Monday, July 02, 2007

Passenger Data Sharing - EU and US

Here is the latest that has been in the press on the provisional agreement (subject to approval by the 27 Member States) between the EU and the US on passenger data sharing
European negotiators reached a provisional deal with the United States on Wednesday, ending a year of wrangling over how to share information about trans-Atlantic air passengers that Washington says is needed to fight terrorism. The tentative agreement will be put to envoys from all 27 European Union nations Friday for approval, said the diplomats, who spoke on condition of anonymity because the deal has not been finalized. Differences over how to balance security needs with concerns over passengers' privacy had deadlocked negotiations since a 2004 deal on data sharing was voided by an EU court last year for technical reasons.
However, see also Statewatch, which has also published the minutes dated 19 June 2007 at http://www.statewatch.org/news/2007/jun/eu-usa-pnr.pdf which provides some details on the provisional deal.

Thursday, June 28, 2007

OECD Recommendations

Here is a new post, I came across on a plan agreed by the OECD on privacy enforcement co-operation between countries transferring personal data.

"The world's most developed economies will co-operate to uphold privacy laws in the face of increasing amounts of cross border data transfer. The member countries of the Organisation for Economic Cooperation and Development (OECD) have agreed the plan. The new deal updates a 25 year old agreement on the upholding of privacy laws. A new deal was needed in order to guard against the privacy risks of the increasing amounts of personal data currently being sent from country to country. "The initiative is motivated by a recognition that changes in the character and volume of cross-border data flows have elevated privacy risks for individuals and highlighted the need for better co-operation among the authorities charged with providing them protection," said a statement from the OECD. The OECD recommendation outlines the ways in which member governments have agreed to help each other to protect privacy by increasing the amount of international cooperation on privacy laws. It also outlines how countries will assist one another in the enforcement of privacy laws."

Source: Out-law International effort on privacy protection is launched

See:

Social Networking

I have been busy lately with trying to get my head down on writing a few articles (one which is due in a fortnight) whilst attending the SCL annual conference (theme was Web 2.0) which was quite interesting. On the theme of social networking, there is a recent report published on Teens, privacy and online social networks by Pew Internet Project showing how the majority of teens manage their online profiles.

The majority of teens actively manage their online profiles to keep the information they believe is most sensitive away from the unwanted gaze of strangers, parents and other adults. While many teens post their first name and photos on their profiles, they rarely post information on public profiles they believe would help strangers actually locate them such as their full name, home phone number or cell phone number. At the same time, nearly two-thirds of teens with profiles (63%) believe that a motivated person could eventually identify them from the information they publicly provide on their profiles. A new report, based on a survey and a series of focus groups conducted by the Pew Internet & American Life Project examine how teens, particularly those with profiles online, make decisions about disclosing or shielding personal information. Some 55% of online teens have profiles and most of them restrict access to their profile in some way. Of those with profiles, 66% say their profile is not visible to all internet users. Of those whose profile can be accessed by anyone online, nearly half (46%) say they give at least some false information. Teens post fake information to protect themselves and also to be playful or silly.
Even without having to look at the law itself (either data protection, privacy etc.) this report sheds light on how individuals (teens) protect their identities when using social networking such as MySpace.

Monday, June 18, 2007

Webcast on Identity Management

There is an interesting webcast on The Management of Identity and Personal Information on the Internet: Public and Private Initiatives for Addressing the Problems. Speakers on this panel include Sir David Normington (Keynote Speaker) Professor Brian Collins; Dr Stefan Brands, Jonathan Bamford, Assistant Information Commissioner (Open Public Panel Chair). The picture (on the right - source: Source: Semantic Pool.de), perhaps, encapsulates the types of personal information we give online. In the meantime, here is the abstract of what the webcast is about:

There is much debate, and a number of competing initiatives, but the problems of identity and personal-information management over the Internet remain unsolved. These problems range from issues of convenience, such as requirements for multiple usernames and passwords, to the inability to carry out many transactions that require authentication of the user, to the security of systems that hold personal information, including identity information. Why do these problems persist? What are the opportunities in sight for moving ahead, and what risks are entailed in mitigating these concerns, including the failure to address these issues?


The Oxford Internet Institute organized a public panel to discuss this topic, chaired by Jonathan Bamford of the Information Commissioner's Office, and with a keynote by Sir David Normington, the permanent secretary at the Home Office. Other speakers include Professor Brian Collins (who combines the roles of academic, civil servant, and IT practitioner) and Dr Stefan Brands (an expert in privacy-enhancing technologies). The panel concludes with questions and an open discussion.

Wednesday, June 13, 2007

Google not covered by the Data Retention Directive

In the next stage of Google's saga, the Data Retention Directive 2006/24/EC does not cover search engine logs. According to Out-Law news:

Google is not bound by the Data Retention Directive when it comes to search engine logs, Europe's data protection committee has said. Google has used the Directive to justify keeping data, but OUT-LAW has learned that the law does not apply. Google has come under increasing pressure in Europe to anonymise its server data, but the company says that it will wait until 18–24 months have passed before anonymising. Among its reasons for this was the Data Retention Directive. However, a senior European data protection official told OUT-LAW today that Google cannot rely on that law as justification for its retention. "The Data Retention Directive applies only to providers of publicly available electronic communications services or of public communication networks and not to search engine systems," said Philippos Mitletton. Mitletton works for the European Commission's Data Protection Unit, which itself is represented on the Article 29 Working Party, the committee of Europe's data protection authorities." Accordingly, Google is not subject to this Directive as far as it concerns the search engine part of its applications and has no obligations thereof," he said. Google offers other services that will be caught by the Directive – notably its email service, Gmail, and its internet telephony
service, Google Talk. If Google's search function were caught by the Directive, it could alarm operators of any site with a search function – i.e. most large websites – because potentially they would be similarly caught and therefore need to store details of every search conducted and the addresses of the computers that instruct each search.

Whilst this provides clarity over the scope of the Data Retentions Directive, one should not forget that we have the Data Protection Directive 95/46/EC (DPD) that applies to the automated processing of personal information and to a lesser extent manual files (if it can be shown that it formed part of a filing system such as card indexes) and the Directive on Privacy and Electronic Communications 2002/58/EC (complementing the DPD). For more on this, visit the European Commission, FSJ website at http://ec.europa.eu/justice_home/fsj/privacy/law/index_en.htm.

See also:

Tuesday, June 12, 2007

Talk about Google!

Here is the latest on Google's data retention policy:

Google on Tuesday said it would cut the time for which it retains users’ personal search data to 18 months from 18-24 months, in a fresh concession to European Union data protection officials. The Article 29 working party, a group of national officials that advises the European Union on privacy policy, sent a letter to Google last month asking the company to justify its policy of keeping information on individuals’ internet searches for up to two years. Peter Fleischer, the internet search group’s global privacy counsel, wrote to Peter Scharr, chairman of the Article 29 group, confirming the move to cut the data retentoin period but pointing out that future data retention laws “may obligate us to raise the retention period to 24 months.” In a posting on the the official Google blog, Mr Fleischer wrote: “The internet is a global medium, and the principles at stake – privacy, security, innovation and legal obligations to retain data – have an impact beyond Europe, and outside of the realm of privacy. These principles sometimes conflict: while shorter retention periods are good for privacy, longer retention periods are needed for security, innovation and compliance reasons. We believe we’ve struck a reasonable balance between these various factors.”

