Thursday, 7 March 2013

Manchester: the ICO does it again

An enormous crowd appeared on Tuesday to attend this ICO’s Data Protection Officer Conference in Manchester. Despite increasing capacity by over 60% this year, the venue simply wasn’t large enough to accommodate everyone who had wanted to attend. It shows how important all this privacy stuff has become. 

I should report that almost everyone was on their best behaviour. The exhibitor’s stands were much appreciated – perhaps because the focus was on the many facets of the ICO, and the organisations that were not “commercial” in nature, but existed to share best practice and offer forums where similarly affected souls could work out how to deal with data protection issues at the coalface, as it were.

Francoise Le Bail, Director General for Justice at the European Commission was present and on fine form. Evidently, if there is a low level of trust in a country, then consumers won’t be as economically active on-line than if there were higher levels of trust. Given the fact that the UK has one of the highest internet penetration rates of any EU Member State, I can only assume that the UK enjoys a relatively high level of trust. But, I was too polite to put that point to the keynote speaker.  

Deputy Commissioner David Smith made a very telling point when commenting on the latest proposals to harmonise EU privacy laws. As far as he was concerned, what was most important was that there should be greater consistency around Europe, as opposed to harmonisation. The law should be consistent with regard to national cultural sensitivities. So, if the German’s didn’t like Google’s Streetview service, then that was fine – so long as the Brits, who evidently liked it, could continue to have it. I am greatly simplifying David’s views, and I do apologise for this, but you get the gist. 

Turning to those who misbehaved.  

I’m not referring to those audience members who, during the Question Time session, applauded me when I asked if the ICO would prefer a power, rather than imposing civil monetary penalties on public authorities (and thus return public funds to the Treasury), instead to require the offending authorities to spend money on data protection awareness campaigns and other initiatives that would enhance local standards.   

Actually, I’m referring to 63 delegates who, by not informing the ICO that actually they wouldn’t be attending, denied a further 63 potential delegates from sharing such a great occasion. But, the ICO does know who they are – so this happy bunch can expect to have their 2014 conference applications rejected, and for the ICO’s enforcement team to “invite” them to apply for a voluntary data protection audit later this year.

As the Chairman of a not-for profit professional conference organisation (the Data Protection Forum), I feel the ICO’s pain when it tries to anticipate delegate numbers and ends up wasting money (on catering costs, etc) when those who have said they will attend ultimately don’t. Or when it has to turn people away when there was space after all.

But that’s a minor quibble. The ICO’s team put on a great event and I can’t wait to learn what surprises are in store for those who are lucky enough to attend next year. A cabaret from the ICO’s chorus singing data protection ditties? Information Commissioner Christopher Graham, Britain's "go to" regulator, appearing on stage in a rickshaw pedalled by the European Data Protection Supervisor?  Or a presentation beamed live from a UK prison featuring someone who has been jailed for committing a data protection offence? 

Pencil the date in your diaries now. 

(Hopefully) looking forward to seeing you at the next ICO’s Data Protection Officer Conference in Manchester on Tuesday 11 March 2014.  


Source:
http://storify.com/iconews/data-protection-officer-conference-2013-dpoc2013
Question Time session - http://www.youtube.com/watch?v=C5FNMruiK6s (at 7mins 22 secs)
.

Sunday, 3 March 2013

Britain’s data protection elite to be split in two this week

Britain’s data protection elite will split into two camps immediately after the ICO’s annual conference in Manchester on Tuesday. Most data protection officers will return to their workplaces and carry on working as usual. A select elite, however, distinguished by the size of their conference budgets, will journey to Washington DC for even more days of data protection conferencing.

Whether those lucky few who face a week’s worth of conference sessions  will be any better informed as to what the proposed General Data Protection Regulation (or Directive – take your pick) will contain, I really don’t know. Actually I think I do know. And the answer is that they will almost certainly be just as mystified about the final outcome as the rest of us.

Why so?

Events, dear reader, events.

Until last week’s elections, I had underestimated the strength of apparent disillusionment at the great European Project by the British electorate in Eastleigh, and throughout Italy generally. And, in a few month’s time, German citizens will be given the opportunity to express an opinion on further European integration, when national elections are held.  

Governments in member states and politicians in the European Parliament will, I’m sure, redouble their efforts to make the EU as great a place to live and to do business in as possible.  And the pressure will be on to respect people’s fundamental human rights - but not at the cost of soaring national social security bills, should sizeable populations from one member state decide to move and apply for more generous social benefits in another member state. “Benefit tourism”, as some commentators describe it.  Or when a court designed to uphold fundamental rights acts in ways that are totally unacceptable to democratically elected Governments. 

