The bash at the Brewery in the Barbican on Thursday evening went well. So well that I can hardly remember the detailed points that each panelist made to the audience. And no, my lack of memory was not due to the evening ending in a sea of alcohol. It was entirely due to my getting home late, immediately falling asleep and then setting out really early the following morning to attend yet another discussion meeting.
Fortunately, I won’t need to rely just on my memory about what I said on Thursday. Journalists, as well as lawyers, were present, So, I’ll be able to read all about it in The Lawyer magazine in a few weeks time. I’ll post a link to the article when it gets published.
Yesterday’s discussion, on building trust and reputation, touched on a few of the old issues we’ve all grown to love. Can data controllers be trusted to act with honour, or are too many of them a bunch of irresponsible cowboys who need to be whipped into shape by an ultra tough regulator? The discussion moved on to how well intentioned- individuals within an enterprise were able to influence the general behaviour of the firm. What is the tone from the top? To what extent are our “dear leaders” sticking their necks above the parapet to show their own determination and commitment to adhering to ethical business practices?
Given the top stories in the national media, which were focussing on corporate misbehaviour in areas other than data protection, it was probably the wrong time to hold such a discussion, but we continued regardless.
In the end, we agreed, it was about role models. How many great examples of great corporate behaviour exist? And how often is the public’s attention diverted to the “wrong uns”, rather than our shining stars?
Perhaps, within the data protection world, it would be helpful to create our own lists of shining stars and cowboys. (I wonder how many names might find their way onto both lists?) Perhaps, if the new accountability principle is fully embraced, our profession will create its own Data Protection Hall of Fame.
Hmmmmmmmmm.
Let’s start with smaller steps. How about a Data Protection Webpage of Fame – a sort of “Who’s Who” in the international data protection community. Or a "Those we have loved" page on LinkedIn.
Or are there too many practitioners who would rather exercise a right to be forgotten, rather than a right to be respected?
Image credit:
http://www.pack1776.com/wp-content/uploads/2012/06/HallOfFame.jpg
.
Saturday, 30 June 2012
Thursday, 28 June 2012
Cookies: I’m a hit with the audience at Olympia
A packed audience liked the data protection jokes I cracked at yesterday’s “MarketingWeek Live” event. The venue was the Grand Hall at Olympia – a great big barn of a place that is used for trade fairs, dog shows and the occasional concert.
My theme was compliance with the new cookie rules: “the cookie conundrum” – as I bill the talk. And, judging from the people who queued to have a quiet word with me after my slot, it went down quite well. I had to tailor the language I could have used to explain some of the more technical aspects of this stuff, and, as there were lots of ladies present, I also cut out all the rude words that the Monty Python team used when giving their version of the tale of King Otto (and the cookies). But at least everyone still laughed in all the right places.
I’m not booked to speak anywhere on that subject for a few more months, so I’ll lay that one to rest for a bit. But, if anyone fancies a private performance, please let me know.
Now I’m preparing for tonight’s show – at The Brewery in the City of London, which will be reviewed in a future edition of "The Lawyer" magazine. I’ll be sharing a platform with, among others, the ICO’s Dave Evans. Spookily, Dave helped write most of the great advice that the ICO has published on cookie compliance. But we’ll both be giving cookies a night off. Instead, we’ll aim to have the audience of some 70 senior lawyers rolling in the aisles as we address other issues that are so close to our professional hearts. Tonight’s session, believe it or not, is focused almost entirely on the data protection aspects of transborder data flows.
How on earth can a panel of four seasoned professionals string out a 90 minute session on that subject? And how can so many eminent lawyers in private practice and corporate general counsels feel so compelled to sit through it?
Well, it is being held in an old brewery, you know.
And if I can remember what went on, I’ll report back later.
.
My theme was compliance with the new cookie rules: “the cookie conundrum” – as I bill the talk. And, judging from the people who queued to have a quiet word with me after my slot, it went down quite well. I had to tailor the language I could have used to explain some of the more technical aspects of this stuff, and, as there were lots of ladies present, I also cut out all the rude words that the Monty Python team used when giving their version of the tale of King Otto (and the cookies). But at least everyone still laughed in all the right places.
I’m not booked to speak anywhere on that subject for a few more months, so I’ll lay that one to rest for a bit. But, if anyone fancies a private performance, please let me know.
