U.K. fines company that collected data from new moms, then sold it to Equifax
Full article621 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Bounty UK collected information from new mothers, mothers-to-be, as well as the birth dates and genders of young children, according to the ICO.
Bounty UK, a pregnancy and parenting club, has been hit with the equivalent of a $524,000 fine for illegally sharing personal information belonging to more than 14 million people with credit reference and marketing agencies, Britain’s data protection authority announced Friday.
The U.K. Information Commissioner’s Office fined Bounty UK £400,000 for collecting personal information “directly from new mothers at hospital bedsides,” through merchandise claim cards, its website and mobile app. The company collected information from new mothers, mothers-to-be, as well as the birth dates and genders of young children, according to the ICO.
Bounty UK then would supply that data, some 34.4 million records, to 39 third party services including Equifax and other data brokers that in the past have failed to protect customer information. The fine was enforced for violations of the U.K.’s Data Protection Act, which requires firm to be transparent in their data collection practices, and involves activity from 2017 and 2018, before the General Data Protection Regulation (GDPR) took effect.
“Bounty’s actions appear to have been motivated by financial gain, given that data sharing was an integral part of their business model at the time,” Steve Eckersley, the ICO’s director of investigations, said in a statement.
“Such careless data sharing is likely to have caused distress to many people, since they did not know that their personal information was being shared multiple times with so many organisations, including information about their pregnancy status and their children.”
Bounty advertises itself as a parenting company that welcomes new mothers “into an online community where they can share problems, worries, tips and achievements with a support network of mums who are going through the same thing.”
One of Bounty’s clients was Acxiom, a database marketing firm which offers an ad targeting tool that allows clients to target customers based on their demographics. Corporate partners include Facebook, Cisco, IBM, Outbrain and MongoDB, according to Acxiom’s website.
Recent security incidents have increased awareness about the potential issues that come with sharing sensitive information without the proper protocols. Researchers discovered in February that an e-ticketing system used by eight airlines, including Southwest, was inadvertently exposing customers’ flight information, CyberScoop reported. Companies throughout the private sector now are experimenting with various ways of assessing their partners’ security risks both because of regulatory scrutiny and the apparent likelihood hackers will steal their information.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/bounty-uk-fine-uk-ico-gdpr/