Saturday, 10 March 2012

We need to talk about Europe ...

I’m commenting on two stories today, both of which question the legitimacy of the European Commission to adopt legislative measures that seem to go well above the heads of national Parliaments.

Before I’m written off as a maverick, let me assure you that I am not a natural Euro-sceptic. I believe in European integration – to some level, but I also believe in the principle of Subsidiarity, too. This is an organizing principle that matters ought to be handled by the smallest, lowest or least centralized competent authority, according to the definition in Wikipedia.

Of course, it’s always easy to find stories criticising the European Commission. When there are positive stories, I will comment on those, too. My aim here is not simply to knock the institution. But it is to question it, and to challenge it in the spirit of the Latin proverb Qui bene amat bene castigat (Who loves well castigates well).

So, for the first story, please step forward Belgium's enterprise minister Paul Magnette. He spoke recently at a conference, auspiciously titled Can one criticize Europe?, organized by the Université libre de Bruxelles. He was bold enough to criticise the European Commission for being "too tough" on his country and pleaded for more "margin of manoeuvre" for national governments to enforce EU budget discipline rules.

The EU's budget discipline dogma had become "monomaniac," he had said, commenting that the only possible result of such policies was recession. In his view, the Commission’s role in approving the Belgian budget was close to micro-management. When it rejected the 2.8% deficit forecast of the Belgian government in favour of its own 3.01% projection, the Commission had put the country in the excessive deficit procedure [EDP], which was nothing less than “nitpicking,. And, as the Commission has more powers vis-à-vis a country under EDP, the feeling was that the Commission "abuses" it’s right of control to leverage its power over member countries.

This is not the first time that Magnette, has courted controversy. He’s also on record for making comments critical to the EU executive, for which he was reprimanded both by Prime Minister Elio Di Rupo and Council President Herman Van Rompuy, a former Belgian Prime Minister.

Reportedly, Magnette had said that the economic and budgetary policy, imposed on EU countries, condemned them "to a 15-year-long recession". He added that he doubted that the Commission had the democratic legitimacy to impose such policy: "We must stand up to the European Commission, as the big states do, or we will slip into an ultra-liberal Europe."

And, for the second story, I’m really grateful to a chum who is following data protection developments within the European Commission even closer than me, and has observed that the fun and games continue apace as everyone in the European Parliament is scrambling to get in on the act on that Regulation. Which MEPs will be appointed to key roles as the measure is considered by the Parliament? Apparently, the power struggle going on is particularly fierce between the European People’s Party and the Greens.

One of the reasons for this, I sense, is that a debate is growing about whose fundamental rights the European Commission and the European Parliament exist to uphold. In the data protection context, are these just the fundamental rights of individuals, or are they also the fundamental rights of companies and public authorities who need to process information about citizens to run public other types of services?

One of the brightest of London’s lawyers pointed out to me recently that: “while fundamental rights are at stake, these are not absolute. The Regulation itself recognises this (see recital 139). As we all know, the purpose of the legislation also is about ensuring the functioning of the internal market - indeed, the very first line of the Regulation acknowledges both the fundamental rights (Art.16 TFEU) AND the internal market dimensions (Art.114(1)/26). In line with the “property” point, recital 139 recognises that the right to the protection of personal data must be balanced against other rights, including the “freedom to conduct a business” (of which the European Court of Justice said some interesting things about in the recent SABAM ruling). Unfortunately, so far the right to property (including the right to intellectual property) has been left out…”

So, where does this leave us? In a bit of a predicament, I think. On the one hand, we have a European Commission that is determined to press on with legislation because it does not trust Member States to legislate adequately. On the other, we have(a number of) National Parliaments who may not be that bothered about giving up sovereignty in this area because they are passionate believers of a European project which requires a strong central European Government and weak national Parliaments. And on yet another hand, we have (a probably smaller number of) National Parliaments who genuinely question the extent of European integration, because they do not believe that the costs of surrendering the margin of legislative appreciation they currently enjoy will be outweighed by the benefits of further and deeper integration.

