Friday, 10 August 2012

Leaving the Article 29 Working Party

It’s summertime. The weather is glorious and the Brits are performing so magnificently at the Olympic Games, which are being held in London.

If ever there were a time for everyone to learn all the words to Rule Britannia, now is it.

Anyway, in my relaxed mood, it’s time to think the (virtually) unthinkable. I’ve been wondering what sort of memorandum might be written by Christopher Graham, our own Information Commissioner, to his colleagues on the Article 29 Working Party, advising them of the consequences of the European Commission getting the politics of European integration horribly wrong and forcing the British Government to decide that it’s in the best interests of Britain for it to go its own way. Yes, and to tear up the “social contract” bits of the European treaties that have been signed. Including the data protection bits.

I wonder if such a memorandum might read like this:

Hi Guys.

I’m afraid it’s not good news. Just like the owl and the pussycat, we’re all at sea. As Edward Lear might have said:

We’ve been negotiating away for a year and a day
In a land where the Commission’s influence steadily grows.
While in a wood a Nationalist stood
With a ring at the end of his nose,
His nose, his nose,
With a ring at the end of his nose.

"Dear regulators, are you willing to sell for one shilling
Your national interests?" Said one plonker, "I will."
So they took him away to get married next day
To a turkey who lives on the hill.

You’ve dined on slogans, soundbites and quotes
Snorted Euro power through rolled up Euro notes;
Hand in hand you’ve created a new vision in sand.
You’ve advanced by the light of the moon,
The moon,
But, for the Brits, you’ve gone too far, too soon.

What does this all mean?

Well, I’m afraid the Euro project is over for us Brits. We’ve been painted into a corner. Yes, we absolutely understand that a consequence of further financial European integration is that everyone in the Euro Zone will get to love each other even more and to follow the exact same rules. But, we Brits aren’t in the Euro zone, and the social rules that you Euro Zoners want to bind yourself together with are occasionally so alien to our British way of life that it would be political suicide for any British politician to say anything nice about them right now.

So, I’m told that we’ll be pulling out. Otherwise the British people will vote for Prime Minister representing the nationalist UKIP party, as the electorate won’t stomach anything else.

Yes, it’s been an absolute pleasure attending all these Article 29 Working Party meetings, and trying to forge common visions of data protection issues. It’s been almost as good as watching the 100 yard dash for people with no sense of direction at the London Olympics. However, there’s only so much fun a regulator can have. Consequently, I’ll be retreating to Wilmslow for a bit, while my political masters work out what data protection landscape awaits a country for whom pragmatism, simplicity, transparency and fairness is more important than impossibly complicated Euro rules that hardly anyone can understand.

Before I go, let’s all have just one last chorus of one of my favourite anthems:

If you see me, say hello, I’ll buy you a cold beer
I’m checking out Monday afternoon, and you’re OK, I hear
I should tell you that I’m all right, though feeling kind of strange
As the rules which have been so familiar are just about to change

We haven’t had a falling-out, like regulators often will
And to think of how I heard that day, it still brings to me a chill
As we complete our separation, it’s piercing me through to my heart
Old ways still live deep inside of me, now from these we need to part

If you get time enough, we’ll have one last drink on me
I’ve always almost respected you, now I’m busting out and gettin' free
Oh, whatever makes you happy, I won't stand in your way
Though that rigid taste still lingers as I know I cannot stay

I see many, many people as I make my rounds
And I’ve said lots of nice things about you, as I’ve gone from town to town
I’ve tried not to undermine you, I’ve quoted from you oft
Either I'm too sensitive or else I'm gettin' soft

When I return to Wilmslow , I will replay the past
I know every article of the Data Directive by heart, they all went in so fast
If you’re passin’ back this way, I'm not that hard to find
You can always look me up - I really wouldn't mind

Best Regards,

Chris


Seriously, I will be doing some hard thinking over the late summer and early autumn on the (frankly, extremely remote) likelihood that the British Government decides that, on balance, it would be more appropriate for 'Blighty to develop its own data protection rules, rather than implement whatever might emerge from the current European proposals. After all, the argument will run, if the Americans can get away with it and do their own thing, like the Canadians, and the BRIC countries, then why can’t the Brits?

