First Two GDPR Enforcement Notices – Lessons Learnt

Fingerprint scanning provides security access biometrics identification with Business Technology Safety Internet Network Ui.

The Information Commissioner’s Office (ICO) recently served only its second Enforcement Notice for breaches of the GDPR.

The first Enforcement Notice was issued in July 2018 against a Canadian company, AggregateIQ Data Services Ltd (AIQ). Strangely it was not published on the ICO’s website but was mentioned in the ICO’s report: “Investigation into the use of data analytics in political campaigns“. Pursuant to section 149 of the Data Protection Act 2018, the notice required AIQ to “cease processing any personal data of UK or EU citizens obtained from UK political organisations or otherwise for the purposes of data analytics, political campaigning or any other advertising purposes.”

The ICO found that AIQ had violated Article 5 and 6 of the GDPR, by processing personal data unbeknown to the data subjects, for undeclared purposes and without a lawful basis for such processing. It had also failed to provide the transparency information, as required under Article 14 of the GDPR.

On 9thMay 2019, the Second Enforcement Notice was served on Her Majesty’s Revenue and Customs (HMRC) ordering it to delete personal data it collected unlawfully as part of a Voice ID system. The background to the notice is thatHMRC adopted a voice authentication, in January 2017, which asked callers to some of its helplines to record their voice as their password. A complaint from Big Brother Watch to the ICO revealed that callers were not given further information or advised that they did not have to sign up to the service. There was no clear option for callers who did not wish to register. In short, HMRC did not have adequate consent  from its customers to collect the data.

In the notice, the Information Commissioner says that HMRC appears to have given “little or no consideration to the data protection principles when rolling out the Voice ID service.” She highlights the scale of the data collection – seven million voice records – and that HMRC collected it in circumstances where there was a significant imbalance of power between the organisation and its customers. It did not explain to customers how they could decline to participate in the Voice ID system. It also did not explain that customers would not suffer a detrimental impact if they declined to participate.

It was also found that a data protection impact assessment (DPIA), that appropriately considered the compliance risks associated with processing biometric data, was not in place before the system was launched. The ICO plan to follow up the enforcement notice with an audit that will assess HMRC’s compliance with good practice in the processing of personal data.

  • Recording voices which can be used to identify the speaker is biometric data. This is classed as Special Category Data under GDPR.
  • If Data Controllers are planning to rely on consent as a legal basis to process such data, then they must remember that any consent obtained must be explicit (see the ICO guidance on informed consent).
  • Large scale use of biometric data is also “high risk” processing and will require a DPIA.
  • Data Controllers must be able to demonstrate their GDPR compliance by putting appropriate technical and organisational measures in place.

Steve Wood says:

“With the adoption of new systems comes the responsibility to make sure that data protection obligations are fulfilled and customers’ privacy rights addressed alongside any organisational benefit. The public must be able to trust that their privacy is at the forefront of the decisions made about their personal data.”

More on these and other developments will be in our GDPR Update webinar and full day workshop presented by Ibrahim Hasan. Act Now runs a full day workshop which can teach you how to do a DPIA. For those seeking a GDPR qualification, our practitioner certificate is the best option.

 

The Facebook Data Breach Fine Explained

2000px-F_icon.svg-2

 

On 24th October the Information Commissioner imposed a fine (monetary penalty) of £500,000 on Facebook Ireland and Facebook Inc (which is based in California, USA) for breaches of the Data Protection Act 1998.  In doing so the Commissioner levied the maximum fine that she could under the now repealed DPA 1998. Her verdict was that the fine was ‘appropriate’ given the circumstances of the case.  For anyone following the so-called Facebook data scandal the fine might seem small beer for an organisation that is estimated to be worth over 5 billion US Dollars. Without doubt, had the same facts played out after 25th May 2018 then the fine would arguably have been much higher, reflecting the gravity and seriousness of the breach and the number of people affected.

The Facts

In summary, the Facebook (FB) companies permitted Dr Aleksandr Kogan to operate a third-party application (“App”) that he had created, known as “thisisyourdigitallife” on the FB platform. The FB companies allowed him and his company (Global Science Research (GSR) to operate the app in conjunction with FB from November 2013 to May 2015. The app was designed to and was able to obtain a significant amount of personal information from any FB user who used the app, including:

  • Their public FB profile, date of birth and current city
  • Photographs they were tagged in
  • Pages they liked
  • Posts on their time lime and their news feed posts
  • Friends list
  • Facebook messages (there was evidence to suggest the app also accessed the content of the messages)

The app was also designed to and was able to obtain extensive personal data from the FB friends of the App’s users and anyone who had messaged the App user. Neither the FB friends or people who had sent messages were informed that the APP was able to access their data, and nor did they give their consent.

