Doing BCS (ISEB) Courses? Top Tips from a Successful Candidate

ANT ISEB WebsiteI have been asked to write a blog on what I had learned from recently taking – and thankfully passing – the ISEB/BCS courses in FOIA and DPA. Maybe I internalised the legislation too much, but for some reason I could only think of addressing it in terms of 8 principles:

1. Start from scratch

Whilst you may have a lot of knowledge and experience in FOI/DPA, try and go back to square one and approach the Acts like new legislation. You may find that, due to the demands of your sector and your role, you know different areas of the relevant Act much better than others. The syllabus leans towards no sector in particular so picking up the legislation again and starting from scratch can really help. Some of the areas I knew least about at the start of the course became the basis of my strongest essay answers.

2. The pen is mightier hard to write with than the keyboard

Writing legibly is one thing. Writing legibly for three hours is a whole different matter. If like me, you are so used to rattling away on a keyboard that you get cramp scrawling a shopping list, then it is time to do some training a good few weeks before your course starts. Start by trying to write a few pages of longhand, even if it is just copying some text. It is worth the effort. Investing in a couple of decent pens really helped my writing, which has never been the neatest.

3. Do your homework!

…as my mum used to shout! This is tough. You may feel inspired by the session and then find yourself back in a hectic day job, and suddenly training day comes round again. Try and find time for it, either over lunch at work or blocking time in the evenings. I knew people who wrote essays perfectly well on the tube – I don’t know how! The homework essay questions are essential to get back into that mode of constructing an argument and recalling facts. Avoid the ‘I did the essay in bullet points’ approach; presenting the argument in paragraphs and prose is as much part of the exercise as knowing the key points. It helps with principle 2 aswell.

4. Expand your mind

Many of us will make use of the ICO’s website or the JISC lists to pick up the latest information. For your exam and for your overall working knowledge it is really worth doing some ‘wider reading’. For matters FOI/DPA there is luckily a thriving blogosphere and twitterati (is that even a word?) to follow the latest developments. This is especially important for the DPA ISEB, where knowledge of the case law is vital. I found the following really useful (in no particular order) – there are many more:

Act Now Training http://www.actnow.org.uk/

Information Rights and Wrongs http://informationrightsandwrongs.com/

FOI Man http://www.foiman.com/

2040Information Law Blog http://2040infolawblog.com/

Panopticon http://www.panopticonblog.com/

Data Protector http://dataprotector.blogspot.co.uk/

David Higgerson http://davidhiggerson.wordpress.com/

whatdotheyknow.com https://www.whatdotheyknow.com/

Campaign for Freedom of Information http://www.cfoi.org.uk/

5. Enjoy the group

In both the DPA and FOI ISEBs, I have been really lucky to be in with a friendly and supportive group of co-students. The benefits of this go way beyond the practicalities of preparing for the exam. It is re-assuring to meet others who have faced the same challenges and problems. They may have tried different approaches to policy or procedural questions. Chat to the person next to you!

6. Don’t mock it

The mock exam is one of the most important parts of the whole course and invaluable in preparing you for the big day. You can do an essay question for homework under exam conditions but it won’t prepare you for starting the same question with only half an hour left on the clock and 25 pages of writing behind you. Treat it as much as possible like a real exam. Even going through the basics in the mock helped (e.g. how to fill out the multiple choice paper). It means that on the exam proper you can focus your stress on the questions themselves. I also learnt that eating an entire packet of mints in 3 hours would not necessarily enhance my exam performance.

7. Revise!

Forget DVD box sets or the football on TV for a few weeks – you have to make the revision count. Go for everything you can fit in: practice questions, podcasts, online seminars. I personally had a lot of difficulty with the Section B ‘bullet point’ questions, which rely on memorising information (e.g. the headings of the FOIA s45 Code of Practice). I found refuge in the humble index card to get the basics down and had friends or family test me. Make the time for yourself – you will reap the benefit come the exam.

8. Treat it as more than just a certificate

Education is becoming increasingly seen as a commodity, something you pay for and get a return from. Fair enough, the ISEB works like this. Work hard and get your certificate. And yet, like all education it does so much more than that. It fills you with ideas to take back to your workplace, makes you think about where you can take your new-found or rediscovered study skills (more part-time education or qualifications?) and develops contacts and networks with other practitioners.

Good luck!

Kit Good is University Records Manager and FOI Officer at the University of London. He has successfully completed both BCS (ISEB) courses with Act Now. Follow Kit on Twitter: @kit_urm and read his blog: http://allabouttherecords.blogspot.com/

Our next BCS (ISEB) courses start in June.  Delegates can now make use of our online resources page  with exclusive access to guidance notes, quizzes and over four hours of videos.

