Jumping on the charity bashing gravy train.

Returned from holiday to a mountain of mail. Usually this is good fun but recently it’s turned into a nightmare of more and more charity mailings. First off today was British Heart Foundation. A good cause and I walk voluntarily into their charity shops regularly to find bargains and do my bit. But because of recent publicity about charity mailings I took a hard line. I rang them up and asked to be taken off their mailing list. The operator was polite and efficient. She asked for the code next to my address beginning 52A so she could add me to their suppression list but when I quoted it she said I wasn’t actually on their mailing list. Strange – I am looking at a letter addressed to me at my address asking for money from BHF.

She was quick to explain however that it was a one off mailing using data supplied by a 3rd party so they didn’t actually process my name and address. They just used it. I trotted out the well worn definition of processing that all BCS certificate holders know and she did admit that it looked as if they were processing after all. I asked who was the 3rd party and it turned out to be Senior Rail Card.

clip_image001

(as an aside these are managed by ATOC Ltd which manages the contract for the issue and use of the Senior Railcard on behalf of the Train Companies. Reference to a ‘Train Company’ or the ‘Train Companies’ means those Train Companies which, pursuant to a franchise agreement, operate Passenger Railway Services in Great Britain. Their website has a cookie policy but no privacy policy. Nowhere on their website do they assure you that they will only use your personal data to supply you with a senior railcard. Nowhere do they inform you that they will pass it on to anyone else.)

To be honest it wasn’t Senior Rail card who gave my details to BHF it was Media Lab group; BHF told me at the same time they told me about Senior Rail card.

clip_image002

Media Lab has a website where it says

“The media landscape may have changed, but the need for data hasn’t. That’s why at Medialab, we live and breathe data. It’s at the centre of everything we do. Our data-driven approach allows us to develop successful multi-channel media plans that are built on econometric analysis, innovation and a passion for our clients’ results. As a leading integrated direct response agency, we plan campaigns for the UK’s leading brands including National Trust, Post Office and Macmillan.”

Bizarrely for a data driven company they don’t have a privacy policy either. They were the company that gave my data to BHF. They got it from ATOC. I’m not sure how the transfer of data was made or whether money changed hands. We just don’t know. But I thought when I bought my senior rail card that my personal data would only be used or me to get cheap rail fares not donate to Heart charities or end up in the hands of List brokers.

The efficient BHF operator said she couldn’t delete me from their mailing list as I wasn’t actually on it. The list really belonged to Media Lab Group. They only used it to mail me. (Did someone at the back say Data Processor agreement and breach of Principle 7?).

However she had a solution to my predicament. She would add me to their database and immediately add me to their suppression list. Brilliant.

Next Alzheimers. Not as we first thought the Alzheimers Society (See comments) but another organisation working in this sector.

They also asked for money (or any donation will do) and they did have a privacy policy and also an undertaking issued by the ICO. They also gave me my Supporter reference number which was why they were contacting me. Because a year ago I filled in an online quiz to see if I was presenting any of the symptoms of dementia. At no time before, during or after the quiz did they give me any indication they would tap me up for money nor I asked if I wanted to become a supporter of theirs.

I rang them up to ask them to remove me from their mailing list but not a lot happened. When I say not a lot there was a recorded message saying “we apologise for the delay” then there was silence for the next 10 minutes at which point I gave up. They could have whistled a tune or even played a song but nothing. It was as if they  had forgotten to answer or they were hoping (like Doc Martin) that I had no patience.

They were right so I used the system they provided to communicate with them.  This time they supplied an SAE and a form where I could inform them of my preferences so I did. They’d used a jocular style to contact me without my consent so I replied in the same vein.

PS

Only 20 more charity letters to deal with… How I hate coming home from holidays.

The Act Now Data Protection Practitioner Certificate is a qualification designed to give candidates a head start in understanding and implementing the proposed EU Data Protection Regulation.

Requesting Your Permission

I received an email last week. It was from someone I’d never heard of.

Email

Translating this into PECR speak

We have a list of emails. We don’t think we have your consent to email you which would lead to us breaching PECR so we’re writing to ask for your permission which in itself is breach of PECR. By putting Request for Permission in the subject line we’re hoping you’ll think we know what we’re doing and that we’re a nice company.

I asked them by email to tell me where they obtained my email. A week later they hadn’t replied. I know a week is a long time in politics but a week is a light year in emails.

I upgraded my request to a Subject Access Request and suggested they pass my request to their DPO. Less than 3 hours later I had a reply which appeared to come from near the top.

Dear Sir

Thank you very much for your email and for reaching out to us with regards to our recent emails to you. We have carried out an investigation into your complaint as we take this type of matter very seriously.

