Tuesday, 9 April 2013

Another daft opinion from the Article 29 Working Party



If I were an academic lawyer, steeped in the minutia of European data protection laws, I would probably savour the latest 70 page opinion from the Article 29 Working Party. Packed with commentaries on legal oddities, surely this is the stuff that keeps the academic community salivating.

If, on the other hand, I were a busy data protection professional, trying my best to develop privacy notices in a language that resonated with customers, I would despair at some of the examples presented in the paper on how to ensure that personal data collected for one business purpose can legitimately be used for another purpose.

Finally, if I were a member of the public, I wouldn’t waste my time reading any of this stuff.  

Members of the public hardly read privacy notices at present, and I fear that even fewer of them are likely to attempt the far more comprehensive notices that are considered necessary if they are dealing with a data controller that has a complex business model and wants to change it.

For what it’s worth, I took the opinion with me to tonight’s meeting of the Crouch End Chapter of the Institute for Data Protection, and we all had a good laugh.

Why? Well, as colleagues opined:

Unfortunately, it suffers from the same problems as most Article 29 opinions in that they do not fully understand the areas they opine on. Most of the scenarios are clearly imagined rather than what companies actually do or want to do – which would have been more helpful. Their continued refusal to consult with experts in the area they are writing about only increases their lack of credibility.

Some of their conclusions of incompatibility in the scenarios are absurd (see 13 on page 35 - are we really going to let people continue to live in unsafe buildings and possibly die in fires because of data protection?!), and some conflate issues (see 14 on page 66 - conflates incompatibility with doing crime mapping properly). 

It goes beyond the law in some places, such as saying that the ‘decisional criteria’ (algorithm) for profiling must be disclosed in a privacy policy. This is not the case and only has to be disclosed if an individual requests this information when making a subject access request.

It is also inconsistent. In one example of a bank saying it processes the data to provide financial services and also to “prevent fraud and abuse of the financial system, and to comply with legal obligations requiring that certain information is reported to the competent public authorities”, it suggests that the fraud and legal obligations uses while compatible are too vague to be a specified purpose. Another scenario involves an energy company using smart meter data to detect fraud and abuse, however, there are no concerns about this and the safeguards in place merely include “transparency towards data subjects”. There is no suggestion about what level of detail an organisation is supposed to provide in relation to uses of data for fraud purposes. Too much information here would allow people to circumvent the fraud detection processes!

Another example highlights how they see the rights of individuals taking precedence over a business being profitable in that a fictional garden and DIY company is so transparent about how its loyalty card customer discounts are calculated that the customers are already swapping tips on forums about how to game the system and get bigger discounts – which is apparently of no issue at all.

The opinion  also goes too far in promoting the Napoleonic code approach: in one scenario where a car manufacturer has a legal obligation to inform buyers of defects in a car that needs to be recalled, and does so by using a database of car owners from another source. Despite the (general) obligation being in law and the public health and safety reasons, they still argue that, although there is a strong indication of compatibility, the law should really be updated to explicitly provide for the disclosure to the car manufacturer.

Example 16 on page 67 suggests that crawling the web and using information individuals have made publicly available for other uses such as marketing, is likely to be an incompatible use. However, the example is so specific as to be useless – people vouching for an alternative medical practitioner by putting up their illness details and how they were helped, and this being crawled by an online vitamin supplement organisation to market their products.  In any event, this example does not work under UK law, as the example is of individuals voluntarily putting their information online and a different company collecting and using the data for marketing. The relevant data protection principle says: "Personal data shall be obtained only for one or more specified and lawful purposes, and shall not be further processed in any manner incompatible with that purpose or those purposes." The vitamin company obtained it for the purpose of marketing and used it for that purpose. Its lawful basis is legitimate interests (schedule 2) and that it was made publicly available (schedule 3).

In summary, the Article 29 Working Party has done it again.

What a missed opportunity. Had they have published the opinion a day earlier, on April 1, we could all have enjoyed it as a joke.


Source:
Article 29 Working Paper
 203 [00569/13/EN]

Saturday, 6 April 2013

British cookie compliance: how good is this!

We Brits really have done a brilliant job in ensuring that we are all following the cookie rules.

How do I know?

Well, I’ve taken a quick squint at the ICO’s casework log. During the first nine months of the current financial year, the ICO’s mighty Privacy & Electronic Communications casework team dealt with just three cases. Yes, three

This compares with 1,175 cases involving automated phone calls, 934 cases involving live phone calls, 873 email and 51 fax cases. Oh, and a case involving telephone directories, too.

This must be a cause for celebration.