Let’s be honest, I can’t think why new British rules might harm British citizens, either. Especially if I have a hand in drafting some of them!


Sources:
Apologies to Edward Lear, who would be turning in his grave if ever he were to have realised what I have done to his poem about the "Owl and the Pussycat."
Also, many thanks to the inspiration of Bob Dylan, whose song “If you see her, say hello” can be found on his “Blood on the Tracks” album. I published an earlier version of this anthem on 26 November 2011.

Image credit:

http://img.ehowcdn.com/article-new/ehow/images/a07/0g/pn/average-cost-divorce-missouri-800x800.jpg

.

Thursday, 9 August 2012

An elevator pitch for data protectors

My business mentor tells me that it’s really important to have a good elevator pitch.

What’s one of those?

Well, it’s a very short presentation which tells people who you are, where you come from, what you do, what sorts of clients you am looking for, and how you can help them.

It’s not really a sales pitch, it’s more of a way of introducing yourself at a networking event. You don’t meet many people who know they have an immediate compliance need. But people do want to know who to turn to when the need arises. Especially people running small and medium sized enterprises, for whom data protection exists as a really obscure concept - one which, they think, if they keep their head down, will never attract any interest from our chums in Wilmslow.

So, my elevator pitch explains how I might be able to help once someone has realised that they actually do need to have a confidential chat with a friendly face.

Here it is.

Let me know what you think. After all, I don’t want to waste anyone’s time telling people stuff they don’t need to know.

Hello everyone.

I’m Martin Hoskins from Privacy Consulting, based in Central London.

If you are concerned about the way your customer records are held, I can help. If you are concerned about the way your staff records are kept, I can help. And, when there’s a complaint that those records have been misused, I can help.

As we live our lives ever more on-line, we are increasingly affected by issues of privacy and trust. But what rights do people have when they share some of their personal information? What are your legal duties when you handle personal information? How can you legitimately exploit it for your own business purposes? And what could the consequences be if things go wrong?

No-one wants to have their passwords compromised, or for the wrong information to be made available to the wrong people. But it happens.

Privacy mishaps are making headlines worldwide. More and more people are being told that they’ve lost control over some of their personal information.

Data security and privacy issues have now moved from the backroom to the boardroom. Regulatory action is becoming more common. So, if you need to know what acceptable standards of data protection look like, then I can help.

Finally, should things go awfully wrong, and you get referred to the Information Commissioner’s Office, then I can help some more.

You can find me at www.martinhoskins.com and www.privacyconsulting.co.uk.



Image credit:
http://static5.businessinsider.com/image/4b61b47a00000000009f71c5/elevator-bank.jpg

.

Wednesday, 8 August 2012

Nothing to confess

According to a recent media report, Oracle and Google have been ordered to reveal the names of reporters, bloggers and other commentators they have paid. The demand, made by a US judge, follows an intellectual property battle the firms fought in court.

Well, you’re not going to find my name on any of those lists. I comment on current events as I see fit, rather than from the perspective of a paid commentator.

Yes, I have in the past enjoyed some of Google’s famous hospitality when visiting their London offices while working for a previous employer. All that free food. But no cash has ever exchanged hands. Nor have any of Google’s services ever been slipped in my direction.

Is this because I’m a “holier than thou” kind of data protector, or simply because I’ve never been asked?

Yes, you are right. I’ve never been asked!


Source:
http://www.bbc.co.uk/news/technology-19181172

.

Tuesday, 7 August 2012

A healthcare nightmare

There’s a really nice picture on the front page of the website of the Torbay & South Devon Healthcare NHS Trust today. It features a group of people most generously donating £1,018.57 to the Make a Wish Foundation to improve the lives of local sick people. I know the area. It’s quite close to where I was born. And charities like this need all the support they can get.

How ironic it is that, yesterday, an ICO press release announced that the Trust will face a Civil Monetary Penalty of £175,000 (reduced to £140,000 if it pays before 31 August) because sensitive personal details of 1,373 staff was inadvertently published on their website.

As the ICO explains, the information was published in April 2011, but the mistake was only spotted when it was reported by a member of the public 19 weeks later. The data covered the equality and diversity responses of the staff and included individuals’ names, dates of birth and National Insurance numbers, along with sensitive information about the person’s religion and sexuality.

