sharing stuff that @barneyc finds interesting
RSS icon Email icon LinkedIn Flickr Delicious FriendFeed Twitter
  • Hell – The Right Approach to a Data Breach

    Posted on July 23rd, 2010 BarneyC View Comments

    hell

    There are any number of approaches to data breaches in business today.  Whilst regulation is ever trying to get to the point where notification of breach is mandatory there are still plenty of businesses out there who will go to all sorts of lengths to sweep things under the carpet rather than own up.

    Not so Hell – a truly rocking pizza company in New Zealand.  Certainly no stranger to controversy – some of their marketing campaigns have been widely criticised, Hell seems to be taking the bull-by-the-horns and going all out to keep people happy.

    Today I received an email from them…

    Dear Valued Hell Customer,

    We have been approached by a party claiming to be in possession of
    customer details from the previous Hell website which is no longer in
    operation.  The samples that we received included details of four customers
    from 2006, including phone numbers and email addresses and order
    information. We can confirm that credit card data was not at risk as this
    is held independently on a secure banking website.

    Whilst we are still investigating the matter, we can confirm that the
    information was obtained without our knowledge and we have approached the
    New Zealand Police with a view to lodging a formal complaint.  Hell
    recognises the importance of protecting customer information and additional
    security measures were implemented earlier this year when our new website
    was rolled out (again, we reiterate that this is not an issue affecting the
    new website). As a further security measure your may wish to consider
    changing your passwords on other sites if they were the same as the old
    Hell Pizza website.

    We apologise for the incident and any inconvenience that this may have
    caused.

    Sincerely,
    Stu McMullin – Director Hell Pizza

    We acknowledge that some of you have asked to be removed from the database
    and we have only included you for the purposes of this notification.

    No mucking about, no bull just a straight forward there might be a problem, we know, the police know so go do this just to be safe.

    This IS the right approach to notification in my opinion.

    I’m not totally up to date on NZ privacy law (a couple of years out of date), so it could well be that by now notification is mandatory.  Even if it is, props to Hell for getting it out there.

    FYI: Hell pizza really is very very good.  Think PIzza Express with attitude.  Even better you can get them in the Hell Pizza UK – well London with branches in Fulham, Shepherds Bush and Clapham.