The Daily Telegraph

Bupa fined over theft of customer data

- By Natasha Bernal

BUPA, the healthcare group, has been fined £175,000 for a “systematic data protection failure” after an employee stole thousands of customers’ data and offered it for sale on the dark web.

The breach, which happened between January and March 2017, affected 547,000 Bupa Global customers, who were not informed until two months after the incident. The Informatio­n Commission­er’s Office (ICO) said it had discovered technical and organisati­onal failures at Bupa that left 1.5 million records at risk for a long time.

The ICO’S investigat­ion revealed the healthcare insurer did not routinely monitor the informatio­n on SWAN, Bupa’s customer relationsh­ip management system, and was “unable to detect unusual activity, such as bulk extraction­s of data”. The employee copied the informatio­n on SWAN, deleted it from the company’s database and then tried to sell it on the dark web.

Due to the timings of the breach, Bupa has not been subjected to the new data protection fines under GDPR, which could have forced the company to pay up to £17million or 4 per cent of its global turnover.

A spokesman for Bupa Global said: “We accept this decision by the ICO and have cooperated fully with its investigat­ion.”

Newspapers in English

Newspapers from United Kingdom