Our survey said…

 

image

 

I bought a new car. On delivery day it was in the showroom draped in a royal blue cloth with a sign saying Reserved for Mr Onassis. The salesman before handing me the keys mumbled in an apologetic fashion “The Sales Manager likes to talk to every customer when they take delivery…”

The Sales Manager didn’t waste much time. He said that I’d shortly be receiving a call from a company who surveys new car buyers to find out what they thought of the dealership. Then he slipped in the hard sell. “They’ll ask you to mark us on a scale of 1 to 10. Only 9 and 10 are positive; anything below that is negative.”

The survey duly arrived. I declined to answer even though I was very happy with the car and the dealership.

Days later my bank called me. I was probably going to be asked to rate my bank. From a list of phrases from very displeased to very pleased I had to choose the phrase that best described my experience. “Please be sure to say you’re very pleased with our service. Anything else is considered negative”. Again I declined to do the survey even though my bank is pretty awful.

Last week a hotel that Act Now Training uses did the same thing. Please let us know what you think of our hotel. This time the hotel manager foolishly put his suggestion “Actually it’s a yes/no question; anything under 8 is negative. We need 9s and 10s” in an email. Now we have the evidence that the practice exists. Previously the conspiracy had only survived by word of mouth.

I haven’t answered yet.

What value does a survey have when the surveyees are primed to deliver the response the company wants? Is every survey result is the product of a self selecting group – the group of people who like to give high scores in surveys? Or is there another group like me who never participate in the survey who feel there’s no value in a survey where the traditional Likert scale has been morphed into a 50/50 shot? Most brits are stiff upper lip types who won’t take a survey if their views would have been critical in case someone contacted them afterwards.

Is the information age producing better information or is the value or a survey subjective, objective or merely the result of a carefully orchestrated customer manipulation.

This article already had 12,500 likes before I posted it. Find them on Ebay.

Paul Simpkins is a Director and Trainer at Act Now Training Ltd. He will be delivering the internationally recognized BCS certificate in Data Protection in June. If you are interested in this or any other Act Now training courses on Information governance, please visit our website www.actnow.org.uk

All Change for Data Sharing?

canstockphoto0925773Last year the Law Commission launched a consultation on the law around sharing of personal information between public sector organisations. The paper outlined the current law and asked 22 broad questions. In July, following analysis of the consultation responses, the Commission recommended a full-scale, UK-wide reform project to consider how the current law can be simplified and modernised.

The legalities of data sharing is a subject which often confuses public sector officials. Local authorities, in particular, are often stumped by the “To Share or Not to Share” question, even if the sharing is for very good reasons (e.g. child protection or crime prevention). More often than not, the Data Protection Act 1998 (DPA) is made the scapegoat for officials’ failure to fully understand the law. It is wrongly perceived as a barrier to data sharing despite offering a range of justifications (e.g. consent, legal obligation, protecting vital interests etc. (Schedule 2)). According to Nicholas Paines QC, the Law Commissioner responsible for public law:

“Data sharing law must achieve a balance between the public interest in sharing information and the public interest in protecting privacy,”

Public authorities are right to be cautious though. See the recent decision in AB & Anor, R (on the application of) v The London Borough of Haringey [2013] EWHC 416 (Admin) (13 March 2013) where a judge ruled that the council’s data gathering had been unlawful because consent from the data subject was not sought.

The Commission received 87 written responses to its consultation paper, from a range of different individuals and organisations.  It published its report, including its analysis of consultation responses on 11 July 2014. The report sets out its recommendations as follows:

“We made three recommendations.

  1. We recommend that a full law reform project should be carried out in order to create a principled and clear legal structure for data sharing, which will meet the needs of society.  These needs include efficient and effective government, the delivery of public services and the protection of privacy. Data sharing law must accord with emerging European law and cope with technological advances.  The project should include work to map, modernise, simplify and clarify the statutory provisions that permit and control data sharing and review the common law. 
  1. The scope of the review should extend beyond data sharing between public bodies to the disclosure of information between public bodies and other organisations carrying out public functions.
  1. The project should be conducted on a tripartite basis by the Law Commission of England and Wales, together with the Scottish Law Commission and the Northern Ireland Law Commission.