We should all feel free to take the rest of the day off.

Message to the European Commission:  You may get tired of us occupying the awkward corner, but when we set our mind to it, we can be mightily impressive at implementing some of the rules!

Footnote:
These statistics do not quite tally with statistics reported elsewhere on the ICO’s website, where a cookie enforcement activity report notes that “Between 25 May and 21 November 2012 we received 550 reports. In the same period, individuals used our website to report over 53,000 concerns about unwanted marketing communications.” There is obviously difference between a “report from an individual” and a decision to open a “case”. But whatever the true figures are, the message is the same – which is that complainants are evidently much more concerned at issues other than cookies.

Sources:

.

Friday, 5 April 2013

Is Viviane Reding telling us the truth? (Or has ‘The Guardian’ got it wrong?)


Owen Bowcott, in today’s on-line edition of The Guardian, has written an article about whether the “right to be forgotten” provision in the draft General Data Protection Regulation actually means very much. 

He quotes, for some reason, however, a claim by Viviane Reding, Vice President of the Commission, that:  "This piece of legislation is one of the biggest market-openers of the last few years. It eliminates 27 conflicting rules [one for each EU state] and replaces them with ... a mechanism for the whole continent. This means saving €2.3bn (£1.9bn) a year.”

It would be great to nail this “savings” claim for once and for all. 

So many people have challenged the claim that I don’t have the energy to list them anymore. But statistics (even those reported in The Guardian) do tend to get repeated endlessly around the internet. 

And we all know how hard it is to remove or correct them following their initial publication.  

If I were a zombie from Outer Space reading Owen’s report, I would be left with the impression that the British Government was opposing a measure that would save European data controllers some €2.3bn a year.

I don’t know anyone who believes that claim – so please, can a group of independently minded folk pop over to the pub this lunchtime and jot down on the back of an envelope a set of more credible figures for us all to appreciate?  

Alternatively, could the European Commission kindly publish its own independently audited cost compliance assessment?

And, if the outcome is that these proposals actually result in a saving of €2.3bn a year, then I will gladly eat my hat and do my best to ensure that the British jury award Viviane Reding’s home country Luxemburg the maximum “douze points” in the forthcoming Eurovision Song Contest.  

Source:

.

Wednesday, 3 April 2013

Data Breach Notification: Shocking proposals for daft new rules


In what can only be described as a moment of madness, a shocking proposal to change the current breach reporting requirements for public electronic communications service providers is making its way through the usual channels within the European Commission.  

The significance of this development is hard to underestimate, as it could affect many more data controllers than just communication service providers. 

This is because the breach reporting rules that currently apply to service providers are quite pragmatic and have been proposed as a much more acceptable alternative to the over-engineered proposals that are contained in the (much criticised) draft General Data Protection Regulation. 

Unfortunately, these rules are evidently far too pragmatic for certain EU officials. So, some bright bods in DG Connect (otherwise known as the Directorate-General for Communications Networks, Content and Technology) have proposed that the breach reporting process should be much more onerous. 

And, as the proposals in this working document are also cast as a Regulation, rather than a Directive, it will be much harder for local regulators to implement them in a way that can be ignored meets local cultural requirements.

If the current (leaked) draft Regulation is passed, the service providers (and the regulators) face new requirements that will be overly bureaucratic while delivering negligible improvements in terms of actually dealing with data breaches.

A great concern is that if we are not careful, all data controllers will be forced to adopt similar breach notification practices should these requirements will be mirrored in the draft General Data Protection Regulation. While the current GPDR proposals are crazy, these are hardly any better.

Any thoughts of a more sensible approach to breach reporting should be held in check until this mess has been resolved.

Those that are sufficiently concerned will be dismayed to learn that a the proposals contain strict requirements to harmonise breach reporting practices across the EU, regardless of whether individual regulators have the resources (or the inclination) or to deal with the incidents that will have to be reported. 

New rules will prescribe what constitutes a personal data breach, the elements to be taken into consideration whilst assessing adverse effect, and on how information notice shall be given to individuals subject to a breach. All data breaches will have to be reported to the regulators, no matter how insignificant. Quite why is anyone’s guess.

There will also be a change in timing. Out goes the (very sensible) rule to notify regulators "without undue delay",  and in comes an obligation for service providers to notify them "no later than 24 hours" after the detection of the personal data breach. And there is a further obligation to update the regulator when the provider has a better understanding of the breach. Just what the regulator will do between the moment of the initial notification and the update is anyone’s guess. Not a lot, I’ll be betting.