As per your inquiry, we have recently acquired a new supplier called “Latest Mailing Database” (latestdatabase.com) who provided us a list of customers’ email addresses interested in travel. They have contractually reassured us that those listed have expressed their consent to be contacted by selected third party partners for marketing purposes.

Upon receiving your inquiry, we have realised that the reassurances we received from this company is in question. While we investigate this further, we have subsequently ceased the use of that mailing list they have provided and all the e-mails, including yours, have now been deleted from our Databases.

We apologise for any inconvenience caused.

Best regards,

Spiros XXXXXXX

Head of International Marketing and Business Development

At least I received a reply but the phrase “They have contractually reassured us that those listed have expressed their consent to be contacted by selected third party partners for marketing purposes” started to worry me. Also a list of people who are interested in travel. Isn’t that a list of everyone in the world? We all travel. Now if they’d asked for a list of those interested in sex and travel we’d have a snappy answer.

Globehunters have a privacy policy which looks pretty good. Just for fun I looked up their company name and their postcode on the ICO Register of Data Controllers. The ICO doesn’t have any record of their name and there are only 2 notifications from their postcode both from the next door building.

I couldn’t resist looking at his source for the emails.

http://www.latestdatabase.com A quick scan through showed their address was Majira Bypass Sajahanpur, Bogra, Bangladesh and they sold email lists. Google maps zeroes in rapidly on a company called seoexparte. A touching review of the company is available.

 

Email 2

 

They had a privacy policy too. http://www.latestdatabase.com/privacy-security-policy/ which was last updated in 2009.

Their UK customer list boasted 2 million records or just $300

Listing Include:

* Frist Name (sic)

* Last Name

* Age

* address

* Email Address

* Ip address

* Phone number

They also have a blog (http://www.latestdatabase.com/appearance-adele-gaga/) and although it would be churlish to mock their poor English if they’re operating in a global marketplace and assuring their customers contractually of the quality of their product it might be a good idea to use a spell checker.

They also seem to run http://emailmarketinglists.bloggets.net. And http://buyemaillists.yolasite.com/contact.php and https://emaillistsforsales.wordpress.com and http://mailinglsit.over-blog.com and http://issuu.com/emaillistsforsale and I gave up at this point.

So where are we now? For £190 a start up company has bought 2 million customer emails. This means that my email is worth 1/100th of a penny. When prodded they realize that they may have bought in a dodgy list so apologise and take my name off their list. A good response but no mention of my Subject Access Request. No Notification for their business and a lead to a major list seller who may just not check their lists that well.

All in day’s work for a PECR vigilante. I’ll see if Spiros comes back.

Act Now Training is one of the UK’s leading provider of seminars and workshops on all aspects of Data Protection, Freedom of Information, Surveillance Law and Records Management. More details www.actnow.org.uk

And so, the end is near, and now we face, the final curtain… or do we?

[ File # csp9290038, License # 2694086 ]
Licensed through http://www.canstockphoto.com in accordance with the End User License Agreement (http://www.canstockphoto.com/legal.php)
(c) Can Stock Photo Inc. / nasir1164In case you missed it over the last week or so it has been confirmed that the European Council have agreed a text of the Draft EU Data Protection Regulation. You would think that would be the final stage but alas no. Instead we now present this version back to the Commission & Parliament for tri-partide discussion and agreement. This really is the final stage of the legal process in which the Council, the EU Parliament and the EU Commission will now negotiate on this document to agree a final text that can become law (promise… it really is the last stage).

However, in typical governmental fashion of not being able to do anything smoothly 2 versions were ‘released’. One is the text of the Council of Minister’s final text agreed on June 15th: Council of Ministers text minus objections from Member States.

The other was a copy of the text of the Council of Minister’s final text agreed on June 15th including the 649 paragraphs of ‘disagreements’ from the member states (oops). Council of Ministers text plus objections from Member States

There is still some discussion to be had however and in the comments version the Council acknowledges this. First up, with regards to police processing of personal data the regulation now includes as a purpose for processing “safeguarding against and the prevention of threats to public security”. Which, at face value, seems rather wide and “loose” in its wording. We all know that defining a “threat to public security” can be open to various interpretations therefore this may meet with some stiff opposition.

The Council has also said that there needs to be some discussion around the “lawfulness of processing” under Article 6 recital (40 and Article 19 (1). The Council is looking to approve final wording on legitimacy of processing data that is incompatible with the original purpose for which it was collected. The current proposal looks to allow such processing but as a condition allows the data subject a means to legitimately object. Again, how this will work in the real world is open to interpretation but given that this is a move away from the current Directive’s standards then it will be interesting to see if the Council and Parliament accept that.

