Originally posted by PerfectStorm
View Post
- Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
- Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
Nixon Williams hit by Cyber Security incident
Collapse
X
Collapse
-
-
Originally posted by PerfectStorm View PostInterestingly, they haven't notified former customers of any breaches.
This means one of two things, that nothing was breached for customers they don't have any more... or data was breached, and they're failing in their statutory duties.
Which do you think it is?Comment
-
Originally posted by PerfectStorm View PostInterestingly, they haven't notified former customers of any breaches.
This means one of two things, that nothing was breached for customers they don't have any more... or data was breached, and they're failing in their statutory duties.
Which do you think it is?
In fact they should keep it for a while anyway, and they have a right to.
I suspect it has been breached but their focus is on current customers not leaving, and not getting fined too much by the ICO.
Anyone got an email address for the JSD/NW Data Protection Officer?
I want to get a DSAR fired off as I suspect that's the only way they'll tell me if my data has been breached.Last edited by Lance; 14 February 2022, 11:55.See You Next TuesdayComment
-
Originally posted by Lance View PostI seriously doubt they have removed old customers data.
In fact they should keep it for a while anyway, and they have a right to.
- an accountant's obligations under GDPR (basically have the bare minimum info you need, and deleting it as soon as you're done with it) and,
- an accountant's obligations under AML (Anti Money Laundering, basically to have lots of personal "know your client" data, and keep it for at least 6 years after a client leaves).
Our understanding is AML trumps GDPR, so accountants have to keep lots of data on you whilst they act, after you've left, indeed even if you ask them to delete all data they hold on you (they won't, and legally are right not to).
It is a bit scary with stuff like this. Yes accountancy firms should take various steps to ensure the data they hold is secure, but they're legally required to hold a lot of data they'd probably prefer not to!Comment
-
Originally posted by Lance View Post
Anyone got an email address for the JSD/NW Data Protection Officer?
I want to get a DSAR fired off as I suspect that's the only way they'll tell me if my data has been breached.Comment
-
Originally posted by ladymuck View Post
According to the privacy policy on the NW site it's this: [email protected]
This pro forma was provided to me by a CISO who called it his 'nightmare scenario GDPR DSAR letter'
Dear Sir/Madam:
I am writing to you in your capacity as data protection officer for your company. I am making this request for access to personal data pursuant to Article 15 of the General Data Protection Regulation. I am concerned that your company’s information practices may be putting my personal information at undue risk of exposure or in fact has breached its obligation to safeguard my personal information.
I was a customer of SJD accountancy, for my LTD. Company <snip>. I expect you will still have my information.
If you require further information, please contact me by email.
I would like you to be aware at the outset, that I anticipate the reply to my request within one month as required under Article 12, failing which I will be forwarding my inquiry with a letter of complaint to the appropriate data protection authority.
Please advise as to the following:
1. Please confirm to me whether or not my personal data is being processed. If it is, please provide me with the categories of personal data you have about me in your files and databases.
a. In particular, please tell me what you know about me in your information systems, whether or not contained in databases, and including e-mail, documents on your networks, or voice or other media that you may store.
b. Additionally, please advise me in which countries my personal data is stored, or accessible from. In case you make use of cloud services to store or process my data, please include the countries in which the servers are located where my data are or were (in the past 12 months) stored.
c. Please provide me with a copy of, or access to, my personal data that you have or are processing.
2. Please provide me with a detailed accounting of the specific uses that you have made, are making, or will be making of my personal data.
3. Please provide a list of all third parties with whom you have (or may have) shared my personal data.
a. If you cannot identify with certainty the specific third parties to whom you have disclosed my personal data, please provide a list of third parties to whom you may have disclosed my personal data.
b. Please also identify which jurisdictions that you have identified in 1(b) above that these third parties with whom you have or may have shared my personal data, from which these third parties have stored or can access my personal data. Please also provide insight in the legal grounds for transferring my personal data to these jurisdictions. Where you have done so, or are doing so, on the basis of appropriate safeguards, please provide a copy.
c. Additionally, I would like to know what safeguards have been put in place in relation to these third parties that you have identified in relation to the transfer of my personal data.
4. Please advise how long you store my personal data, and if retention is based upon the category of personal data, please identify how long each category is retained.
5. If you are additionally collecting personal data about me from any source other than me, please provide me with all information about their source, as referred to in Article 14 of the GDPR.
6. If you are making automated decisions about me, including profiling, whether or not on the basis of Article 22 of the GDPR, please provide me with information concerning the basis for the logic in making such automated decisions, and the significance and consequences of such processing.