Regulators will be obliged to provide secure electronic means for providers to notify personal data breaches in a common format. This is going to be fun, given the practical difficulties that everyone faces in developing secure communications channels. I predict that the “security” of these means will come under regular scrutiny from the hacking fraternity.

Also, the content of the notification forms will be prescribed – which again will be fun. Anyone fancy entering a sweepstake to guess how long the form will be? 

As a friend who is much closer to the issue than me put it: “In a nutshell, the proposals seem to entrench some of the provisions which have attracted substantial criticism in the draft General Data Protection Regulation.” 

Whether those working on this proposal have been in touch with DG Justice, or any of the Parliamentary Committees that have submitted so many amendments to the breach notification provisions in the draft GPDR, is anyone’s guess.  But, given the current text of this measure, it’s hard to believe that they have taken account of any constructive criticism these bodies might have offered.

So what can be done?

First, we need to monitor the progress of this proposal very carefully. Then, we need to ask how draft standards like this can emerge, despite (according to the text) the Article 29 Working Party having being formally consulted. 

Next, data controllers that are not even service providers should consider making representations about these measures – otherwise they might be imposed upon them as a fait accompli. 

And finally, all sensible folk need to lobby to ensure that whatever emerges from this deliberative process is a measure that is fit for purpose, rather than just destined for the regulatory scrap heap.

Its daft proposals like this that give the European Commission a bad name!

Source:
Draft leaked version of COCOM12-25REV2 RegCom N°: D023457/03
If it were not true, this story would have made an ideal April Fool’s joke. However, the image is the front page of the leaked proposal as at 9 January 2013. Presumably it won’t be long before Statewatch publishes the rest of this working document on the internet.

.

Monday, 1 April 2013

Article 29 Working Party publishes opinion on Google Glasses

With impeccable timing, the Article 29 Working Party has published an opinion on the privacy implications of Google Glasses.

Evidently, for the last 7 months, regulators have been given unprecedented access to Google’s research files and have even been able to test the devices for themselves. 
So, as the trial specs are being supplied to a select group of 1,000 Google Beta trialists, the Article 29 Working Party’s opinion is also being made available to them.

258 of these trialists, although American citizens, actually live in the EU, and so it is quite important that they fully appreciate what the European regulators think of this product. I understand that some 87 of these trialists are students who currently live in Germany, but they have each promised only to use the Google Glasses when they travel outside of Germany. 

The 109 page opinion is written mostly in French – but that won’t affect the Googlewearers, as they will be able to use the pre-installed Googletranslate App. This App takes an image of the document the person is reading, and translates it into any language preferred by the wearer, displaying the text on the Google Glass itself. A wave of two fingers in front of the text prompts an aural, as well as a visual, translation of the material. 

Another pre-installed App is the facial recognition feature which, I am told, came in very handy at the last meeting of the Article 29 Working party. Finally, it appears, the regulators were able to recognise all of their colleagues, and from which authority they came from. Consternation arose, though, when a German regulator also managed to activate the Googlecreditcheck App. Representatives from Greece and Cyprus fled the room after he told everyone else how much money they had in their bank accounts.

The only downside to the Working Party’s opinion (other than the fact that the trialists’ data has to be stored on a shared server that only the CNIL and Google’s Data Supremo, Peter Fleisher, can access) is how users have to deal with the plethora of “cookie” notices that appear each time they navigate to a new web page. (Navigation is controlled by was of a shake of the head to the right or the left.) The “cookie” notices remain in view until the user raises one finger in front of the camera to indicate that they accept the installation of a cookie, and then a second finger to indicate that they are really sure they want the cookie to be installed.

So, if you see some odd people, constantly shaking their heads and flicking two fingers at people, please don’t get too upset.  They’re doing no evil. They’re just on Google.

  
Source:
Article 29 WP Opinion 14/13 on privacy implications, fundamental safeguards and appropriate measures for data controllers wearing Google Glasses

.

Thursday, 28 March 2013

Confidential discussions continue

It is evident that confidential discussions are underway between a range of interested parties, all of whom have conflicting views on the proposals for a new legislative framework for European data protection. Indeed, there are so many different sets of confidential discussions going on that barely anything interesting about them is being reported.

People are obviously so busy mulling over this stuff that there’s no time for them to write about what they are up to.

So, I thought I might add something new to the mix.

I have deliberately refrained from reporting any personally identifiable information to deter fellow bloggers or journalists from contacting relevant participants with a view to publishing articles on this development themselves.

An extremely useful meeting took place in a restaurant at the Royal Exchange in the City of London today. A very select group of diners discussed how best to improve the plight of beleaguered data protection officers, who were constantly striving to ensure that they still knew what they actually needed to know to do their job properly.

