Internet God Vint Clef set the room alight today, when he addressed the usual suspects at the annual meeting of the UK Internet Policy Forum in Central London. If there ever existed a living invividual whose personal contribution to mankind exceeds that of Vint, then I would be very surprised. I’m so grateful to my chums at Nominet for making today’s event happen.
For those who don’t know, Vint is the VP and Chief Internet Evangelist for Google. He co-invented the architecture and basic protocols of the internet and has received more awards and honours than anyone would ever need. It was he, some 40 years ago, who put in place building blocks which everyone takes for granted today. So when >The Beatles first sang: “it was 20 years ago today, Sergeant Pepper taught the band to play” back in 1967, it’s absolutely astonishing to think that the band was playing in a pre-internet world.
Just think what has happened since then.
As this was a conference on internet policy, a lot of what Vint had to say really needs to be respected. And, significantly, it is evidence of a profound disagreement about the role that Governments should play in what happens on the Internet. If I were the European Commission, I would doubt that the European view of internet regulation could be readily or properly reconciled with that of the American view.
A principal point was that individuals will always have a desire to communicate. When pressed, he admitted that what has most surprised him about the development of the internet is the extent to which so many people have been so keen to spread information via the internet. Equally, Vint pointed out that not everyone wants to hear what everyone else wants to say. Which is why we rely on search machines, clues from friends or brands to filter the information we are looking for.
He suggested that our greatest concern was the unintended consequence of introducing rules which are designed to prevent some bad things from happening, but also prevented good things from happening. To the American politicians who supported internet censorship, he pointed out that America was born in the aftermath of an anonymous revolution (Tom Payne’s revolutionary writings, published just prior to the American Revolution, were initially published anonymously, as he feared the consequences of State retribution), and that they were making a great mistake if they objected to that.
The issue, today, is the lack of sufficiently precise tools with which to prevent bad things happening, People who generally want control over the internet tend to show people the worst possible cases, and they gloss over that else their tools will prevent. Is this security or are they wolves in sheep’s clothing?
But Vint was also keen to emphasise that we do need to create ways of protecting our citizens. We can’t ignore the need to make society a safe place. But, critically, we should not pay the price of freedom of expression to serve that goal.
So, we have the old argument of freedom of expression against someone else’s fundamental rights. I think I keep hear that argument played out as the EU and US negotiators try to form a coherent view on data protection regulation. In my humble view, agreement is unlikely to break out any time soon.
Vint also made a couple of announcements that will soon turn into pub quiz questions – so you’ve heard them here first:
• Originally, Vint didn’t want to be known as the Chief Internet Evangelist for Google. When first asked for a Google job title, Vint suggested Arch Duke. And then it was pointed out what had happened to an earlier Arch Duke, and how the First World War had followed swiftly afterwards.
• IP version 6 address protocols will officially be in common use from Wednesday 6 June. Currently they are being tested on the internet, meaning they are occasionally turned on, and then off again. But from 6 June they won’t be turned off. Internet browsers will have to process both versions simultaneously, if they are to work properly.
Vint saved the ultra impressive stuff to the last few minutes of his speech. He gave us a truly astonishing overview of the sort of services that Google were just about to offer, and then spent a few minutes talking about his recent role in the Interplanetary Internet Architecture Programme. That’s right. Not only will different national space agencies be able to talk to each other, but plans are also in place to communicate with objects as far away as Alpha Centauri A star (pictured), which requires communications technologies that work over a distance of 4 light years. And yes, they are already being developed.
So, how will the European Commission address the tricky issue of servers in space, when it can’t even sort out workable laws that govern flows of data to countries or territories outside the EEA? Cummon, guys, we are now talking about internet servers in space. And soon.
Very soon.
Just perhaps, space will not be that final (regulatory) frontier, after all.
Image credit:
http://www.solstation.com/stars/cent2.jpg
.
Thursday, 22 March 2012
Tuesday, 20 March 2012
Hurrah! We’re not all doomed when that Regulation is dropped
In a speech delivered yesterday to the Statute Law Society by Philip Coppel QC, I was left with the clear sense that there were indeed some prominent supporters of the current Data Protection Act. The inference of Coppel’s speech was pretty clear: Don’t worry too much if the discussions over that Regulation come to nothing. All is not lost. We can make do with what we already have for the time being – and for some time to come.
Philip Coppel is well known to those who follow litigation involving the Information Commissioner’s Office. A quick squint at his case history reveals he certainly has “form” when appearing in information law cases. He does know his stuff.
The Judiciary are no lovers of data protection legislation, but then again, when you look at the cases that have been argued before various benches, it’s hard to find a less attractive bunch of plaintiffs. Perhaps that’s one of the main problems – if the courts had only more experience in dealing with more reasonable plaintiffs, they might take the protections that the Act can provide a little more seriously. I’ve often thought that the less responsibly the plaintiff’s appears to behave, then the harder the Bench will strive to find some way of denying their application, whatever everyone else thinks the law says.
