Saturday, 14 May 2011

The emerging “science” of data protection


During a recent meeting of data protection aficionados, held under “Chatham House” rules, a phrase emerged and was increasingly repeated - and as it had an ology in it, I guess we’re increasingly embracing “data protection” as a science, rather than an art.

Wikipedia differentiates science and art as follows: Science is enterprise that builds and organizes knowledge in the form of testable explanations and predictions about the world. Art, on the other hand, is the product or process of deliberately arranging items (often with symbolic significance) in a way that influences and affects one or more of the senses, emotions and intellect.

In the early days of data protection, the main emphasis seemed to lie with the phrase no sneaky stuff. Transparency was the order of the say. Not necessarily choice, but transparency. Organisations had long privacy policies which explained what consequences would follow when someone shared their personal information with that organisation. So the "art" of data protection lay in getting individuals to feel better by being reassured about what was going to be happening to their personal information.

These days, the emphasis has shifted from transparency to choice and control. In other words, generally, these days, organisations behave ethically by more actively engaging with the individual in the hope that those individuals will want to share more information which is personal to them for something which will directly (and very quickly) benefit them.

What was this phrase that has caused me to cast off my artistic rags and espouse my scientific credentials (like the Doctor who first used it during the meeting)? It’s this one: the ecology of compliance.

What does it mean?

To my mind, what it means is that we are entering a world where individuals are increasingly aware of their rights, so organisations face a new set of challenges.

In the “old days” generally, most individuals didn’t really give a stuff about data protection, so the Data Protection Regulators felt that it was they who were charged with keeping organisations in line, in the general interests of society as a whole. This can be contrasted to today’s world, where individuals are increasingly aware of the advantages (and disadvantages) of having their personal details shared with other organisations, in a way that provides them with good stuff and bad stuff. In my mind, this emergence of knowledge is catching some Data Protection regulators unawares, as there is, in some EU Member States, a bit of a battle emerging. Some Regulators seem less willing to realise that individuals are now better able to make decisions for themselves. But if an individual is to be empowered to make the decision on their own, then there’s less need for the Regulator to make that decision on their behalf. And some Regulators don’t appear to like this challenge to their authority – and reason for existing.

And where does this leave the organisation?

Increasingly, it appears to leave them between a rock and a hard place.

Just as servants find it hard to serve two masters, organisations can find it hard to meet the expectations of both the regulators and their customers.

Instinctively, the organisation would really want to concentrate on the meeting (and exceeding) expectations of their customers. After all, if they don’t attract customers, they generally find it awfully hard to remain in business. So, when the regulator imposes rules which make it harder for the organisation to engage with their customers, sparks will fly. And that’s a direction I think we’re in danger of heading in.

Do I have any evidence of this difference of emphasis between customers and regulators? Well, let’s consider what’s going on in Germany and Switzerland at the moment. My German and Swiss friends like Google’s Street View Service. Well, they do when they come to visit me in London. They’ve already seen a picture of my home, so they know what to look out for, and what landmarks will appear as travel to my place, to pop over for tea. If only they could have something just like that where they live, they tell me. But they don’t appear to be allowed to.

Well, I reply. Don’t tell me – tell the folks back where you live – like Swiss and German regulators, whose job is sometimes made extremely difficult by national Parliaments who have created rules which don’t appear to meet the real needs of their citizens of today. Is pragmatism a dirty word? It’s not a dirty word in the UK, but then again not everyone shares such common-sense attitudes. There could be a few too many “jobs-worths” elsewhere.

Anyway, back to the plot. My main argument is that organisations are going to increasingly have to get their crystal balls out and predict the likely consequences of their actions with greater accuracy. Fines, civil penalties and public undertakings (which all run the risk of reputational damage) are becoming increasingly common. And budgets are tight, too. But they want to provide things for customers in such a way that they’ll make repeat purchases, so that the companies can provide their staff, when that day comes, with decent pensions.

So how do organisations assess the risk of regulatory action with the risk that their customers will have a less than optimal experience, because the customers are smothered with unecessary protective measures? And how do organisations assess the risk of regulators feeling required to create safeguards that lots of customers care about not one jot? (Or, even worse, resent?)

Déjà vu – it sounds like the health and safety debate all over again. So, in future, we’ll all probably spend more time wearing our risk assessment hats, and working out, scientifically, when the risks of providing services to knowledgeable customers are outweighed by the costs that can be imposed when organisations are caught breaking outdated rules.


