Sunday, 19 September 2010

Reforming Data Protection, FOI and Human Rights – the Minister speaks his mind


Yes, I know the bureaucrats like to consult before presenting policy options and recommendations to Ministers, but I did get an insight into Ministry of Justice Minister Lord Tom McNally’s own thoughts recently. Tom McNally’s political career began in the Labour Party, then with the breakaway Social Democratic Party, and finally to the Liberal Democrats and the coalition with the Conservatives. Of course I have no idea if his officials will finally present him with a set of options that leads to a different conclusion, but it will be interesting to compare his current thoughts with those his Government will finally have once we, the masses, have also had our say.

On the challenges to data protection & data sharing, here are those precious words: “I sound like Fagin in "Oliver" when I say “we’re reviewing the situation” – but I believe people have a right to certain protection of information. One of the challenges of preserving liberties in the 21st century is that the speed and scale of technological change and the ability to gather, exchange and cross-reference information across organisations is now so intense that we have to have legislation in place to protect personal privacy.”

And on the biggest challenge to Freedom of Information? “How we stop the whole proesss from being completely swamped by a kind of cottage industry of people who overload the system. There has to be some balance between the casual “want to know” and the general “right to know”, and I’m not sure we’ve got that quite right. If we are going to expand the range of the Act we have got to make sure it’s efficient.”

Finally, on whether we are going to get a Bill of Rights? “First of all we are going to have a look at how the present legislation fits with national needs. I understand some of the frustrations about the Human Rights Act is often presented in the media, and there may be opportunities to give better explanation to the public about how it might be applied in the UK. But whether it’s the existing legislation or a Bill of Rights of our own, our commitment to the European Convention on Human Rights will be at the heart.”

Where did I get this stuff from – by reading the July/August edition of the MoJ’s staff magazine Insight. Essential reading for anyone wanting to follow their Minister’s thoughts.

So I’m planting his opinions here and look forward to returning to it later, when the settled views of the Government are known. If any gambling syndicates want to engage in a little spread betting, to wager huge sums of money on the extent to which Government policy is affected by anyone other than the Minister himself, feel free to start to place your bets now.

Saturday, 18 September 2010

More CCTV surveillance? Not in my back yard, thanks


Alex Deane, Director of Big Brother Watch, recently told me that, unbelievably, there are more CCTV cameras in the Shetland Islands than there are in the city of San Francisco.

Well, after a few days walking around this wonderful city, I can attest that there must be many more CCTV cameras in Reading than there are, here, in Rome. According to Wikkipedia, Reading has 142,851 citizens, while Rome has (accordind to last year's official figures) 2,726,927.

Why might a city 20 times smaller than Rome need more CCTV cameras? It’s really hard to argue that there must be more to steal in Reading, or that there is a pressing need to prevent vandalism.

Could it be that we have just gone totally over the top on video surveillance?

Walking around Rome, it really did not occur to me that the absence of CCTV surveillance was goading its citizens to behave in ever more feral ways. Indeed, walking around the Fountains of Trevi, or the Spanish Steps, or along the banks of the Tiber, I felt no sense of danger nor unease. Neither from the barbarians, nor the Barberini. And I find it hard to understand how CCTV cameras back in Blighty bestow an additional sense of corporate or social responsibility into anyone. They create good images for the TV programmes that will gratefully rebroadcast the best bits, but I find it hard to understand how effective it’s actually been in preventing the unsociable behaviour from occurring in the first place.

We Brits may just be bred like this. The Italians (and the fellow tourists I encountered) just seem to be beter behaved. Their "cultoral norms", for whatever reason, don't appear to be our "cultural norms".

So, if the greatly anticipated “savage” cuts in public expenditure result in the decommissioning of many thousands of local authority CCTV surveillance initiatives, will I be manning the “Keep CCTV in my Borough” barriers? I think not. Well, not until I’ve been viciously mugged in the full glare of one, anyway.

Thursday, 26 August 2010

European Commission “tweets” its overview of information management in the area of freedom, security & justice


“Allo Allo ... this is your Commission calling. We know you politicos aren’t going to read all 53 pages of our report, so we thought we would tweet you the best bits.

Euroland has got loads of databases in which the cops keep stuff about the bad guys & the usual suspects. The Schenegen Information System holds well over 31.5 million records alone.

They tell us that some records are kept for 15 years, while others are only supposed to exist for a day.

