All Change for Data Sharing?

canstockphoto0925773Last year the Law Commission launched a consultation on the law around sharing of personal information between public sector organisations. The paper outlined the current law and asked 22 broad questions. In July, following analysis of the consultation responses, the Commission recommended a full-scale, UK-wide reform project to consider how the current law can be simplified and modernised.

The legalities of data sharing is a subject which often confuses public sector officials. Local authorities, in particular, are often stumped by the “To Share or Not to Share” question, even if the sharing is for very good reasons (e.g. child protection or crime prevention). More often than not, the Data Protection Act 1998 (DPA) is made the scapegoat for officials’ failure to fully understand the law. It is wrongly perceived as a barrier to data sharing despite offering a range of justifications (e.g. consent, legal obligation, protecting vital interests etc. (Schedule 2)). According to Nicholas Paines QC, the Law Commissioner responsible for public law:

“Data sharing law must achieve a balance between the public interest in sharing information and the public interest in protecting privacy,”

Public authorities are right to be cautious though. See the recent decision in AB & Anor, R (on the application of) v The London Borough of Haringey [2013] EWHC 416 (Admin) (13 March 2013) where a judge ruled that the council’s data gathering had been unlawful because consent from the data subject was not sought.

The Commission received 87 written responses to its consultation paper, from a range of different individuals and organisations.  It published its report, including its analysis of consultation responses on 11 July 2014. The report sets out its recommendations as follows:

We made three recommendations.

  1. We recommend that a full law reform project should be carried out in order to create a principled and clear legal structure for data sharing, which will meet the needs of society.  These needs include efficient and effective government, the delivery of public services and the protection of privacy. Data sharing law must accord with emerging European law and cope with technological advances.  The project should include work to map, modernise, simplify and clarify the statutory provisions that permit and control data sharing and review the common law. 
  1. The scope of the review should extend beyond data sharing between public bodies to the disclosure of information between public bodies and other organisations carrying out public functions.
  1. The project should be conducted on a tripartite basis by the Law Commission of England and Wales, together with the Scottish Law Commission and the Northern Ireland Law Commission.

The Commission suggests that the project could usefully include consideration of the functions of the Information Commissioner in relation to data sharing, including the Commissioner’s enforcement role (Read the ICO’s response to the consultation.)

The Cabinet Office and the Ministry of Justice will now decide together whether to refer a full law reform project to the Law Commission.

Don’t hold your breath. We have been here before! Furthermore, do we really need new laws on data sharing or a better awareness of the existing ones? As I have said before, the current law is adequate to regulate yet allow responsible data sharing. The DPA and the ICO Data Sharing Code can be very useful tools for allowing responsible data sharing if they are properly understood.

STOP PRESS – The final report of the Home Office research into “Multi Agency Working and Information Sharing” was published on 1st August.  The report makes for interesting reading, and sets out a number of commitments the Home Office is making to continue to support multi agency working and information sharing.

Ibrahim Hasan will be conducting full day Information Sharing workshops in Manchester and London in September.


ICO invites practitioners to feedback on its Data Sharing Code of Practice

The ICO is inviting feedback on its Data Sharing Code of Practice.

Published in May 2011 the publication continues to be one of our most popular pieces of guidance. We would like to hear about how you’re using the guidance and how it has helped your organisation meet its data protection and freedom of information obligations.

You can submit your comments using the survey on our website. The deadline for responses is 5 October 2014

The ICO and Seven Shades of Grey

If you’ve nothing to do at lunchtime and you’re an experienced DP person try the ICO quiz on the difference between Data Controllers and Data Processors. You can find it here. After all it’s not a hard quiz. Data Controllers determine the purpose and own the data; data processors just do as they’re told. For years we’ve had this easy to understand relationship and many organisations have outsourced some work involving personal data, drawn up the contract, monitored the performance of it and we all knew where we were. Data Controllers were liable for any problems and Data Processors just did as they were instructed.

Recent guidance from the ICO changes this. Instead of clear yes/no and black/white definitions the commissioner recommends that each relationship with another person processing your data is examined to see how much influence the other person has over how the data is processed. As a result there are no easy answers. Just some shades of grey.

If you are eager to do the quiz and go for it without reading the guidance prepare yourself for a shock. Better DP experts than yourself have taken the test and not performed at all well.

The guidance is well meaning but bends over backwards to accommodate every possible possibility that it’s not that useful.

Image credit www.jimbanks.com

IAPP Privacy and Freedom: A review by Lawrence Serewicz (@lldzne)

The IAPP has republished Alan Westin’s best-known book, Privacy and Freedom, which was first published in 1967. Despite its age, the new version, it is the same text with several introductory essays, provides context for a reader coming to it for the first time. The introductory essays, which include one by Westin on how he viewed his work and its impact, provide a useful context for the author, the book and its relevance.

capture-20140605-122415

Although the introductory essays offer an insight into the book’s impact and the author’s contribution to privacy professional field, a critical essay would have been welcome because the privacy landscape has changed dramatically. The change is more than technological because it includes the change in cultural attitudes to privacy. The cultural and technological changes have undermined his definition.

For most readers, Westin and his book are best known for providing a robust definition of privacy. His book, and his definition, helped start the debate on privacy, in particular, the fair information practices in the United States, which by turn helped influence the Data Protection Directive in the EU. Westin’s definition is the book’s strength and weakness.

“to control, edit, manage, and delete information about them[selves] and decide when, how, and to what extent information is communicated to others.”