The APP was able to use the information that it collected about users, their friends and people who had messaged them, in order to generate personality profiles. The information and also the data derived from the information was shared by Dr Kogan and his company with three other companies, including SCL Elections Ltd (which controls the now infamous Cambridge Analytica).

Facebook Fine Graphic

In May 2014 Dr Kogan sought permission to migrate the App to a new version of the FB platform. This new version reduced the ability of apps to access information about the FB friends of users. FB refused permission straight away. However, Dr Kogan and GSR continued to have access to, and therefore retained, the detailed information about users and the friends of its users that it had previously collected via their App. FB did nothing to make Dr Kogan or his company delete the information.  The App remained in operation until May 2015.

Breach of the DPA

The Commissioner’s findings about the breach make sorry reading for FB and FB users. Not only did the FB companies breach the Data Protection Act, they also failed to comply or ensure compliance with their own FB Platform Policy, and were not aware of this fact until exposed by the Guardian newspaper in December 2015.

The FB companies had breached s 4 (4) DPA 1998  by failing to comply with the 1stand 7th data protection principles. They had:

  1. Unfairly processed personal data in breach of 1st data protection principle (DPP1). FB unfairly processed personal data of the App users, their friends and those who exchanged messages with users of the APP. FB failed to provide adequate information to FB users that their data could be collected by virtue of the fact that their friends used the App or that they exchanged messages with APP users. FB tried, unsucesfully and unfairly, to deflect responsibility onto the FB users who could have set their privacy settings to prevent their data from being collected. The Commissioner rightly rejected this. The responsibility was on Facebooks to inform users about the App and what information it would collect and why. FB users should have been given the opportunity to withhold or give their consent. If any consent was purportedly  given by users of the APP or their friends, it was invalid because it was not freely given , specific or informed. Conseqauntly, consent did not provide a lawful basis for processing
  2. Failed to take appropriate technical and organisational measures against unauthorised or unlawful processing of personal data, in breach of the 7th data protection principle (DPP7). The processing by Dr Kogan and GSR was unauthorised (it was inconsistent with basis on which FB allowed Dr Kogan to obtain access of personal data for which they were the data controller; it breached the Platform Policy and the Undertaking. The processing by DR Kogan and his company was also unlawful, because it was unfair processing.  The FB companies failed to take steps (or adequate steps) to guard against and unlawful processing.  (See below). The Commissioner considered that the FB companies knew or ought to have known that there was a serious risk of contravention of the data protection principle sand they failed to take reasonable steps to prevent such a contravention.

Breach of FB Platform Policy

Although the FB companies operated a FB Platform Policy in relation to Apps, they failed to ensure that the App operated in compliance with the policy, and this constituted their breach of the 7th data protection principle. For example, they didn’t check Dr Kogan’s terms and conditions of use of the APP to see whether they were consistent with their policy (or presumably whether they were lawful). In fact they failed to implement a system to carry out such a review. It was also found that the use of the App breached the policy in a number of respects, specifically:

  • Personal data obtained about friends of users should only have been used to improve the experience of App users. Instead Dr Kogan and GSR was able to use it for their own purposes.
  • Personal data collected by the APP should not be sold or third parties. Dr Kogan and GSR had transferred the data to three companies.
  • The App required permission from users to obtain personal data that the App did not need in breach of the policy.

The FB companies also failed to check that Dr Kogan was complying with an undertaking he had given in May 2014 that he was only using the data for research, and not commercial, purposes. However perhaps one of the worst indictments is that FB only became aware that the App was breaching its own policy when the Guardian newspaper broke the story on December 11 2015. It was only at this point, when the story went viral, that FB terminate the App’s access right to the Facebook Login. And the rest, as they say, is history.

Joint Data Controllers

The Commissioner decided that Facebook Ireland and Facebook Inc were, at all material times joint data controllers and therefore jointly and severally liable. They were joint data controllers of the personal data of data subjects who are resident outside Canada and the USA and whose personal data is processed by or in relation to the operation of the Facebook platform. This was on the basis that the two companies made decisions about how to operate the platform in respect of the personal data of FB users.