Some cops want to pool all the records into a single Euro database & trawl it when investigating serious crimes. But there’s no common definition of what a “serious crime” actually is in the EU.

Yippie! If all the records are in one place, then it’s going to be much easier to pass them to the Americans, the Canadians and the Aussies, when they ask us nicely.

Hang on though, what would the privacy yonks do if they thought we could set up an Uber Database of Euro Bad Guys? May be we’re better off with things as they are.

Pass us the wet towel ... we’ll polish the broad principles we’ve developed, and create some kind of action plan. We’ll kick decisions into the long grass and write a feasibility study – say in 2012.”



If you really want to know more about the information sharing databases that have been created within the EU for various law enforcement programmes, then you’re in luck, as last month the European Commission published an overview for the European Parliament and the Council. It covers the main purposes of each large programme, their structure, the types of personal information held, the list of authorities that have access to such data and the provisions governing data protection and retention.

The overview was published as Member States had asked the Commission to develop a more ‘coherent’ approach to the exchange of personal information for law enforcement purposes.

Naturally, a single, overarching EU information system with multiple purposes would deliver the highest degree of information sharing. But, the Commission has accepted that creating such a system constitutes a gross and illegitimate restriction of individuals’ right to privacy and data protection, and poses huge challenges in terms of development and operation.

So, the Commission considers that a series of compartmentalised (or federated) databases is more likely to safeguard citizens’ right to privacy than any centralised alternative.

The Commission isn’t too sure what to do next. It’s created a bunch of high level principles that will need an awful lot more detailed developmental work before their ideas are ready to be discussed by the rest of us. These high level principles (surprise surprise) relate to
• Safeguarding fundamental rights, particularly privacy & data protection
• Necessity
• Subsidiarity
• Accurate risk management
• Cost-effectiveness
• Bottom-up policy design
• Clear allocation of responsibilities
• Review & sunset clauses

It sounds as though the Bureaucrats and the Eurocops have got many, many more months of passionate debate before the next stage of this proposal sees the light of day.


[The actual communication from the Commission, COM(2010)385 final, published on 20 July 2010, can be found at http://ec.europa.eu/justice_home/news/intro/doc/com_2010_385_en.pdf]

Wednesday, 25 August 2010

100 posts and not out (yet): the verdict


How many of us have started something, only to give it up after a few weeks, after realising that actually, it was a bad mistake and that it didn’t fit into our lifestyle? I’ve done that occasionally with diets. So in this, my 100th posting of this year, I’m going to reflect on the point of blogging and on what it’s done for me.

I took the plunge into the blogosphere last November. I had just given up one craving, and wondered what I should replace it with. I subsequently wondered whether my jottings were going to be of any interest to anyone – before realising that I wasn’t that worried about entertaining anyone else anyway. I was really doing this just for me. “Is this simply an exercise in vanity publishing, or a serious attempt at creative writing?” I was asked by some close friends just after they had noticed that I had started to blog. It didn’t take me too long to realise that I wasn’t going to change the world purely by what I wrote. But, as I have explained, that really wasn’t the intention. Nor was it the intention to leak any state secrets, or place (too much) embarrassing information into the public domain. That’s a role for Wikileaks to play.

What it actually did was to give me a platform away from the office, and a way of forcing myself to both quickly form and express my own opinions on a range of issues – and then remain accountable for those opinions after having been brave (or foolish) enough to post them in an area where anyone could access them. And it’s given me an opportunity to develop a literary style that I could never use in my professional life. It’s taken some time, but I feel that I’ve found my voice on the internet.

It’s given me a vehicle to express views on subjects about which I am passionate. And I hope they are issues which at least interest a few others too. I’ve greatly appreciated the feedback I’ve received. Most of the time, people have written directly to me. On one occasion, comments were sent to my employer – although as this is a blog that is done in my own time, using my own equipment and on my own terms, it’s really not appropriate to associate anything I may blog about with any views that may be held by my employer. So, in future, don’t bother writing to my employer about me. Get hold of me if I publish anything that you find improper or inaccurate or otherwise offends – not anyone else. I’ve set up email account for this blog, which can be found in the “About Me” column on the left of the screen. Use that.

This is not about me and my work for my employer. This is personal!

I also hope that I’ve kept true to 12 rules I set myself last November, shortly after I started to blog. The rules were set out in a posting entitled “Behavioural Blogging: My 12 simple rules of internet etiquette,” The verdict, I submit, when benchmarking the last 100 posts against these standards, is that I have adhered to my rules pretty closely. But I’ll let you be the judge of that.