The Commission suggests that the project could usefully include consideration of the functions of the Information Commissioner in relation to data sharing, including the Commissioner’s enforcement role (Read the ICO’s response to the consultation.)

The Cabinet Office and the Ministry of Justice will now decide together whether to refer a full law reform project to the Law Commission.

Don’t hold your breath. We have been here before! Furthermore, do we really need new laws on data sharing or a better awareness of the existing ones? As I have said before, the current law is adequate to regulate yet allow responsible data sharing. The DPA and the ICO Data Sharing Code can be very useful tools for allowing responsible data sharing if they are properly understood.

STOP PRESS – The final report of the Home Office research into “Multi Agency Working and Information Sharing” was published on 1st August.  The report makes for interesting reading, and sets out a number of commitments the Home Office is making to continue to support multi agency working and information sharing.

Ibrahim Hasan will be conducting full day Information Sharing workshops in Manchester and London in September.


ICO invites practitioners to feedback on its Data Sharing Code of Practice

The ICO is inviting feedback on its Data Sharing Code of Practice.

Published in May 2011 the publication continues to be one of our most popular pieces of guidance. We would like to hear about how you’re using the guidance and how it has helped your organisation meet its data protection and freedom of information obligations.

You can submit your comments using the survey on our website. The deadline for responses is 5 October 2014

To Share or not to share, that is the question

file6771267335956

As many data protection practitioners are well aware, there is a whole raft of legislation affecting the sharing of personal data. There are laws to tell us we must share. There are laws to tell us we absolutely must not share. There are laws that say we can share specific personal data with specific named bodies. There are laws that suggest implicitly that we can share, maybe, if the wind is blowing in the right direction that day…but we could always be challenged on that sort of sharing. It’s a minefield for your data protection officer who dreads that question “Can we share that data?” The response inevitably, and somewhat unhelpfully, is often “Well, it depends….”. With monetary penalties available to the Information Commissioner of up to £500,000 if your organisation gets it horribly wrong, it’s hardly surprising such organisations are often risk-averse when it comes to data sharing with other third parties.

It seems almost impossible for any one individual to be knowledgeable about all of these different rules, hidden within numerous Acts of Parliament, Regulations, and Statutory Instruments (There is no consistent way of publishing these). Take for example birth and death data. Local authorities need to know where new-born babies are, not only to plan future school places but also to meet statutory Ofsted reach targets which require them to contact the new parent or parents to offer services for the child. It would seem obvious to acquire that information from their local authority registration service. Yet the Office of National Statistics point out that Statistics and Registration Service Act 2007 explicitly prohibits the local registration service from passing that information to its local council, its own employer, except for public health purposes.

The Law Commission, which has been studying this issue for the last year, says that it has only just begun to scratch the surface regarding the huge amount of different pieces of legislation that contain references to data sharing. It looks set to recommend this month to Government that there should be a full review of the law relating to information and personal data sharing.

Government Proposals

The Government has for some time realised that this is a problem and wishes to “develop a better understanding of the economy and society, deliver more targeted and joined-up public services, and save public money lost through fraud, error and debt ” through effective, and legal, information sharing.

Current legislative and cultural barriers have resulted in a cottage industry of data sharing agreements between government departments and other partners, which can take time and resources to put in place. The government is well aware, at a time when Care.Data is the elephant in the room, that trust is a key issue in this process. How can the government ensure sensible data sharing to provide more efficient and less costly services for the public, which complies with all relevant legislation (the Data Protection Act 1998, the Human Rights Act 1998 and the more tricky issue of the unwritten common law duty of confidentially) and maintain the trust of the public? To address this it has decided to launch an open policy making process:

“The intention is to embark upon an open policy process that brings together those inside and outside government interested in maximising the benefits and minimising the downsides to citizens of personal data sharing within government.”

The Cabinet Office, in collaboration with other government departments, is leading on the work, driven by Cabinet Minister Francis Maude, who is responsible for the Government’s transparency policy. This work must now dovetail with the Law Commission’s proposals and ultimately the new proposed EU Data Protection Regulation. The process is being coordinated by Involve, a civil society organisation, which has been awarded £20,000 to progress the policy-making process. Initial meetings have been held, a mailing list and website established, and input is now required from anyone interested in helping to shape future data sharing of public sector information.