The Commissioner also concluded that they processed personal data in the context of a UK establishment, namely FB UK (based in London) in respect of any individuals who used the FB site from the UK during the relevant period. This finding was necessary in order to bring the processing within scope of the DPA and for the Commissioner to exercise jurisdiction of the two Facebook companies.

The Use of Data Analytics for Political Purposes

The Commissioner considered that some of the data that was shared by Dr Kogan and his company, with the three companies is likely to have been used in connection with, or for the purposes of, political campaigning. FB denied this as far as UK residents were concerned and the Commissioner was unable, on the basis of information before her, whether FN was correct. However, she nevertheless concluded that the personal data of UK users who were UK residents was put at serious risk of being shared and used in connection with political campaigning. In short Dr Kogan and/or his company were in apposition where they were at liberty to decide how to use the personal data of UK residents, or who to share it with.

As readers will know, this aspect of the story continues to attract much media attention about the possible impact of the data sharing scandal on the US Presidential elections and the Brexit referendum. The Commissioner’s conclusions are quite guarded, given the lack of evidence or information available to her.

Susan Wolf will be delivering these upcoming workshops and the forthcoming FOI: Contracts and Commercial Confidentiality workshop which is taking place on the 10th December in London. 

Our 2019 calendar is now live. We are running GDPR and DPA 2018 workshops throughout the UK. Head over to our website to book your place now. 

Need to prepare for a DPO/DP Lead role? Train with Act Now on our hugely popular GDPR Practitioner Certificate.

LGL Advert

 

Public Health Funerals, Heir Hunters and Freedom of Information

canstockphoto15719562

 

Local authorities are seeing a substantial increase in the number of Freedom of Information (FOI) requests from heir tracing companies for information about those who have had public health funerals. Recent appeal decisions from the Information Commissioner’s Office (ICO) may help to stem the tide.

UK intestacy law states that when someone dies with no will or known family, everything they own passes to the Crown as ownerless property (or ‘Bona Vacantia’). This includes their house, money and personal possessions. Companies who find missing heirs are in a very lucrative business (watch “Heir Hunters” on the BBC). Some require beneficiaries to enter into an agreement to share up to 40% of their inheritance.

In England and Wales, the Bona Vacantia Division (BVD) of the Treasury Solicitor’s Department is responsible for dealing with bona vacantia assets. Everyday BVD publishes an Unclaimed Asset List setting out unclaimed estates which have been recently referred, but not yet administered, and historic cases which have not yet been claimed by entitled relatives. Included in the list is the deceased name, area of death, marital status, place of birth and local authority informant. Sometimes other details will be given (if known) such as spouse’s name, place of marriage and nationality. The list is updated every working day and newly advertised estates appear at the top of the list.

This list is a good starting point for probate researchers but the competition to trace beneficiaries is very fierce and often a number of companies will be trying to trace the same person. That is why such companies often make FOI requests to councils to try and get hold of the information before any of it is passed on to the BVD to publish. If they can identify deceased individuals who may have left a substantial estate, they will have a head start (in tracing the beneficiaries) against their rivals who will not yet be privy to such information.

Many councils have chosen to put a lot of this information on their website; Redbridge, Northampton, Knowsley to name a few. This then allows them to claim the exemption under section 21 of FOI (information is reasonably accessible by other means). Often though the researchers want more than the basic information, which is published by councils.

Of course, where the requested information has been disclosed to the BVD (or is about to be disclosed) and it will appear on the published BVD list, it is open to the council to claim the exemption under section 22 (information intended for future publication). It does not matter that the council will not be publishing the information itself as long as there is a settled intention to publish it on the part of another (in this case the BVD). Section 22 is a qualified exemption and so subject to the public interest test.

Where the information requested by probate researchers is not published, many councils have claimed the exemption in section 31 arguing that disclosure would prejudice the prevention of crime. Some recent ICO appeal decisions lend support to this approach. In a decision involving Barnsley Metropolitan Borough Council (FS50586033) the complainant requested, amongst other things, details of deceased people who had had public health funerals (including names, last known address, date of birth, date of death, date of funeral, and whether the case has been/will be/or even might be referred to the Treasury Solicitor).