The definition has its critics. Roger Clarke for example criticized the definition as favouring businesses and he provides an alternative definition. He defines it as

“Privacy is the interest that individuals have in sustaining a ‘personal space’, free from interference by other people and organisations”

What is common to privacy definitions is the idea of control, which suggests privacy as autonomy. However, neither definition pays enough attention to the context. Westin’s definition is rightly criticized for its focus on business. However, that is not its weakness. Instead, it is the political context. Westin’s first chapter on history of privacy fails to situate privacy within the context of the state system or within a political philosophical tradition. Without that context, we misunderstand the intrinsic limit to any individual’s control and what that control can meaningfully achieve. In this criticism, I suggest something more than a reliance on human rights. His view fails to recognize that far from controlling his or her data, the modern individual is a creature of the state to the extent that they do not own or control their personal data. For example, we do not own our National Insurance Number, nor do we own our birth registration nor our Driver’s Licence number, yet decisions about us and how those are communicated are beyond our influence, let alone our control. These are records created by and for the state. The individual has a claim on them but cannot be said to own or control them in any meaningful sense.

A second limit to the book is its impact. To be sure, the book helped start and shape the debate over privacy. It remains a touchstone for privacy professionals, but it has had little impact on the general understanding of privacy. Despite the book and its definition, privacy has become increasingly problematic and confused. The extent to which businesses have ignored Westin’s privacy definition is clear in the recent debates and concerns over privacy standards at Google and Facebook. Companies today succeed by exploiting privacy, personal data, and limiting the user’s ability to control or access the personal data held by them. Moreover, the right to be forgotten, which suggests the ability to delete data, remains unachieved despite Westin’s definition.

A related concern is Westin’s definition reflects a US perspective as privacy is approached differently in the UK from the US.[1] The contrast between the two systems limits the book’s final section on policy prescriptions. Although he stressed that privacy is not a technological problem, he failed to address the qualitative changes wrought by “big data”. The technological opportunity changes the way that organisations, and states, can exploit, privacy or personal data, which means personal data can become a commodity. What would have been interesting, though beyond the scope of his original book, is a chapter on personal data as a commodity. However, Westin’s definition still resonates.

Westin’s definition still resonates in the way the UK courts now deal with the tort of misuse of personal information.[2] The tension is revealed because Westin’s definition reflects a US approach to individual rights that is closer in spirit to the EU position than the one based on UK common law. We see this tension in the concern over the effect of disclosure, for example seeking an injunction or seeking damages as in the Weller decision for how others have benefitted from the personal information. However, in the cases, the individuals do not control their personal information in a meaningful sense. We may have redress on its use, but that is not control, which the Fairstar decision seems to suggest.[3]

Dr Lawrence Serewicz is a Principal Information Management Officer at Durham County Council. The views expressed in this article are his own and do not represent the views of the Council.

Looking for a Practical DP qualification to enhance your skills and boost your career prospects? The new Act Now Data Protection Practitioner Certificate course is booking up fast.


[1] http://scholarship.law.duke.edu/cgi/viewcontent.cgi?article=3136&context=dlj

RJ Krotoszynski Jr – ‎1990 AUTONOMY, COMMUNITY, AND TRADITIONS OF LIBERTY: THE CONTRAST OF BRITISH AND AMERICAN PRIVACY LAW Duke Law Journal Vol 39 no. 6 1990:1398

[2] See for example, his summary of the tort and its legal context as well as recent cases exploring it. http://ukhumanrightsblog.com/2014/01/23/new-year-new-tort-of-misuse-of-private-information/

See also this analysis http://www.panopticonblog.com/2014/01/16/the-googlesafari-users-case-a-potential-revolution-in-dpa-litigation/ The Weller decision that is the most recent application of the misuse of personal information tort is here http://www.bailii.org/ew/cases/EWHC/QB/2014/1163.html [2014] EWHC 1163 (QB) The judgement provides a good summary of the case law leading to the decision. Imagine rights, let alone personal information rights, is another field to consider. http://inforrm.wordpress.com/2014/04/30/weller-article-8-and-the-recognition-of-image-rights-hugh-tomlinson-qc/

[3] http://www.bailii.org/ew/cases/EWHC/TCC/2012/2952.html fairstar [2012] EWHC 2952 (TCC), [2013] Bus LR D73, [2012] 2 CLC 795

NEW CCTV Code Consultation

CCTV MP900390153

On 20th May 2014, the Information Commissioner’s Office (ICO) launched a consultation on a revised Code of Practice on CCTV. This is intended to replace the current version, which was published in 2008, and aims to:

  • reflect the developments in existing technologies that have taken place in the last six years,
  • discuss the emergence of new surveillance technologies and the issues they present,
  • reflect further policy development in areas such as privacy impact assessments,
  • explain the impact that new case law has had on the area of surveillance systems
  • reflect the wider regulatory environment that exists when using surveillance systems.

Jonathan Bamford, Head of Strategic Liason at the ICO, states in his blog post that the revision covers “everything from automatic recognition of car number plates to flying drones” but emphasises that the underlying principles remain the same.

Since last Summer we have had two codes of practice on CCTV. The Surveillance Camera Code (PoFA code) came into force last year. Made pursuant to the Protection of Freedoms Act 2012 (PoFA) it governs governing the use of surveillance camera systems including CCTV and Automatic Number Plate Recognition (ANPR). The ICO code applies to all data controllers (public and privacy sector) but the PoFA code currently only applies, in the main, to local authorities and policing authorities. As regards its legal effects:

“A failure on the part of any person to act in accordance with any provision of this code does not of itself make that person liable to criminal or civil proceedings. This code is, however, admissible in evidence in criminal or civil proceedings, and a court or tribunal may take into account a failure by a relevant authority to have regard to the code in determining a question in any such proceedings” (paragraph 1.16).

The Surveillance Camera Commissioner (SCC) has been appointed by the Home Secretary but has no enforcement or inspection powers unlike the ICO. He “should consider how best to ensure that relevant authorities are aware of their duty to have regard for the Code and how best to encourage its voluntary adoption by other operators of surveillance camera systems” (paragraph 5.3). The ICO says of its revised CCTV code:

“This code is consistent with the [Home Office] code and therefore following the guidance contained in this document will also help you comply with many of the principles in that code”.