Image credit:
Today's image is quite special. It's taken from a page of Charles Darwin's notebooks around July 1837, showing his first sketch of an evolutionary tree of life. The words I think, in his own handwriting, is some of the earliest evidence that he was developing his theory of evolution.

.

Friday, 13 May 2011

Oh! So that’s what a cookie is ....


Every once in a while, you attend an event and lay your hands on a presentation that really helps you understand what you thought you already knew. Yesterday was one of those occasions. Robert Bond, the maestro from Speechly Bircham who helped organise the International Chamber of Commerce’s session on the impending Cookie Regulations, had slipped a mighty fine presentation into the goodie pack that awaited the delegates. Not only did we get to hear from someone who was partly responsible for the legislation (as a Member of the European Parliament, and someone from the Department of Media Culture & Sport who had helped write the implementing legislation), we also got to hear from someone who was going to be enforcing the regulations and, just as importantly, from some of those who were trying as hard as they could to ensure that their businesses understood and could meet their new obligations.

Robert had evidently been awfully nice to his friends at Barclays, who had very generously provided him with material for a stunning presentation which, in less than 40 slides, cut to the core of the issue and set it out in terms that even a Board Member could understand. That’s no mean feat. No waffle, no embellishments, just a set of slides which explained in simple language just what all this stuff is really about.

Marvellous.

I just wish I had thought of presenting the issues in those terms. Well, I will, from now on!

I’m not going to steal Robert's thunder and reveal all the information on the slides here. That would be rude. If you want to know what I now know, you’re going to have to awfully nice to him, or alternatively, awfully nice to your friends at Barclays.

But to give you a taster of why its important you should try and get a presentation like this in front of your own Board, here’s the contents slide:
• What are cookies?
• What’s inside a cookie?
• Different types of cookies and their characteristics
• When are cookies sent?
• First and third party cookies
• What is the role of cookies?
• How many cookies can a website give?
• Dispelling some common myths about cookies
• Online behavioural targeting and advertising

It’s just what you need your business leaders to know.

And, let’s be honest, it’s just what we all need to know, too. Sometimes we can be afraid to admit to the extent of our own ignorance in these areas – but after reading this presentation, you’re not going to be ignorant any longer.

Here endeth the advert.

Many thanks to Stephen Pattison (Director of the UK arm of the International Chamber of Commerce) and also to Ian Twinn (from ISBA, the voice of British advertisers) for their interventions. They both helped ensure that it was an extremely successful event. They also helped uncork a bottle or two once the formal session had ended.

I’ll be keeping my eye open for other ICC events – when they attract delegates of the calibre that turned up yesterday, you know you’re in good company.


.

Wednesday, 11 May 2011

New cookie guidance: don’t panic! (My cunning compliance plan unveiled)


It’s official. New rules will take effect in less than two weeks. It’s not often that the “business friendly” Coalition Government finds itself in the position of imposing huge changes on extremely significant parts of the economy with virtually no notice whatsoever. In my experience, it’s only the Inland Revenue that can get away with such major changes in such a short timescale.

So let’s get real here. It’s not going to happen.

And, in the UK, we are the “lucky ones”. There are rumours of possible changes in a couple of the other Member States, but most of the European Governments are as concerned at hitting the EU Commission’s deadline of 25 May as they are about winning the Eurovision song contest.

I think I detect a theme here. As Corporal Jones from Dad’s Army used to urge: Don’t panic.

Take a look at the relaxed grins on the faces of those awfully clever people at Department of Culture, Media and Sport, who have miraculously transposed the Directive into UK law just in time. (Well, it will be law once it’s clear that Parliament isn’t going to perform a U-turn and withdraw it). And then take a look at the twinkle in the eyes of those awfully industrious people at the Information Commissioner’s Office, who have laboured night and day to publish stuff on the internet which indicates what they really think of the rules. And then ask yourself "wow, if they’re not worried, then what have I got to be worried about?"

If we’re not careful we’ll all turn into a group of fundamentalists who believe that the demands of the Directive are written in tablets of stone, from which no deviation is possibly permitted.

In a free society, we don’t work like that anymore. Just as citizens can rebel against their Governments, web masters will point out that some of the words in the Directive just don’t make any sense, so they’re not going to meekly comply until their human rights have been respected, too.

Am I calling for an all-out strike here? Or a work to rule? Of course not.