The Council also appears to be looking for further discuss on the right to compensation and liability outlined in Article 77 and recitals (112), (113a), (118), (118b). The current proposal clarifies the roles and liabilities for processing that is not compatible with the regulation. Namely it is looking to narrow the extent of liability for a processor or controller where it can be demonstrated that the controller or processor concerned is not fully liable (IE, it can be clearly demonstrated that it wasn’t their fault). It makes sense but again, how that will go down with the Parliament and Commission will be interesting.

I’ve now had the chance to read through this updated text and in short it smells an awful lot like a beefed up Directive. A lot of the stricter wording that was in the initial draft proposed by the Commission & indeed the Parliament draft have been replaced with general expectations, the finer details of which member state law or local codes of practice are encouraged to work out. Some of the aspects of the regulation even invite member states to write complimentary laws so that those sections can be properly enacted within that member state. (I’m sure that’s the purpose of a Directive you know…).  

Here’s a quick summary for you;

  • Member states can create their own laws on conditions for processing certain types of data (national ID numbers for example). (Article 9 (5)). This also extends to the conditions for processing HR data which can be defined by local member state work agreements.
  • Member states can decide if fines are to be used on public sector bodies.
  • Article 79a – Fines of up to 250,000 euros or 0.5% of previous year global annual turnover for deliberate or negligent breaches & not responding to SARs.
  • Article 79a – Fines of up to 500,000 euros or 1.0% of  previous year global annual turnover for any of the above or;
    • Does not provide information in a timely manner to a data subject
    • Does not provide access or rectify data belonging to the data subject
    • Does not erase personal data belonging to the data subject
    • Processing data in violation of an restrictions on processing outlined in article 17 (Notification obligation regarding rectification, erasure or restriction).
    • Does not communicate any rectification, erasure or restriction requests to 3rd parties
    • Does not provide the data subject with their personal data.
    • Processing of data of objection to processing received and no viable reason for legitimate processing.
    • Does not provide data subject with information about the right to object to processing of information for marketing purposes.  
    • Does not sufficiently determine responsibilities of joint controllers.
    • Does not maintain sufficient documentation pursuant to Articles 28 (Records of categories of personal data processing activities) & 34 (Prior consultation).
  • Article 79a – Fines of up to 1,000,000 euros or 2.0% of  previous year global annual turnover for any of the above or;
    • Processes information without a legal basis for doing so or does not obtain appropriate consent.
    • Does not comply with conditions for automated decision making & profiling.
    • Does not implement measure to demonstrate compliance with articles 22 (Obligations of the controller) and 30 (Security of processing).
    • Does not designate a representative in violation of Article 25 (Representatives of controllers not established in the Union).
    • processes or instructs the processing of personal data in violation of Articles 26 (Processor).
    • does not alert on or notify a personal data breach or does not [timely or] completely notify the data breach to the supervisory authority or to the data subject in violation of Articles 31 (Notification of a personal data breach to the supervisory authority) and 32 (Communication of a personal data breach to the data subject).
    • does not carry out a data protection impact assessment in violation of Article 33 (Data protection impact assessment) or processes personal data without prior consultation of the supervisory authority in violation of Article 34(2) (Prior  consultation).
    • misuses a data protection seal or mark in the meaning of Article 39 (Certification) or does not comply with the conditions and procedures laid down in Articles 38a (Monitoring of approved codes of conduct) and 39a (Certification body and procedure).
    • carries out or instructs a data transfer to a recipient in a third country or an international organisation in violation of Articles 41 to 44 (Transfer of Personal Data to third countries or international organisations).
    • does not comply with an order or a temporary or definite limitation on processing or the suspension of data flows by the supervisory authority pursuant to Article 53 (1b) or does not provide access in violation of Article 53(1) (Powers).
  • Article 38 – Member states can create their own codes of practice and standards for data protection for specific sectors. This need approval by the EU Data Protection Board but can be developed per member per sector.
  • Article 54a – One stop shop concept for regulatory action and complaint handling amongst supervisory authorities remains.
  • Article 12 – Removal of charging for SARs remains.
  • Article 70 – Removal of need to register all processing of personal data remains but instead only high risk processing must be registered (at no charge) and will be published by the supervising authority.
  • Data portability now does not apply to the public sector or any processing for the enactment of a contract. (General  Text, paragraph 55)
  • Article 31 – Breach notification to a supervisory authority is now 72 hours or “without undue delay” if longer than that period.  

This Regulation is as close to a final version as we are going to get for the moment. As we’ve seen in recent weeks and months the majority of Data Protection regulators and even the EU Commission are saying that elements of the Regulation should start to be implemented from this point onwards (e.g. Netherlands are implementing a general DP breach notification law from next year). Some are even using the principle of the Regulation in the interpretation of current law (the ‘right to be forgotten’ for example).

I intend to do a few more articles over the coming weeks to look in more detail at some of the wording and what this could mean if the Parliament and Commission accept the current draft (which is a realistic possibility).