Perhaps that’s why the struggle to carve up data protection between the European People’s Party and the Greens is so important. Both groups sense that the proposal marks a huge step change in creating a new social policy within Europe, and they are both determined to control the shape of that policy. It’s a great opportunity to wrest a chunk of powers away from national Parliaments and have them salted away in the European institutions.

And where is the political influence that we, in ‘Blighty, can have on this process? I don’t see many British MEPs either sitting with the European People’s Party or the Greens. Can we just sit on the sidelines and hope that these groups of politicians will do a deal that won’t leave us too much in the cold?

Or should we adopt another approach, which is to question the legitimacy of data protection matters being removed from the competence of the Westminster Parliament in the first place?


Sources:
http://www.euractiv.com/euro-finance/belgian-minister-vows-resist-ultra-liberal-commission-news-511398?utm_source=EurActiv%20Newsletter&utm_campaign=fe1a36b3ca-newsletter_daily_update&utm_medium=email

Recital 139 of that Regulation: In view of the fact that, as underlined by the Court of Justice of the European Union, the right to the protection of personal data is not an absolute right, but must be considered in relation to its function in society and be balanced with other fundamental rights, in accordance with the principle of proportionality, this Regulation respects all fundamental rights and observes the principles recognised in the Charter of Fundamental Rights of the European Union as enshrined in the Treaties, notably the right to respect for private and family life, home and communications, the right to the protection of personal data, the freedom of thought, conscience and religion, the freedom of expression and information, the freedom to conduct a business, the right to an effective remedy and to a fair trial as well as cultural, religious and linguistic diversity.

Image credit:
This is the poster for the 2011 film “We need to talk about Kevin”. The plot focuses on Kevin's mother, who struggles to love her strange child, despite the increasingly vicious things he says and does as he grows up. But Kevin is just getting started, and his final act will be beyond anything anyone imagined.
http://www.impawards.com/2011/we_need_to_talk_about_kevin_ver5.html

.

Friday, 9 March 2012

Exclusive: An easy way to comply with the cookie regulations

I can finally reveal an easy way to comply with the cookie regulations. Even the Article 29 Working Party is going to be impressed. It could make it's creator – me – a multi millionaire if a significant number of people take it up, and they then start following other pieces of wisdom that occasionally get trotted out in this popular blog.

None of us really want our stats about visitors to our web sites to fall off a cliff – as is evidenced by what happened when the Information Commissioner’s Office unveiled its cunning plan to simultaneously comply with the ePrivacy Directive and remain forever ignorant about what its website visitors actually do when they go to www.ico.gov.uk. The result - pictured - is too horrific even to smile about.

There has to be a better way of web masters behaving like lemmings. So, rather than force customers to make a choice (which they most likely won’t do as they simply don’t understand the implications of the words that are put in front of them) before they’ve had an opportunity to know whether the web site is any good or not and whether they’ll ever want to come back, I’ve had a better idea.

I appreciate that this idea will have financial implications for the huge industry of cookie advisers that has developed over the past few years. Some of the fees I’ve heard being charged for people to receive advice from data protection professionals are so good that I want to get in on the act, too. My advice might not be delivered in as deadpan a manner as some of my learned friends, but at least it will put a smile on people’s faces.

After much research, I’ve concluded that the real problem surrounding cookies is that, for the most part, internet users can’t be bothered to do anything about them. The philosophers may ask if this is because people really don’t care about cookies, or whether people don’t know what harm may be caused to them by someone who places abusive cookies on their devices.

The answer is simple. It lies in a public awareness campaign, and in getting the general public to start asking the questions for themselves, rather than having advice screamed at them from above. It worked with public awareness about the menace of HIV and AIDS. As soon as an Eastenders character found they were living with it, public attitudes changed very quickly – and very much for the better.

And the answer also lies in making such education fun – and healthy.