So why have two codes then? (Answers on a postcard or in the comment field below.) 

CCTV is a hot topic. Following complaints by Big Brother Watch, the ICO has taken enforcement action involving both number plate recognition and cameras recording people’s conversations in taxis. Big Brother Watch has welcomed the latest ICO consultation but has expressed concerns:

“We also remain concerned that, given that the responsibility for legally enforcing the Data Protection Act with regard to CCTV (apart from private cameras, which remain exempt) will remain with the ICO rather than the SCC, public confidence will not be helped if the process of making a complaint and action being taken is not straightforward. Equally, the situation of private cameras not being subject to regulation, with the only power available to the police to prosecute for harassment, is unsustainable as the number of people using them increases.”

The consultation runs until 1st July 2014.

Our full day CCTV workshop will explain the revised code and the wider law on CCTV surveillance in detail. Want a new practical qualification for the modern Data Protection Officer? Click here

The new EU Data Protection Regulation; Shoulda, Woulda, Coulda?

MC900440392

On the 13th March 2014 the European Union (EU) Parliament voted with an overwhelming majority to approve a new Data Protection Regulation within the EU. Voting on the initial text that was put forward by the Commission, and not the text put forward by the LIBE committee, the EU Parliament seem to have taken a “middle path” with regards to how this Regulation should work. Many of the Commission’s proposed appointed powers have gone, there doesn’t appear to be any “strict” provisions in there that the LIBE committee would have wanted and yet this approved draft is proposing a comprehensive and different world for Data Protection.

A fully updated draft has not been released by the EU as yet so I went through the painstaking task of making the edits confirmed by the EU to the original commission text. I can safely say I won’t be doing that again and once the approved draft is published I highly recommend that you read through from the beginning to get a flavour of where the regulation is heading and the wording used. I have however pulled out some of the highlights below for general consumption. Before I start however, I will declare that I am from the private sector but as Data Protection & Privacy is more than just a job for me (it’s a passion) I’m not one of those people that have campaigned against it (even if I think some if it is just barmy in my humble opinion).

For those that have worked only with the UK Data Protection Act this new world comes as a bit of a shock. Instead of a principle based approach the current regulation is more of a “financial regulation” with specific stances, requirements and demonstrations that certain things are occurring within an entity. For example, Point 60 requires Data Controllers to demonstrate and ensure compliance with the regulation, with a new sentence stating “this should be verified by independent internal or external auditors”.

However having said that, the EU Parliament have edited Point 65, so that it clears up the “administrative burden” query (or tries to) by stating that yes controllers must demonstrate compliance with the regulation however “equal emphasis and significance should be placed on good practice and compliance and not just the completion of documentation”. One assumes therefore that auditing to “a check list” isn’t going to occur even though the regulation spells out some things that need to be done specifically. Interesting…

‘Data Protection Impact Assessments’ are now outlined in points 71a&b and are very similar to the commission’s proposal that assessments should be done on the lifecycle of information management for processing of personal data. Section 75 states that for public sector bodies processing sensitive personal data or data on more than 5000 data subjects in 12 months they will need to periodically monitor compliance with the regulation. Is the requirement to self-audit the same as the requirement to tick a box?

The phrase that appeared in the initial draft on ‘data portability’ has also changed. It is still there but now Point 55 changes the “right to data portability” to “controllers should be encouraged to develop interoperable formats that enable data portability”. Encouraged how and by whom still remains to be seen.

Another ‘hot phrase’ in the initial draft and current buzz word after the European Court of Justice decision is the “right to be forgotten”, and as predicted that has been changed to now Point 53 has been updated to state that “the right to be forgotten” is indeed now to be called the “right to erasure” and that this right is overwritten where processing is needed for the performance of a contract or to meet local legal requirements. Point 54 & 54a specifically make reference to “online information” and the requirement for the facilitator to block or remove such data if the data subject requests.

On that point, similar concerns around the watering down of legitimate interests have also tried to be abated in this text, and now Point 39 specifically outlines a purpose for processing personal data being a valid “legitimate interest”. Namely the processing for Information Security / Network Security purposes where strictly necessary. 39a also outlines that ‘legitimate interest’ can also include processing for the prevention or limitation of damages on the controller, providing this does not significantly go against the data subject’s rights and freedoms. 39b adds direct marketing processing as a ‘legitimate interest’ again providing this does not go against the rights and freedoms of the individual. Is it me or do some of these provisions say “You can do it, but…”.

There are some further oddities in here; for example, point 32 states that if a controller does not want to follow ‘data minimisation’ requirements there is a burden of proof to justify the processing of Personal Data for that specific purpose / scenario. Again this is nothing new as this is in line with the principles of the UK DPA but we have not seen a requirement to document and justify before. 32 also states that collecting consent on behalf of 3rd parties is no longer seen as valid consent. Therefore if a business needs 3rd party data alongside the initial data subject’s data would it need to contact said 3rd party to seek consent. But then, isn’t it processing said data in order to contact them to get the consent? How would this work I wonder… citizens aren’t going to this for controllers so what other options are there?

Talking of consent, the concern that consent becomes more specific hasn’t been removed as Point 25 clarifies that consent will require “clear affirmative action” by a data subject in order to be seen as a valid consent. Silence or simply use by the data subject of a service would not be acceptable as a valid consent to process personal data. To the above point, how would a controller get such consent from 3rd parties?

Consent has also been factored in for the use of profiling and that consent can be removed at any time. However Point 58 has been updated to state the for profiling, “Profiling which leads to measures producing legal effects concerning the data subject or does similarly significantly affect the interests, rights or freedoms of the concerned data subject should only be allowed when expressly authorised by law, carried out in the course of entering or performance of a contract, or when the data subject has given his consent”. Now here I believe that “carried out in the course of entering or performance of a contract” means that credit profiling can continue in the UK otherwise these seems to conflict with current legal requirements on Banks and Lenders to ensure that you as the customer can afford the product they offer and that you as the lender are lending responsibly – this can only be done by credit profiling surely?