The Monetary Penalty Notice acknowledges that during the 19 weeks, the Trust’s website received 21,000 visits, and the web page containing the sensitive information received approximately 300 visits. While it was not possible to establish how often the actual spreadsheet was accessed by the public, some 32 of the visits were from unidentified IP addresses.

So, in this case we have a situation where something has evidently gone wrong, but it took 19 weeks before anyone in authority realised. All affected staff received an apology and compensation was evidently offered. No member of staff has apparently complained. The Trust voluntarily disclosed the incident, a full investigation took place and remedial action was taken, and the Trust was fully co-operative with the Commissioner’s Office.

And still, the Trust gets a fine of this size. I just don’t understand how the ICO can argue that the incident was “of a kind likely to cause substantial damage or substantial distress” - which is the statutory test which must be applied - when, evidently, no victim did complain. And these victims have had some 10 months to complain since the incident was reported. Give me evidence-based regulation any time.

But, every cloud has a silver lining.

Hopefully, it will inspire people in similar situations to pick up the phone and call me to explain that they’re in a bit of a mess and they want some help improving their data protection standards before they dare phone the Information Commissioner’s Office. Bad news like this is always good for business.

Also, it will act as an additional incentive to those plucky charity workers in the Torbay and South Devon area to inspire Devonians to dig even deeper in their pockets to replenish the funds that, if spent on healthcare, would certainly have gone some way to improve the lives of local sick people.


Sources:

http://www.ico.gov.uk/news/latest_news/2012/sensitive-details-of-nhs-staff-published-by-devon-trust-06082012.aspx
http://www.torbaycaretrust.nhs.uk/Pages/home.aspx (And no, the website doesn’t mention the ICO’s Civil Monetary Penalty - yet)

.

Monday, 6 August 2012

“Exit that draft Regulation, pursued by an ungovernable crowd”

I must thank our chums at Statewatch for keeping me up all night – they’ve kindly published on the internet a leaked copy of the initial responses of Member States to first 10 Articles of the proposed new Data Protection Regulation.

The document is 170 pages long, so make sure you're not going to be disturbed for a long, long time.

It makes really interesting reading, and it makes you wonder how on earth all Member States are going to be able to accommodate each other’s positions. If I were a betting data protector, I would assume that the only way that this current proposal is going to see the light of day is if the German Government makes it a condition of any future financial assistance from the Federal Republic in respect of a Euro bailout that the recipient Member State immediately appoints a German Data Protection Troika to oversee that Member State’s data protection laws.

And remember, even the Germans (on page 24) are insisting that "Member States must be able to retain their national rules – in particular where they provide a higher level of data protection than that provided in the legislative act – or to enact new ones."

In German eyes, it seems that reform can only be achieved by an upward revision of current data protection standards to the highest that are currently available. Then, we may get somewhere.

But, I mean, how do you reconcile a range of views like this? Talk about a shotgun wedding. I’ve seen less savage exchanges of views at Glaswegian wedding receptions.

So where is the way forward?

In no particular order, I guess we’ll see next proposals floated that support

• a Directive, rather than a Regulation;
• less formal co-ordination from the Commission;
• more (but still relatively informal) co-ordination from a College of Information Commissioners;
• the introduction of an accountability principle, but
• with lots of flexibility as to how controllers will be required to demonstrate their accountability;
• stronger penalties against those who transgress
• and different regulators exercising their disciplinary muscles in different ways
• failed attempts to control non EU based data controllers (blah, blah blah);
• another attempt at the central co-ordination of European data protection policy in, say, 5 years time, when our national leaders have worked out whether the future political path of Europe is leading to the central control of everything, or the re-emergence of nation states.

We, in Blighty, should all rejoice that we will be able to rely on our chums at the Ministry of Justice to carry out the heavy negotiating. Now, we’ll just have to wait and see what emerges from the background deals that will inevitably be offered as someone – presumably the Irish diplomats – assesses the chances of agreement during the Irish Presidency of the Commission in the first half of next year. After all, no Presidency ever wants to feel that theirs was a wasted opportunity to make a mark on the international scene.

But, really, just what does Euro-data protection actually look like?

After reading this report, frankly, I’m none the wiser.