The ICO agreed with the council that section 31 applied and it was not in the public interest to disclose the information. Release of personal details of a deceased individual with no known relatives, and no will, may make the assets of that person vulnerable. The assets of the deceased need to be secured and disclosure of the information may lead to the commission of offences (e.g. arson, identity theft etc.) and cause loss to the unsecured estates. In terms of the public interest the Commissioner states (paragraph 38):

“The Commissioner recognises that there is an inherently strong public interest in avoiding likely prejudice to the prevention of crime. The crime in this case would be likely to include a diverse range from anti-social behaviour, criminal damage, arson, organised groups stripping empty properties to identity fraud and the crimes that can be committed using false documents. The Commissioner accepts that tackling issues like these would involve significant public expense and believes it is in the public interest to protect property and to ensure that public resources are used efficiently. He also accepts that there is a strong public interest in avoiding personal distress to the direct victims of the crime and, in the case of crime related to empty properties, to those in the wider neighbourhood who may be affected.”

Similar decisions were made in complaints involving Birmingham City Council (FS50584670) and the London Borough of Bexley FS50583220. I have still not come across a First Tier Tribunal decision on such requests and so the exemptions, especially section 31, have yet to be comprehensively explored.

Some councils have argued that section 41 (Breach of Confidence) may apply to some of the information requested about the deceased. This can only be the case if the information has come from another party and is highly confidential. Section 41 is unlikely to apply to most requests from probate researchers. For a detailed discussion on access to information about the deceased under FOI, read my article and blog post.

Give your career a boost in 2016 by gaining an internationally recognised qualification in FOI. Keep up to date with all the latest FOI decisions by attending our live webinars and FOI workshops.

The ICO and Seven Shades of Grey

If you’ve nothing to do at lunchtime and you’re an experienced DP person try the ICO quiz on the difference between Data Controllers and Data Processors. You can find it here. After all it’s not a hard quiz. Data Controllers determine the purpose and own the data; data processors just do as they’re told. For years we’ve had this easy to understand relationship and many organisations have outsourced some work involving personal data, drawn up the contract, monitored the performance of it and we all knew where we were. Data Controllers were liable for any problems and Data Processors just did as they were instructed.

Recent guidance from the ICO changes this. Instead of clear yes/no and black/white definitions the commissioner recommends that each relationship with another person processing your data is examined to see how much influence the other person has over how the data is processed. As a result there are no easy answers. Just some shades of grey.

If you are eager to do the quiz and go for it without reading the guidance prepare yourself for a shock. Better DP experts than yourself have taken the test and not performed at all well.

The guidance is well meaning but bends over backwards to accommodate every possible possibility that it’s not that useful.

Image credit www.jimbanks.com

The new EU Data Protection Regulation; Shoulda, Woulda, Coulda?

MC900440392

On the 13th March 2014 the European Union (EU) Parliament voted with an overwhelming majority to approve a new Data Protection Regulation within the EU. Voting on the initial text that was put forward by the Commission, and not the text put forward by the LIBE committee, the EU Parliament seem to have taken a “middle path” with regards to how this Regulation should work. Many of the Commission’s proposed appointed powers have gone, there doesn’t appear to be any “strict” provisions in there that the LIBE committee would have wanted and yet this approved draft is proposing a comprehensive and different world for Data Protection.

A fully updated draft has not been released by the EU as yet so I went through the painstaking task of making the edits confirmed by the EU to the original commission text. I can safely say I won’t be doing that again and once the approved draft is published I highly recommend that you read through from the beginning to get a flavour of where the regulation is heading and the wording used. I have however pulled out some of the highlights below for general consumption. Before I start however, I will declare that I am from the private sector but as Data Protection & Privacy is more than just a job for me (it’s a passion) I’m not one of those people that have campaigned against it (even if I think some if it is just barmy in my humble opinion).

For those that have worked only with the UK Data Protection Act this new world comes as a bit of a shock. Instead of a principle based approach the current regulation is more of a “financial regulation” with specific stances, requirements and demonstrations that certain things are occurring within an entity. For example, Point 60 requires Data Controllers to demonstrate and ensure compliance with the regulation, with a new sentence stating “this should be verified by independent internal or external auditors”.

However having said that, the EU Parliament have edited Point 65, so that it clears up the “administrative burden” query (or tries to) by stating that yes controllers must demonstrate compliance with the regulation however “equal emphasis and significance should be placed on good practice and compliance and not just the completion of documentation”. One assumes therefore that auditing to “a check list” isn’t going to occur even though the regulation spells out some things that need to be done specifically. Interesting…

‘Data Protection Impact Assessments’ are now outlined in points 71a&b and are very similar to the commission’s proposal that assessments should be done on the lifecycle of information management for processing of personal data. Section 75 states that for public sector bodies processing sensitive personal data or data on more than 5000 data subjects in 12 months they will need to periodically monitor compliance with the regulation. Is the requirement to self-audit the same as the requirement to tick a box?