I’m not calling for a sprint to the compliance podium, with the requirement that everyone complies before 25 May. Instead, I’m calling for a reasoned debate on how webmasters can meet the legitimate aspirations of the customers who access their on-line portals, to give them transparency, choice and control over the stuff that really matters. And, I’m calling for those who will be enforcing the Directive to cut some slack with the webmasters, and allow them to be creative and push the barriers out when it comes to deciding how to tailor the user’s visit to the website, to give them a great experience. Which means not overwhelming the poor user with a snowstorm of cookie warnings and other tick boxes that can so easily ruin what should be a wonderful on-line experience.

I’m probably preaching to the converted – so here’s my cunning compliance plan:

AIM – keep customers happy and keep the European Commission off our backs.

PLAN –
1. Demonstrate to the regulator that despite being given virtually no notice whatsoever, we care about compliance. Do this by asking contacts within the business to identify who actually operates the business websites, and whether they know how these websites are constructed.
2. A few months later, suggest to the IT / Sales Department that there really ought to be someone in charge of these websites, and that it would be helpful to know their name so that we can get them to find out what they are really in charge of.
3. Require the person in charge of the websites to carry out an audit of the different types of cookies that are currently on them.
4. Read the guidance that ought to have been prepared by then which categorises these cookies into various types. They are likely to include categories where the webmaster has a legitimate interest in using cookies (as they help provide a great user experience), and categories of cookies which basically track the user when they’re doing other stuff on the internet (which is information that the business or a 3rd party finds useful and can derive some commercial value from, so the user does not have to be charged a fee to access the main website).
5. Check the ICO’s website to see how the guidance on cookies has been revised. We’re only on version 1 now. We’ll probably see a few more versions slip out as the months roll on.
6. Thank your fellow industry colleagues for having the courage to interpret the term “strictly necessary” in a way that makes common business sense, given the prevailing technologies. Support them if (ok, when) they run into any significant resistance from some European regulators, whose understanding of that term causes problems.
7. Follow the market leaders (Google, Amazon, Tesco, EverythingEverywhere etc).
8. And, until you get past point 3, keep reminding the regulators that we do care about compliance, but we also need to take a little time in making sure we’re all creating the best possible experience for our customers.

Finally, don’t be downhearted. Sing along to the words of the Cookie Compliance Song. Keep a smile on your face and let’s hope that Paul Simon or Art Garfunkel won’t get too upset at the liberties we’re taking with their wonderful 59th Street Bridge Song.

Back to the 1960’s, kick off those sandals, and stick flowers in your hair.

Now take a deep breath and sing (and also clap your hands):

Slow down, you movin' too fast
You gotta make this moment last
Just kickin' down the cobblestones
Lookin' for fun and
Feelin' groovy____________

Hello website
Whatcha knowin?
I've come to count these cookies growin'
Ain'tcha got no consent from me?
Wow man, that’s because they’re strictly necessary,
Doo Bee Doo Doo,
Feelin' groovy____________

Got no deeds to do
No promises to keep
I'm dappled and drowsy and ready to sleep
Let the EU drop all its directives on me...
Just wait for guidance, we’re not up a gum tree.
Life, I love you,
All is groovy____________________



Sources:

http://www.legislation.gov.uk/uksi/2011/1208/made (The Privacy and Electronic Communications (EC Directive) (Amendment) Regulations 2011)
http://www.ico.gov.uk/for_organisations/privacy_and_electronic_communications/~/media/documents/library/Privacy_and_electronic/Practical_application/advice_on_the_new_cookies_regulations.ashx

.

Tuesday, 10 May 2011

ACS Law: Another disgrace


In a move that will shock many observers, the Information Commissioner has announced the level of the civil monetary penalty that will be imposed on one of the most awful solicitors of this century. Christopher Graham announced the award – and a bit of the thinking behind it – at a packed reception today in the Strangers Dining Room at the Palace of Westminster, where some of the great and the good of the Data Protection (and Parliamentary) community had assembled to celebrate the launch of the Data Sharing Code of Practice.

In an extremely astute move, Christopher Graham commanded that cake and sandwiches should not be served to us until he had finished speaking. Just as well. If our mouths had been full of any of those comestibles as he gave his explanation, I’m sure that most of us would have coughed the food onto the carpet in disbelief at what we were hearing.

Let’s be clear. Andrew Crossley, the sole practitioner of ACS Law, was involved in a business which people who are far cleverer than I have suggested was morally outrageous. If he has done even half of what he is alleged to have done, then that in itself would cause me to cross the road if I were ever to notice him coming towards me.