So my cunning plan – wait for it – is to seek funding from the European Commission to sponsor an internationally televised competition. Students, youth groups, in fact any teams of friends or work colleagues, are to compete in a song and dance contest. Teams wishing to audition should get their first efforts loaded onto YouTube by 26 May 2012, as it is from this date that the Information Commissioner has announced that he could start to do something more about cookie compliance in 'Blighty.

One catch – I get to specify the song.

And my selection, thanks to the inspiration from Little Nell, Richard O'Brien,and Patricia Quinn, is about worshiping active recorded preferences about cookies.

This may not sound that catchy a title, until you shorten it to the Cookie Warp.

Here are the words. You all know the tune, now come up with the dance!

THE COOKIE WARP

It's astounding, time is fleeting
Madness takes its toll
But listen closely, May’s not that much longer
You've got to take more control

I remember doing the Cookie Warp
Hitting those internet links when
Adds would strike me, as if someone had remembered
Let's do the Cookie Warp again...
Let's do the Cookie Warp again!

Just set your cursor to the left
And then you set it to the right
With your hands on your mouse
You bring your digits in tight
But it's not getting good content that really drives you insane,
Let's do the Cookie Warp again!

The Commission’s so dreamy, so fantasy free me
Now you can't see me, no not at all
I’m in another dimension, with voyeuristic intention
I’ve paid my entrance fee, now I want to experience it all

I’ve seen some sites that are unsavoury
But you must forget my knavery
I’ve got rights (and stuff that I don’t want you to know)
You're keeping too much browsing history (that should really stay a mystery)
Let's do the Cookie Warp again!

Well I was surfing down a site just a-having a think
When this snake of an add man gave me an evil wink
He really shook me up, he took me by surprise
He had my browsing life at hand, I saw the devil in his eyes.
He stared at me and I felt I must change
I’ll put an end to this: my preferences I’ll rearrange
Let's do the Cookie Warp again!


Note:
Spookily, the Rocky Horror Show was being developed, back in 1973, at around the same time that data protection was starting to be taken seriously in Parliaments around Europe.


Further note:
If our chums from DG Justice at the European Commission, or from the Information Commissioner's Office, post their entry onto YouTube by 26 May 2012, then I'll happily donate £100 to the Help for Heroes charity, in their honour.

.

Thursday, 8 March 2012

ISEB Accreditation: Chapter 2

The third formal day of the course of instruction that ought to lead to my ISEB qualification (out of five) has been completed in Manchester. Two more days to go. Not much more black letter law to become reacquainted with. Sue Cullen really knows her stuff. The course gets lighter in tone from now on, as the participants learn more about how the law is actually applied in practice, rather than just what the law is.

I use data protection law as I would a musical instrument. I add a bit of common sense to generate a satisfactory response, rather than simply use it as a noise box to overwhelm everything else in earshot.

A Home Office official, some 20 years ago, really wasn’t lying when he observed that Data Protection legislation was specifically designed to be a cumbersome process. It will be interesting to see whether people are any more able to exercise their rights when the revised proposals see the light of day.

Someone suggested a few days ago that the new proposal (in whatever form it’s going to end up as) could quite radically change the current equilibrium between the legitimate interests of data controllers and the legitimate interests of individuals. This is because the current Directive focuses on protecting certain types of information about individuals, while the new thing is going to focus on protecting individuals. It needs to refocus if it is to be true to its “fundamental rights” agenda, because fundamental rights attach to individuals, not their information.

Is this an important distinction? For some people in the European Commission, I think it must be – which is why they must keep on harking on about the need to protect individuals at all costs. They seem to be less concerned at making sure that public institutions (and private companies) are able to flourish and innovate. Rather than roll out the red carpet when a data controller fancies doing a spot of innovating, some would prefer to smother these new initiatives in red tape.