But enough of my rant.
Coppel saw lots of nods of agreement among the audience as he described the Data Protection Act as: “the ugly relation in the law of privacy.” It’s a thicket and an unpleasant piece of legislation, which takes a lot of guidance before you get to realise how it is actually supposed to work. Tell me about it. I’ve been spending days being lectured on how the various bits of the legislation mesh together, as I mug up for my ISEB data protection exam.
The legislators have also known that for an awful long time. Coppel ruefully remarked that, as the House of Lords commenced the Second Reading of the Data Protection Bill in February 1998, “the chamber emptied itself as quickly as health and safety legislation permitted”.
Even one of the members of the audience, who later introduced himself as a former Home Office official who was heavily involved in progressing much of the data protection implementing legislation through Parliament over a decade ago, commented that: “At bottom, it’s simply not very clear what it’s all about.”
But, Coppel made the vitally important point that when you look at what the Act actually provides for, it’s not as bad as all that: “Properly understood, the Data Protection Act 1992 does provide an adequate system for the protection against intrusion upon privacy of record. Properly applied, it saves the need for bending the law of confidentiality to remedy the obvious wrongs that have spawned a “law of privacy”. The Act has a sophistication which is not going to be matched by the fits and starts of the developing common law.”
There are very good reasons why it’s such a hard piece of legislation to follow. After all, its principal author (whose identity I know so wont embarrass them) is an awfully bright person, and to them, once you know how to navigate around the legislation, it’s really quite straightforward. Had any of the parliamentarians on the scrutiny committees (whose identity I also know, but won’t embarrass them) bothered to take a little more interest in the legislation, rather than dealing with their constituency correspondence during the Committee meetings, there might have been a Parliamentary call for something that was easier to understand. But no. This is what you get when you get Parliamentarians who care about clarity as much as they evidently did.
In closing came the Coppel cry: “The time has come, then, to give true effect to the Data Protection Act 1998. We should learn to appreciate what we have already got. And with that, I would suggest, the cry for a privacy law will in no small part be answered.”
The great and the good of the Statute Law Society then adjourned for drinks and polite discussion, to continue what had started as an extremely agreeable evening.
Source:
Printed copies of his speech, “The Data Protection Act & Personal Privacy”, by Philip Coppel QC, are available from the Statute Law Society. Email: statutelaw@aol.com
.
Philip Coppel is well known to those who follow litigation involving the Information Commissioner’s Office. A quick squint at his case history reveals he certainly has “form” when appearing in information law cases. He does know his stuff.
The Judiciary are no lovers of data protection legislation, but then again, when you look at the cases that have been argued before various benches, it’s hard to find a less attractive bunch of plaintiffs. Perhaps that’s one of the main problems – if the courts had only more experience in dealing with more reasonable plaintiffs, they might take the protections that the Act can provide a little more seriously. I’ve often thought that the less responsibly the plaintiff’s appears to behave, then the harder the Bench will strive to find some way of denying their application, whatever everyone else thinks the law says.
But enough of my rant.
Coppel saw lots of nods of agreement among the audience as he described the Data Protection Act as: “the ugly relation in the law of privacy.” It’s a thicket and an unpleasant piece of legislation, which takes a lot of guidance before you get to realise how it is actually supposed to work. Tell me about it. I’ve been spending days being lectured on how the various bits of the legislation mesh together, as I mug up for my ISEB data protection exam.
The legislators have also known that for an awful long time. Coppel ruefully remarked that, as the House of Lords commenced the Second Reading of the Data Protection Bill in February 1998, “the chamber emptied itself as quickly as health and safety legislation permitted”.
Even one of the members of the audience, who later introduced himself as a former Home Office official who was heavily involved in progressing much of the data protection implementing legislation through Parliament over a decade ago, commented that: “At bottom, it’s simply not very clear what it’s all about.”
But, Coppel made the vitally important point that when you look at what the Act actually provides for, it’s not as bad as all that: “Properly understood, the Data Protection Act 1992 does provide an adequate system for the protection against intrusion upon privacy of record. Properly applied, it saves the need for bending the law of confidentiality to remedy the obvious wrongs that have spawned a “law of privacy”. The Act has a sophistication which is not going to be matched by the fits and starts of the developing common law.”
There are very good reasons why it’s such a hard piece of legislation to follow. After all, its principal author (whose identity I know so wont embarrass them) is an awfully bright person, and to them, once you know how to navigate around the legislation, it’s really quite straightforward. Had any of the parliamentarians on the scrutiny committees (whose identity I also know, but won’t embarrass them) bothered to take a little more interest in the legislation, rather than dealing with their constituency correspondence during the Committee meetings, there might have been a Parliamentary call for something that was easier to understand. But no. This is what you get when you get Parliamentarians who care about clarity as much as they evidently did.