7. I would like to know whether or not my personal data has been disclosed inadvertently by your company in the past, or as a result of a security or privacy breach.
a. If so, please advise as to the following details of each and any such breach:
i. a general description of what occurred;
ii. the date and time of the breach (or the best possible estimate);
iii. the date and time the breach was discovered;
iv. the source of the breach (either your own organisation, or a third party to whom you have transferred my personal data);
v. details of my personal data that was disclosed;
vi. your company’s assessment of the risk of harm to myself, as a result of the breach;
vii. a description of the measures taken or that will be taken to prevent further unauthorised access to my personal data;
viii. contact information so that I can obtain more information and assistance in relation to such a breach, and
ix. information and advice on what I can do to protect myself against any harms, including identity theft and fraud.
b. If you are not able to state with any certainty whether such an exposure has taken place, through the use of appropriate technologies, please advise what mitigating steps you have taken, such as
i. Encryption of my personal data;
ii. Data minimisation strategies; or,
iii. Anonymisation or pseudonymising;
iv. Any other means
8. I would like to know your information policies and standards that you follow in relation to the safeguarding of my personal data, such as whether you adhere to ISO27001 for information security, and more particularly, your practices in relation to the following:
a. Please inform me whether you have backed up my personal data to tape, disk, or other media, and where it is stored and how it is secured, including what steps you have taken to protect my personal data from loss or theft, and whether this includes encryption.
b. Please also advise whether you have in place any technology which allows you with reasonable certainty to know whether or not my personal data has been disclosed, including but not limited to the following:
i. Intrusion detection systems;
ii. Firewall technologies;
iii. Access and identity management technologies;
iv. Database audit and/or security tools; or,
v. Behavioural analysis tools, log analysis tools, or audit tools;
9. Regarding employees and contractors, please advise as to the following:
a. What technologies or business procedures do you have to ensure that individuals within your organisation will be monitored to ensure that they do not deliberately or inadvertently disclose personal data outside your company, through e-mail, web-mail, or instant messaging, or otherwise.
b. Have you had had any circumstances in which employees or contractors have been dismissed, and/or been charged under criminal laws for accessing my personal data inappropriately, or if you are unable to determine this, of any customers, in the past twelve months.
c. Please advise as to what training and awareness measures you have taken to ensure that employees and contractors are accessing and processing my personal data in conformity with the General Data Protection Regulation.
Yours Sincerely,See You Next TuesdayComment
-
I would be sending that to their head office, signed for on delivery. I believe there's more for this story to run. I am not convinced these people are competent enough to abide by their statutory responsibilities.Public Service Posting by the BBC - Bloggs Bulls**t Corp.
Officially CUK certified - Thick as f**k.Comment
-
Originally posted by Fred Bloggs View PostI would be sending that to their head office, signed for on delivery. I believe there's more for this story to run. I am not convinced these people are competent enough to abide by their statutory responsibilities.
I may send one by recorded delivery, after 30 days, and after I report them to the ICO for failing.
I'm too lazy to print it out and walk to the post office basically.See You Next TuesdayComment
-
Originally posted by Lance View Post
Apparently a DSAR can be submitted on toilet paper and handed in to a receptionist at a branch office and still be valid.
I may send one by recorded delivery, after 30 days, and after I report them to the ICO for failing.
I'm too lazy to print it out and walk to the post office basically.Comment
-
Originally posted by ladymuck View Post
What you need is something like this then: https://www.docmail.co.uk/
Thank you.See You Next TuesdayComment
- Home
- News & Features
- First Timers
- IR35 / S660 / BN66
- Employee Benefit Trusts
- Agency Workers Regulations
- MSC Legislation
- Limited Companies
- Dividends
- Umbrella Company
- VAT / Flat Rate VAT
- Job News & Guides
- Money News & Guides
- Guide to Contracts
- Successful Contracting
- Contracting Overseas
- Contractor Calculators
- MVL
- Contractor Expenses
Advertisers
Contractor Services
CUK News
- Five tax return mistakes contractors will make any day now… Yesterday 09:27
- Experts you can trust to deliver UK and global solutions tailored to your needs! Jan 8 15:10
- Business & Personal Protection for Contractors Jan 8 13:58
- ‘Four interest rate cuts in 2025’ not echoed by contractor advisers Jan 8 08:24
- ‘Why Should We Hire You?’ How to answer as an IT contractor Jan 7 09:30
- Even IT contractors connect with 'New Year, New Job.' But… Jan 6 09:28
- Which IT contractor skills will be top five in 2025? Jan 2 09:08
- Secondary NI threshold sinking to £5,000: a limited company director’s explainer Dec 24 09:51
- Reeves sets Spring Statement 2025 for March 26th Dec 23 09:18
- Spot the hidden contractor Dec 20 10:43
Comment