: How Card Processing Firms Might Step Up with Better Value Read More »

JD Sports’ Journey from a Single Store to Global Dominance & Hibbet Sports

In a significant move that strengthens its foothold in the American market, JD Sports Fashion plc, a leading UK-based retailer of athletic apparel, has officially announced its acquisition of Hibbett Sports, a prominent retail player in the United States. The deal, valued at approximately $1.1 billion, underscores JD Sports’ ambitious strategy to expand its global

JD Sports’ Journey from a Single Store to Global Dominance & Hibbet Sports Read More »

IKEA Launches Its Premier Logistics Hub in Ireland

The renowned Swedish furniture giant, celebrated the opening of its first logistics center in Ireland, situated in Rathcoole, Dublin. This expansive 27,000 square meter facility boasts the capacity to store 20,000 cubic meters, accommodating 9,000 distinct product varieties from IKEA’s extensive catalog. This new hub, which has created 200 jobs, promises to slash delivery times

IKEA Launches Its Premier Logistics Hub in Ireland Read More »

We use cookies to improve user experience and analyse website traffic. By clicking ‘Accept’, you agree to our website’s cookie use as described in our Privacy Policy.

Post-Brexit: data protection
Card processor sends sensitive data to wrong address
24 August 2022

Worldline SA subsidiary Payone GmbH has been accused of breaching data protection rules after it sent sensitive employee payroll information to the wrong address by accident. The Worldline Group holdS a 60% stake in the Frankfurt based company who have a small UK market presence.

In June 2021, one of Payone GmbH’s ex UK employees (the data subject) received a “potential data breach notification” from the firm advising him that his salary, National Insurance data, nationality (Special Category Data) was amongst various bits of information sent to an incorrect home address.

This included personal information such as the former employees name, age and address.  It also included details such as the date of birth and the amount of annual work bonus he received in his bank account amongst other identifiable data.

Payone GmbH confirmed that this document was sent out in error following an employee making a mistake when re-entering data processed by their third-party payroll provider.  The error arose when the employee was fulfilling an Article 15 GDPR request. The error was spotted by the data subject when he noticed in an email version of the document that the postal address was incorrect. An attempt to notify Payone GmbH of the error went in vain as the document was already irretrievably despatched.

The data subject was alarmed with the incident which exposed him to the possibility of fraudulent activity, amidst reasonable fears his data could end up on the dark web and used by criminals.  Habitually resident in the UK he complained to the Information Commissioner’s Office (ICO) in June 2021. He similarly raised the concern in Germany via The Hessian Commissioner for Data Protection and Freedom of Information (HBDI).

The ICO reprimanded Payone GmbH for the error in their final decision letter.
Similarly, the HBDI cited a violation of Article 5(f) of the General Data Protection Regulation (GDPR) relating to integrity and confidentiality.

The ICO stated in their July 2021 findings that Payone GmbH, “should take steps to ensure that all personal data records are accurate and up to date. Holding inaccurate information, such as addresses, does increase the risk of personal data breaches and poses risks to the security of information”.

The HBDI confirmed in their October 2021 findings that Payone GmbH had taken remedial action. They concluded that a monetary fine would not be imposed on Payone GmbH as they had taken technical and organisational steps in response to the data breach. Data subjects could now request their data in an autonomous portal.

The GDPR, which came into effect in 2018, gave the Information Commissioner’s Office greater powers to tackle data breaches. The new ‘UK GDPR’ charts its own course after Brexit whilst seeking to maintain EU GDPR adequacy.  In extreme scenarios, organisations face penalties of up to £20m or 4 per cent of their global worldwide turnover, whichever is more.

In the years prior to GDPR, the ICO fines were capped at £500,000.

The data subject said: “I am just glad I spotted it; they were going to resend the document again to another wrong address. Prior to Brexit the process would have been commenced via the ICO who in turn would liaise with the HBDI on the data subjects’ behalf; but I found myself communicating with both authorities separately which was an additional step but in the end was surprisingly
effective. Unfortunately, Payone GmbH again sent my incorrect address to the
Workers Pension Trust in January 2022, and documents yet again went to the wrong address. In my opinion they have not learned from the first time and my complaint is sitting with the ICO yet again”.

The former employee is pursuing a remedy under Article 82 UK GDPR via
the Court’s of England & Wales.

Extraordinary Experiences

Click edit button to change this text. Lorem ipsum dolor sit amet, consectetur adipiscing elit.

Click edit button to change this text. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

Our Core Values

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.