Monday, June 11, 2007

Privacy Watchdog in India?

Came across this latest press release:

A data privacy watchdog is to be set up in India to oversee the country's IT industry amidst international concerns about the security of outsourced customer records and data. India does not have any data protection law equivalent to that in the UK and there have been recent cases of information being leaked from call centres to criminals who have then blackmailed the companies involved. The Data Security Council of India (DSCI) is being set up by Indian IT industry group Nasscom.

Tuesday, June 05, 2007

Reading to do

I have not had chance to read this recent report published by the Select Committee on Home Affairs, but according to the latest press release from Out-Law News:


"We consider that in the area of data protection there is evidence of insufficient political appetite for protective measures as compared to law enforcement ones," said the Committee's just-published Third Report. "We note the Minister's expression of continuing Government support for the Data Protection Framework Decision. However, if proposals for a Framework Decision were to be superseded by the data protection provisions in the PrĂ¼m Treaty, we would have serious concerns as to whether these were adequate."

Here is the full-text of the report:


See also:

Thursday, May 31, 2007

Google Saga

In the latest saga on Google's policy to keep its server log data for more than 18 months, the Art. 29 Working Party has published its letter to Google dated 16th May:

Although Google's headquarters are based in the United States, Google is under legal obligation to comply with European laws, in particular privacy laws, as Google's services are provided to European citizens and it maintains data processing activities in Europe, especially the processing of personal data that takes place at its European centre. As you are aware, server logs are information that can be linked to an identified or identifiable natural person and can, therefore, be considered personal data in the meaning of Data Protection Directive 95/46/EC. For that reason their collection and storage must respect data protection rules.The Article 29 Working Party considers a reduced storage period for server logs generated by the users of Google services as a valuable step to improve Google's privacy policies. However, it is of the opinion that the new storage period of 18 to 24 months on the basis indicated by Google thus far, does not seem to meet the requirements of the European legal data protection framework.The Article 29 Working Party is concerned that Google has so far not sufficiently specified the purposes for which server logs need to be kept, as required by Article 6(1)(e) of Data Protection Directive 95/46/EC. Taking account of Google's market position and ever-growing importance, the Article 29 Working Party would like further clarification as to why this long storage period was chosen. The Working Party would also be keen to hear Google's legal justification for the storage of server logs in general.

See also:

Saturday, May 26, 2007

Data theft - Call Centres

Newsnight presented a short excerpt on data theft, and in particular, the worrying problem of the ease with which personal information can be obtained from call centres located in India. Outsourcing of personal information to companies overseas is not new. However, the questions that will need to be asked (in the context of data protection) is the extent to which a UK organisation(s) (engaged in outsourcing activity) complies with the Data Protection Act 1998? Is there a data protection officer employed? If customer information is being outsourced to a company in India, are there adequate safeguards in place to ensure that data protection rules are in place? Just another reminder that the Data Protection Act 1998 (Sch. 1) contains eight data protection principles:
1. Personal data shall be processed fairly and lawfully and, in particular, shall not be processed unless-

(a) at least one of the conditions in Schedule 2 is met, and

(b) in the case of sensitive personal data, at least one of the conditions in Schedule 3 is also met.

2. Personal data shall be obtained only for one or more specified and lawful purposes, and shall not be further processed in any manner incompatible with that purpose or those purposes.

3. Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed.

4. Personal data shall be accurate and, where necessary, kept up to date.

5. Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes.

6. Personal data shall be processed in accordance with the rights of data subjects under this Act.

7. Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.

8. Personal data shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.

It is the eight data protection principle which is particularly relevant. A list of factors to take into account when considering an adequate level of protection can be found in Sch. 1, Part. II, para. 13 of the UK Data Protection Act 1998:

13. An adequate level of protection is one which is adequate in all the circumstances of the case, having regard in particular to-

(a) the nature of the personal data,

(b) the country or territory of origin of the information contained in the data,

(c) the country or territory of final destination of that information,

(d) the purposes for which and period during which the data are intended to be processed,

(e) the law in force in the country or territory in question,

(f) the international obligations of that country or territory,

(g) any relevant codes of conduct or other rules which are enforceable in that country or territory (whether generally or by arrangement in particular cases), and

(h) any security measures taken in respect of the data in that country or
territory.
India does not currently have data protection laws and the proposal to amend their existing Information Technology Act 2000 is likely to raise questions over the remedies available for breach of data privacy. This (ie. remedies) will need to be strengthened if it has not already been addressed and secondly, there will be a need for better enforcement mechanisms against organisations (based in the UK that outsource the processing of personal information of customers etc. overseas) that do not adhere to the UK DPA 1998. This can be particularly problematic, if an individual based in UK finds that his or her rights under the UK Data Protection Act 1998 is not adhered to because his personal information is processed abroad without the adequate legislative safeguards in place. First point would be to complain to the organisation that holds your personal information. If this is unsatisfactory, then the next point of call would be to contact the UK Information Commissioner's Office. Finally, the amendments to the current India Information Technology Act 2000 under the proposed Amendment Bill (2006) will be worth following. See also:

Thursday, May 24, 2007

Anti-ID theft

The European Commission is proposing legislation against identity theft. How much the proposals will complement the existing European Data Protection Framework (via the Data Protection Directive 95/45/EC and the Directive on Privacy and Electronic Communications 2002/58/EC) is less clear, but reading from the latest press release, this appears to be part of a Cyber crime initiative:

The European Commission is considering new legislation against identity theft. The proposal is contained in a just-published policy on EU-wide plans to fight cybercrime. The European Commission's policy on fighting cybercrime in Europe is the product of many years of consultation and focuses on greater co-operation between European police forces. Though the Commission said that it did not believe that new legislation would be useful at this stage in stopping the fast growth of cybercrime, it said it will consider anti-ID theft laws later this year. "No general legislation on the fight against cyber crime can be expected to be effective at this moment," said a Commission statement. "However … targeted legislative actions may also prove to be appropriate or needed in specific areas. As an example, the Commission will consider an initiative
regarding European legislation against identity theft in 2007. Legislative action could also include developing a regulation on the responsibility of different actors in the relevant sector." Overall, the Commission said that its cyber crime fighting policies would depend on improved co-operation and communication between law enforcement forces across Europe. "The main feature of this policy instrument is a proactive policy in reinforcing the structures for operational law enforcement cooperation," said the Commission statement." The Commission will launch a reflection on how this cooperation can be strengthened and improved."