Another area of concern from the initial text was around breach notification. There is still no useful outline as to what a material breach consists of however Point 67 confirms that data breach notification to the relevant authority “should be presumed to be not later than 72 hours” – somewhat better than the initial 24 hours but still something causing concern among various industries.

On the up side however, a new point specifically referencing Freedom of Information has been added. Point 18 has been updated to make reference to relevant member states Freedom of Information (FOI) legislation and how this regulation interacts with that. That’s some concerns appeased… or is it?

The EU Parliament have also updated what is expected of us DPOs and point 75a states that DPOs should have the following experience / qualifications;

  • extensive knowledge of the substance and application of data protection law, including technical and organisational measures and procedures;
  • mastery of technical requirements for privacy by design, privacy by default and data security;
  • industry-specific knowledge in accordance with the size of the controller or processor and the sensitivity of the data to be processed;
  • the ability to carry out inspections, consultation, documentation, and log file analysis;
  • and the ability to work with employee representation.

The controller should enable the data protection officer to take part in advanced training measures to maintain the specialized knowledge required to perform his or her duties.

Overall the current draft regulation has either been improved from what it was, stayed the same, or gotten worse in some places.

There are some ups and downs, and a few more changes that have been made that I have not referenced here (as I could be here all day). As for next steps for the Regulation I really don’t know who to believe. The ICO in a recent statement stated that they don’t believe there will be a tangible regulation until 2017 at the earliest. But in the same breath they also said (they being David Smith the Deputy ICO) that you should get your house in order now with current requirements as this puts you in a good place ready for the Regulation in 2017. Given how the Parliament approved the text way ahead of schedule and that this piece of legislation is the “most lobbied and campaigned on” in the EU’s history I am inclined to believe that all bets are off. I can see the case that it will come through quickly, especially as the EU is very defensive of Data Protection and Privacy of late. But then I also see the argument and stance from the European Council that they don’t want to rush this and instead want to take their time. As this Regulation would need agreement from the Council, the Parliament and the Commission I can see it rattling on for a while. But, as my favourite TV programme as a child used to say “Stand by for action; anything can happen in the next half an hour”. (For those that don’t know, that was from Stingray – and yes, I am a Geek that needs to get out more).

I have my word document unofficial text which I am happy to share on request but it is very much unofficial and really isn’t to be considered “official” in any capacity. Well worth a read though, and again I recommend that when the official text is finally updated and released (the EU moves at its own pace on such things) that you have it as some bed time reading to fill you with hope (and possibly nightmares).

Nighty night.

Scott Sammons is currently a European Data Protection Officer within the Finance Industry and blogs under the name @privacyminion . Scott is on the Exam Board for the Act Now Data Protection Practitioner Certificate which is a qualification designed to give candidates a head start in understanding and implementing the proposed EU Data Protection Regulation.

To Share or not to share, that is the question

file6771267335956

As many data protection practitioners are well aware, there is a whole raft of legislation affecting the sharing of personal data. There are laws to tell us we must share. There are laws to tell us we absolutely must not share. There are laws that say we can share specific personal data with specific named bodies. There are laws that suggest implicitly that we can share, maybe, if the wind is blowing in the right direction that day…but we could always be challenged on that sort of sharing. It’s a minefield for your data protection officer who dreads that question “Can we share that data?” The response inevitably, and somewhat unhelpfully, is often “Well, it depends….”. With monetary penalties available to the Information Commissioner of up to £500,000 if your organisation gets it horribly wrong, it’s hardly surprising such organisations are often risk-averse when it comes to data sharing with other third parties.

It seems almost impossible for any one individual to be knowledgeable about all of these different rules, hidden within numerous Acts of Parliament, Regulations, and Statutory Instruments (There is no consistent way of publishing these). Take for example birth and death data. Local authorities need to know where new-born babies are, not only to plan future school places but also to meet statutory Ofsted reach targets which require them to contact the new parent or parents to offer services for the child. It would seem obvious to acquire that information from their local authority registration service. Yet the Office of National Statistics point out that Statistics and Registration Service Act 2007 explicitly prohibits the local registration service from passing that information to its local council, its own employer, except for public health purposes.

The Law Commission, which has been studying this issue for the last year, says that it has only just begun to scratch the surface regarding the huge amount of different pieces of legislation that contain references to data sharing. It looks set to recommend this month to Government that there should be a full review of the law relating to information and personal data sharing.

Government Proposals

The Government has for some time realised that this is a problem and wishes to “develop a better understanding of the economy and society, deliver more targeted and joined-up public services, and save public money lost through fraud, error and debt ” through effective, and legal, information sharing.

Current legislative and cultural barriers have resulted in a cottage industry of data sharing agreements between government departments and other partners, which can take time and resources to put in place. The government is well aware, at a time when Care.Data is the elephant in the room, that trust is a key issue in this process. How can the government ensure sensible data sharing to provide more efficient and less costly services for the public, which complies with all relevant legislation (the Data Protection Act 1998, the Human Rights Act 1998 and the more tricky issue of the unwritten common law duty of confidentially) and maintain the trust of the public? To address this it has decided to launch an open policy making process:

The intention is to embark upon an open policy process that brings together those inside and outside government interested in maximising the benefits and minimising the downsides to citizens of personal data sharing within government.”

The Cabinet Office, in collaboration with other government departments, is leading on the work, driven by Cabinet Minister Francis Maude, who is responsible for the Government’s transparency policy. This work must now dovetail with the Law Commission’s proposals and ultimately the new proposed EU Data Protection Regulation. The process is being coordinated by Involve, a civil society organisation, which has been awarded £20,000 to progress the policy-making process. Initial meetings have been held, a mailing list and website established, and input is now required from anyone interested in helping to shape future data sharing of public sector information.