Such an approach to prescribing the role of public authorities, when they, as data controllers, want to do a spot of innovating, might be fine in Member States whose citizens live under formal constitutions. In such states, the powers of these public authorities are formally laid down, so the limits of their authority are clear. But the situation in countries like the UK is different. We don’t live with the benefit of a formal constitution. (Not unless the European Commission has slipped one through and no-one has noticed, that is). In the UK, many powers of local authorities appear to derive from an exercise of the Royal Prerogative, rather than constitutional law. And British Governments have not, in recent generations, had an unhappy history like some former Governments of other European states, where citizens have found that their rights have been abused by the State.

But, in strictly prescribing the powers of the state institutions (in case they can’t be trusted, again), the Commission seems to wish at the same time to prescribe the powers of data controllers in just as strict a manner. But, tell me, which European data controllers have had a history of abusing the rights of individuals? And before anyone spits out the G word, or the F word, let me remind them that these examples aspire to be global data controllers not just European data controllers.

No, a cynic might suggest that the Commission is really trying to get tough with global controllers it knows it can’t tame, anyway.

Note to the Commission: Forget about Google and Facebook for a bit. They are big enough and well resourced enough to look after themselves and their customers. Focus on European data controllers for once. And try not to make life so tough for them that they cease really caring about developing new innovative privacy enhancing services and techniques. If life is made too challenging, they’ll just start to employ people to tick privacy boxes. Which won’t be much fun for those of us who want to work on the new and innovative services.

.

Tuesday, 6 March 2012

I’m a DPO, get me in here!


The 500 lucky winners of this year’s “Get a place at the ICO’s Annual Data Protection Officer Conference” competition assembled today at the Palace Hotel in Manchester to celebrate their good fortune. And also to attend the ICO’s conference. Who needs to travel be among a cast of thousands at an international privacy event in Washington DC this week when the ICO can lay on such a magnificent event – free of charge – for those of us who need some support and assistance in ‘Blighty?

How best to describe the Palace Hotel, Manchester? Think of a Victorian version of Hogwarts, with steps (I didn't manage to find the lifts) leading to lots of floors and hidden spaces, many of which were tastefully decorated in brown and green porcelain tiles. You’ve just about got it. Spookily, “Oliver Twist” was playing at the Palace Theatre just across the road. Fagin would have felt at home in either venue, today.

But, what a great place it was to assemble some 500 souls who were most concerned about British data protection issues. And how amazing to think that there was a waiting list of a further 500 applicants who didn’t make the final cut. It really is reassuring to appreciate that there are so many people who want to apply the rules with such dedication. They wouldn’t have been there, or wouldn’t have applied, if they weren’t.

And, also, how great it was to see at the event so many bods from the Commissioner’s Office in Wilmslow, just up the road. Occasions like this really help reinforce a spirit of shared values and determination. The ICO has worked really hard to maintain a good working relationship with concerned individuals and data controllers, and it is nice to take opportunities like today to acknowledge that most people’s minds are in the right place, even though no-one can be perfect all of the time. But so many of us care, and that’s what matters.

It was so refreshing also to hear the message, from delegates and from many of the ICO officials who spoke during the workshops, that what we really need to focus on is outcomes, rather than procedures. The theme was first evoked by the keynote speaker, Francis Maude, Minister for the Cabinet Office. He characterised the current internet revolution as “an irresistible and unstoppable force.” And, in what he termed as “an immensely constrained fiscal environment,” he appeared determined not to allow data controllers (and especially those who wanted to share data for legitimate business and public purposes, to be hampered by outdated practices: “An overly restrictive environment will restrict our ability to innovate.”

While he also pointed out that the law should not be obscure, nor unclear, I sensed that he was not mightily impressed with all of the plans that the European Commission had recently announced in their plans for a General Data Protection Regulation. The draft text of his speech is available here.

If I were a betting data protector, I would bet that we Brits are really ready for a fight on some of the more prescriptive provisions in “that” Regulation. And I would also bet that a number of British Parliamentarians are going to be mightily unhappy when it dawns on them that, in a an age where reputations (and newspapers) have been lost through poor privacy practices in Britain, it is madness that the British Parliament is to be neutered when responsibility for so many things data protection are transferred from Westminster to the institutions in Brussels. This cannot be right.