So, I’m not giving up just yet. I’ll carry on writing because I enjoy it. People are perfectly entitled to ignore me. If you don’t want to know what I’m writing about, then just avoid squinting at this part of the internet. But before I start to celebrate my centenary, I thought I had better remind myself (and the casual reader) just what rules I have been following. And, again, please feel free to let me know when I overstep them:

1 Tell the truth.

2 Write short blogs.

3 Publish them regularly.

4 Focus on a single issue for each blog.

5 Respect everything supplied in confidence.

6 Stick to what I know (or what I think I know).

7 Use plain language, not technical gobbledegook.

8 Make serious, as well as trivial, points in each blog.

9 Develop my own ideas, in my own time, using my own equipment.

10 Change the text when I write something that causes unnecessary offence or embarrassment.

11 Credit everyone I plagiarise.

12 Try to look on the brighter side of life. (I think I sense a song coming on ...)

Tuesday, 24 August 2010

Has Zurich UK just been mugged by the FSA?


If I were a Zurich UK shareholder, I think I might be asking directory enquiries for the name of a good human rights lawyer, as I would have a feeling in the pit of my stomach that the FSA had just breezed in and ripped off some of my human rights.

What do I think this? Because I’ve just seen a press release from the Financial Services Authority which has fined Zurich UK £2,275,000 for the loss of an unencrypted back up tape which contained confidential (but not “sensitive”, as the Data Protection Act defines “sensitive” data) details of 46,000 customers. The loss occurred 2 years ago. This is something which, had it have occurred 2 months ago, and the Information Commissioner’s Office led the enforcement action, might well have resulted in a penalty of significantly less than £500,000.

How can this be right? How can one administrative body be able to impose a fine of £3.25 million (excluding the “good behaviour” discount) and yet another administrative body can only impose a maximum fine of £500,000 for the worst possible data breach immaginable? It seems perverse, and I do hope to read a press release from the ICO sometime soon outlining its views on whether different regulators ought be permitted to impose penalties of a wholly different magnitude to each other. I wondered if the ICO had already issued a press release on the matter but no – today’s message from Wilmslow focussed on the discovery at a bus stop of an unencrypted CD containing old (“sensitive”) medical records of 112 patients from the intensive care unit of a hospital in Wolverhampton.

What also surprises me is that the most senior management levels within Zurich have apparently agreed to pay the fine. But why? Let’s have a good, public, fight about this. It may only be customer’s money they are playing with, but I really want to see a decent debate about the principles involved here.

On the one hand, Zurich UK appears ready to accept the punishment because the FSA says that it “failed to take reasonable care to ensure it had effective systems and controls to manage the risks relating to the security of customer data resulting from the outsourcing arrangement. The firm also failed to ensure that it had effective systems and controls to prevent the lost data being used for financial crime.”

But, we all know that, from April of this year, the Information Commissioner has new powers to impose fines when the business knew or ought to have known that there was a risk that a serious breach would occur, but failed to take reasonable steps to prevent it.

Call me old fashioned, but I can’t see much difference between the two competing sets of jurisdictions. The only thing that appears to be different is the size of the stick that each regulator can wield. I’m not convinced that this is fair. I don’t like healthcare lotteries, where levels of care vary depending on where someone lives. Nor do I like the concept of regulatory lotteries, where levels of punnishment depend on which regulator claims “dibs” over it first. Thank goodness, in either case, the fines go to the Treasury, rather than the regulator’s own coffers.

So, my brief to counsel would be to construct an argument to the effect that it is wholly unacceptable for Zurich’s customers to be expected to meet the costs of this FSA fine when Parliament, in its wisdom, has only recently given general guidance (in setting the ICO’s fining powers at such a relatively low level) about the true level of punishments that should be meted out to the miscreants who knowingly continue to use dodgy processes that could lead to losses of personal data.

Failing that, my brief to counsel would also be to take Lord McNally, Minister of State for Justice, out for a couple of pints and explain to him that we’ve got this great idea for a new clause in the upcoming Great Constitutional Reform Bill. The aim of the clause would be to set out a statutory code which clarified which regulator was allowed to take action against who and for what – so that Parliament can make the determination, rather than leave it up to any agreements between the regulators themselves.