Now I’m preparing for tonight’s show – at The Brewery in the City of London, which will be reviewed in a future edition of "The Lawyer" magazine. I’ll be sharing a platform with, among others, the ICO’s Dave Evans. Spookily, Dave helped write most of the great advice that the ICO has published on cookie compliance. But we’ll both be giving cookies a night off. Instead, we’ll aim to have the audience of some 70 senior lawyers rolling in the aisles as we address other issues that are so close to our professional hearts. Tonight’s session, believe it or not, is focused almost entirely on the data protection aspects of transborder data flows.
How on earth can a panel of four seasoned professionals string out a 90 minute session on that subject? And how can so many eminent lawyers in private practice and corporate general counsels feel so compelled to sit through it?
Well, it is being held in an old brewery, you know.
And if I can remember what went on, I’ll report back later.
.
Wednesday, 27 June 2012
Comms Data Bill: Battle lines drawn at the Frontline club
Last night, the think tank Demos and the Frontline Club, the London hub for a diverse group of people united by their passion for the best quality journalism, held a session on cyber snooping and the Communications Data Bill. Originally advertised to take place amidst the grand surroundings of the Royal Institution in Mayfair, at the last minute the venue was switched to the debating room at the Frontline Club –which is situated in a part of Paddington that is evidently not going to witness the Olympic flame being paraded past its front door.
The BBC’s Rory Cellan-Jones chaired the session and introduced the speakers, who were Professor Anthony Glees from the University of Buckingham, Isabella Sankey from Liberty, Jamie Bartlett from Demos, and the Rt Hon David Davis MP.
Anthony Glees introduced himself to the audience as: “the skunk at this picnic,” and pointed out that the debate isn't about the interception of communications as we already have legislation in place for that. Nor is it liberty and freedom. It's really about trustfulness. The real problem is a lack of public trust in the security and intelligence community, despite the fact that in the UK we have good and ethical spooks and policemen who practice their tradecraft in an ethical manner. But, Parliament’s Intelligence and Security Committee has simply not done a good enough job to spread the news about just how good these guys are.
In his view, we don’t live in a surveillance state because we simply don’t have enough spooks to justify such a claim. Certainly when compared to the surveillance states of old.
He was optimistic that the Bill would go through.
Jamie Bartlett spoke next, announcing that he was mildly in favour of the Bill. But, the real issue, in his mind, was how the state regulated the investigation of people’s Twitter postings and Facebook accounts, as this “semi public” information probably harvested information that was even more intrusive than much of the communications data that the service providers were expected to retain. We need laws to regulate this stuff, as without a law there always be the potential for real abuses of power to occur.
Jamie sensed that the politicians often didn’t fully appreciate the service requirements of the security establishment, and that it was often too easy to criticise them and the legislation they worked under. There will be technical problems on how the data will be obtained. But, the spooks can't explain what counter measures will be deployed, nor what safeguards will be designed to prevent abuse.
Jamie’s bright idea was that the spooks should be regulated not only by teams of politicians, but also by security cleared members of the public, who can represent independent voices. After all, if the public were entitled to sit on juries, why should they also not be entitled to have a say in how this type of behaviour should be regulated.
Isabella Sankey was up next, announcing that Liberty’s view of the Bill was that it is “rotten to the core.” She made one interesting technical point - what's unclear is whether the technology requires an interception of the content of various communications in order to get the traffic data, which is the only stuff they should really be accessing.
Isabella admitted that it's really hard to measure whether any damage has been done to an individual as a result of the current (and projected) regulatory environment, but even so, Liberty had been inundated with letters from members of the public and its membership has soared as a result of the public debate over the issue. So, even they have seen something good come out of the proposals!
Finally, David Davies spoke. He had considerable political and practical experience of the security agenda, having once served as: “the minister for weapons of mass destruction.” He was really concerned at what can happen when the agencies have relatively unfettered access to giant databases. In his view, the agencies broadly do a good job and they have a problem with this in that they don't have the kit to properly sift through the material that is already available to them. He was worried about the implications of false positive results. He was also worried that the Government was overseeing the creation of a honeypot that would be of interest to practically every divorce lawyer in the country.
