Massive Data Privacy Breach and Incompetence by Impellam
I work as a contractor for a large systems integration company. A few weeks ago it made a decision to outsource their staffing functions for contractors to the Guidant Global division of Impellam. In preparation for the outsourcing, Impellam was sent the personal details of most of the contractors, including mine. Based on my preliminary research into Impellam and reading reviews, I had my doubts about their professionalism. For instance, we were invited to send emails with our questions, however, none of my emails were answered. I received multiple communications from Impellam containing URLs to their website, however, all the URLs had mistakes and it was impossible to get to Impellam’s website using them. I welcomed the opportunity to attend an online meeting with Impellam and ask questions.
During the meeting I asked questions about whether my personal data would be kept secure and GDPR (Data Protection) compliance. I was assured by two Impellam staff members, (assigned Project Managers) that I should have no concerns, and there is complete GDPR compliance. Unknown to me at that time, there had been a massive data privacy breach by Impellam less than two hours earlier. My personal information had been sent to circa 300 individuals who should not of had the information. Hundreds of other people are in a similar situation as a result of the data breach. This was known to the Impellam project manager when he answered my questions as he was the source of the data breach.
Naturally I am very concerned about the data breach since this exposes me to identify theft, impersonation, fraud, and hacking. The leaked information included the my sign-on ID to my employer’s time keeping and expense claim system.
I sent an email to Impellam copying CEO Julia Robertson inquiring into the data breach and follow up actions, but did not receive the courtesy of a reply.
I subsequently received a telephone call from an Impellam employee who advised me she had the private information relating to all contractors and there are no controls in respect of obtaining access to the dat
INCOMPETENCE ON AN INDUSTRIAL SCALE
I believe there was a requirement for Impellam employees to place a URL (Web link) in their email trailer for access to the Impellam data privacy policy. I received emails from multiple Impellam employees with incorrect URLs. Each with a different error, rendering the URLs useless. Even after I pointed out the errors, no corrections were made. This is indicative of several things:
- A lack of professionalism
- A lack of attention to detail
- No lack of understanding of the most basic concepts
- A careless attitude
- A lack of quality control
I advised my employer I could not transfer to Impellam due to the data breach, their dishonesty, and the very real risk that I would be exposed to identity theft if I provided them with identity documents such as a passport or driver’s license. They were very understanding and indicated they did not expect me to have dealings with Impellam in view of what transpired. Instead, they made arrangements for me to continue my contract through a third party consulting company, at great expense.
DISREGARD FOR DATA PROTECTION LAWS
I sent Impellam a statutory Data Deletion request, as prescribed under the Data Protection Act. However, Impellam continued sending me communications as if I was using their payroll service. Apart from their stupidity, it demonstrates a disregard for Data Protection laws. It also demonstrates that Impellam’s data handling procedures are in incomplete disarray.
I will place a recording of the February 28th Impellam presentation in order listeners
can hear for themselves the blatant misrepresentations made by Impellam and the lack of ethics.
28 February 2023
Unprompted review