Author:

Scott Sammons CIPP/E, AMIRMS

@privacyminion

Scott is on the Exam Board for the Act Now Data Protection Practitioner Certificate which is a qualification designed to give candidates a head start in understanding and implementing the proposed EU Data Protection Regulation.

Sell your friend’s email for £25!

refer a friend edited

It’s quite simple. You’ve just bought a product and the company who just sold it to you asks for a friend’s email so they can market to them. If they buy then you (and them) get a cheque for £25. What a great idea!

Unfortunately they seem to have chosen to breach some regulations. To market electronically by email requires prior consent or consideration of the soft opt in option as defined in Section 22 (3) of the Privacy and Electronic Communications (EC Directive) Regulations 2003.

To market by email three conditions should apply.

a) You must have obtained the email address in the course of a sale or negotiations for a sale

b) You should only market similar products

c) You should offer an opt out with every message.

They clearly miss the first one as they have made no sale nor negotiated with your friend. The second one falls by the wayside for the same reason as your friend won’t have bought anything from them, so there is no “similar” test. Finally, we’ll credit them with offering an opt out (although based on their understanding of email marketing so far that’s being generous).

There is a safety valve. If your friend, after being sold down the river does not buy from the company, then their email will never be used by the company. In fact it will be destroyed securely within 30 days. And of course it will never be passed to any other organisation or sold to a list broker.

Unfortunately the company doesn’t offer any of the guarantees in the previous paragraph. They may well do so but they don’t bother with any concept of a fair processing notice. How do you feel about sending your friend’s email to this organisation? If they’re happy to pay £25 to buy an email address that makes a sale what price do they put on a prospect?

I’m not a hacker. I’ve started an online course to learn how to be one. There is no course literature or reading list. The exam which can be taken at any time has one task. “ Your grade is held in a secure area at Hacker’s University. Change it to Pass and email yourself a PDF of your certificate”.

But if I was a hacker I’m sure I could find a way to flood this business that’s trying to buy email addresses with a few long lists of emails. All those on JISCmail data protection list; All people with NHS.net; I have many lists that people have sent me by accident.

Paul Simpkins is a Director and trainer at Act Now Training Ltd.

No time to attend our PECR courses? Try our on demand PECR webinars. One hour of  learning for only £39 plus vat.

Information, Documents or Both – What is available under FOI?

file0002015332264

It is an oft-repeated phrase that the Freedom of Information Act (FOI) provides a right of access to information but not documents. A recent Court of Appeal decision shows that it is not that straightforward an issue.

Section 1 contains the general right of access and uses the term “request for information.” But what exactly is “information”? Section 84 defines it as “information recorded in any form.” This includes information held on paper, computer, video, audiotapes as well as that contained in manuscript notes. No mention is made of access to the actual documents containing the information. However this does not mean that documents cannot be requested.

A request for a document will generally be a valid request for all of the information contained within that document (including visual format, design, layout etc). In considering whether the public authority has complied with the request, the question is whether all of the information recorded in the document has been provided. It will not be sufficient to rephrase the document or provide an outline or summary of its contents unless the applicant has specifically expressed a preference for a digest or summary under section 11(1)(c).

This matter has now been put beyond doubt by a Court of Appeal decision this week. Judges dismissed an appeal by the Independent Parliamentary Standards Authority (IPSA), the body that oversees MPs’ expenses claims, from a decision of the Upper Tribunal requiring it to release copies of MPs’ invoices and receipts. This is the latest in a serious of appeals by IPSA in an attempt to overturn the original decision of the Information Commissioner.

In April 2013 the First Tier Tribunal (Information Rights), ruled that images of MPs’ expense claim receipts were information to which the FOI applied (IPSA v Information Commissioner (EA/2012/0242)). The background to the request was that, following the MPs’ expenses scandal, the then newly-formed IPSA, decided that it would not routinely publish images of the receipts submitted to IPSA by MPs in support of their expenses claims.  Only text transcribed from the submitted receipts would be published.

A journalist made an FOI request for the actual receipts submitted by a number of MPs. The question arose as to whether images of those receipts held by IPSA contained “information” within the meaning of section 1 of FOI, which was not captured by the transcription process favoured by IPSA. The Tribunal concluded that the definition of information (in this case) included logos, letterheads, handwriting, manuscript comments, and even the layout and style of the requested documents. These were not disclosed to the requestor as a result of providing a transcription, rather than a copy, of the relevant receipts.