Organisations are actively being encouraged to become involved. Civil society organisations involved to date include the likes of Big Brother Watch, MedConfidential, No2ID, The Open Rights Group, The Children’s Society, New Philanthropy Capital, Nuffield Foundation, Open Data Institute, Which and the ESRC.

What happens next?

The expected future developments of the process are as follows:

  • The Law Commission will report in April recommending a review of the law relating to data sharing.
  • Proposals will be developed under the new open policy making process until mid-August.
  • A policy document will be produced for mid-September for MPs to consider upon returning from recess.
  • Legal Counsel to produce key draft clauses and a White paper for the Christmas break.
  • Open public consultation Jan – March 2015.
  • The next Government will consider any data sharing proposals in the first session of Parliament after the 2015 General Election.

Clearly there needs to be cross-party support for this project for it to proceed past the next election. It is however very likely that this will be supported by all main parties and should not be a showstopper. The engagement of the organisations mentioned above at this early stage is important. With high profile organisations such as those on board, ensuring that privacy concerns are addressed early, it reduces the chance of problems for the government later in the process… and enables the government to cash in on a potential £16 billion of estimated income from UK data assets.

More importantly for the public though, this more inclusive process will hopefully genuinely address those privacy concerns that appear to have been wilfully ignored during the Care.Data process. This week has seen media reports focussing on HMRC selling our tax records next, and the fact that children’s records are already sold; a fact parents were no doubt unaware of and certainly not consulted upon. It is therefore vitally important that practitioners and organisations on the ground, the ones physically sharing data on a daily basis, can feed into this process in its initial stages to highlight and bottom out real practical issues as well as legislative and cultural ones.

This is no small task, and the timetable is incredibly tight to keep those involved focussed. As Francis Maude said at the last meeting, we don’t even know if we will be able to come up with anything workable; it could simply be too difficult. It is however worth the effort if it simplifies the data sharing process and offers the public a better and cost-effective service, whilst taking into account privacy concerns.

It’s not too late to get involved. If you have experience of information sharing or are a data protection practitioner or privacy expert, you can sign up at the www.datasharing.org.uk website, or join the mailing list, and help shape the proposed White Paper.

Lynn Wyeth is the Information Governance Manager at Leicester City Council. Follow her on Twitter @LynnFoi.

We will be discussing these developments in our forthcoming information sharing workshops.

Data Sharing Consultation – Do we need new laws?

The Law Commission has opened a consultation on the law around sharing of personal information between public sector organisations. Law Commissioner Frances Patterson QC says:

“It could be that more data sharing would improve public services but, if that is so, we need to understand why data is not being shared.  Is there a good reason to prevent data sharing?  Or is the law an unnecessary obstacle?  Are there other reasons stopping appropriate data sharing?  These are the questions we want to answer in this consultation.”

The legalitiecanstockphoto1632442s of data sharing is a subject which often confuses public sector officials. Local authorities, in particular, are often stumped by the “To Share or Not to Share” question, even if the sharing is for very good reasons (e.g. child protection or crime prevention). In some cases, even internal departments have felt constrained from updating each other about a change of a service user’s address.

More often than not, the Data Protection Act 1998 (DPA) is made the scapegoat for officials’ failure to fully understand the law. It is wrongly perceived as a barrier to data sharing despite offering a range of justifications (e.g. consent, legal obligation, protecting vital interests etc. (Schedule 2)).

Many attempts have been made to resolve this “problem”. In May 2011, the Information Commissioner published a statutory Code of Practice on data sharing. The code explains how the DPA applies to the sharing of personal data both within and outside an organisation. It provides practical advice to the public, private and third sectors, and covers systematic data sharing arrangements as well as one off requests for information. Under Section 52 of the DPA, the code can be used as evidence in any legal proceedings and can be taken into account by the courts and the Commissioner himself when considering any issue.