Someone needs to do a bit more selling if businesses (and public authorities) are to welcome the additional costs that appear to be associated with the higher data protection standards that are implied by the latest drafts that are emerging from the relevant European parliamentary committees.

To be frank, I don’t see many people selling the new proposals. Perhaps all the good work is being done behind closed doors, to give the relevant stakeholders ample opportunities to reach private deals.

Given the atmosphere in which private deals will be made, I really don’t think anyone has a clue what will happen.

Does anyone know what the current Italian data protection strategy is? (Or what the next Italian Government’s strategy will be, if another election is called in a few month’s time?) Or what the German Government’s strategy will be after the German elections? 

If we don’t, then how can we judge what deals might be on the table when the elites finally agree on how to lead us all to an even greater future?  


Image credit:
http://albatros-africa.com/tours/namibia-in-a-nutshell-special

.

Saturday, 2 March 2013

The great fines debate continues


Members of LinkedIn’s European Data Protection Forum will be aware of the current debate on the effectiveness of mandatory data protection fines.

You know the issues, so I won’t bother rehearsing them here.

But I have noted that one (German) participant has recently fallen into an elephant trap.

His intervention included the following: 

The right consequence is to strengthen the power of the authorities and give them the option to put higher fines. I mean if people do not care about speed limits in traffic rules one measure might be raising the fines for speeding - that's how easy it is. 

And Germany is a good example that strict data protection rules are not bad for the economy. As I stated in one discussion before Germany has one of the strongest economies in Europe at the moment and the strictest data protection law. Maybe data protection even pushes the economy in the long term?

That intervention caused me to choke on my morning coffee. It wasn’t long before I had sent the following retort:

"Please don't try to argue that Germany has one of the strongest economies in Europe "because" it has the strictest data protection law. If the inference is that economic success is delivered through strong data protection laws, and all "failing" countries have to do to improve their economies is to strengthen their data protection laws, then I find myself violently disagreeing with you. 

Take another example - with the singular exception of Kraftwerk, German contemporary musical culture is abysmal. German bands are awful. But, Germany has a strong economy, So are you also inferring that an abysmal contemporary musical culture is also a precondition of a strong economy?


Image credit:
http://www.philadelphiaplumbingheatingac.com/wp-content/uploads/toilet-bucket-money.jpg
.

Wednesday, 27 February 2013

Surely this can’t be because of data protection ...

If the Daily Mail is to believed (and I appreciate that’s a big “if”), then today I have come across another piece of evidence which indicates that European policy makers may well be incapable of agreeing on the meaning of some of the most important concepts of data protection law, like fairness and consent.

This blog is not designed to criticise the policy makers themselves – more it’s to point out that various communities within Europe have very different social and cultural expectations as to what is considered appropriate behaviour. And I’m all for local communities being able to respect their own cultural sensitivities.

The evidence is the report that policy makers in Berlin have recently decided that it is not appropriate for a German TV company to copy the format of the British TV series One Born Every Minute”, which follows  staff and patients on a busy maternity ward. Why? Well, evidently, because it was an invasion of privacy for newborn babies.

Given that, in the UK, the viewers only get to see each baby for a few seconds after their birth, it’s really hard to appreciate why their fundamental rights can take precedence over the rights of the nursing staff and the patients, who really are the focal points of the programme, and who would certainly have signed as many consent forms as any conscientious broadcaster would have created.

I do hope that this story is inaccurate. I do hope that the inference – which is that “German data protection rules ” have prevented potentially great TV programmes being made in Germany, is incorrect. 

And I am so glad that the bods at the Information Commissioner's Officce are evidently happy that the British version of One Born Every Minute” doesn’t breach any sensible UK data protection rules.

If the German viewers aren't allowed to see their own stories, hopefully they can pick up the British version, so that they can enjoy what they have been forbidden to create themselves.


Source:
http://www.dailymail.co.uk/news/article-2285292/German-city-bans-version-British-reality-One-Born-Every-Minute-claiming-invasion-privacy-newborn.html

Image credit:
OurBabyNews.com
http://www.plushbeds.com/blog/sleep-science/how-to-sleep-when-you-have-a-newborn/

.

Sunday, 24 February 2013

Another wild claim about "that" Regulation?

The Dutch MEP Sophie In 't Veld has high hopes for the forthcoming General Data Protection Regulation (or whatever it will end up being called). 

Apparently, new rules can force companies into innovating, and could give the EU a competitive advantage. I’m not sure over whom, but I suspect that what is meant behind the claim is that those data hungry non EU -based organisations (mentioning no names, of course) would find their services less compelling if only EU the EU organisations got their regulatory acts together.