Last year the Upper Tribunal’s Judge Williams (in Independent Parliamentary Standards Authority v IC & Leapman [2014] UKUT 33 (AAC)) dismissed the appeal by IPSA. At Paragraph 22 of the judgement he said:

“It is to me also trite to note that the wording on a typical receipt or invoice is only part of what a recipient sees when looking at it. Typically there will be verbal and numerical content to be read and understood, but there will also be visual content to be seen, rather than read, but which may also require to be understood for the recipient to have appreciated the whole of the experience, if I may term it that, communicated by the receipt or invoice.”

In the judge’s view information is more than just the words and figures on a piece of paper. Sometimes the nature of the request will mean that the only way to convey all the information on a document is to disclose the original or at least a copy. He gave the example of Land Registry plans, drawings and photographic evidence of a particular building.

In coming to his decision the judge took note of the Scottish Court of Session decision in Glasgow CC v SIC [2009] CSIH 73 under the Freedom of Information (Scotland) Act 2002 (FOISA). As a general point of principle, the Commissioner and the Tribunal is not bound by Court of Session decisions on FOISA, although they may be considered persuasive where the terms of FOISA mirror the terms of FOI. In the Scottish case the applicant specifically wanted the public authority to provide copies of the documents, although he acknowledged that the same information was available elsewhere. The Court confirmed that FOISA entitles requesters to the information within a document, rather than a copy of the document itself. To the extent that this request was specifically for copies of the documents over and above the information they contained, it was invalid. The Court rejected an argument that the copy documents were “information” distinct from the information contained within them.

Paragraph 45 of the Court of Session judgment states:

“Where the request does not describe the information requested… but refers to a document which may contain the relevant information, it may nonetheless be reasonably clear in the circumstances that it is the information recorded in the document that is relevant.”

However paragraph 48 should be noted:

“The difference between the original and a copy… does not consist in any difference between the information recorded in each document: that information, if the copy is true and accurate, will be identical.” (my emphasis)

To quote one of our FOI trainers (Philip Bradshaw), much will also in practice depend on the wording of the request. Contrast “How much did you spend on pencils?” with “Can I have a copy of your pencil invoices”. You can clearly provide in permanent form all the recorded information within scope of the first request without copies, but not perhaps for the second.

In the IPSA case, the judge ruled that transcriptions of the requested receipts would not be “true and accurate”, as they would not contain all the same information as on the originals e.g. logos, style, layout etc.

This is an interesting decision especially for those public authorities who often insist, when refusing to supply actual documents (such as minutes of meetings) that FOI is about access to information not documents. Sometimes the requestor is interested in the document, which contains the requested information, as it will give a further insight into its background and the thoughts/observations of the producers/subjects of the document.

IPSA has been given time to consider taking the case to the Supreme Court.

Ibrahim Hasan will be discussing this and other recent FOI decisions in the FOI Update workshops which are delivered in one hour online sessions as well as full day face to face sessions.

Is my PD my PD?

image

Myopic readers will have noticed that the selling of spectacles has migrated to the internet. There are many suppliers who will take your order, make up your glasses and post them to you for a very reasonable price. They don’t do eye tests obviously but you can have one done elsewhere and the optician will give you a copy of your prescription which you can take to any other optician including the web. So money savers everywhere will take up this option and consequently will save money on their next pair of specs. They may not hold them in their hands or perch them on their nose until they are finished but they will save money. After sales service is another issue and I have no experience of this.

Er… No.

What high street opticians do is take other measurements when doing the test and use these to tailor the spectacles to each individual. They will have a range of frames for people to try on and they will crucially measure and use your Pupillary Distance when preparing your spectacles. They’ll use expensive accurate machines to do this and it will make better fitting lenses for you.

You can do it yourself with a ruler, a mirror and a large dose of optimism or you can find a friend to help you. Unsurprisingly there are web opticians who will guide you.

But when the optician hands you your prescription as they are required to do they don’t volunteer your Pupillary Distance. Web opticians will suggest you ask for it but intimate that your optician may charge you for a figure fairly close to 63mm. If you’re Mr or Mrs Average this may not be a crucial issue but anyone with a strong prescription may need to have the best data available to make up their new spectacles.

But is your Pupillary Distance your personal data? It certainly relates to you and may even be sensitive data. If it is why can’t you have it without charge? What gives opticians the right to withhold it from you? I’ve squinted at the Opticians Act 1989 and the sight testing regulations 1989 but nowhere does it say what must or must not be done. Can you make a Subject Access request for it? Is the going rate the £10 that Subject Access can cost? Shouldn’t it be free? Or is it not Personal data? Can an optician tell me he holds no personal data on me?

Just because it’s easy to measure it yourself (badly) but hard to measure it accurately (at an optician) and will have a significant impact on your vision does it make it special in any way? You can weigh yourself every morning and know the result without anyone charging you for it.

Other health providers will carry out measurements of various parts of your body (and mind) and will give you the results. What makes Opticians different? Is there a legal power to charge? Or is it protectionism that keeps the high street Opticians trading and holds back the web offshoot?