The discussion moved on to how companies who had little concept of compliance with data protection mumbo jumbo matters could better consider just what risk they ran.

A cunning plan was hatched.

This plan will see the light of day in the fullness of time, once the principal stakeholders complete their Easter breaks and return to work.

Who might be concerned at this development? 

Certainly not people who are keen to promote high data protection standards.

Perhaps people who hope that their sloppy data protection standards will remain unnoticed for a few more years.

The best bit about the event was that almost no one mentioned “the draft Regulation”. And the person who mentioned “the draft Regulation” very quickly realised what they were doing, and changed the subject.

No. Today saw a group of Brits considering a British solution to a British data protection problem. The answer won’t have to wait for any co decision procedures between the European Parliament and the Council of Ministers. It can go ahead this year. Not next, nor the year after.

More news on precisely what cunning plan has been hatched to address the issue under discussion will emerge later.

Meanwhile, happy holidays.


Note:
If anyone fancies meeting for lunch towards the end of April for a confidential sharing of information about what everyone’s up to and what we think is likely to be achieved (Regulation-wise), please let me know and I’ll arrange something in the City.


Image credit:
http://jolamble.com/wp-content/uploads/2011/06/shh.jpg

.

Friday, 22 March 2013

Something for the weekend?

I have enjoyed reading this Parliamentary report, which says little that is new and contains recommendations that are likely to be mostly ignored duly noted with care and concern by the Government. There may well be one significant recommendation that the Government will strongly support though – which is to ignore a recommendation in the Leveson Report that the ICO be reconstituted it as an Information Commission, led by a Board of Commissioners with suitably broad expertise. Evidently, the current model is still fit for purpose – although it ought to be accountable directly to (and funded by) Parliament, rather than be funded by the Ministry of Justice.

Two key issues struck me as I read it.

First, funding for the ICO’s Freedom of Information work has been slashed with severity that would shame even Quentin Tarantino. That budget has been cut by 23% from £5.5 million in 2011–12 to £4.25 million in 2012–13. In line with public spending targets, there will be a further cut of 6% in 2013–14,  and the Ministry of Justice has asked for a business case showing how the work would be impacted by a further 5% cut in that year.

The message to those who fancy exercising their FOI rights in future is that they should be prepared to dig deep into their own pockets to fund the civil litigation that could be necessary to help enforce their statutory rights. The ICO is unlikely to be able to intervene to a significant extent on their behalf. Public authorities are hardly likely to be able to fund many FOI posts, either. The message to public authorities who fancy ignoring an FOI request in future is that such temptation may be even harder to resist.

Second, the public concern at unlawful data handling practices has not been reflected by the penalties that the courts impose. Accordingly, it may not really matter if the maximum fine levels are dramatically increased – current evidence is that the actual level of fines will continue to remain at the bottom end. The reason for this is clear – the level of the fine depends on the means of the defendant, and in most cases, prosecutions are launched against people who are involved in domestic disputes and who have very few savings anyway.

Behaviours might well change, though, if Section 55 offences became “recordable offences”. These are the offences that are recorded on the Police National Computer, and where those who are prosecuted also have their fingerprints and DNA samples recorded for whatever period the police currently set. That might focus a few minds as to the severity of such offences. 

The Government continues to refuse to allow custodial sentences for DPA offences because other charges are capable of being made against defendants that do permit custodial sentences to be imposed (paragraph 43). These charges include:

·         Unlawful interception of communications: Regulation of Investigatory Powers Act 2000
·         Unauthorised access to computer material: Computer Misuse Act 1990
·          Dishonestly making a false representation: Fraud Act 2006
·         Bribing another or being bribed: Bribery Act 2010
·         Unauthorised access to computer material: Contrary to section 1 of the Computer Misuse Act 1990
·         Unauthorised access to computer material with intent to commit another offence: Contrary to section 2 of the Computer Misuse Act 1990
·         Phone hacking: Regulation of Investigatory Powers Act 2000
·         Misconduct in public office: common law offence
·         Inchoate and accessory offences including attempt and conspiracy

This is an interesting point, and I would love an academic to set his students the research task of identifying how these offences have been prosecuted over the past few years (should the CPS also have been able to have charged the defendant with a Section 55 offence), what penalties have been imposed and whether they really have served as an effective deterrent.

If you have not already done so, you might like to read the report this weekend.


Source:
http://www.publications.parliament.uk/pa/cm201213/cmselect/cmjust/962/962.pdf