Well, if that happens, then I’m all in favour of the new  rules. 

But is it likely to happen? 

How much additional red tape usually results in a company obtaining a competitive advantage?
 
Answers, please, on a postcard, to the usual address.

And make the handwriting legible this time. Too much time at the keyboard kills those essential handwriting skills. 


Source & Image credit:

.

Wednesday, 20 February 2013

Decision time at the European Parliament

Glancing at a recent news report, I see that, coincidentally, some European Parliamentary Committees are voting on a wide range of amendments to the proposed General Data Protection Regulation at almost the same time that various European regulators are threatening (again) to take action against Google for apparently behaving in an awful manner.

Presumably, these events are not linked.

Presumably, there is no attempt on the part of certain regulators to keep stories about awful overseas-based data controllers in the minds of the public (and their MEPs) at the very time that some MEPs are supposed to be wading through documents stuffed with impenetrable data protection amendments. 

If the rules were changed to allow European parliamentarians only to take part in votes on amendments and issues that they understood, I expect that the number of politicians eligible to take part in votes on the Regulation would drop quite substantially.

As it is, I’m sure that lots of amendments will be waved through by people who may not fully appreciate the financial implications of what they are doing.

But never mind.

Perhaps when the Member States have had their say on what the instrument should look like, the text will have radically changed again.

Source:
http://www.irishtimes.com/newspaper/world/2013/0220/1224330264816.html

.

Monday, 18 February 2013

ICO fires more shots at the Regulation


At 82 pages in length, some people will be grateful that the ICO has just decided to publish in full its views on the proposed General Data Protection Regulation. Many more people will hope that someone else will read it for them, and produce a note summarising the highlights.  

(Top tip – if you can’t stomach all 82 pages, there are a 2 pages of similar stuff elsewhere on the ICO’s website.)

Well, this blog is not a note about any of the highlights.

But it does cast some light into the debate about two of the controversial areas – one of which I suspect that many Data Protection Officers will not have been unduly concerned about. However, the issue still deserves careful thought by Member States. It concerns the structure of the European Data Protection Board. This is evidently what enough members of the Article 29 Working Party are planning to call themselves, although I’ve recently heard that not all members of the Article 29 Working Party could agree on a new name for that august body.  

Anyway, the issue concerns the European Data Protection Supervisor, and the role that person has to play in future. As we all know, the EDPS is an independent supervisory authority devoted to protecting personal data and privacy and promoting good practice in the EU institutions and bodies. He does so by monitoring the EU administration's processing of personal data; advising on policies and legislation that affect privacy; and cooperating with similar authorities to ensure consistent data protection.

And, as we all know, Article 2.2(b) of the proposed Regulation does not apply to the processing of personal data by the Union institutions, bodies, offices and agencies;.

So why should the proposed European Data Protection Board have to include someone who is not tasked with regulating any relevant institutions? The concept is hard for some people to accept.

But, it gets better.

Article 69 of the Regulation provides that: “The European Data Protection Board shall elect a chair and two deputy chairpersons from amongst its members. One deputy chairperson shall be the European Data Protection Supervisor, unless he or she has been elected chair.”

The ICO has commented: “We are not clear how this can provide for an election if one of the deputy chairpersons has to be the EDPS.”

I commend the ICO for its restraint. Others may well protest at the absurdity of a situation where a democratic election may need to be “fixed” to guarantee the election of a regulator who is responsible for institutions that are exempted from the regulation he is supposed to be supervising.

If this is European democracy in action, then I’m a banana.

In the UK, rotten boroughs in Parliamentary elections were abolished in the 19th Century. The most notorious borough was Old Sarum in Wiltshire. At one election, the electorate comprised 3 houses and just 7 voters, yet they had the responsibility of electing 2 Members of Parliament. It would be deeply ironic if the Regulation were to effectively propose their reintroduction.  

The second controversial area I want to highlight in this blog are the ICO’s very wise comments on Article 63, which provides that: For the purposes of this Regulation, an enforceable measure of the supervisory authority of one Member State shall be enforced in all Member States concerned.”

In a masterpiece of understatement, the ICO has suggested that: “We need to think through the implications of this degree of harmonisation. It could lead to the prohibition of a processing operation which is acceptable to the citizens of the UK – or – on the other hand – to unacceptable processing being legitimised on the basis of a simple majority vote.”

Just wait until those gentle folk in UKIP get to hear about this one. Other commentators might have preferred to shout “Keep your towels off our lawns.” We Brits don’t mind harmonisation when it makes sense, but we do bristle when we are required to adopt practices that go against the grain of our culture and national identity.

Sources:

.