More advice about BCS ISEB and how to pass here:

http://actnowtraining.blog/2012/05/23/do-you-want-to-be-certified/

http://actnowtraining.blog/2012/01/31/how-to-pass-the-iseb-certificate/

Proposed EU Data Protection Regulation and Research

Man Reading Book and Sitting on Bookshelf in LibraryDavid Erdos believes a bid to tighten European data protection will have a chilling impact on social science and humanities research.  He writes:

Even with the advent of Web 2.0, data protection law is still often seen as technical and only narrowly applicable. Technical abstruseness aside (and data protection’s reputation here is certainly deserved), this understanding could not be more wrong. The existing European data protection framework really is breathtaking in scope. It applies to anything done electronically with any information about an identified or identifiable person – possibly including the dead. According to the European Union, even innocuous details in the public domain are protected (perhaps even the title of an author’s book). Moreover, if the information reveals the particulars of, for example, a person’s ethnic origin, political opinions, religious belief, trade union membership, health or criminality, then it is classed as “sensitive” and subject to even tighter controls. The European data protection framework is not only broad but often onerous. Barring specific exceptions (including a liberal one that can be invoked for journalism, literature and the arts), there is a presumption that individuals will be informed about the processing of data about them and given a right to object, that the processing of “sensitive” personal information will be banned and that no personal information will be transferred outside the European Economic Area without “adequate protection”.

So the popular perception of data protection is woefully inaccurate – which leads to a radical underestimation of the threat these regulations pose to the enjoyment of other fundamental rights and the pursuit of legitimate activities. Nowhere is this more the case than in social science and humanities research. Since the advent of the EU’s framework in the 1990s, researchers have witnessed dramatic restrictions on their freedom to use “sensitive” data and to deploy covert methods. Coupled with the growth of sometimes intrusive “ethical review” policies, the barriers and burdens placed in the way of even ordinary, innocuous, yet socially beneficial research and on researchers have become considerable.

It might have been hoped that the proposed EU Data Protection Regulation would provide an opportunity to reverse this. But if the European Parliament’s recently published draft amendments are anything to go by, the converse is true.

Contunue reading here.

This article was originally published in the 14-20 February 2013 edition of Times Higher Education and is published with the author’s permission. You can also read it on the Constitutional Law website.

The draft EU DP Regulation will be examined in our forthcoming 1 hour Data Protection Update Webinar : http://www.actnow.org.uk/courses/930

Unkindleness

Likkindlee many other dads, and mums and ordinary human beings I received a Kindle as a Xmas present.

Having ripped off the wrapping paper and found it had power I registered my device in the process passing my contact details to Amazon.

I quickly found a book I’d been looking for in charity shops and libraries for just £1-99 so bought it and 30 seconds later there it was on my shiny hi-tech beautiful slimline direct marketing device.

It’s the adverts you see. Now and again it shows me an advert. I didn’t ask for it. I never had a legitimate expectation I’d have adverts on my Kindle. I couldn’t find a way to turn them off. Research on the net shows that Amazon subsidise the price of a Kindle and if I refund the subsidy (about £15) I can stop the ads.

Amazon didn’t tell me nor did the retailer. The price paid was for a Kindle not a discounted Kindle. Do I have any rights here? Answers on a postcard to Section 10, Act Now Training, The Internet.

I will write to Argos (my retailer) and point out that they shouldn’t send me Marketing  and no doubt they’ll pass me on  to Amazon. Or is it direct marketing? Have Amazon found a way to direct market to me in an indirect way? Will Big  Chris listen to my complaint and take action or do I need to find another 99 people who feels the same as me. Answer in several months. Watch this blog.

Leveson: What future for Data Protection?

LevesonThe Leveson Report has finally been published.

The Report recommends that a tougher form of self-regulation backed by legislation should be introduced to uphold press standards. Much has already been written (http://www.bbc.co.uk/news/uk-20543936) and will continue to be written about this central recommendation and whether it is good or bad for democracy and a free press. But amid the furore about whether the Prime Minister should or should not accept the central recommendation, it is easy to forget that the report will also have implications for Data Protection Act and the Information Commissioner.

One of the areas that Lord Justice Leveson was required to consider was ‘the extent to which the current policy and regulatory framework has failed, including in relation to data protection’.

I started writing a blog post on the way back from London, and got as far as the above, when an e mail from the good people at 11KBW  (Panopticon Blog) landed in my inbox.