In closing came the Coppel cry: “The time has come, then, to give true effect to the Data Protection Act 1998. We should learn to appreciate what we have already got. And with that, I would suggest, the cry for a privacy law will in no small part be answered.”
The great and the good of the Statute Law Society then adjourned for drinks and polite discussion, to continue what had started as an extremely agreeable evening.
Source:
Printed copies of his speech, “The Data Protection Act & Personal Privacy”, by Philip Coppel QC, are available from the Statute Law Society. Email: statutelaw@aol.com
.
Saturday, 17 March 2012
A deluge of data protection events?
Do you often feel bemused by the volume of invitations received to both “free” and “commercial” privacy events these days? Do you ever wonder how on earth you are going to be able to get the day job done, let alone try to keep briefed on the latest issues? No wonder so many events are quite thinly attended. Reading about contemporary data protection matters is one thing. But getting up close to a speaker is something entirely different. And the gossip and the networking that goes on in the margins of these events can be of critical importance to a data protector on a mission. Or a job hunt.
One conference organiser was seriously unhappy when I recently replied to their phone call asking me if I was interested in attending a particular upcoming data protection event. After all, I was assured, the event had been precisely tailored to my immediate needs, so of course I was going to be interested in being corralled with a group of my peers to be spoken at for a couple of hours. Wasn’t I?
No, I wasn’t. I was already busy that day, and they ought to have known that. I was planning to attend a free event to get a very similar perspective from speakers just good as those that this conference organiser wanted to charge a significant sum of money for.
This unhappy exchange set a cunning plan running in my head, and one that I’ll be asking for your advice and support over. If it works, it will take off. If it doesn’t, well at least I tried.
My cunning plan is to publish an independent list of upcoming data protection events. It will have several purposes. From the perspective of the conference organiser, it will help remind everyone what’s already likely to be happening around that time, as that could have a very significant impact on attendee numbers (and thus the viability of the project). And from the perspective of the data protection officer, it may help remind people what is likely to be going on in the next few months, so that ever decreasing conference and training budgets can be focused on the events that are more likely to be of real value. And for conference speakers, it can help forewarn them about who else is currently on the circuit talking about “their” pet subject.
I’m not doing this for any financial reasons, but simply to share knowledge of what data protection events are being planned, and held. And to help us busy data protectors to better plan our time.
I started compiling the list some three weeks ago. 10 of these events have already happened, so I've moved them into a separate list. And there are another 25 in the pipeline. But I know I have not really begun to scratch the surface yet of privacy events that are likely to be of interest to a British data protector. But I think it may be useful to bring information about them all together into one place. So, please get in touch and help me add details of other credible events to the list.
If you are at all interested in this initiative, then please pop over to my serious data protection website and take a squint.
The list of upcoming events is here. The archive of past events is here.
I’ll review this initiative in a few months time and will report back.
Image credit:
http://27.media.tumblr.com/tumblr_kxy52x17rJ1qa1nx7o1_500.jpg
.
One conference organiser was seriously unhappy when I recently replied to their phone call asking me if I was interested in attending a particular upcoming data protection event. After all, I was assured, the event had been precisely tailored to my immediate needs, so of course I was going to be interested in being corralled with a group of my peers to be spoken at for a couple of hours. Wasn’t I?
No, I wasn’t. I was already busy that day, and they ought to have known that. I was planning to attend a free event to get a very similar perspective from speakers just good as those that this conference organiser wanted to charge a significant sum of money for.
This unhappy exchange set a cunning plan running in my head, and one that I’ll be asking for your advice and support over. If it works, it will take off. If it doesn’t, well at least I tried.
My cunning plan is to publish an independent list of upcoming data protection events. It will have several purposes. From the perspective of the conference organiser, it will help remind everyone what’s already likely to be happening around that time, as that could have a very significant impact on attendee numbers (and thus the viability of the project). And from the perspective of the data protection officer, it may help remind people what is likely to be going on in the next few months, so that ever decreasing conference and training budgets can be focused on the events that are more likely to be of real value. And for conference speakers, it can help forewarn them about who else is currently on the circuit talking about “their” pet subject.
I’m not doing this for any financial reasons, but simply to share knowledge of what data protection events are being planned, and held. And to help us busy data protectors to better plan our time.
I started compiling the list some three weeks ago. 10 of these events have already happened, so I've moved them into a separate list. And there are another 25 in the pipeline. But I know I have not really begun to scratch the surface yet of privacy events that are likely to be of interest to a British data protector. But I think it may be useful to bring information about them all together into one place. So, please get in touch and help me add details of other credible events to the list.
If you are at all interested in this initiative, then please pop over to my serious data protection website and take a squint.
The list of upcoming events is here. The archive of past events is here.
I’ll review this initiative in a few months time and will report back.
Image credit:
http://27.media.tumblr.com/tumblr_kxy52x17rJ1qa1nx7o1_500.jpg
.