However, turning to the matters that were of concern to the Information Commissioner, according to the ICO's findings, he routinely handled large amounts of personal data, in an internet environment, and had used a legal assistant with no IT qualifications to research and recommend a new web-hosting company and package to him. The “home” web-hosting package cost £5.99 a month. It was never intended for significant business use, nor did it appear to provide any guarantees to the data controller in relation to the security of the personal data. So, he knew or ought to have known that failing to take professional IT advice about an appropriate web-hosting company and the implementation and development of his associated IT systems might lead to deficiencies in the data controller’s IT systems.

As a result, a large amount of personal data and sensitive personal data leaked on-line relating to around 6,000 individuals. The ICO’s findings do not specify what this data is, but friends of mine who know about these things are truly shocked at what was leaked. This information has been distributed worldwide and could be available to third parties indefinitely. The contravention was of a kind likely to cause substantial damage and distress to the data subjects.

And the fine – well, we know that civil monetary penalties are not designed to impose financial hardship on a data controller. The Statutory Code makes that pretty clear.

So, if Andrew Crossley pays in full by 6th June, the fine will be £800.

I claim more than that in expenses, some months.

As I heard the reasoning behind the decision to set the figure that low (he’s a small businessman who is fully co-operating with the ICO, and hasn’t got any money left anyway – it’s all been spent, blah blah blah) my mind turned to the work of Thomas Luis de Victoria (1548 - 1611), whose 400th anniversary we celebrate this year. He was the Andrew Lloyd Webber of his time – and one phrase from his Lamentations (composed for the Holy Saturday of the Easter festival) is particularly apt: Recordare Domine quid acciderit nobis: intuere, et respice opprobrium nostrum. For those scholars amongst us whose natural classical language is not Latin, the English translation is Remember, O Lord, what has befallen us: look and see our disgrace.

Some disgrace.

If the best the ICO is capable of doing (under the circumstances) is issuing a fine of £800 to someone as notorious as Andrew Crossley, the “custodial sentence” brigade are going to be rising forth, demanding penalties that fit the crime a little more closely than those Parliament have currently empowered the Commissioner with.

I wanted to suggest to David Davies MP, who was also at today’s Parliamentary reception, that perhaps Parliament should bring in a new punishment, to allow the Commissioner to have miscreants paraded through the streets of Wilmslow before being beaten on the bottom with a copy of the Woman’s Weekly.

If it’s a punishment that is sufficiently invigourating for Victoria Wood, then it ought to be good enough for the likes of Andrew Crossley.

Sources:
http://www.ico.gov.uk/~/media/documents/pressreleases/2011/monetary_penalty_acslaw_news_release_20110510.ashx
http://www.ico.gov.uk/~/media/documents/library/Data_Protection/Notices/acs_law_monetary_penalty_notice.pdf


.

Monday, 9 May 2011

Twitter - trumping the right to be let alone


I’ve just read some stuff on Twitter which reports on behaviour that is so naughty that (apparently) some English Judges have issued super-injunctions, forbidding me to let you know all about it.

So I won’t.

But I expect you know all about it anyway. You, and several million others.

It took me, thanks to Google’s brilliant search engine, less than 3 seconds to get to what others have probably paid lawyers thousands of pounds to try and suppress. And I didn't even have to go to Twitter to read it. It's been re-tweeted and had appeared on an extremely reputable website. Of course, what I might have read could have been a load of codswallop. It could all have been complete lies. But, somehow, I don’t think so. If the former model Katie Price had been mentioned, then I would have suspected that it was a load of made up tosh. But her name didn’t feature anywhere. Thank goodness for that.

Instead, I read about a smattering of television personalities, most of whom I would have failed to recognise even if they were in front of me, operating a check-out till at my local Waitrose, sportsmen (the same) and an actor (oh no, I think I would recognise that actor). They are probably all wishing that the European Commission would hurry up revising the Data Protection Directive, and give them stronger rights to be let alone.

One of the proposals contained in the European Commission’s recent plan to amend the data protection directive came from the premise that individuals should always be able to access, rectify, delete or block their data, unless there are legitimate reasons, provided by law, for preventing this.

Cummon, lets get real here. People who profit from their celebrity are going to have to work pretty hard to control all aspects of their personal behaviour in today’s online and interconnected world. And none of us are really going to want to forgo our delicious pleasure at reading about the fascinating antics of people whose lifestyles we can only dream of.

Still, lets see what’s going to happen.

If the serivce had been offered by Google, rather than Twitter, I would have expected a chorus of (varying degrees of) disapproval to have instantly erupted from the Data Protection regulators in many EU Member States. Some regulators might already probably have announced that they were contemplating significant fines, or custodial sentences, against the "Twitterati", while others might just just be thinking of asking Twitter executives to pop by for afternoon tea and a polite chat.