On well if you can’t beat them, read them! Here is their excellent analysis of the DP recommendations of Leveson:

http://www.panopticonblog.com/2012/11/29/leveson-inquiry-report-spotlight-on-proposed-data-protection-reforms/

I was only training round the corner and passed the QE2 centre where LJ Leveson was giving his press conference. Perhaps, I should have camped out overnight to beat the Panopticon Team?

Privacy Conference – Call for Papers

The Fifth Northumbria Information Rights Conference will take place on Wednesday 1 May 2013 at the Centre for Life, Newcastle Upon Tyne, UK.   The theme of the conference will be “Changing notions of privacy”.

The aim of the conference is both to explore developing understandings of privacy, and the tensions that exist between privacy, openness and freedom of expression. The following topics will be explored within the overall theme, and papers will be grouped for presentation accordingly:

  • What is privacy?
  • Privacy v freedom of expression
  • Technology and the challenges of protecting privacy
  • Privacy in a commercial context
  • Privacy and the Freedom of Information Act 2000
  • Privacy or openness
  • Privacy and the Data Protection Act 1998

The university will also consider abstracts which do not fall within these themes but which are nonetheless relevant to the overall theme.

This call is open to academics, postgraduate students and practitioners from all disciplines, but particularly law, politics, information science and records management. Ibrahim Hasan presented a paper to this conference last year examining the Government’s proposals to change RIPA and whether they were a sledgehammer to crack a nut. We would urge our readers to get involved.

Those interested in presenting a paper are invited to submit abstracts to the conference administrator Maureen Cooke: email maureen.cooke@northumbria.ac.uk. Abstracts should be submitted by 7th December 2012. They should not exceed 300 words. Submission must be by Word document e-mail attachment at the email address shown above and should include, in addition to the abstract, your title, name and organisation/institutional affiliation and your email address for correspondence.

All proposals will be reviewed, and successful applicants will be notified at the latest by 21st December 2012. Please contact maureen.cooke@northumbria.ac.uk for any general enquiries about the conference or telephone 0191 243 7597.

Nobody cares for me. Signed DC.

Dear Mr xxxxxxxx, 

As a registered user of www.tpexpress.co.uk we are legally required under the Data Protection Act 1998 to contact you with the information outlined below.

Please note: This is not a marketing communication and does not affect your opt-in/out preferences for marketing emails.

What is changing?
We will be changing our online booking system during November and we are writing to you to notify you of the change in data controller from thetrainline.com to ourselves as a result of this change.

What does this mean to you?
Your retail contract will be exclusively with:
First/Keolis Transpennine Limited (FTPE),
50 Eastbourne Terrace,
Paddington,
London,
W2 6LG
Company Registration Number 04113923

Can anyone tell me which section of the Act requires a Data Controller to inform a data subject of a change of data controller? Or is it just good business practice? Or just plain “we don’t know what we’re doing”?

Answer on a postcard please to

DPO, Customer Relations, Some Train Operator, Leaves on the line, Adelstrop.

What’s the difference between PCC & BCC

The picture that said a thousand suppliers.

Fresh from being elected with less than 10% of the electorate in favour of him a recently appointed Police Commissioner writes to all the suppliers to tell them the email addresses of all their suppliers (and a few extra organisations – such as rape crisis centres, police officers, probation officers and some personal email addresses).  Still no harm done eh? No law broken, no real personal data involved. No brain cells used in the distribution of this list.

Makes me feel like Phillip Schofield. (When I say this it doesn’t mean I feel like him as in desire him – more like feel I’m in a similar predicament…)

How not to write a social media statement.

It’s the coming thing – having a social media policy. Cases such as Wetherspoons vs Preece illustrate the value of having one but there’s good ‘uns and inevitably bad ‘uns.

A family member recently accepted a job in a ski-ing company and they included the following in their T & Cs about Social Media. What do you think of it?

So a young person who’s going out with his mates for a few beers after work needs to seek legal advice before letting alcohol pass his lips in case he says something he wasn’t planning to say about his employer.

You can imagine two young thrusting lawyers sitting in  a bar.

  • “What’s your line then?”
  • “I look after unwittingly defaming people on social media”
  • “Business good?”
  • “Never better”

Do you commit libel? Sounds a bit strong.., Do Drivers commit speed? Do shoplifters commit shoplifting.

How can you tell you’ll unwittingly do something? Or to  really screw it up how can you tell you’ll wittingly do something?

You can’t express your views while you are employed by this company (but it’s only seasonal so by Easter you can say what you want again (Err… no. This contract forbids you from speaking out for the remaining 75 years of your life (my family member is one of those lucky people who will live to be 100)

The final sentence is just plain bizarre. I’d better not sign this contract in case I’m in breach of it…

Who writes this rubbish? I know, of course, but I can’t possibly tell you as I might unwittingly say something I might regret for nearly a century.