See: Out-Law: Europe mulls anti-ID theft

Saturday, May 19, 2007

New book on Privacy and Technology

There is a recent book published by the National Academies Press entitled Engaging Privacy and Information Technology in a Digital Age:

Privacy is a growing concern in the United States and around the world. The spread of the Internet and the seemingly boundary less options for collecting, saving, sharing, and comparing information trigger consumer worries. Online practices of business and government agencies may present new ways to compromise privacy, and e-commerce and technologies that make a wide range of personal information available to anyone with a Web browser only begin to hint at the possibilities for inappropriate or unwarranted intrusion into our personal lives. Engaging Privacy and Information Technology in a Digital Age presents a comprehensive and multidisciplinary examination of privacy in the information age. It explores such important concepts as how the threats to privacy evolving, how can privacy be protected and how society can balance the interests of individuals, businesses and government in ways that omote privacy reasonably and effectively? This book seeks to raise awareness of the web of connectedness among the actions one takes and the privacy policies that are enacted, and provides a variety of tools and concepts with which debates over privacy can be more fruitfully engaged. Engaging Privacy and Information Technology in a Digital Age focuses on three major components affecting notions, perceptions, and expectations of privacy: technological change, societal shifts, and circumstantial discontinuities. This book will be of special interest to anyone interested in understanding why privacy issues are often so intractable.

The book is fairly lengthy, but a number of recommendations have been made including the establishment of a privacy commissioner. Here is a short extract from the executive summary, but worth reading the actual book:

Individuals can take a number of steps to enhance the privacy of their personal information and to become better informed about the extent to which their privacy has been compromised, although the effectiveness ofthese measures is bound to be limited. The committee thus recommends that if policy choices require that individuals shoulder the burden of protecting their own privacy, law and regulation should support theindividual in doing so. Firms and other organizations can design and implement self-regulatory regimes for protecting the privacy of the personal informationthey collect. Self-regulation is limited as a method for ensuring privacy,although it nevertheless offers protections that would not otherwise beavailable to the public. The committee offers a number of concrete recommendations to enhance the effectiveness of privacy policies. Specifically, organizations with self-regulatory privacy policies should take both technical and administrative measures to ensure their enforcement, routinely test whether their stated privacy policies are being fully implemented, produce privacy impact assessments when they are appropriate, strengthen their privacy policy by establishing a mechanism forrecourse if an individual or a group believes that they have been treated in a manner inconsistent with an organization’s stated policy, and establish an institutional advocate for privacy. The committee found that governmental bodies have important roles to play in protecting the privacy of individuals and or groups and in ensuring that decisions concerning privacy are made in an informedfashion. However, the U.S. legal and regulatory framework surrounding privacy is a patchwork that lacks consistent principles or unifying themes. Accordingly, the committee concluded that a less decentralized and moreintegrated approach to privacy policy in the United States could bring agreater degree of coherence to the subject of privacy. Two recommendationsf ollow from this conclusion. First, the committee recommends that the U.S. government should undertake a broad systematic review of national privacy laws and regulations. Second, the committee recommends that government policy makers should respect the spirit of privacy-related law.
See also

Friday, May 11, 2007

Privacy Enhancing Technologies

A recent press release from the European Commission on the promotion of Privacy enhancing technologies ("design information and communication systems and services in a way that minimises the collection and use of personal data and facilitate compliance with data protection rules") :

The Commission adopts today a Communication with the purpose of identifying the benefits of Privacy Enhancing Technologies (PETs) and laying down the Commission's objectives in this field, to be achieved by a number of specific actions supporting the development of PETs and their use by data controllers and consumers. The development of information and communication technologies is constantly offering new services which improve people's life. However, alongside these benefits, new risks also arise for the individual, such as identity theft, discriminatory profiling, continuous surveillance or deceit. Vice-President Frattini, Commissioner responsible for Justice, Freedom and Security, highlighted that: "To ensure that breaches of the data protection rules and violations of individual's rights are not only something forbidden and subject to sanctions under the existing legal provisions, but also technically more difficult, the Commission puts forward a set of actions aiming at developing and promoting the use of Privacy Enhancing Technologies." Viviane Reding, Commissioner for Information Society and Media added "On line services provide a lot of benefits and convenience to citizens and huge competitive advantages to European businesses. Yet for such services to enjoy large scale growth and so boost Europe's economy, people must have sufficient confidence that their personal privacy and legitimate business interests are being properly safeguarded".The use PETs can help to design information and communication systems and services in a way that minimises the collection and use of personal data and facilitate compliance with data protection rules. The use of PETs should result in making breaches of certain data protection rules more difficult and /or helping to detect them, therefore having a positive impact on consumer trust, in particular in cyberspace, all without losing the functionality of the information system. The Commission Communication adopted today reflects on the benefits of PETs, lays down the Commission's objective to promote these technologies and sets out clear actions to achieve them in the future by supporting the development of PETs and their use by data controllers and by consumers. To pursue the objective of enhancing the level of privacy and data protection in the Community, the Commission intends to clearly identify the need and technological requirements of PETs and further promote the development of these technologies (in particular through RTD projects and large-scale pilot demonstrations) and their use by industry and public authorities, involving a vast array of actors, including its own services, national authorities, industry and consumers. The aim is to provide the foundation for user-empowering privacy protection services reconciling legal and technical differences across Europe through public-private partnerships. To ensure respect for appropriate standards in the protection of personal data through PETs, standardization and coordination of national technical rules on security measures for data processing are envisaged.
See also:

Monday, May 07, 2007

European Data Protection Intensive Conference 24-25 May 2007

A two-day conference organised by Data Protection Law and Policy is being held in Amsterdam, 24-25 May 2007:

The European Data Protection Intensive is a unique event designed to solve the challenge faced by so many data protection professionals: to find authoritative information, and reliable advisors, on the data protection rules and regulations throughout Europe. Data Protection Law & Policy has organised this two-day Intensive to provide you with all the information and analysis on the legal and practical issues throughout Europe. The European Intensive is supported by the data protection specialists of Ecomlex, a network of 18 European law firms. This pan-european conference brings together leading data protection experts and a strong multinational representation. At the European Intensive you will find data protection experts from all twenty-seven EU states, plus Switzerland and Norway, who will be available to lead discussions as well as to meet for individual appointments. KEY ISSUES IN PLENARY SESSIONS The two-day Intensive will feature a day of Plenary Sessions which will focus on the key issues facing European data protection professionals, followed by a day of Group Interactive Sessions. SIX GROUP INTERACTIVE SESSIONS The Six Group Interactive Sessions will enable participants to ask experts directly about their particular concerns in any and every country in Europe. COVER EVERY COUNTRY The programme has been structured to enable participants to cover every single country, if they so choose, in the course of the second day of the Intensive.