Friday, 16 March 2012
Cookies – Barclays wins a glittering prize
I’ve just been invited to a brilliant bash. It’s to celebrate the fact that one company, that banking behemoth Barclays, has apparently found a cunning way to comply with the new cookie rules. And their compliance method is so utterly, utterly brilliant that both Christopher Graham, the Information Commissioner and Ed Vaizey, the Minister for Culture, Communications and Creative Industries in the Department for Culture, Media and Sport, will be delivering keynote speeches on this prestigious occasion.
Praise indeed.
To be absolutely honest, I would be more impressed if Barclays offered a better rate of return on their Loyalty Reward ISA, but I can’t have everything. Instead, I’ll make do with appreciating their cunning cookie compliance methodology.
I understand that data controllers who are not as fast off the mark as Barclays will have an opportunity to ask questions about the new cookie requirements at this event, and it will be really interesting to work out, from Ed Vaizey’s replies, just how high a priority he really sees cookie compliance. Other speakers will include our chums from the Internet Advertising Bureau and the International Chamber of Commerce. So it ought to be good.
Places are limited, so I hope you will forgive me if I don’t announce the details of the venue and when it will be held. But I will blog about it afterwards.
One of the reasons I want to attend is so that I can respond to journalists who are writing negative stories about all this cookie chaos. One article that very recently caught my eye shouted that “Online marketers really dislike Europe’s new digital privacy law”. Fancy that! Apparently, 82% of them think the European Union’s new cookie law is bad for the web, according to survey results released by the market research agency Econsultancy.
Econsultancy surveyed 739 marking professionals earlier this month via e-mail, Facebook and Twitter to learn their thoughts about the requirements, which the journalist claimed “takes effect this spring and generally requires web sites to ask for permission before placing a cookie on a consumer’s browser to track her behaviour. Those cookies can tell marketers where that consumer has come from and what she’s viewed and searched for—which in turn enables marketers to target web ads based on those behaviours, or tweak discount and merchandising tactics. The law doesn’t require permission for cookies that track items put into shopping carts or which remember a consumer’s shipping address.”
Reported comments from survey respondents pointed to lingering confusion about the law and scepticism that it will do any good. “There's total confusion on how to apply it and what it should be applied,” read one such comment from a survey participant. “There are a few nice implementations [but] nothing which everyone agrees on, which means a disjointed user experience from site to site.”
Other comments included: “There are still a number of grey areas and the legislation has obviously been put together by people that do not understand the workings of online marketing.” Someone else commented: “We just need to be sensible about how we interpret it and ensure that we turn this into positive legislation for the online industry.”
Somewhat reassuringly: “57% of respondents claimed to have actually read the EU privacy directive that requires consumers to opt in for most web tracking by retailers and marketers, and 54% report their employers have carried out a cookie audit in advance of the law’s May 26 deadline for compliance. Only 7% of respondents say they think that online consumers understand how cookies work.”
I was astonished to read that as many as 57% of respondents had actually read the thing. I would have thought it was more likely to have been 5-7%. I’m not at all surprised that so few respondents understand how cookies work. After all, I don’t know how the engine in my car works. All I need to know is where to put the key and who to call when I have a problem with it.
I do hope this great forthcoming bash will give me plenty of material to blog about. Actually, I’m so convinced it will that I’ve already accepted the 4pm speaking slot at the prestigious Marketing Week Live event at Olympia on 27 June to talk about it. But if the cunning plan from Barclays turns out to be a complete dud, then I’ll have to think swapping my 4pm speaking slot with that of the 4am presenter!
Source:
http://www.internetretailer.com/mobile/2012/03/14/online-marketers-really-dislike-europes-new-digital-privacy-law?list_type=cat&cat=ROOT&ordered=1&index=1
.
Praise indeed.
To be absolutely honest, I would be more impressed if Barclays offered a better rate of return on their Loyalty Reward ISA, but I can’t have everything. Instead, I’ll make do with appreciating their cunning cookie compliance methodology.
I understand that data controllers who are not as fast off the mark as Barclays will have an opportunity to ask questions about the new cookie requirements at this event, and it will be really interesting to work out, from Ed Vaizey’s replies, just how high a priority he really sees cookie compliance. Other speakers will include our chums from the Internet Advertising Bureau and the International Chamber of Commerce. So it ought to be good.
Places are limited, so I hope you will forgive me if I don’t announce the details of the venue and when it will be held. But I will blog about it afterwards.
One of the reasons I want to attend is so that I can respond to journalists who are writing negative stories about all this cookie chaos. One article that very recently caught my eye shouted that “Online marketers really dislike Europe’s new digital privacy law”. Fancy that! Apparently, 82% of them think the European Union’s new cookie law is bad for the web, according to survey results released by the market research agency Econsultancy.
