Major UK supermarket managers/ colleagues sharing customer names, addresses, phone numbers, door codes, and front door photos on personal WhatsApp — how severe is this GDPR breach?
​
Home delivery operations for one of the major UK supermarkets, and I’m deeply concerned about a widespread, unmonitored practice happening at store level that I believe is a major data protection nightmare.
Managers and colleagues have established informal, personal WhatsApp groups on their personal mobile devices to manage daily operational issues and driver updates.
Because these groups are run on personal, unmanaged phones rather than secured corporate systems, the following data is routinely broadcast, downloaded, and stored across dozens of private handsets:
Full Customer PII: First and last names, direct personal telephone numbers, and full home addresses.
Property Access Data: Private gate codes, keylock numbers, door entry passcodes, and safe-place instructions.
Residential Property Photos: High-resolution photos of customers' front doors, driveways, and private building entryways taken on personal cameras.
Why this feels extremely dangerous:
Zero Data Lifecycle Control: When colleagues or managers leave the business, there is no corporate IT oversight to remote-wipe their personal devices. Ex-employees leave with complete camera-roll archives containing customer addresses, phone numbers, door codes, and photos of private properties.
Physical Security Risk: Pairing exact residential addresses and phone numbers with door access codes and visual photos of entryways creates a tangible physical security and burglary risk for homeowners.
UK GDPR & Data Protection Act Breaches:
This completely bypasses corporate security controls (Article 5(1)(f) Integrity and Confidentiality) and processes customer data outside its intended delivery purpose (Article 5(1)(b) Purpose Limitation).
My Questions:
From a legal and UK GDPR perspective, how severely does the ICO view major retailers allowing personal messaging apps to process customer PII and access codes?
If reported to the ICO, is this the kind of systemic breach that triggers mandatory corporate audits or enforcement fines?
What is the most effective route to force accountabilityreporting directly to the ICO, consumer privacy watchdogs (like Which?), or news media?