“… contains abundance of 16-digits card numbers, card holder full names and addresses, and 4-digits clear PINs as examples of the type of information that a ‘hacker’ might seek.”
“The amount of evidence is really extensive - ~36 GB, so I am attaching only initial material and sending it via two emails. Please forward it to the Reviewing Officer. If he/she requires all data I can send it via USB memory stick or any way you will advise. 1. Examples of private and sensitive data of members of public, included in the CPS material: Visa/Mastercard unencrypted PANs, PINs, CVV2s, Expiry dates, cardholders addresses, emails, phone numbers, Passwords and million of records of corresponding card payments transactions. …”
“I was provided with a big volume of files that contain data I believed should be protected. Along with card numbers the files contain CVV2s with corresponding expiry dates and unencrypted PINs. So please respond to this email so I can report this data breach accordingly.”
“The file you have been given would have been served to you via the Crown Prosecution Service (CPS). The reason they would have sent this file would be to do with disclosure which they have to do with all criminal cases. The data would have been blocked by the banks when it was seized by the Police back in 2017. Therefore, the data is no longer valid data and therefore not subject to PCI DSS, therefore no data protection breach. I would advise that you should be careful about sharing such material, where you have stored this information and where it is viewed, as the police may see this as being in possession of fraud data and you could be committing further offences [sic] by having it in your possession and distributing it. The CPS are the ones that served you with the information. I suggest you contact them if you believe you have been sent the data in error and return it to them. We thank you for bringing this to our attention but as the data is dead data this matter is not a Visa issue and we deem the matter closed.”
“Further to my request for review of April 1, 2021 please add to the 2021/151245 case the attached my email communications to Visa and Mastercard organisations (Correspondence to Visa and Mastercard (emails).docx) ...”
“This email is to let you know that due to Metropolitan Police and CPS failure to inform the members of the public affected by the data breaches (Police ref PC4361/20, CPS ref 431-2020-2021) and enforceData Protection Act and The Payment Services Regulations 2017 s73, s99, starting November 6, 2021 we will be contacting the affected people and businesses via direct email communications. According to available to us information, hundreds thousands of holders of Visa and MasterCard cards, which were issued and processed by [at the time of the incident] Dubai/Isle of Man-based company Global Processing Services on behalf of numerous FCA-regulated “Fintech” companies such as Wirecard, Revolut, Monzo and Starling Bank were affected, and their private data was distributed to various parties, including ourselves. The data contains clear Visa/MasterCard card numbers, unencrypted PINs, CVV2, expiry dates, unencrypted usernames and passwords, cardholder names, email addresses, phone numbers, residential addresses and history of their financial transactions, and based on our communication with Visa and MasterCard organisations no cardholders were informed about the use of their data, neither their active payment instruments were cancelled. No actual private data will be sent within our emails but the affected people will be offered to receive their personal data along with detailed evidence coming from the investigation material into conducts of MPCCU, CPS and a specific Global Processing Services employee as summarised in the attached ‘Data breaches Met Police investigation report.pdf’ and corresponding ‘Correspondence to Visa and Mastercard (emails).pdf’ documents.”
“Please see attached a draft grounds I currently think of. I will very likely have more once I receive/not receive a response to my enquiries to Met/CPS.”
“In my opinion, therefore, the disclosure of documents by the prosecution as unused material under its common law obligations did generate an implied undertaking not to use them for any collateral purpose. I agree with the reasoning of Brooke J. on this point in Mahon v. Rahn and I think that Sir Michael Davies was right to strike out the action for the reasons which he gave. I do not propose to express a view on the further points which arose in Mahon v. Rahn [1998] Q.B. 424, namely whether the undertaking applies also to used materials and whether it survives the publication of the statement in open court. I do not do so because these questions may well have been overtaken by the express provisions of theCriminal Procedures and Investigations Act 1996 . But I would draw attention to the comments of Brooke J. in Mahon v. Rahn on the question of whether the provisions of Ord. 24, r. 14A (which was introduced in response to a decision of the European Court of Human Rights holding that the previous law unduly limited freedom of expression) and, by parity of reasoning,section 17(3)(6) of the Act of 1996, are not too widely drawn. There seems to me much force in his view that the court should nevertheless retain control over certain collateral uses of the documents, including the bringing of libel proceedings.”
“… it is apparent from Lord Hoffman’s words that the law is not clear, …”
“Disclosure not falling within s.17(1) (such as that made before “the relevant time”, § 12-49) is subject to an implied undertaking not to use the material for any purposes other than the proper conduct of the particular case: Taylor v Director of the Serious Fraud Office [1999] 2 A.C. 177, HL.”
“11.93 … In criminal cases, it was thought for a time that there was no implied undertaking of confidentiality analogous to that applying to documents disclosed in civil proceedings.182 It is now clear, however, from the decision of the House of Lords in Taylor v Serious Fraud Office 183 that documents seized during a criminal investigation are to be treated as confidential. 11.94 The provisions of the 1996 Act apply only to unused material; that is to say, there is no protection for material which has been read out or exhibited in open court. …”
“Compliance by the prosecution with its obligation to disclose material to the defence generates an implied undertaking at common law not to use unused (and probably also used) material for any purpose other than the conduct of the defence.218”
“Taylor v SFO [1999] 2 A.C. 177 HL. In Canada it has been held that no undertaking exists in relation to documents provided by the Crown: Consolidated NBS Inc v Price Waterhouse (1992) 94 D.L.R. (4th) 176 Ont. Ct.; though see also P (D) v Wagg (2004) 239 D.L.R. (4th) 501 Ont. CA. In Breslin v McKenna [2008] IEHC 122, the Irish High Court left open the question whether there was an implied undertaking in respect of documents disclosed for the purposes of criminal proceedings.”
“… , three elements are normally required if, apart from contract, a case of breach of confidence is to succeed. First, the information itself, in the words of Lord Greene M.R. in the Saltman case on p. 215, must 'have the necessary quality of confidence about it.' Secondly, that information must have been imparted in circumstances importing an obligation of confidence. Thirdly, there must be an unauthorised use of that information to the detriment of the party communicating it. ...”
“The accused may use or disclose the object or information— (a) in connection with the proceedings for whose purposes he was given the object or allowed to inspect it, (b) with a view to the taking of further criminal proceedings (for instance, by way of appeal) with regard to the matter giving rise to the proceedings mentioned in paragraph (a), or (c) in connection with the proceedings first mentioned in paragraph (b).”
“All of the acts referred to above were carried out with a view to clearing my name and appealing against my conviction.”