Organisations are actively being encouraged to become involved. Civil society organisations involved to date include the likes of Big Brother Watch, MedConfidential, No2ID, The Open Rights Group, The Children’s Society, New Philanthropy Capital, Nuffield Foundation, Open Data Institute, Which and the ESRC.

What happens next?

The expected future developments of the process are as follows:

  • The Law Commission will report in April recommending a review of the law relating to data sharing.
  • Proposals will be developed under the new open policy making process until mid-August.
  • A policy document will be produced for mid-September for MPs to consider upon returning from recess.
  • Legal Counsel to produce key draft clauses and a White paper for the Christmas break.
  • Open public consultation Jan – March 2015.
  • The next Government will consider any data sharing proposals in the first session of Parliament after the 2015 General Election.

Clearly there needs to be cross-party support for this project for it to proceed past the next election. It is however very likely that this will be supported by all main parties and should not be a showstopper. The engagement of the organisations mentioned above at this early stage is important. With high profile organisations such as those on board, ensuring that privacy concerns are addressed early, it reduces the chance of problems for the government later in the process… and enables the government to cash in on a potential £16 billion of estimated income from UK data assets.

More importantly for the public though, this more inclusive process will hopefully genuinely address those privacy concerns that appear to have been wilfully ignored during the Care.Data process. This week has seen media reports focussing on HMRC selling our tax records next, and the fact that children’s records are already sold; a fact parents were no doubt unaware of and certainly not consulted upon. It is therefore vitally important that practitioners and organisations on the ground, the ones physically sharing data on a daily basis, can feed into this process in its initial stages to highlight and bottom out real practical issues as well as legislative and cultural ones.

This is no small task, and the timetable is incredibly tight to keep those involved focussed. As Francis Maude said at the last meeting, we don’t even know if we will be able to come up with anything workable; it could simply be too difficult. It is however worth the effort if it simplifies the data sharing process and offers the public a better and cost-effective service, whilst taking into account privacy concerns.

It’s not too late to get involved. If you have experience of information sharing or are a data protection practitioner or privacy expert, you can sign up at the www.datasharing.org.uk website, or join the mailing list, and help shape the proposed White Paper.

Lynn Wyeth is the Information Governance Manager at Leicester City Council. Follow her on Twitter @LynnFoi.

We will be discussing these developments in our forthcoming information sharing workshops.

Surveillance and the DPA

survey_iconRoger J Bescoby of the Brownsword Group writes:

Brownsword Group is often engaged to undertake covert surveillance on behalf of clients, including public bodies and insurance companies, where, for example, there are allegations of insurance fraud or spurious personal injury claims. All surveillance is done in compliance with relevant laws and codes of practice including the Data Protection Act 1998.

In the last two weeks we have been asked to clarify two procedural points in relation to the submission of video surveillance evidence. In both matters we were fully confident of our position, but in order to confirm beyond doubt, we have received excellent and swift support from the Information Commissioner’s Office (ICO). We would like to share the events with you:

TO PIXELATE OR NOT TO PIXELATE?

We were asked to comment as to the necessity of pixelating the faces of ‘others’ (third parties) when submitting a covert video surveillance report. Our client was of the opinion that this may indeed be a requirement under the Data Protection Act (DPA).

We do not routinely pixelate the faces of others captured on film, irrespective of them being adults or minors, believing there is no such requirement. (The filming of minors and ‘others’ is avoided at all times, where logistically possible, to minimise any collateral intrusion. This is a key element in our operatives’ training regime.)

Following direct consultation, the ICO confirmed to us that there is no requirement under DPA to pixelate out the faces of others in Civil Cases such as personal injury claims. The only time the DPA requires pixelation is when providing film data under a Subject Access Request (SAR).

The ICO helpfully went further, saying that pixelation could be seen or construed as ‘tampering’ with the evidence upon which all parties are to carry out an evidential assessment. It could also deny the data subject the opportunity to identify potential witnesses which may assist their case.

Pixelation is a laborious process that adds time and expense to the production of evidence. We think any such requests should be strenuously refuted, quoting the ICO’s clear opinion above. (see also the ICO’s CCTV Code of Practice)

FILMING OF MINORS?

One of our surveillance films was recently used in evidence in an Employment Tribunal. The circumstances were that an employee, off sick with a severe back condition, was believed to be ‘malingering’. Surveillance evidence strongly suggested this was the case; at one stage during the surveillance the subject was observed to freely bend down to pick up his infant child and secure him in a car seat, involving continued bending and twisting etc.

The employee instructed a Trade Union lawyer to represent him at Tribunal, during which the extraordinary claim was made that ‘filming of children is illegal’.

Again we were fully confident that our processing here was justified, fair and relevant. The Tribunal (who you would have thought should know better) however required confirmation on the point. We made immediate and urgent contact with the ICO requesting a clarification. By return of email the ICO confirmed that the DPA 1998 does not prohibit the processing of personal data  relating to children as such. What it does is set out is how personal data should be processed, i.e. fairly and lawfully. Furthermore the ICO confirmed the Act would not prohibit filming of a child if it were proportionate in the circumstances and was of such evidential worth that the omission of the images would be prejudicial to the case in hand.

There is no doubt that a new air of sensitivity exists surrounding the filming of minors. Brownsword Group have strict policies and procedures in place that ensure we avoid the capturing of children on film wherever logistically possible. The ‘Savile /and others’ enquiry has understandably played its part in this, but it is important to be alert to spurious arguments now being raised, perhaps with a scurrilous intent to muddy the waters?

Collateral Intrusion is recognised, fully understood and accepted by the ICO, providing there is evidence that the surveillance operative has, overall, demonstrated the due discrimination and proportionality that the DPA requires.

THE ICO AND COVERT SURVEILLANCE GENERALLY

We have had several extremely useful meetings with the ICO recently, finding them very helpful and indeed supportive of some exciting initiatives we have put forward.