The Cat came back

Halloween and a postcard dropped through the letterbox. It was from the local vet. The one who earlier this year couldn’t make a diagnosis about our Tiddles and refused to hand over his medical records so we could take a second opinion. Tiddles didn’t make it and we told the vet not expecting to hear from them again.

The postcard was addressed to me and said it was time for our pet’s jabs but after the postcode on a line all of its own was the single word – Tiddles. We were clearly upset; how insensitive of the surgery to mail me about a  recent bereavement. If it had been a hospital and a dead child it might have even hit the media. We weren’t even a customer as we were dissatisfied with the service. It still didn’t feel right.

Any breaches of the law here? Principle 4 – Accuracy? Section 10? Right to object to prevent processing likely to cause damage and distress?

Probably not but it’s another entry in the catalogue of errors.

Sat Nav Bad Day

In March 1998, High Court Judge Lord Justice Brown threw a claim out of court by the Police against a motorist who was caught using a Radar Detector. The Police claimed that under the Wireless Telegraphy Act of 1949, the motorist was illegally using the device. The Judge ruled that the Radar Detector did not actually receive any intelligible police information and that the Detector was only picking up the presence of radar and not any information within it. This case set a precedent and made the use of Radar Detectors legal in the UK. To over-rule this judgement, the Road Safety Act 2006 specifically bans the use of radar and laser detectors. Most drivers are happy with this situation. They know where cameras are because a fair processing notice is in place (to comply with principle 1 of the DPA) and this is usually a picture of an old fashioned camera recognised by millions. Even the mobile cameras that travel to different locations have their way of delivering an FPN although it is usually found on the web rather than in situ.

So we’re relatively happy. We know where all the speed cameras are and we see them in map books, on the net; We hear about mobile cameras on local radio and TV and we’re cool about it. We buy our TomToms and justify using them saying “it’s just an electronic version of publicly available database”. Then we go to France on holiday.

Since decree n°2012-3 was introduced on 3 January 2012 it has been illegal to be warned about the position of fixed or mobile speed cameras while you are driving in France. If your sat nav has this function and you continue to use the service, you risk a fine of up to €1500. Even if the device is switched off and not operational the possession of such witchcraft is the work of the devil. Ken Russell would have loved to have made a film about it. Good old data subjects from Blighty being thwarted by sneaky foreigners not even bothering to use Schedule 2 (6) just ignoring the rights of individuals and worse disapplying the Subject Information Provisions.

Initially this sounds quite tough. There have been discussions on the web, advice from motoring lobbys and horror stories of motorists having their boot searched by a bold gendarme emerging triumphantly from black plastic sacks of dirty washing with an old device and demanding instant payment of a fine. There is also the other view that the law is unenforceable; that Gendarmes cannot search for satnavs, cannot operate them if they see one as it is technically a computer and their common law powers don’t extend to interrogating them, they cannot check your smart phone for that app you downloaded for free…

The truth naturally lies in the middle. There’s been discussions between french satnav manufacturers and government (one french firm feared 2,000 job losses) and they’ve come up with a concept of danger zones. Instead of listing cameras they list danger zones where there may be a hazard (such as a level crossing or a school or where people might speed) and the satnav can issue a warning of the danger.

The french authorities meanwhile are pushing ahead with a programme of taking down existing signs warning of cameras; they are setting up new cameras and not telling drivers where they are and generally acting very french. Pah! I spit on your schedule 2 requirement.

Other solutions suggested in hyperspace include modifying your satnav camera POIs and labelling them lay bys. (or transport caffs); Registering your car in Lithuania; Buying your next satnav from France and specifying UK maps…(although we did hear that french spoken instructions interpret M25 as Monsieur Vingt Cinq) or exploring Germany which has excellent weissbier and many ancient castles.

Glossary.

A speed camera is un radar (pronounced rad – ah).
A satnav is a GPS (pronounced shay pay ess)
Zones of danger – zits noirs
Breathalyser is un alcooltest (did we forget to tell you that by law you must carry two of these in your car as well as a dayglo yellow vest for each passenger)

Useful phrases

  • Bordelle de merde, espece de radar
  • Fer cryin’ out loud a bloody speed camera
  • Est-ce qu’il y a une brasserie independante dans ce trou a rat, j’ai envie d’une biere?
  • Please direct me to a real ale pub if you have one in this dump of a town.
  • Va te faire cuire un oeuf, sale gendarme.
  • I don’t agree with you officer.

Bonnes Vacances!