But Twitter? How does an domestic Data Protection regulator deal with an organisation that, being based in San Francisco, California, probably has no formal establishment in that Member State in the first place? Does it even recognise that the “foreign” celebrities face their reputations being challenged in the minds of the local citizens who can read and freely discuss what cannot be mentioned in polite society within the jurisdiction of the English courts?

Let’s see how the regulators (and the courts) play this. The challenge is on. How many people need to know about the stuff that “dare not speak its name” before they realise that the internet has won? And will this teach a lesson to those who wish to interfere with the rights of those who decide to ignore an individual who tries to block access to their data, on the grounds that the “illegitimate” act they apparently committed has affected their commercial value?

If we cherish internet freedoms sufficiently to enable citizens in various countries to spontaneously erupt against their own Governments, how can we expect the odd individual to acquire (even in a democratic society) the right to require the state to censor reports about their own less illustrious behaviours?

For just how long should you be entitled to exist, you inconvenient truth?


Source:
Oh no, you're on your own, this time!

.

Sunday, 8 May 2011

New privacy regulations – enter the moral maze


Three cheers for us Brits! Good Europeans as we are, we will hit the EU’s deadline of 25 May to bring some European legislation into force to provide an even better level protection to users of communications services. I’m not too sure how many other EU member states will also hit the deadline, but I doubt that many people will care too greatly if they don’t.

Laid before Parliament last Thursday, we can now put some hot towels around our heads to work out just what this stuff actually means. Please don’t think that all you need to do is to read it to be fully appraised of the true meaning of these words. Oh no. As the Statutory Instrument seeks to amend existing regulations, you really need to have a copy of the existing regulations on one side of your desk, and these regulations on the other, and then when you read them both together some interesting things emerge.

Last time the relevant regulations were changed, the old ones were completely replaced by a new text – so there was only one document to refer to. This way of revising the regulations means a bit more work – both for me, to understand what the new ractually mean, and for people who want to work out whether any of their rights have been infringed when a Communications Service Provider, or anyone else mentioned in the, for that matter, acts in a way that may be contrary to what is to be prohibited.

What did I think was going to happen? I had expected the Coalition Government to “copy and paste” the terms that appeared in earlier Directive, as I was not expecting any “gold plating” to emerge. So I was expecting something about communications service providers being required to notify data breaches to the regulators. I wasn’t expecting the SI to require “all” breaches. I had thought that there might have been some threshold below which those chaps in Wilmslow were not to be bothered about. Well, no threshold appears in the SI – just a statement in the explanatory notes to the effect that Regulation 5 inserts a new provision into the 2003 Regulations which relates to the notification of personal data breaches. In all cases, the Information Commissioner must be notified. In some cases, the subscriber or user must also be notified where there is a risk that the breach would adversely affect the personal data or privacy of that user.”

All cases? Well, to encourage all cases to be notified, the Regulations allow the Information Commissioner to impose a fixed monetary penalty of £1,000 (reduced to £800 if the miscreant pays the fine within 21 days) for cases where an “undue delay” in notifying the Commissioner had occurred. I didn’t see that in the original Directive.

Will this lead to communication service providers adopting the same behaviours as health trusts, where even the most minor of breaches are reported? And will it lead to the Commissioner issuing press releases about these minor breaches and then requiring the heads of these organisations to sign public undertakings to get things corrected? Well, yes it might. At least with NHS trusts, there are rather a lot of them, so I doubt that the heads of these organisations will feel the wrath of the ICO’s Head of Enforcement too often. There are many fewer Communication Service Providers, however. So they could, if the Chief Executive Officers are not careful, be signing more than one public undertaking each. Wo betide the person who has to brief the CEO every time a snafoo emerges that requires a breach notification. Sally Anne Poole, the ICO’s acting Head of Enforcement, could well be spending more time than she actually wanted dealing with the perceived failings of the CSPs – despite the fact that they are all relatively well resourced organizations with professional compliance teams who try as hard as they can to get things right.

I do hope that the ICO takes such factors into account when receiving yet another report of a minor breach. Companies with large customer databases are likely to incur a few breaches - but at least they're unlikely to relate to information as sensitive as the health records that can get lost by less well resourced organisations within the NHS.

While the CSPs may not be required to tell customers of trivial breaches, of course individuals will always be able to write to the ICO to make a Freedom of Information request about the volumes of breaches that have been reported to them by particular CSPs. And the ICO will not have to warn the CSP of such an enquiry - so the first time the CSP may know about it is when the media report emerges about the volumes of notices that each CSP had generated.

