The Privacy Policy was Perfect. The Customer Care Failed.
Mortgage firms love using GDPR Article 5 as a shield; for years now, they've leaned on the idea of data minimization to argue that gathering detailed info on a customer's vulnerability is too much of a privacy risk. They tell their auditors and themselves that holding less data is just safer.
It isn't safety. It's a strategic avoidance of operational responsibility.
The FCA and ICO put out a joint warning that pretty much kills this excuse. It's blunt. You can't use data protection laws to justify failing vulnerable customers. This is the most serious bit of regulatory coordination we've seen in the sector this quarter (which says something). For too long, firms have treated "Privacy by Design" as a mandate to ignore the human being on the other end of a mortgage application until they're invisible enough to be ignored legally.
When a firm claims it can't provide tailored support because doing so would require processing sensitive data that might violate minimization principles, they aren't practicing privacy. They're practicing neglect.
The higher ups always say the same thing: if we don't record the vulnerability, it can't leak during a breach, and it sounds like common sense in a board meeting. But the logic falls apart when you realize that ignoring a vulnerable customer causes systemic harm that is way worse than the risk of a single encrypted data entry, and GDPR doesn't stop you from processing sensitive data. It just asks for a legal basis and real safeguards. The duty to treat customers fairly gives you that basis.
The fallout here won't just hit the firms.
The second-order effects are going to hit auditors and professional indemnity insurers who signed off on these so-called "minimalist" compliance frameworks. For three years, consultants have been selling a version of compliance that prioritizes a clean spreadsheet over a functional outcome (which is weird). If an auditor validated a data retention policy that purposefully blinded a firm to its customers' needs, they didn't find a control; they helped build a blind spot.
We're seeing this "compliance as a cloak" trend in other places, too, and take the Florida DMV, where just under 200,000 records are currently circulating on shattered.io. Then there is the hospital employee recorded in their own restroom (yikes), which has triggered a HIPAA class action. In both cases, there was likely a policy on paper that looked immaculate while the actual operational reality was an absolute shambles.
Compliance isn't the absence of data; it's the presence of the correct data handled with integrity.
It comes down to whether these firms actually change how they onboard people. Or maybe they'll just tweak some wording in their privacy notices to look better, and if those CRM vulnerability flags stay empty, they're just ticking boxes.
Will the ICO start issuing fines for this specific kind of omission? I'm waiting to find out; until that happens, firms will keep pretending that ignoring customers is some kind of privacy victory.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- FCA and ICO tell firms GDPR is no excuse for failing vulnerable customers - Mortgage Soup Compliance Week (Google News)
- Lawsuits filed after potential massive driver’s license data breach - MSSP Alert Data Privacy (Google News)
- Class action suit filed by hospital employee recorded in restroom - - dominionpost.com Data Privacy (Google News)
- SEC's Adit Case Maps 5 Fault Lines In Pre-IPO Funds - law360.com Compliance Week (Google News)
- St. Clair Shores weighs restrictions on Flock license plate cameras - The Detroit News Data Privacy (Google News)
- Florida DMV Claim: 200K Records, $2,500 DPPA Risk [2026] - shattered.io Data Privacy (Google News)
- Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity Information - cyberpress.org Data Privacy (Google News)
- Appeals Court Rules IRS Can't Share Taxpayer Data With ICE - sg.news.yahoo.com Data Privacy (Google News)