The phrase that appeared in the initial draft on ‘data portability’ has also changed. It is still there but now Point 55 changes the “right to data portability” to “controllers should be encouraged to develop interoperable formats that enable data portability”. Encouraged how and by whom still remains to be seen.

Another ‘hot phrase’ in the initial draft and current buzz word after the European Court of Justice decision is the “right to be forgotten”, and as predicted that has been changed to now Point 53 has been updated to state that “the right to be forgotten” is indeed now to be called the “right to erasure” and that this right is overwritten where processing is needed for the performance of a contract or to meet local legal requirements. Point 54 & 54a specifically make reference to “online information” and the requirement for the facilitator to block or remove such data if the data subject requests.

On that point, similar concerns around the watering down of legitimate interests have also tried to be abated in this text, and now Point 39 specifically outlines a purpose for processing personal data being a valid “legitimate interest”. Namely the processing for Information Security / Network Security purposes where strictly necessary. 39a also outlines that ‘legitimate interest’ can also include processing for the prevention or limitation of damages on the controller, providing this does not significantly go against the data subject’s rights and freedoms. 39b adds direct marketing processing as a ‘legitimate interest’ again providing this does not go against the rights and freedoms of the individual. Is it me or do some of these provisions say “You can do it, but…”.

There are some further oddities in here; for example, point 32 states that if a controller does not want to follow ‘data minimisation’ requirements there is a burden of proof to justify the processing of Personal Data for that specific purpose / scenario. Again this is nothing new as this is in line with the principles of the UK DPA but we have not seen a requirement to document and justify before. 32 also states that collecting consent on behalf of 3rd parties is no longer seen as valid consent. Therefore if a business needs 3rd party data alongside the initial data subject’s data would it need to contact said 3rd party to seek consent. But then, isn’t it processing said data in order to contact them to get the consent? How would this work I wonder… citizens aren’t going to this for controllers so what other options are there?

Talking of consent, the concern that consent becomes more specific hasn’t been removed as Point 25 clarifies that consent will require “clear affirmative action” by a data subject in order to be seen as a valid consent. Silence or simply use by the data subject of a service would not be acceptable as a valid consent to process personal data. To the above point, how would a controller get such consent from 3rd parties?

Consent has also been factored in for the use of profiling and that consent can be removed at any time. However Point 58 has been updated to state the for profiling, “Profiling which leads to measures producing legal effects concerning the data subject or does similarly significantly affect the interests, rights or freedoms of the concerned data subject should only be allowed when expressly authorised by law, carried out in the course of entering or performance of a contract, or when the data subject has given his consent”. Now here I believe that “carried out in the course of entering or performance of a contract” means that credit profiling can continue in the UK otherwise these seems to conflict with current legal requirements on Banks and Lenders to ensure that you as the customer can afford the product they offer and that you as the lender are lending responsibly – this can only be done by credit profiling surely?

Another area of concern from the initial text was around breach notification. There is still no useful outline as to what a material breach consists of however Point 67 confirms that data breach notification to the relevant authority “should be presumed to be not later than 72 hours” – somewhat better than the initial 24 hours but still something causing concern among various industries.

On the up side however, a new point specifically referencing Freedom of Information has been added. Point 18 has been updated to make reference to relevant member states Freedom of Information (FOI) legislation and how this regulation interacts with that. That’s some concerns appeased… or is it?

The EU Parliament have also updated what is expected of us DPOs and point 75a states that DPOs should have the following experience / qualifications;

  • extensive knowledge of the substance and application of data protection law, including technical and organisational measures and procedures;
  • mastery of technical requirements for privacy by design, privacy by default and data security;
  • industry-specific knowledge in accordance with the size of the controller or processor and the sensitivity of the data to be processed;
  • the ability to carry out inspections, consultation, documentation, and log file analysis;
  • and the ability to work with employee representation.

The controller should enable the data protection officer to take part in advanced training measures to maintain the specialized knowledge required to perform his or her duties.

Overall the current draft regulation has either been improved from what it was, stayed the same, or gotten worse in some places.