Despite the clear guidance in the code, the Government has sometimes toyed with the idea of new laws. Last year, according a story in the Guardian newspaper, proposals were to be published by the Cabinet Office minister, Francis Maude, which would make it “easier” for government and public-sector organisations to share confidential information supplied by the public:

“In May, we will publish proposals that will make data sharing easier – and, in particular, we will revisit the recommendations of the Walport-Thomas Review that would make it easier for legitimate requests for data sharing to be agreed with a view to considering their implementation,” said Maude, adding that current barriers between databases made it difficult for public sector workers to access relevant information.

“It’s clearly wrong to have social workers, doctors, dentists, Job Centres, the police all working in isolation on the same problems.”

The Guardian reported that the proposals are expected to include fast-track procedures for ministers to license the sharing of data in areas where it is currently prohibited, subject to privacy safeguards.  I could not find the proposals on the web. Anybody know whether they were ever published?

Confusion around data sharing continues to reign! The tragic case of Daniel Pelka is one example. The recent report into the four-year-old’s death, published by the independent Coventry Safeguarding Children Board identified a number of missed opportunities where professionals across a number of agencies should have done more to protect Daniel. Amongst other things, it concluded that the sharing of information and communications between all agencies was not robust enough.

Ill informed comments about the current law (especially the DPA) do not help. In a recent Daily Telegraph article by Michael Gove, the Education Minister claimed that, whilst tying to understand the underlying causes of child exploitation, he discovered that OFSTED “was prevented by “data protection” rules, “child protection” concerns and other bewildering regulations from sharing that data with us, or even with the police.” There is nothing in the DPA which prevents this. Don’t just take my word for it. Read the Information Commissioner’s riposte to the learned Mr Gove.

Do we really need new laws on data sharing or a better awareness of the existing ones? My view is that the current law is adequate to regulate yet allow responsible data sharing. The DPA and the Data Sharing Code need to be properly understood. They can be a tool allowing responsible data sharing. Most public sector data sharing will be lawful if organisations comply with the Eight Data Protection Principles; particularly the First Principle which requires information to be processed fairly and lawfully. There are also numerous exemptions in the Act including where sharing is required for the purpose of prevention or detection of crime (section 29).

The Law Commission consultation runs until 16 December 2013 and the paper may be accessed at: http://lawcommission.justice.gov.uk/. Responses can be emailed to data.sharing@lawcommission.gsi.gov.uk or sent by post.

More Information: Read our article for a full explanation of the ICO Data Sharing Code or watch this free webinar. We also run full day Multi Agency Information Sharing workshops.

The PM has set up an Information sharing task force.

info4And what will the task force do? It will report back.

In what way will it report back? Urgently.

What sort of priority will it have? The highest.

What will the report do? It will land on the PM’s desk.

What will be called for in the report? Better information sharing.

How will this be achieved? By departments working smarter.

What will result from the report? A drive.

What will be done to the drive? It will be spearheaded.

What will the spearheaded drive have? The PM’s blessing.

What will he lend to it? His weight.

In what way will he do this? He will call a Downing Street Summit.

What sort of spectrum of society will attend the summit? A wide one.

What privacy experts will attend? Shami Chakrabati  & Simon Davies

And what sort of industrialists? Top.

How long will the summit last? It will be an all-day summit.

And what will the attendees actually do? They will pose for a photograph.

What sort of squad will be appointed as a result of the summit? A hit squad.

And what will happen to this hit squad? It will be spearheaded.

By what kind of leader will it be spearheaded? An Information Tsar.

What kind of task will the Tsar have? An urgent one.

What type of barriers will they tackle? Public concern & privacy threats.

How will they tackle these concerns? By reassuring individuals.

In what way will they be answerable to the Prime Minister? Directly.

What will the Tsar propose? Information sharing measures.

What type of measures? A whole raft.

What will the Prime Minister do with measures? He will take them on board.

What will then be set by the Prime Minister? A target.

Can you be more specific about this target? It will be a performance target.

What adjective best describes this performance target? Tough.

What must happen to this performance target? It must be measured up to.

How will this “measuring up” be expressed? In league tables.

How will those not sharing be punished? They will be named & shamed.

