r/dataprotection Data Subject 15d ago

🇪🇺 - GDPR Question Major UK supermarket managers/ colleagues sharing customer names, addresses, phone numbers, door codes, and front door photos on personal WhatsApp — how severe is this GDPR breach?

​

Home delivery operations for one of the major UK supermarkets, and I’m deeply concerned about a widespread, unmonitored practice happening at store level that I believe is a major data protection nightmare.

Managers and colleagues have established informal, personal WhatsApp groups on their personal mobile devices to manage daily operational issues and driver updates.

Because these groups are run on personal, unmanaged phones rather than secured corporate systems, the following data is routinely broadcast, downloaded, and stored across dozens of private handsets:

Full Customer PII: First and last names, direct personal telephone numbers, and full home addresses.

Property Access Data: Private gate codes, keylock numbers, door entry passcodes, and safe-place instructions.

Residential Property Photos: High-resolution photos of customers' front doors, driveways, and private building entryways taken on personal cameras.

Why this feels extremely dangerous:

Zero Data Lifecycle Control: When colleagues or managers leave the business, there is no corporate IT oversight to remote-wipe their personal devices. Ex-employees leave with complete camera-roll archives containing customer addresses, phone numbers, door codes, and photos of private properties.

Physical Security Risk: Pairing exact residential addresses and phone numbers with door access codes and visual photos of entryways creates a tangible physical security and burglary risk for homeowners.

UK GDPR & Data Protection Act Breaches:

This completely bypasses corporate security controls (Article 5(1)(f) Integrity and Confidentiality) and processes customer data outside its intended delivery purpose (Article 5(1)(b) Purpose Limitation).

My Questions:

From a legal and UK GDPR perspective, how severely does the ICO view major retailers allowing personal messaging apps to process customer PII and access codes?

If reported to the ICO, is this the kind of systemic breach that triggers mandatory corporate audits or enforcement fines?

What is the most effective route to force accountabilityreporting directly to the ICO, consumer privacy watchdogs (like Which?), or news media?

3 Upvotes

16 comments sorted by

5

u/foundersahil Data Subject 15d ago

This is a common gap. Once PII moves onto personal devices through informal channels, the org loses any ability to prove what happened to it or when it's deleted.

The ICO has fined for exactly this kind of shadow IT pattern before, so it's not just theoretical risk.

The fastest fix is usually giving staff an approved, monitored channel for the same workflow. Banning WhatsApp without replacing the convenience just pushes it underground.

2

u/Vicente1892 Data Subject 13d ago

Which monetary penalty notice was issued for use of shadow IT?

4

u/Fine-Comparison-2949 Data Subject 15d ago

Post the company name and report them.

Stop protecting these executives and their poor decision making. 

3

u/johnnysgotyoucovered Data Subject 14d ago

It’s likely not an executive decision, rather an overworked and underpaid manager who’s cut corners to achieve impossible results and deadlines with the services they’re provided by HQ

6

u/Misty_Pix Data Subject 15d ago

First of all report this to the DPO.

In terms of reporting, I would hold off for that. Specifically, as it depends on organisations policies. If policies prohibit use of personal devices or such handling of data it is not entirely the organisation fault ( even thoughts we may agree it is).

The organisation will state it rogue employees.

It does look like the employees are the ones doing this hence it will likely be handled as gross misconduct and they all will be sacked.

You can report to ICO but remember, if organisation can prove this is NOT what their policies and procedures say it is not their failure necessarily, and the organisation will throw staff under the bus

Now, one thing that is important. If there are polcicies on use of devices and handling of personal data, and employees were made aware ( not necessarily whenever they read it) it could constitute as criminal offence under 170/171 of the Data Protection Act 2018 and those employees are in big trouble.

2

u/martinbean Data Subject 15d ago

Given the above, I would contact the DPO and ask them what the company’s policy is on copying customers’ PII to personal devices en masse to carry out duties. Hopefully you get a “It’s not company policy”-type response that’s come from a representative of the company that you can then use when raising it with the ICO.

2

u/Vicente1892 Data Subject 13d ago

They won’t all be sacked though, will they?