David was also concerned at the potential costs of the initiative, and the potential for a breach of security by miscreants hacking into these giant and sensitive on-line databases, which, after all, are opposed in Germany, the Czech Republic and Romania. So, he expects the Bill to get squashed in Parliament. What he might accept was a “fully up fronted warranted Bill” - whatever that is. In his view, the more power you give the agencies, the tougher the oversight needs to be.
His last remark was also pretty telling – “A lot of those who are against the bill are the experts in this business.” And he expected these experts to have their say, later. Personally, I’m not sure just how accurate that assertion is. But we’ll all find out in due course.
Source:
The 90 minute debate was streamed live on the web and is currently available on the Frontline Club’s upstream channel at http://www.ustream.tv/frontlineclub
The BBC’s Rory Cellan-Jones chaired the session and introduced the speakers, who were Professor Anthony Glees from the University of Buckingham, Isabella Sankey from Liberty, Jamie Bartlett from Demos, and the Rt Hon David Davis MP.
Anthony Glees introduced himself to the audience as: “the skunk at this picnic,” and pointed out that the debate isn't about the interception of communications as we already have legislation in place for that. Nor is it liberty and freedom. It's really about trustfulness. The real problem is a lack of public trust in the security and intelligence community, despite the fact that in the UK we have good and ethical spooks and policemen who practice their tradecraft in an ethical manner. But, Parliament’s Intelligence and Security Committee has simply not done a good enough job to spread the news about just how good these guys are.
In his view, we don’t live in a surveillance state because we simply don’t have enough spooks to justify such a claim. Certainly when compared to the surveillance states of old.
He was optimistic that the Bill would go through.
Jamie Bartlett spoke next, announcing that he was mildly in favour of the Bill. But, the real issue, in his mind, was how the state regulated the investigation of people’s Twitter postings and Facebook accounts, as this “semi public” information probably harvested information that was even more intrusive than much of the communications data that the service providers were expected to retain. We need laws to regulate this stuff, as without a law there always be the potential for real abuses of power to occur.
Jamie sensed that the politicians often didn’t fully appreciate the service requirements of the security establishment, and that it was often too easy to criticise them and the legislation they worked under. There will be technical problems on how the data will be obtained. But, the spooks can't explain what counter measures will be deployed, nor what safeguards will be designed to prevent abuse.
Jamie’s bright idea was that the spooks should be regulated not only by teams of politicians, but also by security cleared members of the public, who can represent independent voices. After all, if the public were entitled to sit on juries, why should they also not be entitled to have a say in how this type of behaviour should be regulated.
Isabella Sankey was up next, announcing that Liberty’s view of the Bill was that it is “rotten to the core.” She made one interesting technical point - what's unclear is whether the technology requires an interception of the content of various communications in order to get the traffic data, which is the only stuff they should really be accessing.
Isabella admitted that it's really hard to measure whether any damage has been done to an individual as a result of the current (and projected) regulatory environment, but even so, Liberty had been inundated with letters from members of the public and its membership has soared as a result of the public debate over the issue. So, even they have seen something good come out of the proposals!
Finally, David Davies spoke. He had considerable political and practical experience of the security agenda, having once served as: “the minister for weapons of mass destruction.” He was really concerned at what can happen when the agencies have relatively unfettered access to giant databases. In his view, the agencies broadly do a good job and they have a problem with this in that they don't have the kit to properly sift through the material that is already available to them. He was worried about the implications of false positive results. He was also worried that the Government was overseeing the creation of a honeypot that would be of interest to practically every divorce lawyer in the country.
David was also concerned at the potential costs of the initiative, and the potential for a breach of security by miscreants hacking into these giant and sensitive on-line databases, which, after all, are opposed in Germany, the Czech Republic and Romania. So, he expects the Bill to get squashed in Parliament. What he might accept was a “fully up fronted warranted Bill” - whatever that is. In his view, the more power you give the agencies, the tougher the oversight needs to be.
His last remark was also pretty telling – “A lot of those who are against the bill are the experts in this business.” And he expected these experts to have their say, later. Personally, I’m not sure just how accurate that assertion is. But we’ll all find out in due course.
Source:
The 90 minute debate was streamed live on the web and is currently available on the Frontline Club’s upstream channel at http://www.ustream.tv/frontlineclub
Tuesday, 26 June 2012
Who really falls for internet scams like these?