Who will be sent in when information is not shared? A data hit squad.

What adjective best describes the powers of the hit squad? Wide-ranging.

What type of anxieties could arise from this? Very real ones.

What will the PM do to these anxieties? He will address them.

What further action will he take? He will take them on board.

What person will the PM appoint? A privacy watchdog.

What will this watchdog possess? Teeth.

Where will the watchdog report? Back.

In what way? Urgently.

To help with the project who will join in? The big society.

What kind of approach would they have? A no-nonsense approach.

What would be harnessed? Their energy and their goodwill.

What will then be called for on the Today programme? More resources.

How will the Chancellor stand? Firm.

In what way will the PM react? He will not be dictated to.

What is the result likely to be? A privacy crisis.

How will this crisis manifest? By extended news bulletins & public concern

How will the crisis be solved? The PM will set up a task force.

With acknowledgements to Oliver Pritchett who wrote the original in 2000.

New Data Sharing Laws: Too Far, Too Fast?

According a story in the Guardian newspaper last week, proposals to be published in May by the Cabinet Office minister, Francis Maude, are expected to make it easier for government and public-sector organisations to share confidential information supplied by the public.

“In May, we will publish proposals that will make data sharing easier – and, in particular, we will revisit the recommendations of the Walport-Thomas Review that would make it easier for legitimate requests for data sharing to be agreed with a view to considering their implementation,” said Maude, adding that current barriers between databases made it difficult for public sector workers to access relevant information.

“It’s clearly wrong to have social workers, doctors, dentists, Job Centres, the police all working in isolation on the same problems.”

The Guardian reported that the proposals are expected to include fast-track procedures for ministers to license the sharing of data in areas where it is currently prohibited, subject to privacy safeguards.

Maude has hit back at the reporting of the proposals. Whilst the detail is awaited, one has to wonder whether this is the right time to consider such measures. The recent announcement of a new law to require Internet firms to give intelligence agency, GCHQ, access to everyone’s communications data on demand and in real time as well as the ongoing controversy about the failure to regulate press intrusion has already raised concerns about the Government’s commitment to “roll back the surveillance state”.

Civil liberties campaigners are already saying that the new plans are further evidence of the revival of “The Database State” proposed by New Labour. In a recent article the Campaign Group, NO2ID, argued that the Government should establish clear guidelines on people’s rights to privacy to put a brake on official bodies sharing data.

This is not the first time that concerns have been raised about data sharing. In July 2008 “The Data Sharing Review Report” was written by the then Information Commissioner, Richard Thomas, and Wellcome Trust director, Mark Walport. In it they warned:

“The tenor of the government’s argument has focused closely on the benefits of data sharing, paying perhaps too little attention to the potential hazards associated with ambitious programmes of data sharing,” stated the report. “The government has consistently laid itself open to the criticism that it considers ‘data sharing’ in itself an unconditional good, and that it will go to considerable lengths to encourage data-sharing programmes, while paying insufficient heed to the corresponding risks or to people’s legitimate concerns.”

Is the current law not adequate to regulate yet allow responsible data sharing? The Data Protection Act 1998 (DPA) already governs all processing of personal data including the sharing of it. Whilst it is still conceived as a barrier, if properly understood, it can be a tool for responsible data sharing. Most public sector data sharing will be lawful if organisations comply with the Eight Data Protection Principles; particularly the First Principle which requires information to be processed fairly and lawfully. There are also numerous exemptions in the Act including where sharing is required for the purpose of prevention or detection of crime (section 29).

In May 2011, the Information Commissioner published a new statutory Code of Practice on data sharing. The Code explains how the DPA applies to the sharing of personal data both within and outside an organisation. It provides practical advice to the public, private and third sectors, and covers systematic data sharing arrangements as well as one off requests for information.

So is there really a need for a new law on data sharing? The Information Commissioner’s Office has issued a short statement on the proposals. Reading between the lines, it seems to be saying that the current law and the ICO Code are adequate. What do think?

Read our article for a full explanation of the ICO Data Sharing Code.

You can attend our full day Multi Agency Information Sharing workshops

We also have a one-hour online seminar on this subject.