
The Mormon Church experienced a significant data breach affecting both current and former members. The retention of personal data after membership removal raises serious privacy concerns, particularly under European data privacy laws. This incident highlights the need for better data management practices within large organizations.
Large corporations suffering data breaches is nothing new. The Mormon Church, with an estimated net worth of almost $300 billion, is no exception. On October 13, 2022, an email from the church's data privacy office informed individuals that their personal data may have been affected by an unauthorized network intrusion. This incident raises important questions about data retention practices and privacy rights.
On March 23, 2022, the Mormon Church detected unauthorized access to certain computer systems. Following this discovery, they promptly notified federal law enforcement authorities in the United States. Initially, they were instructed to keep the incident confidential to protect the integrity of the investigation. This confidentiality was lifted on October 12, 2022, allowing the church to disclose the breach publicly.
While data breaches are common, the specifics of this incident are particularly noteworthy. The church did not only notify current members but also reached out to individuals who had previously had their membership removed. This raises a critical question: why did the church retain data on individuals who had opted out of their membership?
The data breach revealed that the church retains a significant amount of personal information even after a member has resigned. This includes:
This retention of data can be seen as disrespectful to those who wish to sever ties with the church. Moreover, it poses potential legal issues, especially under European data privacy laws, which grant individuals the right to be forgotten. According to these laws, individuals have the right to request the deletion of their personal data.
In response to inquiries from former members, the church has claimed an exception to the right to be forgotten based on the historical nature of the information and its doctrinal importance. They stated:
"As a result of your membership resignation, we do not hold personal information about you, and information about your former affiliation with the church is not held by or accessible to leaders or congregations in Great Britain."
However, they also acknowledged that limited historical information is retained in the United States, including name, birth date, and a record of the ordinances provided to the individual. The church maintains that this information is held in a secure and static restricted access file, justifying its retention as a matter of doctrinal importance.
The church's claim of retaining data for historical and doctrinal reasons raises significant privacy concerns. The retention of personal information, especially after a member has requested its deletion, contradicts the spirit of the right to be forgotten. This situation is further complicated by the fact that some individuals who attempted to remove their records were still victims of the data breach.
The church's assertion that the data is stored securely is called into question by the breach that occurred six months after they made this claim. This incident suggests that their data security measures may not be as robust as they believed.
In light of these events, it is worth considering what information the church truly needs to retain. The only essential data for membership purposes might be a person's name and membership number. Other details such as birth date, gender, mailing address, and phone number may not be necessary. If someone chooses to rejoin the church, they can provide this information again, and much of it may have changed since their departure.
The rationale for retaining email addresses, in particular, is unclear. It raises questions about the church's data management practices and their commitment to respecting the privacy of individuals who have chosen to leave.
The data breach at the Mormon Church highlights significant issues surrounding data privacy and retention practices within large organizations. As data breaches become increasingly common, it is crucial for institutions to evaluate their policies and ensure they are in compliance with privacy laws. The right to be forgotten should be respected, and organizations must prioritize the security of personal information to protect individuals from potential harm.
This incident serves as a reminder of the importance of transparency and accountability in data management, especially for organizations with vast amounts of sensitive information. As we move forward in a digital age, the protection of personal data must remain a top priority for all institutions.
Paste a YouTube link and let Magica create the key takeaways.
Summarize another video