Skip to content
Solved
SearchBrowse
Sign in

Contents

Official guidance
Debt Management and Banking Manual

DMBM510200 · Customer contact and data security: confidentiality

  • DMBM510210 · Introduction
  • DMBM510220 · Responsibility
  • DMBM510230 · Disclosing information
  • DMBM510240 · Notes on record
  • DMBM510250 · Recording bank details
  • DMBM510260 · Subject Access Request (SAR) made under the DPA 2018.
  • DMBM510270 · If in doubt
  • DMBM510280 · Bogus callers
  1. Customer contact and data security: confidentiality: contents
  2. Customer contact and data security: confidentiality: recording bank details

DMBM510250 | Customer contact and data security: confidentiality: recording bank details

From HM Revenue & Customs · Debt Management and Banking Manual

Some content of this manual is being considered for archiving. If there is content you use regularly, please email [email protected] to let us know as soon as possible.

Electronic recording

You should never manually record bank account details in free format notes on any of our systems.

When data is stored in this way it can be manipulated. It would also have to be made available if a request was made under the Data Protection Act which may raise concerns from our customers. For more information on the act, see DMBM513170.

Therefore, make sure you do not manually record bank account or debit/credit card details on the notes screen of any of our computer systems. This includes the IDMS Action History.

If, on further investigation, you discover there has been a breach of security, you should report it as a security incident to the Security & Information Directorate (S&ID).

(This content has been withheld because of exemptions in the Freedom of Information Act 2000)

PreviousNext
PrivacyTerms