A trawl through the web shows plenty of blogs and opinions  where optomotrists either label their customers as morons or cheapskates or alternatively (and encouragingly) suggest a small fee for a professional service in the hope they will retain the customer but the issue doesn’t seem easily resolved. More like on a case by case basis (that’s spectacle cases to you…).

Hmmm. If only there was an access mechanism I could use to obtain information from public bodies. Spoiler Alert.

image

What about Freedom of information? Surely Opticians involved with General Ophthalmic Services are covered by the Act?

If an Optician fails to answer my SAR on the grounds it isn’t personal data they cannot thereafter cite section 40 (or 38) as a valid exemption. The cost of using FOI might even be lower than the £10 the DPA allows.

My two requests are in. By the very nature of DP & FOI surely one must succeed or maybe I’ll find a philanthropic myopic interested in the topic and he’ll see his way to giving me what I want without a charge.

Watch this space between my eyes.

Keep up to date with the latest DP developments by attending our workshops and online courses.

Section 56 is here! Oh no it isn’t! Oh yes it is!

Interstate56

Section 56 prevents employers from requiring people to use their subject access rights under the DPA to obtain and then provide certain records, as a condition of employment. It also prevents contracts from requiring certain records as a condition for providing or receiving a service. Section 56 does not, however, prevent such requests where the record is required by law or is justified in the public interest.

Section 56 was due to be commenced on 1 December 2014. Commencement was delayed because of a technical issue encountered when finalising arrangement for introduction. This issue has now been resolved.

Section 56 was commenced on 10 March 2015. There is a SI 2015/312, entitled, ‘The Data Protection Act 1998 (Commencement No. 4) Order 2015′.

It makes it a criminal offence to require an individual to make a subject access request and supply it to a potential employer for the purpose of obtaining or continuing in employment. It also relates to a supplier of goods, facilities and services to the public who require the production of a record to access that service. The ICO webinar suggests insurance might be such a case. They also suggest it applies to volunteers who help your organisation even they may not be in employment.

Most practitioners called it Enforced Subject Access. In November 2014 the ICO ran a webinar outlining what this means and it’s worth look. See the webinar on youtube at https://www.youtube.com/watch?v=zTYBvr-tb5U. It’s 36 minutes long so set aside a lunch hour and buy your sandwich first. It does a good job looking into all the minor points and ends up with a few good examples of how it will be used.

It’s quite a logical and straightforward concept. Why on earth would you require someone to produce their police record to progress their application for employment? Certain jobs with vulnerable people involve disclosures from the Disclosure & Barring Service and Disclosure Scotland is widely used but employers in these area know about this. Making people outside these areas obtain and produce a relevant record is clearly wrong.

There are some defences to a Section 56 charge – the usual suspects of under enactment, rule of law, court and also in the public interest but specifically excludes prevention or detection of crime from the public interest.

Now it’s time to watch the webinar, download the ICO guidance from https://ico.org.uk/for-organisations/enforced-sar/ and wait for the first case involving section 56.

Looking for a DP qualification? The Act Now Data Protection Practitioner Certificate is a practical four day course. The syllabus is endorsed by the Centre for Information Rights based at the University of Winchester. 

Freedom of Information Case-law Roundup

Big Railroad Model-3

Section 5 of the Freedom of Information Act (FOI) enables the Secretary of State to designate a body as a public authority if it appears to the Secretary of State :

(a)… to exercise functions of a public nature, or

(b) is providing under a contract made with a public authority any service whose provision is a function of that authority.

The Freedom of Information (Designation as Public Authorities) Order 2015 was recently debated in the House of Lords. It will make Network Rail subject to FOI from March 2015. Much has been said about extending the reach of FOI to private companies delivering public services. Don’t expect anything to happen before the election.

Fees and 16

How far does a public authority have to go in providing advice and assistance to an applicant whose request is over the fees threshold (£450/£600)?

On 22nd October 2014, in Commissioner of Police for the Metropolis v The Information Commissioner and Donnie Mackenzie, [2014] UKUT 479 (AAC) , the Upper Tribunal ruled that the standard imposed by section 16 is set at a relatively low level. It agreed with the First Tier Tribunal (Information Rights) (FTT), in Beckles v Information Commissioner (EA/2011/0073 & 0074), that:

“S.16 requires a public authority, whether before or after the request is made, to suggest obvious alternative formulations of the request which will enable it to supply the core of the information sought within the cost limits. It is not required to exercise its imagination to proffer other possible solutions to the problem.”

Time limits

Section 10(1) of FOI sets out the time limit for dealing with a request for information:

“a public authority must comply…promptly and in any event not later than the twentieth working day following the date of receipt.”