Econsultancy surveyed 739 marking professionals earlier this month via e-mail, Facebook and Twitter to learn their thoughts about the requirements, which the journalist claimed “takes effect this spring and generally requires web sites to ask for permission before placing a cookie on a consumer’s browser to track her behaviour. Those cookies can tell marketers where that consumer has come from and what she’s viewed and searched for—which in turn enables marketers to target web ads based on those behaviours, or tweak discount and merchandising tactics. The law doesn’t require permission for cookies that track items put into shopping carts or which remember a consumer’s shipping address.”
Reported comments from survey respondents pointed to lingering confusion about the law and scepticism that it will do any good. “There's total confusion on how to apply it and what it should be applied,” read one such comment from a survey participant. “There are a few nice implementations [but] nothing which everyone agrees on, which means a disjointed user experience from site to site.”
Other comments included: “There are still a number of grey areas and the legislation has obviously been put together by people that do not understand the workings of online marketing.” Someone else commented: “We just need to be sensible about how we interpret it and ensure that we turn this into positive legislation for the online industry.”
Somewhat reassuringly: “57% of respondents claimed to have actually read the EU privacy directive that requires consumers to opt in for most web tracking by retailers and marketers, and 54% report their employers have carried out a cookie audit in advance of the law’s May 26 deadline for compliance. Only 7% of respondents say they think that online consumers understand how cookies work.”
I was astonished to read that as many as 57% of respondents had actually read the thing. I would have thought it was more likely to have been 5-7%. I’m not at all surprised that so few respondents understand how cookies work. After all, I don’t know how the engine in my car works. All I need to know is where to put the key and who to call when I have a problem with it.
I do hope this great forthcoming bash will give me plenty of material to blog about. Actually, I’m so convinced it will that I’ve already accepted the 4pm speaking slot at the prestigious Marketing Week Live event at Olympia on 27 June to talk about it. But if the cunning plan from Barclays turns out to be a complete dud, then I’ll have to think swapping my 4pm speaking slot with that of the 4am presenter!
Source:
http://www.internetretailer.com/mobile/2012/03/14/online-marketers-really-dislike-europes-new-digital-privacy-law?list_type=cat&cat=ROOT&ordered=1&index=1
.
Thursday, 15 March 2012
ISEB Accreditation: Chapter 3
The fifth formal day of the course of instruction that ought to lead to my ISEB qualification has been completed. Just the mock, and then a whole day’s tutorial, then the actual exam. Roll on the end of April. Then I need to ask myself what to do with the 4” (10cm) pile of notes that course presenters Chris Pounder and Sue Cullen have so lovingly prepared, distributed, and let me scrawl all over. I think I know just the place for them, but first I had better pass the exam.
To describe the course so to someone who has not considered taking the ISEB qualification before is not easy. After all, why would anyone want to give up a significant portion of their private life for a few months to take it? Well, first they had better be a dedicated data protection professional. Second, they ought to be astute enough to realise that about the only thing no Member State has criticised the European Commission about in that Regulation is the way it will significantly raise the profile of data protection officers in future.
The more responsible data controllers will be obviously feel obliged to employ people who have an appropriate qualification. And the really good news is that, if we play our cards right, the law will compel them to employ/engage someone, so the head hunters should be out in droves, linking-in with people who have suddenly become endowed with some very marketable skills.
This could become a problem for those companies whose salary structures are such that they find it hard to pay market rates for (anyone, let alone) qualified data protection professionals. And, if the ludicrous fining proposals in that Regulation manage to become law, the pressure on salaries can surely only be in one direction. Data protection officers could be as eagerly sought after as members of that popular boy band. I do hope that public sector organisations won’t find it too hard to recruit and retain the right people. Presumably, our head hunter chums will be causing a few headaches in the Information Commissioner's Office’s Human Resources team too, when it becomes clear that former ICO staff are even more highly prized than they currently are.
But I can’t think too far ahead. I can barely think at all, right now. My mind is stuffed with concepts like the subject information provisions and the non-disclosure provisions. And also trying to distinguish between Article 7 rights, Section 7 rights, Principle 7 issues, and Schedule 3 (7) conditions. Oh yes, I’m also trying to get my head around the distinction between the grounds for processing in Schedules 2 and 3 and the non-disclosure exemptions. And understanding how the law of confidence potentially interacts with the First Data Principle.
And it goes on. And on. And on. It’s not a doddle. You have to seriously know your stuff.
Whoever finally gets certified really deserves a badge to wear as a talking point so that they can tell anyone who asks just what they’ve had to go through. The International Association of Privacy Professionals confers on appropriately certified IAPP/E professionals the right to wear a badge emblazoned with the letter “E”. I think that the British Computer Society ought to confer an equivalent tight on appropriately certified ISEB professionals a badge too.
And what should it say?
If I had my way, it should simply say “£”.