I also overheard, in the margins of the meeting, gossip that one of the first Council meetings to review the proposal didn’t go as well as the Danish hosts might have expected. Despite carefully laid plans to ensure that the attendees got through a certain proportion of the text, delegates insisted on speaking their minds, rather than keeping to the timetable. So, progress was not as made as quickly as planned. If they don’t start curtailing official debates soon, all bets will be off that the gestation period will be merely 18 months.

But, delegates at today’s conference were very careful not to make any political points, nor was there any public criticism (from ICO officials, anyway) about the current legislative environment. This was not the day to discuss such sensitive matters. Instead, today was the day to discuss ever more innovative ways of getting it right.

In terms of delegate numbers, the runaway success of this conference series is truly astonishing. Perhaps it’s because it’s free, so public sector DPOs have no reason to be denied attending on internal budgetary grounds. It’s getting so large that the ICO should consider using the main conference hall in Manchester’s GMEX centre, soon. And that is a wonderful way to celebrate that we Brits are serious about getting this data protection stuff right, even though our ways of doing things aren’t always the ways that our colleagues in the Commission would prefer.

We Brits don’t need to rely on complicated forms prescribed by clever Eurodataprotectorcrats to try and get it right. We pride ourselves in preferring to rely on our own ingenuity and pragmatism to deliver culturally acceptable, good privacy practices.

Anyway, let me end by sending my best wishes to those folks currently en route to Washington DC for the International Association of Privacy Professionals’ bash. I do hope that your event is as entertaining – and as productive – as this one has been.

.

Saturday, 3 March 2012

A battle hymn for the chocolate factory

If you can access electronic media, you must have been reading about Google this week. After all, who now can’t be aware that changes have been made to the words of the privacy policies that are associated with Google’s services? I’m not sure if, since people have not actually changed their privacy settings, it means that Google will actually be doing lots of stuff that they weren’t in the past. The vast majority of us probably don’t have much time to care, and are grateful that the Article 29 Working Party will be doing the caring for them.

I have not had the time or the energy to find out for myself precisely what’s gone on and, frankly, given the fuss that has been generated by this issue, I’m happy to wait until the courts tell me what it all means.

What a difference a few years make! It was only 27 months ago that Google was being praised to the skies by regulators for their foresight in creating a Dashboard control panel, which enables people to more easily access and adjust their own privacy settings. It was launched at an international data protection conference in Madrid on 4 November 2009.

I was so taken by the launch that I (somewhat) respectfully paid a tribute to Alma Whitten, one of Google’s gurus for privacy & safety, in the style (and using many of the phrases) of Julia W Howe. It was she who, during the American Civil War, wrote the original verses of the "Battle Hymn of the Republic" in single evening at the Willard Hotel, Washington DC, on 18 November 1861.

Spookily, that's so close to where thousands of privacy professionals will be flocking in a few days time, to attend the IAPP's annual Global Privacy Summit.

I hope Alma won't be offended. I’ve met her and have really enjoyed her easy manner, professionalism and deep commitment to fairness and transparency. She's still one of Google's shining stars!

My tribute was crafted during the course of a single evening, too. And it shows. It was originally posted on this site on 6 December 2009, and, with just a tweak or two, I think it’s time has come again.

A BATTLE HYMN FOR THE CHOCOLATE FACTORY

Mine eyes have seen the glory of the coming of the Board
It’s a simple way of knowing how your preferences are stored
All set up to win every privacy award
It’s truth is marching on.

Glory! Glory! It's the Dashboard! Glory! Glory! It's the Dashboard!
Glory! Glory! It's the Dashboard! The truth is marching on.

I've heard Alma speaking softly to a hundred data chaps
They have built her a chrome platform which reads emails and her maps
It can also find her schedules and those pics of her kneecaps
Her day is marching on.

