This story about TK Maxx is one of many, at the moment there is no legal obligation on companies in the UK to notify their customers of a data breach. In California, and soon across USA, this right of notification is mandatory. And I thought European privacy laws were supposed to be advanced……?
TK Maxx owner hit by card breach
Stores in the US, UK, Canada, Ireland and Puerto Rico are affected
Hackers have stolen information from at least 45.7 million payment cards used by customers of US retailer TJX, which owns TJ Maxx, and UK outlet TKMaxx.
In a statement to US watchdogs the firm said it did not know the full extent of the theft and its effect on customers.
TJX added that the security breach may also have involved TK Maxx customers in the UK and Ireland.
But the company did add that at least three-quarters of the affected cards had expired or data had been masked.
The company also told the BBC that 100 files were moved from its UK computer system in 2003, and two files were later stolen.
Question marks
However, a spokesperson admitted that the firm may never know what was in those files.
“We don’t know what was in those files – the technology the hacker used prevents TJX from knowing, and also the fact that TJX system routinely deletes files,” the spokesperson added.
The data was accessed on TJX’s systems in Watford, Hertfordshire, and Massachusetts over a 16-month period from July 2005 and covers transactions made by credit and debit card dating as far back as December 2002.