Be in no doubt, the ICO fully understand the necessity and the vital role covert surveillance plays in the prevention and validation of insurance fraud. The DPA still usefully provides the same ‘Legitimate Interest’ exemptions that have existed since 1998. All the ICO reasonably ask is that surveillance is undertaken fairly, justifiably and proportionately.

We know exactly how the ICO like things to be – follow those rules and surveillance is there, ready and waiting to be deployed just as it always has been – to protect honest policyholders.

Please get in touch if you require further information on any of the above.

Roger J Bescoby MABI is Director of Strategic Development at Brownsword Group (Visit www.brownsword.com & www.talk-safe.co.uk)

Act Now is running a series of webinars on aspects of surveillance law including the CCTV Code and an update on RIPA. Details here: http://www.actnow.org.uk/content/93

RIPA Part 2 Inspections: Common Criticisms by the OSC

examThe Office of Surveillance Commissioners (OSC) is responsible for overseeing the use of covert surveillance by designated public authorities by carrying out regular inspections. (Appendix E of the Chief Surveillance Commissioner’s Annual Report (2012-13) lists those whom the OSC inspects and how often.) In the UK the inspections check councils’ compliance with Part 2 of the Regulation of Investigatory Powers Act 2000(RIPA) (and in Scotland The Regulation of Investigatory Powers (Scotland) Act 2000 (RIP(S)A)) for use directed surveillance, intrusive surveillance and covert human intelligence sources (CHIS).

As part of our provision of tailored in house training, we have to read OSC inspection reports. The following is a list of common mistakes highlighted by the OSC. They are not attributable to any particular organisation.

FORMS

  • Use of out of date forms
  • No Unique Reference Number (URN)
  • Not amending forms so that only those grounds are present which are available to the public authority e.g. councils – preventing or detecting crime
  • Pre completed forms
  • Use of cut and paste in boxes/repetitive narrative

AUTHORISATION PROCESS

  • Rubber stamping – no real thought given to authorisation
  • Necessity, proportionality and collateral intrusion not fully understood/considered by investigators and authorisers
  • Likelihood of obtaining Confidential Information not fully considered
  • Some ‘open source’ internet research is being conducted which may actually meet the criteria of Directed Surveillance and therefore require authorisation
  • Confusion re: reviews and renewals
  • Lack of understanding of when a person is a CHIS
  • Two many Authorising Officers
  • Authorising Officers are not making adequate provision for destruction of product that is collateral intrusion or of no value to the operation
  • Several authorities are pooling resources but then not obtaining authorisations and keeping records in relation to a proper designated authority
  • Confusion about interference with property powers under Police Act 
1997
  • NB councils cannot do this
  • More robust management and quality assurance procedures required 


RECORD KEEPING

  • Central records not compliant with the Code of Practice
  • Inadequate monitoring, recording and audit of surveillance equipment
  • Inadequate handling and storage of surveillance product/evidence 


POLICIES AND PROCEDURE DOCUMENTS

  • Inadequate/no RIPA policy
  • In adequate guidance document (or out of date)
  • No CCTV protocol/procedure
  • OSC may wish to visit your CCTV control room

TRAINING AND AWARENESS

  • Inadequate training
  • Lack of regular training/refresher trainer
  • Inadequate record of those who have been trained
  • OSC may ask to see recent training materials

If you are considering refresher training for RIPA investigators and authorisers, please see our full program of RIPA Courses and our online webinars. We can also deliver tailored in house training at your premises.

Ever since the changes to the council surveillance regime, which came into force on 1st November 2012, the OSC has taken an interest in ensuring councils do not authorise surveillance under RIPA for “minor offences.” In addition they have been keen to ensure that council’s have an agreed protocol and procedure for presenting authorisation applications to the Magistrates’ Courts. Finally where surveillance needs to be done outside the scope of RIPA then a Non RIPA authorisation policy should be implemented and followed.

Do your RIPA documents need revision? Avoid re inventing the wheel! Our RIPA Policy and Procedures Toolkit gives you a standard policy as well as forms (with detailed notes to assist completion) for authorising RIPA and non-RIPA surveillance. Over 200 different organisations have bought this document (available on CD as well).

(Probably) The First Group Action For Damages under the Data Protection Act

DPA4

In December 2013 a group legal action was settled against the London Borough of Islington following breaches of the Data Protection Act 1998 and the Human Rights Act 1998. Anna Thwaites, partner at Hodge Jones & Allen LLP, and Ruth Brander, counsel from Doughty Street Chambers, acted for the claimants.

Anna explains the background and legal basis for the claims below:

Hodge Jones & Allen LLP & Doughty Street Chambers acted for 14 Claimants in a Group Action against the London Borough of Islington after it leaked their personal data to unauthorised third parties on two separate occasions in 2012.

The First Breach – April 2012

In April 2012, Islington Council sought injunctions against thirteen youths for anti-social behaviour. The injunctions were served on ten of these between 20th and 24th April 2012. On 26th April it became known to the council that personal information regarding residents who had made complaints about anti-social behaviour had been disclosed to the injunctees. An unredacted spread sheet of Anti-Social Behaviour (ASB) Hotline calls and concierge reports had been included. These contained complaints from 50 individuals. In many cases this included the name, telephone number and estate/street name.

The police retrieved seven out of the ten injunction packs issued to the individuals. The police also warned the injunctees that they should not use the information to contact any witness. In the immediate aftermath, there was a police presence on the Andover Estate and some residents moved from their properties to new locations.

An Information Commissioner’s Office (ICO) investigation was instigated and various recommendations made. The Council agreed to a voluntary inspection rather than a monetary fine. 