Plagiarism Disclaimer:
Peter Fleisher from Google has also been warning in his personal blog that there are not enough experienced data protection officers to meet the impending legal requirements and that more need to be trained. He might have said it first, but I wasn’t aware of that until I was about to publish this blog today.
.
To describe the course so to someone who has not considered taking the ISEB qualification before is not easy. After all, why would anyone want to give up a significant portion of their private life for a few months to take it? Well, first they had better be a dedicated data protection professional. Second, they ought to be astute enough to realise that about the only thing no Member State has criticised the European Commission about in that Regulation is the way it will significantly raise the profile of data protection officers in future.
The more responsible data controllers will be obviously feel obliged to employ people who have an appropriate qualification. And the really good news is that, if we play our cards right, the law will compel them to employ/engage someone, so the head hunters should be out in droves, linking-in with people who have suddenly become endowed with some very marketable skills.
This could become a problem for those companies whose salary structures are such that they find it hard to pay market rates for (anyone, let alone) qualified data protection professionals. And, if the ludicrous fining proposals in that Regulation manage to become law, the pressure on salaries can surely only be in one direction. Data protection officers could be as eagerly sought after as members of that popular boy band. I do hope that public sector organisations won’t find it too hard to recruit and retain the right people. Presumably, our head hunter chums will be causing a few headaches in the Information Commissioner's Office’s Human Resources team too, when it becomes clear that former ICO staff are even more highly prized than they currently are.
But I can’t think too far ahead. I can barely think at all, right now. My mind is stuffed with concepts like the subject information provisions and the non-disclosure provisions. And also trying to distinguish between Article 7 rights, Section 7 rights, Principle 7 issues, and Schedule 3 (7) conditions. Oh yes, I’m also trying to get my head around the distinction between the grounds for processing in Schedules 2 and 3 and the non-disclosure exemptions. And understanding how the law of confidence potentially interacts with the First Data Principle.
And it goes on. And on. And on. It’s not a doddle. You have to seriously know your stuff.
Whoever finally gets certified really deserves a badge to wear as a talking point so that they can tell anyone who asks just what they’ve had to go through. The International Association of Privacy Professionals confers on appropriately certified IAPP/E professionals the right to wear a badge emblazoned with the letter “E”. I think that the British Computer Society ought to confer an equivalent tight on appropriately certified ISEB professionals a badge too.
And what should it say?
If I had my way, it should simply say “£”.
Plagiarism Disclaimer:
Peter Fleisher from Google has also been warning in his personal blog that there are not enough experienced data protection officers to meet the impending legal requirements and that more need to be trained. He might have said it first, but I wasn’t aware of that until I was about to publish this blog today.
.
Wednesday, 14 March 2012
That Regulation: the red lines emerge
If you were at, or had dialled into, yesterday's meeting of the Data Protection Forum, you would have appreciated the political significance of what was being discussed.
In a historic first for the Forum, speakers from equivalent data protection organisations in France and Germany had travelled to Central London to share their thoughts about that Regulation, and to see what common ground existed between them.
What very quickly emerged was a shared determination to ensure that local citizens could continue to enjoy the standards of data protection they had grown to expect. A "one size fits all" approach is a complete non starter. Until, that is, Member states are abolished and we all become grateful citizens of the European Union. But we are absolutely not there, yet. And as discussions turned to how local laws would need to be enacted to take account of very important bits of data protection law that were missing from the current draft, the more the logical inconsistency of such a thing as a Regulation became apparent (at least to me). Who can describe to me the practical difference between a legislative package which comprises (1) a Regulation and a bunch of local laws to meet local needs, and (2) a Directive and a bunch of local laws to meet local needs?
What also emerged during the discussions was how very different was the role that was played by Data Protection Officers in three countries. This is in terms of their legal standing, duties and their working relationships with local data protection authorities. If the new legal instrument is to require certain organisations to have such an animal, is it to look more like the German, the French or the English DPO? Given the (potentially) very significant role that such animals will play in future, it is vital that Member States get this bit right. Especially if these DPOs are to have fixed contracts. How will a DPO act if they spy something dodgy, say, just six months before their contract is due for renewal? Will concerns about not having their contact renewed cloud their judgement about the most appropriate course of action to take?
Surely not!
I don't intend to go into any greater detail about what was discussed as that might only forewarn our chums in Brussels about what's going to be hitting them. So no, I will keep my powder dry. If you want to know more about these vitally important issues, all you need to to is become a member of the Data Protection Forum and witness at first hand how policy is developed. Forum members now understand what's about to happen, and why. My other readers can just sit back and marvel at the way things are about to unfold. Or unravel! With membership at just £150 for 4 meetings a year, this has to be the greatest value around for anyone who is serious about data protection in 'Blighty. More information about the Forum and how to join it is available here.
Perhaps I should just plant one thought with the Commission officials before I end today's blog, though. Just as a taster for things to come: There are some data protection rights that are too important to be entrusted into the hands of the European Commission. In fact, they are so important that they will be left in the hands of Member States, whatever the Commission thinks.