See:

Thursday, May 03, 2007

Revisiting the notion of "Processing" and the UK Court of Appeal's Decision in MDU v Johnson

Some who are working in the data protection field will be aware of the recent decision issued by the UK Court of Appeal over the notion of "processing" in MDU v Johnson. Without going too much into the details of the case, however, the decision by the CA, appears to run contrary to the spirit of the European Data Protection and in particular, the interpretation of what constitutes "processing" of personal data. Art. 2(b)of the Data Protection Directive 95/46/EC provides that:

(b) 'processing of personal data' ('processing') shall mean any operation or set of operations which is performed upon personal data, whether or not by automatic means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction;

Processing is given a wide definition by the Directive and this is again, followed by other EU Member States. Perhaps, a belated response on one's part, but given the UK's implementation of the Data Protection Directive 95/46/EC, the discussion by the Courts to the Lindqvist decision was not helpful. The Lindqvist judgment provides that:

25. According to the definition in Article 2(b) of Directive 95/46, the term processing of such data used in Article 3(1) covers any operation or set of operations which is performed upon personal data, whether or not by automatic means. That provision gives several examples of such operations, including disclosure by transmission, dissemination or otherwise making data available. It follows that the operation of loading personal data on an internet page must be considered to be such processing.

26. It remains to be determined whether such processing is wholly or partly by automatic means. In that connection, placing information on an internet page entails, under current technical and computer procedures, the operation of loading that page onto a server and the operations necessary to make that page accessible to people who are connected to the internet. Such operations are performed, at least in part, automatically.

27. The answer to the first question must therefore be that the act of referring, on an internet page, to various persons and identifying them by name or by other means, for instance by giving their telephone number or information regarding their working conditions and hobbies, constitutes the processing of personal data wholly or
partly by automatic means within the meaning of Article 3(1) of Directive 95/46.

The UK Court of Appeal in MDU v Johnson at paras. 33-34 stated that:

I should also note that reference was made to the decision of the European Court of Justice [ECJ] in Case C-101/01 [2004] QB 1014 (Lindqvist). A web page containing personal information about L and some of her fellow parishioners was composed by L on her home computer and placed on the internet. She was prosecuted for processing personal data by automatic means. The national court referred to the ECJ the question:

Does it constitute 'the processing of personal data wholly or partly by automatic means' to list on a self-made internet home page a number of persons with comments and statements about their jobs and hobbies etc?

The ECJ held that the listing of the parishioners was the processing of their personal data, and that the process had been "performed, at least in part, automatically" because of the loading of the page on to the server. The selection of the data had been purely manual, yet there was no suggestion that the processing taken as a whole was not automatic. It is, however, important to remind ourselves of the terms of the question that was asked in Lindqvist, which was limited to whether using the computer to place the list on the net was processing. Plainly it was, for the reason given by the ECJ. By the same token, when Dr Roberts caused the computer to transmit her conclusions to the RAG data was being processed. But it does not help [J] to establish the latter point, because what he complains of is unfair conduct in the reaching of those conclusions, before that processing of the conclusions took place. I think that in the end it was agreed by the appellant that Lindqvist does not assist in our present concerns. But [Counsel] has more formidable support from authority nearer home, the decision of this court in Campbell v MGN Ltd [2003] QB 633.

That case was regarded by the Judge as conclusive in [J's] favour on the processing issue, and it must therefore be analysed in some detail.

The judgment is slightly lengthy and warrants another article to be written. At this stage, however, much work is still needed (whether by academics, policy makers, lawyers etc) to inform not only the public about the European Data Protection Directive 95/46/EC and what it is intended (see also the UK Information Commissioner's Website), but that if the UK Data Protection Act 1998 continues to be narrowly construed (in the light of cases such as Durant and Johnson), data protection laws in the UK may, in all but name, be considered weak!

ONI Conference: The Future of Free Expression on the Internet

There is a conference being held on the 18th May and hosted at the Oxford Internet Institute, which judging by the website is well worth going:

The OpenNet Initiative is holding its first public conference to discuss the current state of play of Internet filtering worldwide. The conference will be hosted by the Oxford Internet Institute on May 18, 2007. The conference is free of charge and open to the public.

Results from the first global study of Internet filtering carried out by the OpenNet Initiative will be on the table for a day of discussion involving ICT development experts, speech and human rights advocates, journalists and bloggers, international laywers and scholars, and others interested in state responses to online information flows. We hope you will join us in exploring interpretations and implications of our data and helping to shape the OpenNet Initiative's evolving research agenda.

The day will conclude with a debate hosted by the Oxford Union - Resolved: the Internet is the greatest force for democracy around the world.

Further details can be found at:

Wednesday, May 02, 2007

House of Lords Decision in Douglas v Hello

As some may be aware, there has been a lot of press coverage about the House of Lords judgment on the Douglas v Hello case. This time, it is about the Hello and OK magazine. The judgment is fairly lengthy, but a good summary is provided by 5RB:

Facts: Michael Douglas and Catherine Zeta-Jones entered into an agreement with OK! magazine by which OK! were given exclusive rights to publish photographs of the Douglas-Zeta-Jones wedding. At the wedding and reception photography was prohibited; employees signed agreements not to take photographs and guests were searched for cameras. Shortly after the wedding OK! became aware that Hello! magazine planned to publish surreptitiously taken photographs of the wedding. OK! brought claims against Hello! for breach of confidence and causing loss by unlawful means (the Douglases also brought proceedings but these were no longer in issue).Lindsay J held Hello! liable for breach of confidence. The Court of Appeal reversed the judge’s decision on the ground that the obligation of confidence for the benefit of OK! attached only to the photographs which the Douglases authorized them to publish and not to any others. OK! appealed.

Issue (1) Whether Hello! were lable to OK! for breach of confidence;(2) Whether Hello! were liable to OK! for interfering with their business interests by unlawful means.

Held Allowing the appeal by a 3-2 majority:(1) Reversing the judgment of the Court of Appeal; OK! had paid £1m for the benefit of the obligation of confidence imposed upon all those present at the wedding in respect of any photographs of the wedding and were entitled to enforce that obligation. It had no claim to privacy nor could it make a claim parasitic on the Douglases rights. (Per Lord Nicholls and Lord Walker dissenting) The unapproved photographs contained nothing not in the approved photographs and therefore, once the latter had been published, there could be no breach of confidence. (Per Lord Walker dissenting) The law would not protect exclusivity in a ‘spectacle’.

(2) If it were necessary to consider this, Hello! had the necessary intention to cause loss but had not used unlawful means to interfere with the actions of the Douglases.
See also:

No doubt, there will be some academic discussion about the law of torts in this area (particularly, the protection of an individual's image). Commitments permitting, one will have to start writing an article on this.