Source:
http://www.statewatch.org/news/2012/jul/eu-council-dp-reg-ms-positions-9897-rev2-12.pdf

The document comments on the first 10 Articles. The draft Regulation contains 91 Articles, so we can look forward to a few more documents this size being uploaded onto the internet in the fullness of time.

.

Sunday, 5 August 2012

Data Protection Crime (and Punishment)


When you’re a Data Protection Officer, writing a business case for something or other, it’s always useful to have the odd fact up your sleeve to help emphasise the need (and urgency) for action.

For some time, many of us have been using the ICO’s “£500,000 fine” line, assuming that the possibility of a civil monetary penalty as enormous as this would inspire the business to start to invest in data protection at a level that really was commensurate with the risk that was being run.

Of course, it’s worked – to a limited extent. And, with each new Civil Monetary Penalty, some businesses get even more concerned that their dodgy practices might come to light.

The trouble is, of course, that fines are only money. And, in the public sector, removing money from public authorities it simply means less public funding for essential services.

If I had my way, I would have the Chief Executive Officer of the relevant authority washing cars in the Commissioner’s car park for a day, to atone for his sins. Or I would have the ICO having the power to aware an order requiring the authority to invest £x in enhanced data protection safeguards, rather than having that £x returned to the Exchequer.

Perhaps there’s another line that Data Protection Officers can use, which might be even more effective in delivering higher standards.

How about jobs!

A little while ago, our chums at BigBrotherWatch did some work to learn how many policemen were misbehaving, data protection wise. Police authorities were asked to provide a clear, itemised list of the offences committed by the individual in question i.e. "Abusing privileged access to the Police National Computer" or "Passing information to an unauthorised third party”.

The research revealed that, between May 2008 and May 2011:
• 243 police officers and staff received criminal convictions for breaching the Data Protection Act;
• 98 police officers and staff had their employment terminated for breaching the DPA;
• 904 police officers and staff were subject to internal disciplinary procedures for breaching the DPA.


These are quite impressive figures – not only have the police authorities actually collected this information, but they indicate a level of internal HR activity which shows that the police do recognise that such behaviour really is unacceptable.

Such levels of internal HR activity possibly explain why the ICO has not found it appropriate to take court action against individuals in many cases. The last 3 ICO annual reports contain relatively few examples of action being taken against offenders.

The 2011/12 annual report contained one report of a prosecution action at Reading Magistrates Court against an employee of Slough Borough Council Benefits Office in March 2012 and two company directors. The employee had obtained and sold personal data to associates who were directors of a letting company, which was used by that company to chase up their tenants’ outstanding debts. Both company directors were each fined a total of £260 for two offences under the Data Protection Act. The Slough Borough Council employee was fined £690 for three offences under the Act.

The 2010/11 annual report noted that the ICO took prosecution action in five DPA cases, two of these relating to offences for unlawfully obtaining personal data. Both defendants in these cases pleaded guilty in the Crown Court. Due to the unlawful sale of data taking place over the course of a year and the amount of money involved, confiscation proceedings under the Proceeds of Crime Act 2002 were started and £78,000 was recovered.

The other three cases, involving two estate agents and one private investigator, were prosecuted in the Magistrates Court for failing to notify the Commissioner that they were processing data electronically. All three defendants had failed to respond to correspondence from the office reminding them of their requirement to notify.

The 2009/10 annual report noted that seven bodies (a mix of individuals and organisations) were prosecuted for failing to notify as data controllers with the ICO. Two were prosecuted in the Crown Court and one received a fine of £5,000. In another, a director was also convicted in his individual capacity and received a separate penalty to that of the organisation. Two other organisations were prosecuted for failing to respond to enforcement notices. One was an individual who was prosecuted for not notifying and was dealt with in the Crown Court. The other individual received fines totalling £5,200.

The ICO also investigated suspicions that a covert blacklist was operating in the construction industry. The custodian of the list was the Consulting Organisation. Ian Kerr (on behalf of the CA) was sentenced to a £5,000 fine and ordered to pay £1,187.20 in costs.

OK. What about recent Computer Misuse Act offences? Is a pattern emerging here? Can we use these prosecutions to support the need for greater data protection standards?

