So, a configuration snafu by the sound of it. But it's also drawn attention to the fact that they share customers' phone numbers with 'selected trusted partners' which will probably come as a surprise to many. If their audit mechanisms and processes are so lax that sharing phone numbers with the whole internet wasn't recognised, how well managed can we expect the 'trusted partners' white list to be?
> "A: The only information websites had access to is your mobile number, which could not have been linked to any other identifying information we have about customers."
The problem here is not that it was only the mobile number, rather that these sites are able to link your mobile number to the content that you have viewed. There's a scenario here in which sites that had collected this information could publish (or otherwise leak, i.e. through hacking) lists of mobile numbers to URLs visited.
In an age of lax privacy protections and data-sharing it's not hard to obtain people's mobile numbers. What would happen when a potential employer googles your mobile phone number and finds the crawled data?
Steps we now need to take:
1) Some kind of request to get the full list (Subject Access Request under DPA, as pointed out below?)
2) If there is no opt-out process, lodge a Data Protection complaint to the ICO
> A Freedom of Information request to get the full list,
Although (as far as I know) the FOI Act only applied to public bodies (government and organisations like universities). So O2 wouldn't need to comply with a request under that act. Not sure if the ICO could force them to disclose that info, but I doubt it.
That is correct. You can issue Subject Access Request under the Data Protection Act to find out information about an individual (yourself) and who this has been shared to. You can only issue a SAR in writing and there is a capped charge for £10 for the privilege.