The Second Breach – 26 June to 14 July 2012

Whilst responding to a Freedom of Information Act request on the website ‘What Do They Know,’ the Council sent an Excel spreadsheet containing details of housing allocations to an organisation called mySociety. The spreadsheet included sensitive personal data on people offered social housing by the Council. This included their name, address, gender, ethnicity, religion, sexuality, relationship status and assessment of housing priority needs. Over 2,400 residents were affected.

Between 26 June and 14 July 2012, there were 7 download requests on this website. It is not possible to know whether any of the people downloading this information accessed the Excel spreadsheets containing this highly personal and sensitive information.

Following this breach there was an ICO investigation and the Council was fined £70,000. This was in addition to the compensation paid to the individual Claimants.

The Claims

We acted for four Claimants affected by the first breach, eight Claimants affected by the second breach and two Claimants affected by both breaches.

The Claimants’ principal claims were for stress, distress and frustration. Some Claimants believed the breach exacerbated existing psychological or psychiatric conditions. Very few Claimants had incurred financial losses arising from the Council’s breaches.

Around April 2013, Letters of Claim were sent to the Council for each Claimant alleging a breach of the Data Protection Act 1998 and Human Rights Act 1998 following a breach of Article 8 ECHR (the right to family and private life).

The parties entered into a limitation standstill agreement in respect of the Human Rights Act claim. Under section 7(5) of the Human Rights Act 1998, a claim must be brought before the end of the period of one year beginning with the date on which the act complained of took place or such longer period as the court considers equitable having regard to all of the circumstances. This was the best way to preserve the Claimants’ position without issuing court proceedings.

At the conclusion of the Council’s Pre-Action Protocol Investigations, they admitted liability in July 2013 for breaches of the Data Protection Act and Article 8 ECHR for all but one of the Claimants. In relation to this Claimant, they advised that the Claimant had been erroneously informed that their data had been breached, when in fact it had not. The Council made Part 36 offers in settlement to all Claimants ranging from £500 to £5,000.

Following settlement negotiations, all claims settled in December 2013 without the need to issue court proceedings. The Claimants were awarded over £43,000 in compensation. The awards ranged from £1,000 to £5,000 depending on how the breach impacted on each Claimant.

As part of the terms of settlement, the Council provided an unreserved apology and provided a detailed letter to each Claimant outlining how the breach happened, how it was discovered, the changes made subsequently and lessons learnt. All of the Claimants’ cases were funded under Conditional Fee Agreements under the pre 1 April 2013 regime.

Thoughts on the Case

It was clear from the outset that there had been a breach of the Data Protection Act, but in order to be entitled to compensation under section 13(2) a Claimant must suffer damage.

The difficulty with these cases is that many of the Claimants were unable to establish a financial loss or a personal injury arising from the Council’s contravention. This issue was not explored in depth during litigation given the Council’s early admission of liability and Part 36 offers in settlement, but the case of Halliday v Creation Consumer Finances [2013] 3 CMLR 4 would have assisted the Claimants on this point.

In this case, the Court was prepared to award nominal damages of £750 for distress to reflect a breach of the Data Protection Act, even if there was insufficient evidence to establish a substantial breach. The Court did not penalise the Claimant for being unable to establish a financial loss arising from the breach. The Claimants’ cases are clearly analogous and this case also provided some helpful guidance on the level of compensation the Courts may award depending on the facts of the case.

Another factor which potentially led to early settlement is that Article 8 ECHR does not have the same requirement as the Data Protection Act to establish ‘damage,’ although there is very little case law on the level of damages the Court may award in this type of case. Traditionally compensation for breaches of the Human Rights Act have been less generous than compensation awarded by the domestic courts.

It would also be interesting to see if the Council’s approach would have changed if the claims were brought on the basis of the Data Protection Act alone or outside the time limits for a Human Rights Act claim.

However, these cases clearly demonstrate that a failure to comply with the Data Protection Act 1998 and/ or Article 8 ECHR will be at a Defendant’s peril. This was an extremely costly mistake for the Council, who failed to learn from their mistakes and breached the Data Protection Act 1998/ Article 8 ECHR not only once but twice in as many months.

It is hoped that, following the ICO investigation and litigation, the same mistakes will not be made again. A clear message has been sent to Public Authorities of the potential consequences of failing to comply with their obligations to safeguard citizen’s personal data. This case also shows how Data Controllers can be held accountable for their actions.

Keep up to date with the latest DP developments by attending our workshops and online courses.

Definition of Personal Data: Durant Revisited

DPA22December 2013 marked the 10-year anniversary of one of Data Protection’s most notorious developments, but it came and went without any great fanfare.

It’s not really surprising that the Information Commissioner’s Office (ICO)  didn’t issue a press release celebrating the Durant judgment’s birthday, as they have been quietly attempting to erase it from history. The result of a long-running dispute between a former Barclays Bank customer and the now defunct Financial Services Authority, Durant v Financial Services Authority [2003] EWCA Civ 1746 was a significant case. The Court of Appeal judges took a sharp look at the definition of personal data, what kinds of manual files are covered by subject access, and the purposes for which subject access can be used – with controversial results. I happened to speak to a former colleague at the ICO a day after Durant was published, and he described the atmosphere as ‘panic’.

Some of Durant is helpful – the judgement proposes that personal data:

should have the putative data subject as its focus rather than some other person with whom he may have been involved or some transaction or event in which he may have figured or have had an interest”.

Those who have worked on Data Protection for a long time will have encountered the view that the mere mention of a person’s name in an email meant that they were entitled to receive it. Durant torpedoed that notion. Other elements remain contentious – the ICO has never agreed with the assertion in paragraph 27 that subject access should not be used “to obtain discovery of documents that may assist him in litigation or complaints against third parties”, The new ICO Subject Access Code rejects this notion altogether, despite the fact that the lower courts have followed the principle every since. However, Durant’s most irksome element – ‘biographical significance’ – has been put in its place by the same court that invented it.