Well, these figures are not easy to decipher. Between 2006 and 2010, there were some 100 prosecutions involving the Computer Misuse Act, but the number of prosecutions may well have declined over recent years. As John Leydon of The Register explained: “It would be rash to read too much into the figures, especially since the stats only cover prosecutions where computer hacking offences were the principal offence under consideration by the courts. So if a suspect was convicted of banking fraud or phishing as well as computer misuse, and received a harsher sentence for the fraud, then the computer hacking prosecution would go unrecorded. In addition, the figures supplied provide no breakdown on the number of UK computer hacking prosecutions that actually resulted in a conviction.”

So what does this tell us?

Not much, admittedly.

It tells me, at least, that there are some people who are getting prosecuted for data protection offences. But there aren’t many of them. Whether the whispered additional powers (yes, criminal sanctions for more types of offences) that are to be added to the Data Protection Act will have much effect, only time will tell. After all, who knows when this will happen. And even when it does, who knows what appetite the authorities will have to actually use them. With ever fewer resources being made available to the Crown Prosecution Service, I expect that they will be hard pressed to continue to make full use of the existing powers they have, let alone have the resources to apply new sanctions to new categories of miscreants.

Source:
http://www.bigbrotherwatch.org.uk/Police_databases.pdf
http://www.theregister.co.uk/2012/05/18/uk_hacking_prosecutions_decline/

Image credit:
http://www.baycityguide.com/alcatraz/images/500/Alcatraz_prison_cell.jpg


.

Friday, 3 August 2012

A plea for simple data protection rules

The first day back from my summer holiday was celebrated by having lunch with a prominent data protection academic / practitioner in the City of London.

The conversation touched on the different perspectives that practitioners and academics had to data protection. From my perspective, practitioners were those who tried to adopt relatively simple rules, so that compliance teams could more easily understand what was required. This involved having to make complex judgments about what language to use to ensure that normal people could understand what was meant by the difficult language that data protection law was so frequently cloaked in.

Some members of the academic community appear to focus on more on the balancing exercise that is necessary to ensure that the fundamental rights of individuals are fully observed, and that data controllers respect these fundamental rights as completely as possible. So, they can be less tolerant of the use of accessible language. For them, precision is king. And if that meant that the language has to contain a certain degree of complexity, then so be it.

I’m in the simple camp, myself. I reminded myself of this as I tried to refresh my memory by re-reading chunks of “that” Regulation, to get myself up to speed to develop some possible amendments to the current text. It’s amazing how quickly you can forget what some of the obscure drafting actually means, when you take a short break.

The realist, rather than the optimist, in me accepts that what the European Parliament will probably pass is a text that only the finest minds in the data protection community will actually understand. The largest and the most complex data controllers will inevitably have the resources to implement it, but I do worry how the vast majority of Europe’s data controllers (let alone Europe’s citizens) will react.

What can we do? Can we force European Parliamentarians to take a data protection test before they vote on the text, so we European citizens can be reasonably sure that they know what it is that they are actually doing? Probably not. They’re all busy people and it’s not possible to expect them to fully understand the implications of every legal instrument they are expected to vote on.

What we can do, hopefully, is expect that our chums in Wilmslow might prepare some Plain English versions of the new rules. They do have a great track record here. After all, remember the recent fears that the cookie rules as prescribed by the ePrivacy Directive were gobbledygook?

Well, take a look at the ICO’s blog, posted on 25 May, with its guidance which clarifies the following points around implied consent:

• Implied consent is a valid form of consent and can be used in the context of compliance with the revised rules on cookies.
• If you are relying on implied consent you need to be satisfied that your users understand that their actions will result in cookies being set. Without this understanding you do not have their informed consent.
• You should not rely on the fact that users might have read a privacy policy that is perhaps hard to find or difficult to understand.
• In some circumstances, for example where you are collecting sensitive personal data such as health information, you might feel that explicit consent is more appropriate.


Brilliant. Normal people (and SMEs) can understand that sort of language.

What a pity there isn’t a Plain Language Directorate within the European Commission, which might ensure that all proposals can generally be understood by those to whom they are intended to apply.


Source:
http://www.ico.gov.uk/news/blog/2012/updated-ico-advice-guidance-e-privacy-directive-eu-cookie-law.aspx


Image credit:
http://www.minimalwall.com/wp-content/uploads/minimalwall-10-52-1-minimal-wallpaper-keep-it-simple-.png

.