There obviously has to be one born every minute, but I really do wonder just how many people are foolish enough to be taken in by emails such as this one, which has recently landed in my spam box. My old English teacher would be turning in her grave, if she were to realise how people write these days. Mrs Bramble really was a stickler for punctuation and the correct use of capital letters:
PLEASE ENDEAVOUR TO USE IT FOR GOD.
Hello My Dearest,
I know how surprise this email might appear to you but i want you to consider it as a request for an assistance from a dying woman. My Name is Mrs. Elizabeth Wilson. from Israel but now undergoing medical treatment in Abidjan the capital city of Ivory Coast.
I am married to late Mr Benson Wilson, who worked with Israeli Embassy in Ivory Coast for Eleven years before he died in the year 2008, after a brief illness that lasted for only Ten days.
We were married for Eighteen years without any child. After the death of my husband i vowed to use our wealth for the down trodden and the less privileged in our society.
Recently, My Doctor told me that I may not last for the next seven months due to cancer problem, though what disturbs me most is my stroke and deaf problem.
Haven known my condition i decided to Serve God with our wealth. When my late husband was alive we kept the sum of ($7.6 Million U.S. Dollars) Seven million six hundred thousand united states dollars Having known my condition I decided to Give out this fund to a church or an individual or better still a God fearing person who will utilise this fund the way I am going to instruct here in.
I want an individual that will use this fund to provide succour to the poor and indigent persons, orphanages, widows around him or her and Schools etc. As soon as I receive your response I shall give you the contact of the Bank where the said fund is deposited I will also issue you the documents that will prove you the present beneficiary of this fund.
Any delay in your reply will give me room in searching for an individual or this same purpose, always be prayerful all through your life.
Please assure me that you will act accordingly as I Stated herein. Hope to receive your reply soon.please reply me through this email eliza_jj03@yahoo.co.jp
Thanks and Remain Blessed.
Mrs.Elizabeth Wilson.
Image credit:
http://scamtrick.com/wp-content/uploads/2011/06/internet-scams.jpg
.
Monday, 25 June 2012
Accounting for good data protection

With apologies for the awful pun, today’s blog celebrates our chums in the accounting profession, who have recently launched a report on building trust in the digital age. The report was published in November 2011, but the formal launch occurred on 19 June 2012. Sometimes, accountants take their time.
The broad thrust of the report, on rethinking privacy, property and security, is pretty clear: “Today’s good practices are not enough.” What is required is “an accepted framework of social expectations and laws.” And, because digital technology is disrupting and challenging, we “need to encourage widespread engagement, understanding and debate of the issues to build a social and legal framework which is broadly accepted and can underpin individual business actions.”
Top tip – if you don’t fancy paying £45 for your own ICAEW (Institute of Chartered Accountants of England and Wales) bound copy, you can download it for free from here.
By the time you’ve read this 98 page report, you will, according to the blurb, have benefited by:
• Helping management make better decisions about digital information and improve the business performance in relation to information risks; and
• Informing the widespread public debate about digital information and thereby support the development of a variety of regulatory, industry and social solutions.
OK, I think I get it. But, everyone cries, how are we going to do it? Or, as I reported about the question my nephew asked me last week, what does good data protection look like?
Well, I’ve recently given my own reply three times so far. Once to my family and the other times, to audiences of different types of professionals. Each audience laughed in different places as I made my pitch. Do professional stand-up comics get such a varied reaction to their material, too? I really ought to follow someone around the comedy circuit for a while, just to find out.
Anyway, the good news is that everyone told me that they liked what I had to say. I’m delivering it once more, next week, to yet another audience of another type of professional, and then I’ll stop taking and I'll be blogging about it.
Apparently, as some professional comics keep telling me, there’s only so long you can trot out the same old stuff on the comedy circuit before you have to refresh your material.
Obviously, they’ve never heard of Ken Dodd.
Source:
http://www.icaew.com/~/media/Files/Technical/information-technology/business-systems-and-software-selection/making-information-systems-work/building-trust-in-the-digital-age-report.ashx
.
Sunday, 24 June 2012
Let’s focus on a little less spam, please

Two texts were sent to my mobile last week, within hours of each other. The first, from 07923 098061 said: "Due to new legislation, those struggling with debt can now apply to have it written off. For more information text the word ‘INFO’ or to opt out text stop."