Image credit:
http://www.red-lines.co.uk/images/redlinesflame.jpg
.
In a historic first for the Forum, speakers from equivalent data protection organisations in France and Germany had travelled to Central London to share their thoughts about that Regulation, and to see what common ground existed between them.
What very quickly emerged was a shared determination to ensure that local citizens could continue to enjoy the standards of data protection they had grown to expect. A "one size fits all" approach is a complete non starter. Until, that is, Member states are abolished and we all become grateful citizens of the European Union. But we are absolutely not there, yet. And as discussions turned to how local laws would need to be enacted to take account of very important bits of data protection law that were missing from the current draft, the more the logical inconsistency of such a thing as a Regulation became apparent (at least to me). Who can describe to me the practical difference between a legislative package which comprises (1) a Regulation and a bunch of local laws to meet local needs, and (2) a Directive and a bunch of local laws to meet local needs?
What also emerged during the discussions was how very different was the role that was played by Data Protection Officers in three countries. This is in terms of their legal standing, duties and their working relationships with local data protection authorities. If the new legal instrument is to require certain organisations to have such an animal, is it to look more like the German, the French or the English DPO? Given the (potentially) very significant role that such animals will play in future, it is vital that Member States get this bit right. Especially if these DPOs are to have fixed contracts. How will a DPO act if they spy something dodgy, say, just six months before their contract is due for renewal? Will concerns about not having their contact renewed cloud their judgement about the most appropriate course of action to take?
Surely not!
I don't intend to go into any greater detail about what was discussed as that might only forewarn our chums in Brussels about what's going to be hitting them. So no, I will keep my powder dry. If you want to know more about these vitally important issues, all you need to to is become a member of the Data Protection Forum and witness at first hand how policy is developed. Forum members now understand what's about to happen, and why. My other readers can just sit back and marvel at the way things are about to unfold. Or unravel! With membership at just £150 for 4 meetings a year, this has to be the greatest value around for anyone who is serious about data protection in 'Blighty. More information about the Forum and how to join it is available here.
Perhaps I should just plant one thought with the Commission officials before I end today's blog, though. Just as a taster for things to come: There are some data protection rights that are too important to be entrusted into the hands of the European Commission. In fact, they are so important that they will be left in the hands of Member States, whatever the Commission thinks.
Image credit:
http://www.red-lines.co.uk/images/redlinesflame.jpg
.
Monday, 12 March 2012
The pressure facing today’s data protection regulators
The latest word from the Information Commissioner’s Office is that there is some interest in seeing me hand over £100 to the charity Help for Heroes if a video of an ICO team doing a Cookie Warp dance is posted on YouTube by 26 May. If you have no idea what I’m talking about, please take a quick look at my blog dated 9 March.
One wag has been in touch to suggest that the charitable donation could easily multiply just to ensure that certain members of the ICO’s staff are not heard singing (and that’s before the money floods in to make sure certain others are not donning any Frank N Further style costume…).
They also suggested: “Perhaps their version should be the song that refers to the sword of Damocles hanging over their heads….”
This person has a serious point. The pressure on regulators to enforce legislation (even if they themselves don’t believe it’s been properly thought through) must be pretty awful. I’m glad I’m not in that position.
So, in honour of those who are charged with carrying out such a very difficult job, I thought I should pen a little ode just for them. I didn’t find it that easy to come up with lyrics that rhymed with Damocles and made much sense, though. If you’re interested, I toyed with lines which ended in words such as: please, he’s, squeeze, she’s, wheeze, disease, faeces, species, Chinese, herpes, trapeze, appease, freeze and Maltese.
Oh the pressure of producing a data protection ditty to order! And then inspiration hit me. So today’s effort, inspired by David Bowie and Queen, is dedicated to those regulatory folk in Wilmslow and Brussels who are bold enough to put their heads above the policy parapet.
Now, three cheers for the dedicated band of people whose guidance is eagerly craved, and then just as eagerly criticised when it finally comes!
