ICO knew about T-Mobile data breach for a year
A freedom of information request has shown the investigation has been underway since last December.


T-Mobile first notified data watchdogs that members of its staff were selling off personal data nearly a year ago, the Information Commissioner's Office (ICO) has admitted.
Last month, the ICO said it was investigating one of the major mobile operators - later found to be T-Mobile - after employees were discovered be selling off user data.
Since then, a Freedom of Information Act request has revealed that T-Mobile notified the ICO of the problem on 16 December last year.
The request also asked the ICO to detail how many people were involved in the case, how many warrants had been doled out, and correspondence between the watchdog and the firm - all of which the ICO refused to do, as such information is exempt from the act.
An ICO spokeswoman told IT PRO that the watchdog has several ongoing investigations that have not been made public, and that the year between the case being handed to it and now has been spent investigating. Since December, the ICO has "launched a full investigation and is preparing a a case for possible prosecution," she said. "We don't make public most of the details in our investigations."
Why no Phorm investigation?
The FOIA request, sent by P John, also asked why the ICO "would take such drastic action against T-Mobile, yet take no action at all with respect to the BT/Phorm scandal?"
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
To that, the ICO responded: "As you will appreciate the issues involved in these two matters are very different. In respect of the T-Mobile issue the ICO is looking into possible criminal offences committed under the DPA [data protection act] whereas the matter of BT and Phorm regarding targeted online marketing did not involve any criminal offences under the DPA but raised issues of fair processing and compliance with the first Data Protection principle."
Freelance journalist Nicole Kobie first started writing for ITPro in 2007, with bylines in New Scientist, Wired, PC Pro and many more.
Nicole the author of a book about the history of technology, The Long History of the Future.
-
CyberOne appoints Microsoft’s Tracey Pretorius to its advisory board
News The threat intelligence leader will provide strategic guidance to CyberOne’s executive team
By Daniel Todd
-
CISA issues warning in wake of Oracle cloud credentials leak
News The security agency has published guidance for enterprises at risk
By Ross Kelly
-
TikTok to open first European data centre in Ireland
News The move could signify a desire to shift its operations away from the US as well as secure its position in the European market
By Sabina Weston
-
MPs in a muddle over GDPR and storing voters' personal data
News Labour MP Chris Bryant says his staff were told to delete constituents' data
By Bobby Hellard
-
Trump resort will not be charged for breaching data laws
News Presidential hopeful's Scottish golf course failed to register under the Data Protection Act for four years
By Adam Shepherd
-
Banks urged to share data but warned over security
News Experts voice concern over security of open API recommendations
By Rene Millman
-
EU centralises European open data through one portal
News Open Data Portal will enable public sector bodies to share information
By Rene Millman
-
Experts question sheer scale of data storage required by Snooper's Charter
News Who will foot bill for physical infrastructure to house UK's browsing histories?
By Jane McCallion
-
Snapchat's T&Cs update could put user data at risk
News Kaspersky said giving the service permission to share pictures with third parties could lead to a serious breach of privacy
By Clare Hopping
-
Transport Systems Catapult launches data sources catalogue
News Intelligent Mobility Data Index could push forward smart transport innovation in the UK
By Caroline Preece