These financial services people appear to live in another world, when it comes to fines and financial losses. I wonder if that was one of the reasons that the new Coalition Government are so determined to restructure the FSA and get its feet closer to the ground.

The FSA’s press release which explains what they did and why they did it can be found at http://www.fsa.gov.uk/pubs/final/zurich_plc.pdf

The ICO’s press release, explaining its views on the issue, does not yet appear to exist.

Monday, 23 August 2010

MoJ officials in listening mode


In a move that may well dismay civil servants working for administrations in some other EU Member States, the data protection team at the Ministry of Justice is so keen to assemble a body of evidence to support the UK’s case for reform of the Data Protection Directive that it’s not only asked for stakeholders to write in with their views, but it’s also hosting a series of workshops - to give stakeholders an opportunity to explain their views and have them debated. What a great idea. There’s probably still time for the civil servants in the other Member States to extend the same courtesies to their own stakeholders – but I wonder how many will.

The first set of workshops was held today, in Petty France. That’s the name for the building that used to house the Home Office (and is now the home of the MoJ). It’s recently been gutted and completely refurbished, and has become a very pleasant place to work. The old Home Office got so grotty that I often wished there was a mat by the front door – so the visitors could wipe their feet as they left.

In the spirit of these harsh economic times, no free lunch was served today. But the staff restaurant is extremely good. Some of us who were saying for both morning and afternoon workshops enjoyed a hearty meal there, rather than braving the rain to sprint over to the sandwich shops.

Anyway, back to the plot. The purpose of the workshops today was to enable data controllers, and representatives of organisations that comprised or serviced the larger data controllers, to present evidence which supported their views on matters relating to subject access requests and the costs of compliance, and also on the powers and penalties of the Commissioner. (I'm sure that other events will be held which will offer a similar platform to other groups of stakeholders.) None of the evidence was offered on Chatham House grounds. What I mean by this is that those who spoke were prepared to be accountable for what they said. And what they said was noted down by some awfully smart people, whose jottings will, I’m sure, be made available to the wider (data protection) community in the fullness of time.

None of what was said today will come as a surprise to the close observers of the British data protection community, although it may well appear a bit odd to people who are used to the workings of other jurisdictions. We Brits can be a passionate lot – and also quite a pragmatic bunch too. We like following general guidance, but we like the flexibility to do things in culturally appropriate ways. One size does not necessarily fit all. We like common sense, and having the confidence to apply common sense, rather than stick to rigid rules which could, if followed to the letter, result in perverse outcomes. We’re also quite a sociable bunch, so we like chatting to regulators to see if things can be sorted out informally, before anyone has to put their head above the parapet and go on the record. And, having a flair for theatricality, we also like it when someone wields a big stick, or when someone gets locked up. That makes us all feel better (unless we’re on the receiving end of the stick, or have just got ourselves locked up).

There was general agreement about issues relating to subject access requests – and I’ll leave it to the carefully crafted words of the rapporterus today to announce just what it was we all actually agreed on.

And as usual, we went off-piste, so to speak. You know what data protection professionals can be like. We weren’t asked for our views on data protection registration and notification issues, but we provided them anyway. We could all see the point in letting the ICO know who we were, roughly what we did, who the ICO should contact within the company when it became aware of a problem, and also how we were going to pay the registration fees. But that was about it. We couldn’t see much point in providing any more information on long and complicated forms – especially if that prevented lots of staff from the Commissioner’s Office from being able to escape from the drudgery of the Notification Department and be set free to work on the sexy stuff – like actually offering data protection advice, or helping resolve complaints.

More workshops at the MoJ are scheduled, and I’m looking forward to attending at least one of them. And of course I’m also looking forward (as we were all reminded a couple of times today) to sending in written comments, and real evidence, too. Feel free to write to Kavita Perry at informationrights@justice.gsi.gov.uk as well - we've all got until 6th October before we have to start asking for the deadline to be extended.

And, most importantly of all, I’m really looking forward to empowering the teams from the MoJ to engage with their European counterparts over the coming months. I want to do my bit to ensure that these guys really do know what they are expected to be talking about. They’ve looked us straight in the eyes, and they are taking the opportunity to understand just why it is we think the way we do. To civil servants in foreign climes, who prefer a more hands-off approach to those whom they wish to regulate, this British way of doing things may not be sufficiently pure in terms of developing data protection law and theory. But believe me, it tends to work awfully well in practice!


