Anybody heard of Young Labour? It's the youth wing of the Labour Party and recently they had a big push about the fact that you could join for just a quid (no peerage included). The interesting thing is that if you go to the section to join online they ask, as you'd expect, for your personal details. You might notice that the page does not get that little secure socket padlock showing that your connection to the server is not encrypted.
If they were just asking for your name perhaps this wouldn't be a big deal, but, unbelievably, they're asking for people's credit card details as well. What's more they even seem to be suggesting people fraudulently join up too as they say "The credit card holder must be the person joining, or someone from the joiner's household." The data is then sent in plain text to god knows where by a basis POST request.
Will they ever learn? If they can't even be bothered to protect their own membership what can we honestly expect of their ability to protect data in Government?