Mr Durant sought data about the FSA’s investigation into his complaints about Barclays, and his lawyers used an expansive interpretation of ‘personal data’ to stake his claim. The FSA’s focus was on Barclays and its practices, which meant that much of the correspondence Durant wanted was about the bank. He also wanted the names of the FSA staff that had dealt with his complaint. Unfortunately, Auld LJ linked the sensible idea of focus to a notion of ‘biographical significance’ test, stating that personal data must be “information that affects [a person’s] privacy, whether in his personal or family life, business or professional capacity”. This was a complicating and potentially unhelpful development. Focus makes sense – an email in which your name is mentioned in passing may well not be about you. But biographical significance is an unnecessary and restrictive innovation.

For example, when looking at a CCTV image with a person in the centre and bystanders in the background, the idea of ‘focus’ allows you to distinguish between the obvious subject of the image and the others. But asking whether the image is biographically significant raises the possibility that a clear picture of a living, identifiable person isn’t actually personal data if it has no private connotations. Is an image of me walking down the street biographically significant? Many have adopted biographical significance as a rule of thumb, a test to apply whenever the question of personal data was raised. In the public sector, it could mean that data about people that wasn’t biographically significant could be disclosed under the Freedom of Information Act 2000 (FOI) because it wasn’t technically ‘personal data’. In the private sector, anything not ‘biographically significant’ could be legally invisible, subject to none of Data Protection’s requirements.

The ICO’s approach to Durant – after the alleged panic subsided – was initially mixed, but for quite a few years it has been consistent. As some sort of riposte to Durant, in 2007 they published technical guidance on the meaning of ‘personal data’ called ‘Determining what is personal data’ – rather than Durant’s narrow, privacy-piercing interpretation. There are few references to Durant anywhere in the ICO’s output, but the technical guidance makes clear that testing ‘biographical significance’ is far from being an automatic or necessary step – it is for borderline cases when context and common sense don’t get you to the answer.

Many data controllers have been tempted to use Durant as a way of shrinking Data Protection down to a comfortable size. Indeed, when considering FOI cases involving personal data, the First Tier Tribunal appears to see the test as an inherent part of the decision, and biographical significance is often a feature of FOISA decisions by the Scottish Information Commissioner. Nevertheless, the ICO’s 2007 interpretation of Durant is logical. LJ Auld himself said that biographical significance was a notion “that may be of assistance” rather than a fundamental key to understanding personal data. Just as important was the balance provided by Buxton LJ, who noted at the end of the judgement that the tests were “a clear guide in borderline cases”. The Durant case was – in effect – about Mr Durant’s case, and didn’t change Data Protection as much as some have suggested.

For confirmation of this, fast-forward to Edem v IC & Financial Services Authority [2014] EWCA Civ 92, a Court of Appeal decision on a different case concerning another unhappy FSA (now the Financial Conduct Authority) complainant published this month. Mr Durant wanted to use Data Protection subject access to obtain his own data, and everything connected with it. Mr Edem wanted to use FOI to find out data about other people – specifically, the names and job titles of the junior staff who had dealt with his complaint. The FSA and Information Commissioner agreed that the data was personal, and that disclosure was unfair. So far, so uncontroversial. A spanner was thrown into the works by the First Tier Tribunal, to which Mr Edem appealed the ICO Decision. Using the biographical significance test, the FTT found that names and job titles were not biographically significant, and the focus of the information sought by Mr Edem was the investigation. The Edem FTT case was like a hall of mirrors, distorting and reflecting Durant to the extent that a type of information Mr Durant couldn’t get from the FSA under DP was now available to Mr Edem under FOI.

An appeal to the Upper Tribunal restored the ICO position, and so Mr Edem went to the Court of Appeal. A few cases – mainly resulting from appeals on FOISA decisions – have gone high enough in the UK court system to challenge Durant, but all skirted Durant itself. The Edem case was different – Durant and biographical significance had to be looked at head-on. The result is good news for common sense and data subjects, but bad for anyone who wants to finagle their way out of an awkward subject access request.

Paragraph 17 of the Edem Court of Appeal case isn’t the death knell for Durant, but it’s a healthy and heavy dose of context:

The First Tier Tribunal were wrong to apply Auld LJ’s “notions” in this case”.

When trying to work out whether a person’s name is personal data, the Court says that biographical significance is irrelevant. The question is whether the data identifies a living individual, and without any complicating or contradictory factors, the data is all you need. My name is Tim Turner, and while that’s not enough to find the bearded Act Now Trainer on the internet (there are country singers and ice hockey players and the man who played the Invisible Man in TV in the 1950s to sort through), it’s easily enough to locate information about me in any of the places I have worked. The Court of Appeal in Edem wholly endorses the ICO view of biographical significance as an occasional add-on, and uses Buxton LJ’s comments from Durant itself to back up that approach.

If it was wrong to overplay the effect of Durant, it’s equally wrong to overplay Edem. For the public sector, Durant was always blunted by the onset of FOI – if you successfully argued that data wasn’t personal data about the subject access applicant, they could always ask for it under FOI. The new judgment doesn’t give new rights to data subjects or expand Data Protection’s reach. A person who wants to use Data Protection to get access to large amounts of information to which they have some loose or stretched connection will come to grief just as Mr Durant did. But the Edem case does restore logic – data that identifies a person, even in a relatively benign or innocuous way – is personal data. The Eight DP Principles apply. Even when at work and doing mundane professional tasks, the DPA is likely to be engaged. An apparent loophole has not been closed – the Edem case simply confirms that it was a lot smaller than it may have appeared. The ICO approach is vindicated, and both the First Tier Tribunal and bloody-minded data controllers may have to think again.

Tim Turner is one of Act Now’s well-known data protection experts. He will be considering this and other latest Data Protection developments in his forthcoming DP Update workshops . Read more of Tim’s expert analysis on his blog. Readers wanting to see how the Durant case has been applied in previous decisions should read Ezsias v The Welsh Ministers (2007).