European Data Protection Supervisor's Annual Report

The European Data Protection Supervisor's Annual Report 2006 has been published. For those who do not want to read the full report, Out-Law.com provides a summary:


The number of complaints to the European Data Protection Supervisor (EDPS) almost doubled in 2006, but only 20% were valid complaints for the privacy watchdog of the EU institutions, its annual report has said. The number of complaints remained small, rising from 27 in 2005 to 52 in 2006. All but 10 of the complaints should have been directed to national data protection authorities and not the European Supervisor. In 2005 all but five of the complaints were similarly misdirected. The EDPS is still a new body, having only been formed in 2004. It increased in size last year from having 19 staff to having 24, and its budget increased from €3 million to €4m. "A large majority of the complaints received continued to fall outside of the supervisory competences of the EDPS, for instance because they dealt exclusively with processing of personal data on the level of the member states, where national Data Protection Authorities are competent," said the report. The report revealed that the body is conducting an audit of Eurodac, the database of fingerprints of illegal immigrants and applicants for asylum. The in-depth security audit is due to report by the middle of this year, the EDPS said. The report acknowledged that the EDPS still has not managed to make data protection an automatic part of working life for EU bodies. "[One challenge] is the implementation of data protection rules and principles in the whole EU administration and to develop a data protection culture as part of good governance," said the report..

See also:

Tuesday, May 01, 2007

ICO to call for more powers

This is a recent press release from the UK's ICO office calling for new privacy safeguards against a surveillance society:


The Information Commissioner, Richard Thomas, is today proposing new safeguards – including privacy impact assessments and inspection powers –to ensure public confidence in initiatives and technologies which could otherwise accelerate the growth of a surveillance society.Giving evidence before the Home Affairs Select Committee the Information Commissioner will also call for stronger powers to allow his Office (the ICO) to carry out inspections and audits. Currently the Commissioner must gain consent before inspecting an organisation for compliance with the Data Protection Act. Information Commissioner, Richard Thomas, said: “People now understand that data protection is an essential barrier to excessive surveillance. But it is wrong that my Office cannot find out what is happening in practice without the consent of each organisation. The risks that arise from excessive surveillance affect both individuals and society as a whole. As well as risks such as identity mistakes and security breaches there can be unnecessary intrusion into people’s lives and loss of personal autonomy. There is also a concern that too much surveillance will create a climate of fear and suspicion. It is essential that before new surveillance technologies are introduced fullconsideration is given to the impact on individuals and that safeguards are inplace to minimise intrusion.”The introduction of privacy impact assessments will ensure organisations set out how they will minimise the threat to privacy and address all the risks of new surveillance arrangements prior to their implementation...

See also:

On Privacy Impact Assessments, see also:

Monday, April 30, 2007

Virtual conference on Negotiating Identities

There is a virtual conference on negotiating identities: E-Congress on Negotiating Identities, which is taking place online on the 15th and 16th of May:


Registration is free and focus is to bring together people who study and explore social identities in a variety of contexts. In particular, we aim to support people in thinking and moving beyond their and others’ social categorisation. Registration also allows you access to the weblinks in the library and the forum (cafe).


More details can be found at http://identityresearch.org/.

Friday, April 27, 2007

House of Lords Committee: Surveillance and Data Collection

The House of Lords Committee has launched a new inquiry into the impact that government surveillance and data collection have upon the privacy of citizens and their relationship with the State. See extract at:

The inquiry, which is set against a backdrop of increased use of CCTV, the creation of the national DNA database, the new NHS Spine and the proposals for ID cards, will seek to find out if increased surveillance and data collection by the state have fundamentally altered the way it relates to its citizens. Some of the questions the Committee will be seeking answers to include:

What forms of surveillance and data collection might be considered constitutionally proper or improper? Is there a line that should not be crossed? How could it be identified?

What effect do public and private sector surveillance and data collection have on a citizen’s liberty and privacy?

How have surveillance and data collection altered the nature of citizenship in the 21st century, especially in terms of citizens’ relationship with the state?

Is the Data Protection Act sufficient to protect citizens? Is there a need for additional constitutional protection for citizens in relation to surveillance and the collection of data?

Commenting ahead of the publication of the Committee’s call for evidence, Lord Holme of Cheltenham, Chairman of the Constitution Committee, said:

“The nature and extent of surveillance and data collection have changed dramatically in recent years. We now have close to 4.2 million CCTV cameras in the UK and with the introduction of the NHS Spine and the ID card database the government will hold more information about us than ever before. “The broad constitutional implications of these changes have not thus far been sufficiently closely scrutinised. As a Committee we hope to get to the bottom of how these changes are altering the relationship between individuals and the State, and to ascertain whether necessary protection is in place."

Perhaps, an interesting question to ask about the sufficiency of the DPA 1998 to protect citizens. The DPA 1998 provides safeguards for the collection of personal information. Whether the existing legislative data protection framework is sufficient to prevent the surveillance is questionable. Do we need toughter penalties? On the subject about additional constitutional protection for citizens in relation to surveillance and the collection of data, the first starting point would be to look at the Human Rights Act 1998, which incorporates the ECHR and includes the"'right to respect for private and family life." Although the right to privacy is not absolute, it would be a good starting point.

See also:

Thursday, April 26, 2007

DCA Consultation on Freedom of Information Regulations

The DCA has issued its consultation on the draft regulations for the Freedom of Infomation Regulations. The first consultation period has ended, so this is a consultation for a subsequent paper. See extract below:

The Government has drafted amended FOI fees regulations which will allow public authorities to take into account more comprehensively the work involved in dealing with an FOI request. This consultation asks for views on the draft Regulations. The initial consultation period closed on 8 March 2007. A supplementary paper opened a second period of consultation on 29 March 2007 inviting views on the principle of amending the 2004 Regulations and also any further views on the draft Regulations themselves as set out in the consultation paper of 14 December 2006.

Saturday, April 21, 2007

Interpretation of "Processing"

Another important case has reached the UK Court of Appeals, Johnson v MDU and examines the notion of "processing" personal data. Here is a short extract from Out-Law.com.

David Paul Johnson took a case against the Medical Defence Union (MDU), a non-profit body which provides indemnity policies for its members. The MDU had refused to renew Johnson's policy after it conducted a review of his case and Johnson argued that the organisation had not
processed his data fairly and had therefore breached the Data Protection Act. The MDU operates a scoring system of its own invention which allocates points to certain complaints or allegations made against a doctor, even if they are never proved or pursued. By 2002 Johnson, who had been an MDU member since 1986, had built up enough of these points to trigger a review of his policy by the MDU. He had built up points by consulting the MDU over professional issues, including complaints. He had never been the subject of a claim of professional negligence. His case had been judged after an MDU staff member had looked through his files and collated information from them into a new computer document. Most of the files were manual and fell outside the Data Protection Act's definition of a "relevant filing system". Three were computer based, though, and so their use was controlled by the Act. Johnson claimed that this task was processing, as defined and controlled by the Act's first principle, which says that processing of personal data must be fair and lawful. Johnson claimed that his data was unfairly processed, in breach of the Act. The High Court agreed that the activity carried out by the MDU was processing under the Act, but said that it was unfair only in a minor and inconsequential way, and that therefore there was no breach. Both parties appealed the judgment, Johnson arguing that the processing was unfair and the MDU arguing that the High Court was wrong to say that its actions counted as data processing. The Court of Appeal said that the actions were not data processing. "Mr Johnson, who agrees that he has no right in contract or in any other chapter of English law to challenge [MDU examiner] Dr Roberts's selection of the information contained in his personal data, asserts that he can nonetheless mount these proceedings because her act of analysis is covered by the First Data Protection Principle," said presiding judge Lord Justice Buxton in his ruling. "I would not be prepared to conclude that the 1998 Act has had that effect, and the other widespread effects suggested above, unless I was driven to it. Far from that being the case, neither the 1998 Act nor the Directive give any support to the appellant's case. I would therefore hold that the Judge was wrong to find that Dr Roberts's selection of the data amounted to processing of data in the terms of the Act," he said.

