Showing posts with label data protection. Show all posts
Showing posts with label data protection. Show all posts

Thursday, 19 July 2018

Data protection and the redistribution of public funds

Data protection. You can't get away from it. I am spending nearly all my working hours at present helping clients comply with the General Data Protection Regulation - a piece of legislation that, however well-meaning, is crazily technical and obscure (as I remarked in a post a little while ago). Even my morning scan of The Guardian's website has thrown up a data protection story this morning.

The story (and I don't use the word to suggest that it is made up!) says that the ICO has fined the independent inquiry into child sexual abuse £200,000 for revealing a number of email addresses from which individuals could be identified - the email was sent to 90 participants in the inquiry, 52 of whom were identified by name in their address, and "vulnerable people were placed at risk", although the report doesn't say how - it depends in part on where the email went, I suppose. One complainant was reported to be very distressed, which I don't think requires any explanation. This all seems to me to be exactly what data protection law is there to deal with.

How did this disclosure come about? By a failure to use the bcc box for email addresses. So simple, so damaging, so expensive. It doesn't seem the most egregious breach of the law, but the potential consequences are probably completely out of proportion to the mistake, and equally out of proportion to the ease of making sure it didn't happen. Human error can be largely avoided if humans are trained in how to do their jobs - but I've come across so many instances where people have been ignorant of the importance of using bcc.

A further twist is that the IICSA hired an external provider - a data processor in the terminology of the Data Protection Act 1998, which although now repealed and replaced was the governing law at the time - to handle its mailing list, and in doing so breached its own privacy notice. There's an object lesson in the importance of keeping these things under review and making sure you aren't doing things with people's data that you haven't told them you are doing.

The IICSA is a statutory inquiry under the Inquiries Act 2005, although it started life as a panel inquiry and has had a chequered history, which I think it's fair to say just became even more chequered. In the year ending 31 March 2017, according to its financial report, it spent £20.8 million. The data protection penalty will therefore be a substantial part of its spending, although the report says that its "full year budget" for the financial year ending 2017 was £30.94 million, which I must say sounds rather odd but I don't feel I need to look into it for the purpose of this blog. My point is that it's a lot of public money, and even when it is just being redistributed to another emanation of the state it is a pretty appalling state of affairs. Even if the inquiry isn't spending its entire budget, I'd prefer that its money was going on looking into the important matters that it was set up to deal with rather than filling the coffers of the Information Commissioner.

One final point: under the new legislation, the very wonderful General Data Protection Regulation, the ICO is able to levy much larger financial penalties. Perhaps, with a little effort, the Information Commissioner could appropriate the entirety of the UK's public spending! Only if public bodies continue to make such appalling errors, and I hope the lesson is not lost on them.

Wednesday, 23 May 2018

"Have you not considered Recital 171?"

This week, few lawyers have the luxury of not having to be data protection experts, which is why the subject is intruding into my IP blog. Thank goodness it will all be over on Friday and we can settle down to working with the General Data Protection Regulation, until data protection law is repatriated and instead we have the Data Protection Act 2018 and "the Applied GDPR".

We are all acutely aware that many data controllers are taking the opportunity to refresh consents from the people whose data they publish. It's a great opportunity to do some housekeeping, of course, but not all the consents are necessary, nor do they need to be refreshed. First of all, consent should rarely be the lawful basis of choice for data processors: the legislation offers several other possibilities, of which "legitimate interests" is probably the most useful. The data processor's legitimate interests in processing personal data must, it is true, be balanced against the interests and fundamental rights and freedoms of the data subject, which may override them - thus removing the lawful basis: so legitimate interests per se are not a lawful basis. But when will the data subject's interests (etcetera) override them? How long is a piece of string? It's questions like this that make advising on data protection like nailing jelly to a wall.

For data controllers who still feel the need for consent, it's not always necessary to get it afresh at this point, as this article from The Guardian reports. Consent obtained under the old law, provided it meets the conditions of the GDPR, still works. How do we know? Because (apart from common sense) Recital 171 to the Regulation tells us so. And that, I think, tells us a great deal about this almost impenetrable piece of legislation ... (What do you mean, you gave up before you got to Recital 171?)

Friday, 30 December 2011

Tougher data protection laws on the way

The European Commission has long been concerned about how Internet businesses treat personal data. Its proposals for a new data protection regulation (to replace the present directive and overcome the problems that arise from the need to transpose the rules into national law) are due to be published on 25 January. The Commission aims to give consumers the power to control the way their personal data are processed by companies, and to impose a bit more discipline on data controllers by introducing fines of 5% of global turnover for businesses who are found to be in breach of data protection laws.

The draft also proposes to introduce obligatory data protection officers for all public sector bodies and private sector bodies with more than 250 employees. The directive made that something that Member States could choose to have: Germany already had it when the directive came into force, hence its inclusion, but the UK government always said it would not be taking up the option. Now it seems it will have no choice - but what organisation of that size doesn't already have a data protection officer, even if they have a load of other responsibilities too?

Friday, 23 December 2011

Penalties for breach of Data Protection Act

The Information Commissioner's Office has had the power to impose financial penalties (not fines) since April last year. Already there have been several examples of this new power being used. Now comes news of the biggest so far: on a local authority, for £130,000, for sending sensitive information about a child protection case to the wrong recipient. Unfortunately, data breaches don't come much worse than that (though there are plenty of examples that are about as bad, but different). The same authority had already had a formal warning from the ICO after to a similar breach. The ICO has also ordered that the authority's staff should be trained in the proper implementation of the authority’s data protection policy.

 

blogger templates | Make Money Online