Glory! Glory! It's the Dashboard! Glory! Glory! It's the Dashboard!
Glory! Glory! It's the Dashboard! Her day is marching on.

I have read a fiery press release which really makes you feel
“You bureaucrats are ignorant and just don’t get the deal”
See the Hero, born a woman, crush the Commission with her heel
Since Alma’s marching on.

Glory! Glory! It's the Dashboard! Glory! Glory! It's the Dashboard!
Glory! Glory! It's the Dashboard! Since Google's marching on.

Alma's helped to build a Dashboard where the picture is complete
She is sorting out the hearts of men before they start to tweet
Oh, with self control, now plead with her: “Come photograph my street”
Our Alma’s marching on.

Glory! Glory! It's the Dashboard! Glory! Glory! It's the Dashboard!
Glory! Glory! It's the Dashboard! And Google marches on.

In the beauty of the lilies she was born across the sea
With a glory in her bosom that transfigures you and me
As she works to make stuff useful, let us work to keep stuff free
While Alma marches on.

Glory! Glory! It's the Dashboard! Glory! Glory! It's the Dashboard!
Glory! Glory! It's the Dashboard! While Google marches on.

She is coming like the glory of the morning on the wave
She is wisdom to the mighty, She is honour to the brave
I will start to use the Dashboard if Google promises to behave
As Alma marches on.

Glory! Glory! It's the Dashboard! Glory! Glory! It's the Dashboard!
Glory! Glory! It's the Dashboard! Yes, Google marches on.


.

Friday, 2 March 2012

EU/US Privacy: Who blinks first?

I want to return to the theme I referred to yesterday about the different privacy initiatives that have emerged, almost at the same time, but from different sides of the Atlantic. Both addressed the perceived needs of the same group of people, ie the developers who create mobile applications for users around the globe.

Richard Brennan has been making some very interesting comments on privacy recently. Who is he? He’s is a Vice Director of Huawei’s industry standards department, based in China and Europe. He also represents the China Standards Authority internationally, and was asked for his impressions of the direction that the EU and US jurisdictions were taking.

It was a pretty bleak assessment: “In the US it is ‘freedom of speech’, in the EU it is all about constitutional privacy: those are opposing forces that cannot be balanced.”

What a perceptive comment from someone so steeped in the Chinese privacy culture.

When asked to expand his remarks, he said: “I think there are concerns generally about these two different models. One is the controlled internet versus a very open construct, which is governed by freedom of speech and not much else. They need to be balanced. As businesses we have to respect the desires of our customers and the environment in which they are doing business. We need to follow the decisions, understand and comment in a positive way in each area where those decisions are being made, we are looking at the EU environment discussing them over a broad set of issues to make sure that the network technical capabilities mirror well the policies that are being asked for on the regulatory side.”

So, there is good will on the part of the legislators to meet and talk, but it’s not at all clear how their deeply held views can be reconciled. Of course we all know how hard it is to reconcile contrary views. After all, look at the herculean efforts that the Article 29 Working Party is making to ensure that, even within Europe, regulators develop a common approach to cross border issues. And look at how much further they have to go before us European privacy watchers sense that there actually is a more joined-up approach.

Perhaps there is too much introspection at the moment. And perhaps we need more observers who, from an Asian, Indian Pacific and South American perspective, can join this debate and expose a few more home truths.

Source:
http://www.euractiv.com/specialreport-broadband-driving-recovery/huawei-exec-tension-technology-privacy-hampers-industry-int

Image credit:
http://singularimages.wordpress.com/2009/03/ Two Little Gunslingers, San Juan Capistrano, March 2009. Photograph copyright of Douglas Stockdale

.

Thursday, 1 March 2012

A lack of joined up working – and inappropriate fines

I wasn’t planning to wax lyrical today. Instead, I was planning to write a blog commemorating the great work of the GSM Association in publishing guidelines for people who develop applications for mobile devices, pointing out that there are such things as data protection laws, and that here are some relatively straightforward ways of trying to comply with them.