There are some ups and downs, and a few more changes that have been made that I have not referenced here (as I could be here all day). As for next steps for the Regulation I really don’t know who to believe. The ICO in a recent statement stated that they don’t believe there will be a tangible regulation until 2017 at the earliest. But in the same breath they also said (they being David Smith the Deputy ICO) that you should get your house in order now with current requirements as this puts you in a good place ready for the Regulation in 2017. Given how the Parliament approved the text way ahead of schedule and that this piece of legislation is the “most lobbied and campaigned on” in the EU’s history I am inclined to believe that all bets are off. I can see the case that it will come through quickly, especially as the EU is very defensive of Data Protection and Privacy of late. But then I also see the argument and stance from the European Council that they don’t want to rush this and instead want to take their time. As this Regulation would need agreement from the Council, the Parliament and the Commission I can see it rattling on for a while. But, as my favourite TV programme as a child used to say “Stand by for action; anything can happen in the next half an hour”. (For those that don’t know, that was from Stingray – and yes, I am a Geek that needs to get out more).

I have my word document unofficial text which I am happy to share on request but it is very much unofficial and really isn’t to be considered “official” in any capacity. Well worth a read though, and again I recommend that when the official text is finally updated and released (the EU moves at its own pace on such things) that you have it as some bed time reading to fill you with hope (and possibly nightmares).

Nighty night.

Scott Sammons is currently a European Data Protection Officer within the Finance Industry and blogs under the name @privacyminion . Scott is on the Exam Board for the Act Now Data Protection Practitioner Certificate which is a qualification designed to give candidates a head start in understanding and implementing the proposed EU Data Protection Regulation.

ICO 2013 Conference Review

Roger Bescodpoc2013website.ashxby reviews the recent ICO conference…

I was on my travels last week and on Tuesday (5th May 2013) found myself at the ICO Data Protection Officers’ Conference  in Manchester. Over 800 people present and about 300 ‘waiting outside the door’ as they say. It was, and always is, massively oversubscribed. It is the main event in the ICO calendar and a fantastic opportunity to get a feel for the way the regulators are thinking. Well worth getting on the guest list.

This is the third year I have attended this Conference and once again I found myself pretty much the only representative from the insurance investigation sector. Can you believe that??  Here we are, post Leveson, NOTW and with worrying EU Regulation on privacy coming out of our ears – and only Brownsword Group there from the entire industry. Does that make us ‘anoraks’ or supremely responsible chaps??  Answers on a post card…

I picked up on two main points that I would like to share with you all:

Europe?  You Never Had It So Good…

There are some massive EU reforms on the way in the form of new European Regulation on Data Privacy. By 2016 it’s looking like we are going to be regulated centrally by Brussels on DP. ‘Fine’ you may say, but when you consider the vastly differing attitudes towards Data Protection by the 27 Member States, and that the UK currently has a considerably more liberal attitude than most, it’s time to look at what might be coming our way.  The explosion in social media is being blamed for the need for tougher regulations – an observation difficult to argue with.

You may remember I highlighted last year that current proposals in Brussels suggest that personal data can only be shared if it falls into one of the new proposed exemptions. Sharing of data by insurers for the purposes of fraud prevention is NOT currently listed amongst the exemptions. This seems to be a glaring omission and now evidently an oversight.  The Association of British Insurers (ABI) and the Financial Services Authority (FSA), amongst others, have been lobbying hard on this very point and seem to have now made some headway. The issue is currently now under review by no less that 5 COMMITTEES in Brussels, all presumably deliberating on what has to be the most obvious decision they will ever have to make – but remember – this is the EU Parliament we are talking about!

During the mass Q&A in the afternoon, Assistant Commissioner David Smith answered a question put by a delegate in a grey suit and Salford accent, on the very point. He admitted that there were several points within the current EU proposals with which the ICO had issues and that this was a typical example. He went on to say that he felt confident that data sharing would always be justified if it was being done for the purposes of the ‘legitimate interests’ and for the ‘prevention and detection of crime’ and that he had not seen anything in the new proposals that changed that.

So, on the face of it, good news but it really is worth keeping an eye on the EU proposals. Wouldn’t we all feel happier if the insurance fraud world was specifically recognised by way of an exemption?

And what does the EU think of secret filming? If the UK were forced to adopt even some of the tough regulations on covert surveillance that exist across much of mainland Europe we would see the biggest upheaval in recent history in our sector. I detected an insatiable appetite from the regulators on the issue of ‘consent’ to processing. The nightmare scenario of having to say to a surveillance subject,  “Hi Mr Smith, is it OK if I film you next Tuesday in relation to your claim?” may not be as farcical as it seems. I kid you not!