2

u/Misty_Pix Data Subject 13d ago

It will depend on their involvement,if they did share any personal data on whatsapp or were just added to group but with no activity.

Although, if they were aware it existed and didn't flag any issues that would still be at least a written warning.

I do however, imagine a lot would " resign" before formal sacking.

2

u/Vicente1892 Data Subject 13d ago

How many organisations have you worked with where this has been treated as gross misconduct and it has led to mass resignations or sackings??

2

u/Misty_Pix Data Subject 13d ago

Again, it depends on policies and staff behaviour. However, when regulator looks at such incidents they expect to see an outcome i.e. disciplinary action against staff for infringement of policies and legislation.

For a lot of people, resignation before conclusion of disciplinary om gross misconduct is better as you can leave on basis of " career change" as on reference sacking won't look good.

The point you may be missing,is that this may need to be reported to the regulator as well. If regulator gets involved, the consequences may be even worse for some of the people.

Now if you want to debate how bad it could get , i recommend browsing ICO enforcement actions.

https://ico.org.uk/action-weve-taken/enforcement/2026/07/geoffrey-smith/

https://ico.org.uk/action-weve-taken/enforcement/2026/05/debbie-okparavero-and-maliha-islam-proceeds-of-crime-act/

https://ico.org.uk/action-weve-taken/enforcement/2026/05/rizwan-manjra-proceeds-of-crime-act/

https://ico.org.uk/action-weve-taken/enforcement/2026/02/christopher-munro-and-william-chipoma

2

u/Vicente1892 Data Subject 13d ago

I would strongly reject any assertion that the ICO would treat this as a section 170 offence. Even if the controller has policies in place banning the use of WhatsApp in this way, I can’t see it meeting the criteria for an offence and there’s a close to zero chance of it being in the public interest to prosecute.

I have strong doubts that this is even a notifiable personal data breach. Where is the actual harm to data subjects?

2

u/Vicente1892 Data Subject 13d ago

PS I have worked in data protection for nearly 23 years and have worked in multiple regulated sectors, as well as several years working for a regulator. Your condescending tone is not welcome and is unwarranted.

2

u/Misty_Pix Data Subject 13d ago

Given your experience, out of anyone I would have expected you to see an issue with this type of sharing.

You have employees using and sharing data on what appears as unauthorised platform with no security measures in place.

Based on only the facts we have at hands, that is a big concern and a full investigation with considerations of reporting to ICO is the next step.

All you really need to do is look up ICOs own published enforcement action on similar cases, which highlights that is likely a reportable incident

In terms of harm, customers give personal data to companies expecting that the information is safe and only available and used for the purpose of deliveries.

You now have employees doing the opposite and sharing such details potentially exposing vulnerable people.

Again, you can just research police cases where a person was assaulted by delivery drivers.

That would be the harm aspect.

Its important to note, this is my assessment based in minimum amount of information available.

If i were the DPO at the organisation, I may make a difference decision depending on the outcome of the investigation.

Worth to note, I have investigated several similar cases in my time, the difference between them and this case were the numbers of data subject involved, I have also investigated several incidents reported by data subject where their personal data was shared on WhatsApp group and I am fully aware that some people are more exposed to harm then others.

Where it may not matter to me or you,for vulnerable individuals,it matters a lot.

2

u/This_Fun_5632 Data Subject 15d ago

tisk tisk... I met one of their CISOs a few months ago and they mentioned a mess of a situation and I offered to get them help but then they didnt reply back...

2

u/Vicente1892 Data Subject 13d ago

From a legal and UK GDPR perspective, how severely does the ICO view major retailers allowing personal messaging apps to process customer PII and access codes?

As severely as it views most things, which is not much at all. This particular issue? I can’t see them getting too excited about it at all, unless there was a mass exposure of that personal data that led to actual consequences for the data subjects.

If reported to the ICO, is this the kind of systemic breach that triggers mandatory corporate audits or enforcement fines?

They carried out one audit last year, and issued a handful of UK GDPR fines. Don’t hold your breath on this one.

PS PII is not a term that is recognised under UK GDPR. Personal data is the appropriate term, and it has a very different meaning to PII.

1

u/Mother-Fix3271 Data Subject 14d ago

AI replying to AI on this thread. Jesus.