I have a real problem with the pretense posed by the article that the club has no blame. They should have understood the risk they were taking on by subcontracting a vendor to collect passports, and better vetted that vendor. Obviously the service provider was completely inept, but that doesn't absolve the fools using them.
I preach to my clients this sort of PII should be treated as a toxic, hazardous substance. Ideally don't touch it with a 10 foot pole, and if you can't help it then limit the scope, protect it with strong access policies that severely limit who can touch it (including encryption keys conservatively custodied), and securely delete it all as soon as possible.
Too many companies these days point you to shoddy third parties for some kind of functionality (e.g. book an appointment, perform KYC on you, host the online learning platform for your course, etc.), inappropriately foisting both a new business relationship on you that you never asked for along with their partner's terms of service that you have no bargaining power in negotiating.
This is a side-effect of the SaaS era, and the model is broken.
If these kinds of breaches were actually costly, then people would indeed treat PII as toxic. But they aren't. The media brouhaha blows over within a week or so, and things are fine again.
Leaking PII should be very, very expensive, and then this idiocy would stop.
Everything is paid for by the customer. If you spend an absolute fortune protecting someone's named and address combination, that will be paid for by the customer.
So then the customer will just pay more, because the "prevent you from getting fined into oblivion" insurance businesses you just created with the flick of a pen will need to get paid their overhead and won't do it without a profit.
Then over confident, short sighted or shady characters will accept those directorships and/or sign off on the design because they think nothing will happen or don't care for jail.
What you didn't have was a computerised database which could spam everyone on that list in milliseconds, or profile everyone's character, purchase history, medical history, and more.
We used to do a lot of worse stuff too, like eat radium hoping for brighter skin.
The Payment Card Industry takes breaches deadly seriously. It is my opinion that any organization that collects PII should be held to the same standard (and penalties) that any organization that collects/processes credit card information.
It is quite interesting how this is handled world wide.
For me PII is very sensitive and I advice people to be very cautious.
Every business in the EU (were I live) also has to be very careful with such data by law. Fines are now at a level were they can hurt the business significantly.
During vacation in an Asian country on the other side all of this was basically a no brainer for smaller to medium businesses.
I once rented a scooter there and the business owner had all her documents organised in WhatsApp chats.
Including now my passport plus drivers licence...
The people in general in that country were also very relaxed when it came to giving out their contact details to random businesses.
I don't want to throw shade on them, thus no country name.
Incredible friendly and welcoming people there.
The article in the OP is about a company in the EU (the clubs) not taking this seriously by outsourcing their stuff to an Irish company, who also is not taking it seriously. Hell, in the article, the CEO pretty much says “yea we ignored EU law, we will get fined, whatever”.
Processing such PII here with an external AI partner:
- last week, we had bug: I said: "couldnt you just re-run the same step with the same data again" - their answer: "we cant! look at paragraph XY in our GDPR agreement, we are deleting all input documents everything after it has been processed"
Very well implemented! :)
(though, I had to upload and re-initiate eveything again)
> the pretense posed by the article that the club has no blame.
Remember that these clubs are mostly small, local businesses. Their owners just don't have the technical sophistication to evaluate software security.
Or the clout to demand an audit.
I preach to my clients this sort of PII should be treated as a toxic, hazardous substance. Ideally don't touch it with a 10 foot pole, and if you can't help it then limit the scope, protect it with strong access policies that severely limit who can touch it (including encryption keys conservatively custodied), and securely delete it all as soon as possible.
Too many companies these days point you to shoddy third parties for some kind of functionality (e.g. book an appointment, perform KYC on you, host the online learning platform for your course, etc.), inappropriately foisting both a new business relationship on you that you never asked for along with their partner's terms of service that you have no bargaining power in negotiating.
This is a side-effect of the SaaS era, and the model is broken.