I also heard one opinion from a senior ICO official that he favoured following the RIPA example, that of seeking Magistrates’ approval if you wish to put somebody under surveillance in non Public Authority scenarios…you have been warned! (Certainly some form of written authorisation for non-RIPA surveillance is favoured by the Office of Surveillance Commissioners and others – Ed)

‘Unmanned’ Surveillance – Too Risky??

There were two excellent breakout sessions at the conference dealing specifically with surveillance.  The way covert video evidence was captured, and in particular the justification for filming individuals, was discussed at length. The point was made most emphatically by the ICO officials that they would only condone the covert processing of personal data (i.e. filming) if it was evidently targeted upon the data subject, and of course that the intrusion could be justified.

They then made the further point that such covert data processing must be discriminate and that every attempt must be made to avoid the inadvertent capture of footage of ‘un-connected’ individuals. They went on to say that whilst some ‘collateral intrusion’ was inevitable, the installation of static unmanned covert cameras, vehicle based or otherwise, was absolutely  ‘unfair and excessive processing’ and breached basic DPA principles.

I know that some surveillance companies out there openly recommend and market such tactics – suffice to say it is not a route The Brownsword Group will be going down. The thought of maybe two dozen ‘friends and neighbours’ of a legitimate surveillance target bringing privacy actions against our client is a risk we will not be taking – and that’s before the ICO themselves come down like a ton of bricks.

And Finally – Something Else……..The FSA and a ‘Thematic Review’ of the Use Of Private Investigators

I can advise that the FSA Conduct Business Unit have embarked upon what they are calling a ‘Thematic Review’.   They are “seeking information from  firms about the controls, oversight and due diligence procedures operated by insurance companies regarding the use of private investigators.”

I understand that specific attention is being paid to TCF, the payment of any inducements or incentives, the frequency and success of investigator involvement and also whether the 2007 ABI Guidelines are being adhered to. It is not surveillance specific.

Insurers can expect a visit in the coming months. Brownsword Group have written to the FSA offering help, assistance and guidance in the production of the review, hopefully providing a view from the ethical  investigator’s side of the fence.

It is likely that at this stage the FSA will have little first hand knowledge of the vital working relationships that exist between Insurers and investigators. This, and in the light of current suspicious attitudes from certain regulators towards the investigation sector, may suggest that a degree of education may be necessary from insurers and investigators alike.

Hopefully, in the fullness of time, the FSA will interact with us on this and we will be able to explain the value of the investigators support role to the insurance sector.

I hope you found the above of interest, comments and questions welcomed.

Roger J Bescoby is Director of Strategic Development at the Brownsword Group. Visit www.brownsword.com & www.talk-safe.co.uk

Data Protection Update workshop – Analysis of the latest DPA cases, developments and news from the ICO. Our next workshops are in Manchester on the 28th May and in London on the 31st May.

Leveson: What future for Data Protection?

LevesonThe Leveson Report has finally been published.

The Report recommends that a tougher form of self-regulation backed by legislation should be introduced to uphold press standards. Much has already been written (http://www.bbc.co.uk/news/uk-20543936) and will continue to be written about this central recommendation and whether it is good or bad for democracy and a free press. But amid the furore about whether the Prime Minister should or should not accept the central recommendation, it is easy to forget that the report will also have implications for Data Protection Act and the Information Commissioner.

One of the areas that Lord Justice Leveson was required to consider was ‘the extent to which the current policy and regulatory framework has failed, including in relation to data protection’.

I started writing a blog post on the way back from London, and got as far as the above, when an e mail from the good people at 11KBW  (Panopticon Blog) landed in my inbox.

On well if you can’t beat them, read them! Here is their excellent analysis of the DP recommendations of Leveson:

http://www.panopticonblog.com/2012/11/29/leveson-inquiry-report-spotlight-on-proposed-data-protection-reforms/

I was only training round the corner and passed the QE2 centre where LJ Leveson was giving his press conference. Perhaps, I should have camped out overnight to beat the Panopticon Team?

Those Were the Days!

Martin Gibson, of Buckinghamshire County Council, reflects on the challenges facing a Data Protection Officer and how relationships with the Information Commissioner’s Office have changed over the years.

Read more here