However, something threw me. I've just noticed that, last week, the Attorney General of California issued a press release advising she had reached an agreement with Apple, Google, Microsoft, RIM, Amazon and HP that they will ensure users of mobile apps are given privacy policies before an application is downloaded. The agreement also requires the companies to: "educate developers about their obligations to respect consumer privacy and to disclose to consumers what private information they collect, how they use the information, and with whom they share it. The platforms will also work to improve compliance with privacy laws by giving users tools to report non-compliant apps and committing companies to implement processes to respond to these reports.” The Attorney General will review progress made in six months time.

Talk about spooky – I thought I had been working on an almost identical project with the GSM Association in London for the past few years. And, if my memory serves me right, I'm sure we consulted our chums over there, and invited them to express an interest in participating in the European one. The GSM Association’s initiative was launched this week. But I wonder how the likes of Apple, Google, Microsoft, RIM and Amazon and HP managed to keep their amazing work from so many privacy professionals this side of the pond until it was formally announced?

I wonder who knew about both projects being developed in parallel. Perhaps it was a lost opportunity not to have been able to create a joint initiative between the mighty European companies and the mighty American ones. What a shame.

Just like London buses, you can wait a long time to see a privacy initiative, and then suddenly two similar ones come along just about the same time.

At least both are trying to do pretty much the same thing, so the end result ought to result in some consumer benefit, not consumer detriment.

Anyway, what really caught my attention today was a statement from Information Commissioner Christopher Graham commenting on the recent conviction of four private investigators who had pleaded guilty to stealing confidential information and selling it to paying clients. Because the ICO worked with the Serious Organised Crime Agency, and convictions were secured under the Fraud Act, they faced custodial sentences. But, in a virtually identical case, held in another court at almost the same time, because the defendant was tried under Data Protection legislation, they were only fined some £200.

And I was quite shocked to realise that the proposed Regulation, despite its grotesque fining powers for data controllers, is silent on any requirement to impose custodial penalties on corrupt employees, private investigators or social engineers. No jail time for them? Surely this will be made more specific, soon. The vague reference in Article 78 to Member States laying down rules on penalties, applicable to infringements of the provisions is surprising given how prescriptive most of the rest of the Regulation is. If there were anywhere in the Regulation where a little more prescription might be welcome, its here.

Sitting on the tube on the way home today, a fellow passenger's headphones were leaking the sounds of the late Ian Dury and the Blockheads. So, what could be more appropriate than this little ditty:

HIT ME WITH YOUR FINING STICK

Lost on a laptop, in Milan
Were the health records of ev'ry woman, ev'ry man

Hit me your fining stick, hit me, hit me
Je t'adore, ich liebe dich, hit me, hit me, hit me
Hit me with your fining stick
Hit me slowly, hit me quick
Hit me, hit me, hit me

In the wilds of Wilmslow can be found the ICO
“How much should we levy, let’s be macho”

Hit me with your fining stick, hit me, hit me
Das ist gut, c'est fantastique, hit me, hit me, hit me

Hit me with your fining stick
“Is that all you can do? That’s lunatic”
Hit me, hit me, hit me

Hit me, hit me, hit

Tucked in that Regulation, meantime
In Article 79, are grotesque powers to fine
For not returning a form in time

Hit me with your fining stick, hit me, hit me
C'est si bon, mm? Ist es nicht? Hit me, hit me, hit me
Hit me with your fining stick
One million Euros, tick, tick, tick
Hit me, hit me, hit me

Hit me, hit me, hit me - hit me, hit me ....



Sources:
http://oag.ca.gov/news/press_release?id=2630
http://www.ico.gov.uk/news/latest_news/2012/statement-private-detectives-jailed-for-blagging-27022012.aspx

Image credit:
http://www.megachwiep.com/PaulHardcastle/Hit_Me_with_Your_Remixes/IanDuryandtheBlockheads-HitmewithyourRhythmStick100.jpg

.