Under the Environmental Information Regulations (EIR) the response to a request must be made “as soon as possible and no longer than 20 working days after the date of receipt”. In Keating v Information Commissioner and Oxford City Council (EA/2013/0226) the FTT said that whether it is an FOI or EIR request the principle is the same:

“In our judgement, whichever time limit applies, it is necessary to be realistic. Whilst both pieces of legislation contemplate a speedy response, the urgency intended is not such as to require a public authority to “drop everything” in order to reply.”

We now have a binding authority for this principle, in the form of an Upper Tribunal decision (John v ICO & Ofsted 2014 UKUT 444 AAC.).

Third Party Personal Data

Section 40 provides an exemption from disclosure of personal data about the requestor as well as that of third parties. With regards to the latter, the public authority must show that disclosure would breach of one of the Data Protection Principles (usually the first one). In the absence of consent this usually requires consideration of condition 6(1) of Schedule 2 of the Data Protection Act 1998:

“The processing is necessary for the purposes of legitimate interests pursued by the data controller or by the third party or parties to whom the data are disclosed, except where the processing is unwarranted in any particular case by reason of prejudice to the rights and freedoms or legitimate interests of the data subject.”

In a recent Upper Tribunal Decision, Goldsmith International Business School v IC and Home Office (GIA/1643/2014), the judge endorsed the ICO’s 8 rules when applying the test in condition 6. These are essential reading for all FOI officers.

Names of legal Advisers

Names of staff are clearly personal data. We have examined the application of section 40(2) in a number of FTT decisions (read our blog post here). The test is, is there a legitimate interest in knowing the names and is disclosure necessary to satisfy that interest?

In November 2014 the FTT (in Timothy Couzens v IC EA/2014/0146) upheld the Care Quality Commission’s refusal to supply the names of individuals who provided it with legal advice on the de-registration of a care agency. The FTT found that Couzens had “provided no persuasive argument that disclosure of the names in question would contribute to transparency, given that the substance of the legal advice has been disclosed, as a result of the CQC waiving its right to rely upon the exemption provided by FOIA section 42 (legal professional privilege).”

Staff Salaries

Is there a difference between a request for salaries of administrative staff and that of academics in a university?

Yes, according to a recent FTT decision involving King’s College, London (EA/2014/0054). The case concerned a request to the college for the job titles and departments of those staff (academic and none academic) earning over £100,000 per annum, in bands of £10,000. The FTT ruled that salaries of most non-academic staff employed by the college should be disclosed. Read this excellent analysis by lawyers at SGH Martineau.

Local authority colleagues will know that a certain amount of salary information has to be proactively published in compliance with the Local Government Transparency Code.

Motive Blind

FOI is normally motive and purpose blind. The FTT decision in Hepple v IC and Durham County Council (EA/2013/0168) shows that this is not an absolute rule.

The background is that the Council received an FOI request for a copy of the investigators’ report into a disciplinary incident at a pupil referral unit run by the council. At that time, disciplinary proceedings were pending against each of the suspended members of staff.

The council refused the request, relying on a number of exemptions including section 38 (health and safety). The FTT upheld the decision of the ICO on this point mainly because the requester had sent text messages to some of the individuals involved “with the purpose of menacing those whose addresses the Appellant had acquired”. The FTT said “assessing an information request on this “motive blind” basis ought not to prevent us from considering the potential risk to safety posed by the requester him/herself”.

Legal Advice

The Section 42 exemption is often relied upon by public authorities when refusing to disclose legal advice. It is a qualified exemption. A few decisions have required disclosure of legal advice on public interest grounds but these have been few and far between. Indeed, following the Tribunal decision in Bellamy v The Information Commissioner which stated that there is an inherent public interest in maintaining privilege, most authorities were almost treating section 42 as an absolute exemption.

A September 2014 decision of the FTT reminds us that the public interest in disclosing legal advice has to be considered carefully. The Bingham Centre for the Rule of Law v Information Commissioner (EA/2014/0097) concerned a request to the Home Office for independent legal advice, which was referred to in a Home Office report, entitled “Intercept as Evidence.” The FTT disagreed with the ICO’s decision giving more weight to public interest factors in favour of disclosure.

Ibrahim Hasan will be discussing these and other recent FOI decisions in his FOI Update workshop . If you want an internationally recognised qualification in FOI, please consider our BCS FOI Certificate course.

Information Governance in Health & Social Care Conference

capture-20141210-161914Act Now is pleased to announce that it will be holding a major conference in the new year on the 24th of March entitled ‘Health Now – Information Governance in Health and Social Care – Where are we now?’ Speakers from the ICO, many areas of the NHS, NADPO and Act Now will be meeting in Leeds to discuss the future of information governance and patient care.

