JL1985
Striker
I made a complaint to an energy company a few weeks ago and when they responded, they mixed me up with another customer on a few occasions. I notified them about this and they then sent me the below email.
“In regard to the incident, we understand that while responding to your complaint, the personal details of another customer were incorrectly shared with you due to human error. We apologise for this error.
As an organisation, we take our data protection obligations very seriously and have an obligation to comply with the Data Protection Act 2018, and other relevant data protection legislations. We therefore legally require you:
1) to not share any information, you have received with anyone else
2) immediately delete and dispose securely of any copies of the data you have received regarding the other customer and confirm to us once you have done so.
To confirm, we have contacted the affected customer and have let them know that their information was sent to another recipient by mistake.
To reiterate, can you also please confirm to us when you have completed the above actions in regard to the affected customer’s detail.”
Do I actually legally have to do anything of what they say?
Any advice would be appreciated.
Thanks
“In regard to the incident, we understand that while responding to your complaint, the personal details of another customer were incorrectly shared with you due to human error. We apologise for this error.
As an organisation, we take our data protection obligations very seriously and have an obligation to comply with the Data Protection Act 2018, and other relevant data protection legislations. We therefore legally require you:
1) to not share any information, you have received with anyone else
2) immediately delete and dispose securely of any copies of the data you have received regarding the other customer and confirm to us once you have done so.
To confirm, we have contacted the affected customer and have let them know that their information was sent to another recipient by mistake.
To reiterate, can you also please confirm to us when you have completed the above actions in regard to the affected customer’s detail.”
Do I actually legally have to do anything of what they say?
Any advice would be appreciated.
Thanks