This “backdoor publicity” about data breach volumes could cause some CSPs to query the necessity of advising the ICO of all breaches. Will the risk of incurring a potential fine of £1,000 (if the breach subsequently becomes public) be worth running if the business fears that the reputational cost of publicising the most minor of breaches are far greater than £1,000? This is surely the sort of issue that listeners of BBC Radio 4’s excellent programme The Moral Maze would want to explore.

What side would I be on? Well, you’ll just have to wait until I’m asked to be a Moral Maze panelist (or witness) – and then you’ll find out!

There’s lots more to mull over in these new Regulations, but they can wait for another blog posting.


Source:
http://www.legislation.gov.uk/uksi/2011/1208/made (The Privacy and Electronic Communications (EC Directive) (Amendment) Regulations 2011)

.

Sunday, 24 April 2011

Resetting my mojo


I can cruise on auto pilot for only so long. Then I need to check my bearings, to confirm that I’m still heading in the right direction. Are my prejudices the same as everyone else’s prejudices? If they are, then that’s probably ok. When they diverge, I need to sit down and work out whether it’s me, or whether it’s them, in terms of whose policy compass needs adjusting.

In data protection terms, I’ve taken a few months off blogging about various events, as I needed to rediscover my own bearings. This has not been a particularly easy process, as I have tried to strip my policy principles back to the basics. I’ve been asking myself some profound questions, like
• What is it that I want to do
• How should I engage with other people to find out whether their aims are similar
• How do I maintain the confidence and trust of these people when it’s apparent that our aims appear to conflict with those held by other opinion formers.

As I’ve been thinking about these things, I’ve sensed that some of the tensions that have been simmering between various data protection practitioners may be about to emerge into the public arena. Proposals for a revised Data Protection Directive will draw all manner of people to the negotiating tables. I don’t think that there’s much wrong with this, although I sense that a few egos will be splashed on the carpet as the familiar arguments are rehearsed. I’m not expecting blood to be spilt. Data Protection isn’t a physical pursuit, in that sense. But I do expect some of the more self righteous of our community to want the world to know just how very very annoyed they are, before they realise that the shining light they are holding is actually attracting very few followers.

In my day job I juggle with a variety of issues. On the one hand, I exist (professionally) to advocate high data protection standards. At the same time, I also campaign for efficient data protection regulation. And finally, I do my best to flex inappropriate data protection laws. I try to weave a common-sense approach to issues where I find that I’m being asked to accommodate the views of the Data Protection Fundamentalists, that group of people for whom no deviation from any EU or UK regulation is ever to be contemplated, period, and the Data Protection Hippies, that group of people who have forgotten the need to respect a concept which has evolved into a more recognisable fundamental human right. It’s the hippies who forget that individuals have a right to be consulted about that which belongs to them. What’s best for the data controller may not always be what’s best for the individual.

The more I think about these competing tensions, the more I realise that its often not appropriate just to plot a path which is mid way between the aspirations of the fundamentalists and the hippies. Why should I always strive for a path that will inflame both sides in equal measures? What is it that I really feel in these circumstances – and does it then really matter whether what I feel is either closer to the heartbeat of the fundamentalist, or closer to the heartbeat of the hippie?

After some 20 years in this data protection game, I’m resetting my mojo. I intend to spend the next phase of my data protection career campaigning for what I feel is best for society as I experience it, rather than feeling that it’s my duty to parrot some line or other, just because it’s the “official” line. I have experienced the nauseating feeling of trying to implement policy, just because some bunch of politicians or bureaucrats felt it politically convenient at a particular time to insert text into an EU Directive that actually no-one really understood then or even understands now. I've had my fill of that. Now, I’m moving into a phase of my professional life where I will empower myself to treat EU Data Protection Directives as instruments which set out the general direction of travel, rather than a detailed route map from which any deviation is forbidden.

And in deviating from the official route map, I fully expect to have some fellow travellers accompany me – at least along part of my journey. Some of them may even be the politicians, bureaucrats or regulators who once thought it was a good idea to insert what will become a stupid or incomprehensible rule. I won’t hold that against them. I’ll just be grateful that they too appreciate that my way is also a way that meets the needs of my fellow citizens.

I’ll continue to be discrete about the identities of all of my fellow travellers. But I do hope they also enjoy the alternative route I’ll occasionally be travelling along as much as me.

.