Then, as if by magic, another cowboy, this time using 07926 047555, spookily sent me exactly the same message.
Could these cowboys be related, perhaps?
It’s surely more than a bit naughty to send messages like this to vulnerable people. Would an ethical debt-defying service provider stoop as low as this to scoop up the details of people in financial difficulties, so that they could (probably) make some money out of them too? But there must be enough folk around who are tempted to respond, and who subsequently get sucked into these information flows, otherwise there would be no financial incentive for the original sender of the message to make the investment that is required to send the messages.
For the record, I’m sure I have not consented to these messages. But that’s not really the point.
The point, I think, is that our regulators have got a huge task on their hands trying to decide how to allocate their investigative resources to enforce all of the data protection rules.
I appreciate that, recently, the political focus has been on the implementation of the cookie rules. Which is obviously why we have seen so many websites start to become more transparent about the way cookies are used on their websites. Quite whether this has changed users’ behaviours is another story. Perhaps, in a few years’ time, some research will be published on the extent to which users have changed their cookie preferences following the initiative to deliver greater transparency. My guess, for what it’s worth, is that there will be little change in the overall pattern of preferences that are currently set, and that users will continue to pay as much attention to their right to set cookie preferences as they do to all the other sections of the privacy policies, and rest of the regulatory blurb that various industries are required to publish.
My plea to our enforcement chums in Wilmslow today is quite simple. Let’s not forget we do need to go after the cowboys behind this type of spam, even though their brands won’t have the same high profile as those that are trying to me more transparent about their cookies. It’s these guys that are probably capable of causing far more harm to individuals than those who are setting inappropriate cookies on people’s electronic devices.
And my plea to our chums who are overly concerned about non compliance with the cookie requirements is to loosen up a bit, and remember that the ICO also calibrates its enforcement strategy on the likely harm that is being caused, or is capable of being caused, to victims, rather than just technical breaches of any of the rules that data controllers are required to follow.
.
Saturday, 23 June 2012
Best data protection quote of the week

There can only be one winner for my latest “best data protection quote of the week competition”.
It is awarded to Phil Jones, who is currently a special advisor in Promontory’s global privacy and data protection practice in London. Almost everyone who is anyone in British data protection will have benefited from Phil’s advice – for it is he who spent 20 years at the Information Commissioner’s Office, playing a key role in the authoritative practical implementation of British data protection law.
What he has to say matters. It mattered then and it still matters. So it’s especially important to listen when he speaks about the draft Regulation.
Phil was a panelist this week at a conference organised by PDP, held at the impressive offices of SNR Denton in Central London. He referred to accountability as a excellent data protection principle, but stressed that the European Commission, by proposing that all data controllers adopt overly bureaucratic structure to demonstrate just how accountable they were, were weakening the very principle the Commission was trying to promote.
The levels of detailed prescription in the draft Regulation, together with the reserved powers for the Commission to impose more detailed requirements on data controllers, comprised: “an awful attempt to impose harmony through prescription. It undermines and makes it very difficult to sell the reason for doing it.”
I absolutely agree.
I can understand the desire for policymakers to make policy. But they have to have more than half an eye on the practicalities of implementing the policy. In the regulatory culture I have been brought up in, new data protection policy is not something you can wave a magic stick act and assume that everyone will follow whatever whim passes through Parliament (or the Regulator’s offices). Politicians – and regulators - need to think how they can woo their audience of data controllers, not tie them up with obscure rules and red tape, especially if they intend to develop long lasting relationships with them, based on mutual respect and trust.
I fully understand that the regulatory culture may be different elsewhere within Europe. And that in some countries, people prefer to be told precisely what to do. But that doesn’t work in ‘Blighty. If British citizens react so vigorously against the concept of ID cards, I really don’t think that British enterprises will take that readily to an over complex system of requirements, controls and audit tools.
Let’s refocus the debate back to transparency – and to fairness. And let’s continue to ensure that whatever data controllers do, they would always feel comfortable explaining it to the mighty Jeremy Paxman on BBC’s Newsnight programme, if they were ever required to do so.
Image credit:
http://www.chappellofbondstreet.co.uk/sites/chappellv3.17/productimages/big/SHU-55SH2-MIC.jpg
.
Subscribe to:
Posts (Atom)