[If you want some hints about the sort of evidence the MoJ is after, take a quick squint at http://www.justice.gov.uk/consultations/call-for-evidence-060710.htm]

Sunday, 22 August 2010

Facebook Places – Will it be tweaked before it arrives in the EU?


Millions of us are becoming very comfortable thinking about privacy issues these days – and thanks to our friends at Facebook, concepts which were alien to most of the public just a few years ago are commonplace now. What is it that “the great unwashed” are about to have at their fingertips, and to what extent is it likely to cause them harm? These are a couple of the questions that the “usual suspects” will be considering as they think through the privacy implications of Facebook’s new location based tool. Currently available in the States, let’s see how quickly the pressure builds for it to be exported to more privacy sensitive countries (like ours!)

I remember participating in a series of earnest discussions with a trade body representing the UK mobile phone networks who managed to craft a series of measures to protect people from being harmed by the first wave of location based services about 8 years ago. My, have times changed. At that time the great fear was that children could be harmed by predatory adults, and therefore a whole series of protective layers needed to be verified and set in place before parents and guardians would be entitled to know the “rough” location of their offspring’s mobile device. The fear was that people could be subject to unwelcome pressure of others who had realized that the devices were not in the location they were supposed to be, etc. Were the kids really at school, or were they bunking off for the day? Perhaps they had just left their device on the bus. We’ll never know.

The result, I suppose, was to create a Code of Practice on Location Based Services which incorporated standards that were high enough to stifle the development of personal location based services using mobile devices for half a decade. They deemed (particularly by those who were determined to stamp out child abuse in all its forms) OK for corporate use, but not for social use. The code could be policed effectively by mobile network operators as they controlled “who” got to see the network records which explained “where” a device was at any given time.

These days, though, technological changes mean that a large number of stakeholders – not just mobile network operators – collect information which can reveal the location of a mobile device or laptop. Hey, some of these new players can even pick up tiny snippets of the content of someone’s communications (by mistake, of course) as their vehicles are driving over the place generating maps and other images and stuff!

But I digress.

As we spring forward and embrace the rapid advance of smart devices and the internet, for the first time it’s really make it possible for these services to be made available in a manner which far more transparent in terms of who had been given permission to see what. Location Baser Service providers could now, thanks to dashboards, offer a huge range of privacy options to users. This really wasn't possible just a few years ago, when mobile phones just had tiny screens above the keypad.

And, what has really impressed me, is the scale of the media coverage that accompanies the launch of the some of these location based services these days. Opinion formers are almost falling over themselves to discuss the privacy protections now available, and journalists are also getting in on the act by producing material which is incredibly easy to read and useful. Take a look at Patrick Miller’s great article in PC World which explains, using prose and pictures, just how Facebook’s new Places feature works on a smartphone or laptop.

Patrick explains how to set up the “places” account, and learn more about the places your friends are checking into. A flag will allow you to set which friends you wish to share your locations with – and naturally the flags can be disabled too. Business owners will be able to turn the listings to proper Facebook pages – and the mind boggles at the commercial implications of this smart move. Finally, Patrick explains how to turn off the whole application – which is (currently) a bit more complicated than setting it up in the first place.

OK, so if its going to be acceptable for the Americans, what will need to be tweaked for European sensibilities? I wonder if the regulators in some Member States are going to get excited at the possibilities of young people broadcasting their current locations to their friends, or people of certain religious views having to demonstrate to their mums that they really are at their regular place of worship, rather than behind the Co-Op. Will some European regulators demand that such a service should only be used by mature adults, rather than all smart phone and laptop users? If I have an “Anti Social Behaviour Order” and am banned from entering a shopping centre, will one of my “friends” – who co-incidentally is also a security guard at the shopping centre – have lawful authority to track me and get his employers to take action against me if he sees me somewhere I shouldn’t be?

Lots of questions. And hopefully a few answers will emerge from the American experience soon. And as it’s over there now, it won’t be long before it’s over here too!


For those sufficiently interested, the term “the great unwashed” was coined by the Victorian novelist and playwright Edward Bulwer-Lytton. He used it in his 1830 novel Paul Clifford: "He is certainly a man who bathes and ‘lives cleanly’, (two especial charges preferred against him by Messrs. the Great Unwashed)."

Patrick Millar’s excellent article can be found at: http://www.pcworld.com/article/203819/how_to_use_facebook_places.html