Friday, April 13, 2007

Monitoring of Electronic Communications

A colleague had sent me some information about a recent case (Copland v UK) that has reached the European Court of Human Rights, which concerned an individual's personal communications (including e-mails) that were being monitored without her consent. The Court unanimously held that this was an infringement of her violation to her right to respect for private and family life under Art. 8(1) of the European Convention of Human Rights. Clearly, the monitoring of employees emails have important privacy and data protection implications.
Whilst the privacy of communications is not absolute (sufficient warning by the employer), it would be useful to consult the UK's ICO's employment practice code as a starting point. Plus, the ICO's recently commissioned report on surveillance (pdf).

Wednesday, April 11, 2007

DNA database

There is a case pending before the European Court of Human Rights concerning the storage of DNA. This is an interesting case as it concerns an individual who has not been charged with an offence. No doubt DNA of an individual is "personal data" within the meaning of the Data Protection Directive 95/46/EC ("sensitive data" if it relates to the health of the individual). See the extract below from Out-Law News:

The Government's DNA retention policy combined with increasingly sophisticated statistical techniques means that eventually most citizens in the UK will be linked to data stored on the police's DNA database, according to a privacy law expert. The outcome of an appeal to the European Court of Human Rights (ECHR) that challenges the UK's DNA retention policy will not limit the ultimate reach of the DNA database, only the speed of its compilation, says Dr Chris Pounder of Pinsent Masons. Under last year's Police and Justice Act, the police are allowed to retain DNA data on those arrested even if those arrested are not convicted of or even charged with any crime. Data derived from these samples are then added to the National DNA Database. Michael Marper's case before the ECHR could change this law. Marper was accused of harassment by his partner. He was arrested and DNA samples were taken. The charges were dropped when he reconciled with his partner, but police refused to destroy his DNA samples and related data. Marper exhausted his appeals through the English courts and then complained to the ECHR that the retention of his DNA is a breach of his rights to privacy under the European Convention on Human Rights. Earlier this year the ECHR decided that there was enough of importance in the case that it will hear it. "The Court finds that serious questions of fact and law arise, the determination of which should depend on an examination of the merits," said the ECHR in January. "The application cannot be regarded as manifestly ill-founded within the meaning of the Convention. No other grounds for declaring it inadmissible have been established." The ECHR has previously ruled in favour of the police's right to retain DNA, but that case involved a man who had been convicted of a crime. A Dutch bank robber, Mr Van der Velden, argued that police had failed to respect his private life by storing his DNA profile. The ECHR said that this interference with his privacy was proportionate.

See also:

Tuesday, April 10, 2007

ICO's response to proposed changes to the FOIA by the Government

The UK ICO has issued its response to the Government's proposals to introduce changes to the FOIA in reducing the number of FOI requests. The ICO is of the view that existing rules would enable the government to achieve its objectives without having to introduce further changes. The main points are:

a more robust application of section 14 (exclusion of vexatious requests) would, to a very significant extent, address the mischief at which the new cost proposals purport to be directed;
• there are grave doubts about the extent to which the aggregation of non-similar requests would be workable in practice, particularly if determined applicants took steps to circumvent the new provisions;
• the proposed concepts of reading, consultation and consideration time, will present very real difficulties for challenge and adjudication;
• the proposals will introduce new layers of procedural and bureaucratic complexity. There is likely - as feared by Frontier Economics - to be “a substantial increase in
requests for internal review and appeals to the ICO, with a substantial increase in costs”.
• there will certainly be a surge of difficult procedural complaints to ICO which can be predicted to start no less than two months after the new Regulations have been implemented. Unless further resources are made available, regrettably, the net effect – at least for the forthcoming year - has to be the prospect of more time taken to resolve difficult cases, an increase rather than a reduction in the backlog of complaints and the diversion of resources onto complaints about costs rather than substantive issues of disclosure of official information in the public interest....

5. The ICO believes that a more robust application of section 14, in line with the published guidance and decision notices, would, to a very significant extent, address the mischief at which the new cost proposals purport to be directed.

See also:

Monday, April 09, 2007

Telemedia Act 2007

The German Telemedia Act 2007 (Telemediengesetz) replaces the German Teleservices Act, the Teleservices Data Protection Act and the Federal Media Services Treaty. It takes effect on March 2007 and regulates all electronic information and communication services except pure telecommunication and broadcasting (so-called "Telemedia Services"). It covers webshops, mobile commerce, newsgroups, music download platforms, video on demand (VOD), internet search engines, emails and even simple company websites, but not to live-streaming of video, web-casting, IPTV (Internet Protocol TV) or VoIP (Voice Over Internet Protocol - internet telephony). The new Act has been criticised for not going far enough to protect the privacy of the user on the internet. There is no English translation available, but Wikipedia has an entry on this (in German). See also:

Saturday, April 07, 2007

Another paper

I have been away for the last few days attending the SLSA Conference 2007, hence the lack of blog posts. This is a jointly written paper, but may be of interest to those who have experience with this aspect of work. Here is the abstract:

Title: "All or nothing: this is the question?: the application of Art. 3(2) Data Protection Directive 95/46/EC to the internet"

The Data Protection Directive 95/46/EC (hereinafter the “Directive”) was passed in 1995 to harmonise the national data protection laws within the European Community with the aim of protecting the fundamental rights and freedoms of individuals including their privacy as set out under Art. 1 of the Data Protection Directive. The rules governing the processing of personal data are deemed to be inapplicable in the two instances outlined by Art.3(2). Processing of personal data taking place as part of activities falling outside of Community law are excluded from the DPD. The Directive is also deemed to be inapplicable if the processing of personal data is undertaken by a natural person in the course of a purely personal or household activity. It is the second part of Art. 3(2) which is examined in more detail. The ruling by the European Court of Justice in Lindqvist provides us with a fresh opportunity to re-examine whether the policy justifications for the exclusion under Art 3(2) continue to remain relevant in the light of widespread use of new technologies such as blogs, podcasts and web pages for processing and distributing information. Greater clarity regarding the implication of new communication technologies for DPD policy is necessary if the laws on data protection are to evolve in a coherent and principled manner.

Keywords: Data Protection Directive 95/46/EC; internet, private purposes, blogs, podcasts

Although this is still a work in progress, we hope to have this published by the end of the year. Any thoughts or views are welcome.