PRESSURE
Pressure pushing down on me
Pressing down so much – I didn’t ask for
Under pressure - that so wears me down
Splits friends in two
When people meet me they stare and frown
It's the terror of knowing
What this stuff is about
Watching some good people
Screaming: You know nowt
Pray for tomorrow (its gotta get better)
Pressure on people - people everywhere
Protecting the weak from my worst nightmare
Kicking my brains round the floor
Fighting off those whom I deplore
There are days when it rains but it will never just pour
It's the terror of knowing
What this world is about
Watching some good friends
Screaming: You know nowt
Pray for tomorrow (it’s gotta get better)
Don’t know what it must feel like to be a blind man
Sat on the fence but it didn't work
Tired, hungry and bored at some conference in Cannes
Finding solutions – before going berserk
Under pressure
Insanity laughs under pressure we're cracking
Some light relief comes when we give Google a smacking
Shouldn’t allow controllers that one more chance
They’ll only send us on another merry dance
Under pressure
Fair and lawful are such old fashioned words
Yet praise for our efforts is so seldom said
Smiling while working in a field of turds
Keeps the pressure steadily building in my head
But someone’s got to do it
(And it obviously ain’t gonna be you)
It's the terror of knowing
What this stuff is about
Watching some good people
Now I’m screaming: Let me out
Pray for tomorrow (its gotta get better)
This is our last chance
Standards we should enhance
This is ourselves
Under pressure
Under pressure
Pressure
Image credit:
http://allthingsd.com/files/2011/12/damocles.png
The Sword of Damocles parable illustrates the constant fear with which many people in authority live. Wikipedia explains that in the fourth Century BC, Damocles was a courtier in the court of King Dionysius II of Syracuse, Italy. In the parable, Damocles praised his King that, as a great man of power and authority surrounded by magnificence, Dionysius was truly extremely fortunate. The King then offered to switch places with Damocles, so that Damocles could taste that very fortune at first hand. Damocles quickly and eagerly accepted the King's proposal. Damocles sat down in the king's throne surrounded by every luxury, but the King arranged that a huge sword should hang above the throne, held at the pommel only by a single hair of a horse's tail. Damocles finally begged the King that he be allowed to depart, because he no longer wanted to be so fortunate.
.
One wag has been in touch to suggest that the charitable donation could easily multiply just to ensure that certain members of the ICO’s staff are not heard singing (and that’s before the money floods in to make sure certain others are not donning any Frank N Further style costume…).
They also suggested: “Perhaps their version should be the song that refers to the sword of Damocles hanging over their heads….”
This person has a serious point. The pressure on regulators to enforce legislation (even if they themselves don’t believe it’s been properly thought through) must be pretty awful. I’m glad I’m not in that position.
So, in honour of those who are charged with carrying out such a very difficult job, I thought I should pen a little ode just for them. I didn’t find it that easy to come up with lyrics that rhymed with Damocles and made much sense, though. If you’re interested, I toyed with lines which ended in words such as: please, he’s, squeeze, she’s, wheeze, disease, faeces, species, Chinese, herpes, trapeze, appease, freeze and Maltese.
Oh the pressure of producing a data protection ditty to order! And then inspiration hit me. So today’s effort, inspired by David Bowie and Queen, is dedicated to those regulatory folk in Wilmslow and Brussels who are bold enough to put their heads above the policy parapet.
Now, three cheers for the dedicated band of people whose guidance is eagerly craved, and then just as eagerly criticised when it finally comes!
PRESSURE
Pressure pushing down on me
Pressing down so much – I didn’t ask for
Under pressure - that so wears me down
Splits friends in two
When people meet me they stare and frown
It's the terror of knowing
What this stuff is about
Watching some good people
Screaming: You know nowt
Pray for tomorrow (its gotta get better)
Pressure on people - people everywhere
Protecting the weak from my worst nightmare
Kicking my brains round the floor
Fighting off those whom I deplore
There are days when it rains but it will never just pour
It's the terror of knowing
What this world is about
Watching some good friends
Screaming: You know nowt
Pray for tomorrow (it’s gotta get better)
Don’t know what it must feel like to be a blind man
Sat on the fence but it didn't work
Tired, hungry and bored at some conference in Cannes
Finding solutions – before going berserk
Under pressure
Insanity laughs under pressure we're cracking
Some light relief comes when we give Google a smacking
Shouldn’t allow controllers that one more chance
They’ll only send us on another merry dance
Under pressure
Fair and lawful are such old fashioned words
Yet praise for our efforts is so seldom said
Smiling while working in a field of turds
Keeps the pressure steadily building in my head
But someone’s got to do it
(And it obviously ain’t gonna be you)
It's the terror of knowing
What this stuff is about
Watching some good people
Now I’m screaming: Let me out
Pray for tomorrow (its gotta get better)
This is our last chance
Standards we should enhance
This is ourselves
Under pressure
Under pressure
Pressure
Image credit:
http://allthingsd.com/files/2011/12/damocles.png
The Sword of Damocles parable illustrates the constant fear with which many people in authority live. Wikipedia explains that in the fourth Century BC, Damocles was a courtier in the court of King Dionysius II of Syracuse, Italy. In the parable, Damocles praised his King that, as a great man of power and authority surrounded by magnificence, Dionysius was truly extremely fortunate. The King then offered to switch places with Damocles, so that Damocles could taste that very fortune at first hand. Damocles quickly and eagerly accepted the King's proposal. Damocles sat down in the king's throne surrounded by every luxury, but the King arranged that a huge sword should hang above the throne, held at the pommel only by a single hair of a horse's tail. Damocles finally begged the King that he be allowed to depart, because he no longer wanted to be so fortunate.
.
Subscribe to:
Posts (Atom)