If you work in information governance, records management, data protection, freedom of information, IT, compliance, information and compliance management, data & information management then this is for you. Over 100 delegates are expected from Local and Central Government, Health and Social Care and associated sectors.

To download your advance copy of the conference flyer click here. With a delegate fee of only £199 we expect a high demand for places. Book Now for Health Now! See our other courses for the health and social care sector here.

Peter Paul and Mayhem.

 

clip_image002

A story of email marketing gone wrong. Surnames have been deleted to protect the guilty.

On 20 Sep 2014, at 12:53, Peter wrote:

Hi Paul,

I have seen your CV details on one of the job boards and I am very keen to discuss an OLE Design opportunity with you. 

What is the best number to contact you on?  Are you currently looking for opportunities?

The CV I can see for yourself is out of date so if you could forward me your updated CV that would be great.

Look forward to hearing from you.

Regards,

Cameron

Senior Consultant

A recruitment gency

A posh address in London

First time in my life I’ve been headhunted but as I’m nearly on the final lap of the 10,000 metres of life I don’t really want to be employed. Strange how the email address is different to the name of the sender. But I felt aggrieved enough to reply.

From: Paul


Dear Peter/Cameron

Nice to know you’ve seen my CV on a job board. I am currently 62 years old and not seeking work of any nature so I suspect you are being economical with the truth in your marketing approach. The out of date CV you talk about is not just out of date – it doesn’t exist. I don’t have a CV as my V is based on not working. I am not on any jobs boards (whatever they are).

I presume you acquired my email from a third party as I have no relationship with you at all and that you never considered the PECR 2003 which forbid cold emailing unless the soft opt in exists which it doesn’t so you are in breach of these regulations and liable to a monetary penalty of up to £500,000 if the regulator feels it appropriate.

An apology would be nice but I’m not expecting one. Have a nice day.

I did consider copying in the ICO and asking for them to consider it as a complaint under PECR but decided to be lenient.

On 1 Oct 2014, at 09:45, Peter wrote:

Dear Paul,

Many thanks for your email.  Thank you advising that you are not looking for work.  I can confirm we are not being “economical” in our approach.   I can confirm your CV does exist & the existence is on Railway People (www.railwaypeople.com) which was last updated in August 17th 2012.

As proof I felt best to show you a copy of the CV that is currently on Railway People.  As you will see the CV does exist.  As your details are on Railway People we wanted to check your current situation and whether a contract opportunity would be of interest, but you have confirmed you are now retired.  May I also confirm that we do not use any third party sources and did not acquire your details from any such source.

I can also confirm we are not in any breach of any regulations as your details are on the site.  Apologises if you feel aggrieved by the approach but we were only contacting you as your details are on the site.

Have a nice day.

At this point I looked at the website Railwaypeople.com and couldn’t enter the site on account of not having an account with them so rang the sales team. I met a nice young man who was sympathetic and very helpful. A few facts exchanged with him revealed that candidates who were looking for work in the railway industry uploaded their CVs (carefully fulfilling schedule 2,1 condition) and recruitment consultants would download CVs they thought looked interesting. (I suspect money changed hands here). There was person on the site with same name as me but he lived in Derby and had a different birthdate. Craig agreed to confirm this in writing.

On 1 Oct 2014, 09:45, Craig wrote:

Hello Paul,

As discussed, I can confirm that we hold no contact details for you on our RailwayPeople.com database.

I’m able to tell you that Peter from xxx Recruitment downloaded the CV of a candidate by the name of Paul xxxx with a similar email address to your own.

I’m assuming you have been emailed in error by Peter so I would double check with the agency if you still have concerns.

Regards,

Craig
Account Manager

From: Paul

Hi Peter

I’ve been in touch with Railway people and they have confirmed in writing that they do not have any CV for me (checking my home address and a few other key facts). They do have a Paul xxx based in Derby and linked to the railway industry and with a similar email address and told me you had viewed this.

All I can surmise is that somewhere between you picking up this person’s data you managed to turn his email address into mine. 

Regards

Paul (not the Derby one)

Hi Paul,

I can see where the confusion lies.  Apologise for the confusion & the email in the first place.

Regards,

Peter

So Peter found a CV on an internet site despite him assuring me in an email that “May I also confirm that we do not use any third party sources and did not acquire your details from any such source. It wasn’t my CV. He then emailed what he thought was a person in Derby but managed to spell the email address wrong and reached me. Not having any relationship with me and ignoring the soft opt in exemption (or maybe not even knowing of its existence) means he breached PECR.

First class service from Craig at Railway People. He acted quickly and correctly.

Missed the connection at Crewe for Peter. Emailed without consent; breached principle 4 DPA; argued he was right; breached regulations about electronic marketing (which is his day job) but had enough guts to apologise at the end.

All in a day’s work for a DPA/PECR nerd.