Data Protection - a new website

Here is another website on data protection in the EU - Set up by Dr JĂ³ri, Data protection.eu aims to 'carry out a comparative analysis of European data protection legislations, that can help the data protection community of Europe to answer them.'
Information on data protection laws is certainly needed and trying to find up-to-date sources can be difficult, so the website will indeed be useful to those who work in the data protection field. Other websites worth visiting include:

Friday, March 30, 2007

Enquiry into a "Surveillance Society"

An enquiry is being conducted by the UK Parliament into the surveillance of citizens by the Government. Here is a short extract from the latest press release.

The UK Parliament has launched an enquiry into the surveillance conducted on citizens by the Government. It will investigate the growing number and scope of government databases holding increasing amounts of information on citizens. The Home Affairs Committee will conduct the inquiry, called 'A Surveillance Society?', so that it can produce rules for Government to follow when building up increasing amounts of sensitive and private information on the general public. "The inquiry will consider the growth of numerous public and private databases and forms of surveillance," said a Committee statement. "They either derive directly from the work of the Home Office and its related public functions or are controversial because whilst they offer the potential to play a part in the fight against crime their use may impinge on individual liberty." "The inquiry will focus on Home Office responsibilities such as identity cards, the National DNA Database and CCTV, but where relevant will look also at other departments’ responsibilities in this area, for instance the implications of databases being developed by the Department of Health and the Department for Education and Skills for use in the fight against crime," it said.

Data Protection Resources: new URL

Just a reminder Data Protection Resources has a new URL address. It is now at http://freespace.virgin.net/r.wong253/. Please update your webpages.

Royal Academy of Engineers - Report on Privacy

The report on privacy (entitled Dilemmas on Privacy and Surveillance) has finally been published by the Royal Academy of Engineers and can be found here (pdf). The underlying theme is that engineers should design systems that protect the privacy of individuals. The report is about 64 pages long. Here is a short extract from the executive summary:
This study identifies likely developments in information technology in the near future, considers their impact on thecitizen, and makes recommendations on how to optimize their benefits to society. The report focuses on an area wherethe developments in IT have had a particularly significant impact in our everyday lives - the use of IT in surveillance,data-capture, and identity management. It looks at the threats that these technologies may pose and at the roleengineering can play in avoiding and managing these risks.

Tuesday, March 20, 2007

RFID - changes to the Directive on Privacy and Electronic Communications 2002/58/EC

There has been a lot of discussion surrounding the privacy implications through the use of RFID by companies, but in the latest press release, the European Commission is anticipated to introduce changes to the Directive on Privacy and Electronic Communications 2002/58/EC (pdf) to take account of RFID chips. Here is a short extract:

The European Commission will make changes to the Privacy and Electronic Communications Directive to take account of the exploding market in radio frequency identification (RFID) chips, it has said. Amendments will be proposed by the middle of this year. The Commission has published a Communication, intended as "a step towards a policy framework," for dealing with RFID chips, whose usefulness is seen by some to be at odds with privacy and data protection. RFID is a radio technology which allows chips to be identified at short distances by chip readers. The chips themselves are so cheap – just a few pence each – that they are useful in all sorts of commercial applications, from goods transit to stock management and even shop checkouts. It is the application of the chips to people and the things people do with the chipped goods, though, that has always worried privacy activists. Information Society and Media Commissioner Viviane Reding said that the advisory group she was forming to monitor RFID would work in conjunction with the Article 29 Data Protection Working Group, an existing, independent EU advisory body. Reding announced the creation of an RFID Stakeholder Group to help the Commission develop its RFID policy as part of an action plan to address the potential pitfalls and benefits of using RFID technology.

One has still to read the Communication (pdf) issued by the European Commission, but see:

Thursday, March 15, 2007

Search Engine results

Google has decided to anonymise personal data that it receives from its search engine. Whilst the discussion of search results derived from search engines is not new, the privacy implications are important. The types of data that could be held about a user include information such as the search term itself, the IP address, and details of how a user makes searches, such as the browser used and previous queries to Google. Perhaps the question is whether any individuals has put in a request to Google about information held about them from the search engines?
Here is a short extract from the BBC website:
Privacy bodies have welcomed Google's decision to anonymise personal data it receives from users' web searches. The firm previously held information about searches for an indefinite period but will now anonymise it after 18 to 24 months. "This is an extremely positive development," said Ari Schwartz, deputy director of the Center for Democracy and Technology, a US-based watchdog. "It's the type of thing we have been advocating for a number of years." However, governments could still force Google to hold onto data or hand it over to authorities. "By anonymising our server logs after 18 to 24 months, we think we're striking the right balance between two goals: continuing to improve Google's services for you, while providing more transparency and certainty about our retention practices," a statement from the search giant said. It's a step forward, but I would like to see them anonymising data in a much shorter period Richard Clayton, Cambridge University It added: "Unless we're legally required to retain log data for longer, we will anonymise our server logs after a limited period of time." Peter Fleischer, Google's privacy counsel for Europe, said the decision has been taken after consulting with privacy bodies in theUS and Europe. He said: "We believe that privacy is one of the cornerstones of trust. We will be retroactively going back into our log database and anonymising all the information there."

Thursday, March 08, 2007

Privacy law in the US?

I came across a press release whereby Microsoft Chairman Bill Gates urges Congress to pass legislation on privacy:

Microsoft Chairman Bill Gates has added to his legislative wish list, renewing his push for Congress to pass an "all-inclusive" consumer privacy and security law by year's end.

In his keynote speech at a dinner here Wednesday hosted by the advocacy group Center for Democracy and Technology, Gates shifted his focus away from the calls for education and immigration changes that dominated his appearance at a morning Senate hearing. There's a critical need for federal privacy rules that require transparency about data collection practices, grant users access to their own data and dictate what companies must do if a breach occurs, Gates told an audience of about 900 people in a cavernous ballroom at the Ritz-Carlton Hotel here. Microsoft isn't alone in requesting federal privacy legislation. The Windows maker is allied with a number of tech titans, including eBay, Hewlett-Packard, Google, Intel and Oracle, that have begun lobbying Congress to override what they deem a patchwork of disparate state laws.

Privacy in the US certainly seems to be patchy, but whereas the European Data Protection Framework is much stricter in protecting the privacy of individuals (Art. 1 states fundamental rights and freedoms of individuals), this cannot be said of the US. Whether the legislation will be framed along the lines of the European Data Protection Directive is not clear, but for anyone interested in the differences between the US/Europe protection of privacy, see:

  • Kang and Buchner. Privacy in Atlantis, Harvard Journal of Law and Technology, Vol. 18, No. 1, Fall 2004.
  • Reidenberg, R. and P. Schwartz. Data privacy Law (Michie, 1996).

Tuesday, March 06, 2007

Art. 29 Working Party: Opinion on transfer of PNR to US Authorities

The Art. 29 Working Party has issued its opinion aimed at travel agents/airlines that provide travel services to passengers flying to and from the United States. Here is the executive summary:
This opinion and its annexes (frequently asked questions and model notices) are aimed attravel agents, airlines, and any other organisations providing travel services to passengersflying to and from the United States of America. This opinion and the annexes update andreplace the previous opinion of 30 September 2004 (WP97).The current legal framework for transferring PNR information to the US authorities iscovered by the interim agreement of 16 October 2006. Negotiations for a new agreementare expected to start in 2007.There remain obligations on travel agents, airlines and other organisations to provideinformation to passengers about the processing of their personal information, and thisopinion aims to give advice and guidance on who needs to provide what information, how and when. Information should be provided to passengers when they agree to buy a flight ticket, andwhen they receive confirmation of this ticket.The opinion gives advice on providing information by phone, in person and on theinternet. The Art. 29 Working Party has established the model information notices (the annexes tothis opinion) to make providing this information easier for organisations, and to makesure the information provided is consistent across the European Union.The shorter information notice gives passengers summary information about transfers oftheir data to the US authorities, and how to find out more information.The longer notice is in the form of frequently asked questions and has more details aboutthe processing. It explains passenger data more widely, before focusing on PNR data. It also includes links to the interim agreement and other relevant documents.

See:

Monday, March 05, 2007

Data Protection Resources: New URL

Just a note that I have a new URL for my website on Data Protection Protection Resources. It is now http://freespace.virgin.net/r.wong253/. Please update your links.

Freedom of information

Some of you may be aware that there are likely to be changes to the UK Freedom of Information Act 2000 and introduce restrictions on information to be requested. In the Times today:
The Information Commissioner will tomorrow demolish one of the main arguments being used by Government to introduce restrictions on people’s right to know about the State. Richard Thomas, who will be appearing before MPs on the Constitutional Affairs Committee, is expected to say that public bodies already have wide-ranging powers to ignore requests that are designed to waste civil servants’ time. The Government believes that laws introduced in 2005 requiring much greater disclosure of information from the public sector place an unfair burden on civil servants. However campaigners say that the proposed restrictions are unnecessary and designed to save the Government from embarrassment after a series of damaging disclosures.
The Freedom of Information Act 2000 already has a provision that does not allow for "vexatious or malicious requests". Are the changes necessary? I leave this with you to decide.

Saturday, March 03, 2007

File Sharing and Privacy

I came across a news report from Sky News yesterday on file sharing and identity theft. Trying to find a repeat of the report (podcast) on Sky News website has proven difficult, but there is a short piece asking for views on file-sharing worries. On the report, though, one user on a peer-to-peer networking found, to his surprise that he was not merely downloading files, but also downloaded personal details belonging to individuals. Although he notified Sky News on this, it raises questions about personal data and protection of individuals' personal information online. No doubt, identity theft is a problem, but is the UK Data Protection Act 1998 or even the European Data Protection Directive 95/46/EC satisfactory in dealing with these difficult issues?
The UK Data Protection Act 1998 places a responsibility on "data controllers" (those who hold our personal information) to make sure that our personal information is carefully safeguarded (not the actual legal terminology, but see Schedule 1 of the DPA 1998 for a start). However, with file sharing, is it always identifiable who the data controller is? Probably technological means such as the data controller's IP address (of their computer) is one way of ascertaining the identity of the data controller, but even then, there is the question of being certain that the IP address belongs to the filesharer. No doubt, these will be issues that will have to be considered by the ICO.

Tuesday, February 27, 2007

First UK case on Spyware

There was a recent case R v Waters, that reached the Court of Appeal about a man who had conspired to install spyware software on his wife's computer. He was sentenced to four months imprisonment and the Court of Appeal upheld the ruling:

Computers are an established part of modern life. An increasing amount of personal and private information is kept on computers, not only by the State and large organisations but also by individuals. The privacy of that information must be protected and it is vulnerable to the kind of unauthorised interference and intrusion that occurred in this case. The judge correctly identified deterrence as an element of sentencing in this case. In our judgment, a sentence of imprisonment for offences such as this was not wrong in principle.


For further reading, see also:

  • Deterrent sentence appropriate for "computer spying" [2007] Justice of the Peace & Local Government Law 171(7),
    115



Thursday, February 22, 2007

Data Protection Act 1998

I received a recent press release about changes to be made to the UK Data Protection Act 1998 to strengthen the penalties against those who misuse personal information.


Following the results of a consultation paper launched last summer, the Department of Constitutional Affairs has announced that much tougher powers to sentence those found guilty of breaching Data Protection principles will be given to courts. For the first time, this will mean that courts may impose prison sentences for individuals who trade in, or deliberately misuse personal data. The change is intended to combat the illegal trade in personal information which has become highly profitable in recent years. Several reports by the Information Commissioner have highlighted the inadequacy of current penalties, as the fines imposed on those who breach the provisions of the Data Protection Act do not appear to have deterred others from participating in the trade. In the worst cases, judges will have the power to impose prison sentences of up to two years in addition to unlimited fines.

This follows a recent report from the ICO who called for tougher penalties against those who are involved in the illegal trade of personal information. See:

Thursday, February 15, 2007

Data snooping

There was a recent press release from the BBC on the confusion surrounding data snooping laws.
Balancing the needs of the police to investigate crimes online with the privacy of individual web users has become controversial as governments seek to extend their snooping rights in cyberspace. Already European ISPs and phone companies are in the process of implementing an EU directive which forces them to retain a variety of communication data for up to two years. Now, a republican congressman, Lamar Smith, has put forward a bill for discussion in the US Congress that could see a similar regime operating Stateside. Experts think it is unlikely that the US will introduce draconian data retention laws any time soon, not because they do not want to but because similar European legislation is currently in varying degrees of disarray.
The Data Retentions Directive 2006/24/EC (pdf) amends the Data Protection Directive 95/46/EC and Directive on Privacy and Electronic Communications 2002/58/EC. It will require organisations to store data of up to 2 years (Art. 6). However, some provisions continue to remain unclear when considering how the Directive (when implemented) will work in practice. For example, the Directive draws a distinction between retaining "traffic data" and "location data", but is it always necessarily clear how this is applied to the internet? Some articles/websites worth reading:

Friday, January 26, 2007

Data protection/privacy bloggers

For those interested in data protection/privacy, there are a few blogs that are worth following:

PIPEDA Blog - Written by a Canadian Lawyer, this contains information related to the Personal Information Protection and Electronic Documents Act (aka PIPEDA) and other Canadian and international laws.
Privacy Podcast - By Aaron Titus, with a US bias on keeping identity secure.
Marketing by Permission - By Tim Trent with a UK focus on data protection developments
SpyBlog - Need no further explanation.

Let me know if there are any new blogs that have a data protection/privacy focus.

Tuesday, January 23, 2007

Sensitive data

I have been doing a lot of writing lately, hence the lack of any blog posts recently. Anyway, the latest article that I recently wrote is on sensitive data which examines the current data protection framework and in particular, the Data Protection Directive 95/46/EC and its categorisation of sensitive data under Art. 8 as applied to the internet. The article can be found here. Any views on this subject are welcome.