Monday, May 08, 2006

FOI request

I recently made a freedom of information request to the UK Information Commissioner concerning the number of complaints involving the processing of personal data on the internet. I have finally received a reply. Unfortunately, the office cannot give me the number of complaints that they receive because their electronic system does not enable them to search through a specific criteria (ie. keyword search). What was interesting however, was their response to information published on the websites.

We have in the past received correspondence about data published on websites run by private individuals, such as amateur genealogy websites and personal home pages. Processing in these cases is often exempt from the DPA (Data Protection Act 1998) by virtue of the exemption at section 36 (which states that personal data processed by an individual only for the purposes of that individual's personal, family or household affairs (including recreational purposes) are exempt from the DPA.

Although this approach is pragmatic, it does not take account of the narrow interpretation given by the European Court of Justice in Lindqvist of Art. 3(2) of the Data Protection Directive on domestic purposes and presents a particular problem. Is this provision (section 36) in line with Art. 3(2) Data Protection Directive? I have yet to consult my legal colleagues on this matter, but I am beginning to wonder whether the Data Protection Act and its application on the internet has any relevance in the UK? Perhaps I should write an article on this.

Sunday, May 07, 2006

Interesting developments

I have been away for a conference and the paper I gave was well received. I expect that the paper will be published at some point.

Anyway, returning to this, I received some interesting news about data protection developments. According to the Irish Times,

Ireland's Minister for Justice, Equality and Law Reform, Michael McDowell, is currently drafting the core elements of a new Privacy Bill. Rather than granting citizens new rights, the legislation will more clearly illustrate rights currently available under the Constitution and the European Convention on Human Rights.

Secondly, a government committee in Singapore is studying how well Singapore laws protect the privacy of personal information. It aims to produce its recommendations by the middle of this year. To date, there is no Singapore data protection laws and it appears quite odd to me that there is no appetite to introduce legislation on data protection. There is one article written on the Singaporean developments in the International Journal of Law and Information Technology.


Thursday, April 27, 2006

Guidance on Outsourcing

The UK Information Commissioner has issued some guidance on outsourcing. This is particularly important if companies intend to outsource their operations to countries outside the EEA because Art. 25 of the Data Protection Directive 95/46/EC (DPD) prohibits the transfer of personal data to third countries (outside the EEA) unless it satisfies the adequacy requirement under Art. 25 DPD. This is implemented under the 8th data protection principle of Schedule 1, Data Protection Act 1998. There are exemptions to Art. 25 under Art. 26 including obtaining consent from the data subject (customers/staff etc); transfer is necessary for the conclusion or performance of a contract and so forth. For more details, see:

Monday, April 24, 2006

Data Retention Directive

The Data Retention Directive 2006/24/EC (pdf) is now available. However, according to latest news reports, the US has taken an interest in the Directive. What is unclear is whether they will follow the EU's example.

In the meantime, it will be worth reading the Data Retention Directive. At first glance, the Directive should be implemented by 15 September 2007 (Article 15). The application of the Directive to the retention of communications data relating to internet access, internet telephony and email can be postponed by each member state until 15 March 2009. Art. 15(3) provides as follows:

Until 15 March 2009, each Member State may postpone application of this Directive to the retention of communications data relating to Internet Access, Internet telephony and Internet e-mail. Any Member State that intends to make use of this paragraph shall, upon adoption of this Directive, notify the Council and the Commission to that effect by way of a declaration. The declaration shall be published in the Official Journal of the European Union.

Saturday, April 22, 2006

Panel discussion

With two weeks to go before I present (at a conference on privacy), there is a panel discussion that I will be involved in with two other academics. The theme of the panel discussion is Privacy: inroads and threats to privacy. One is reminded of Scott McNealy's famous words back in 1999 "You have zero privacy anyway--Get over it".

We should not forget that privacy is not absolute and the law (Art. 8 of the European Convention of Human Rights) provides for exceptions to the protection of privacy. Has technology eroded privacy? To a greater extent - examples I can think of include RFIDs; mobile phones which have a camera facility as well as a possibility of revealing the location of individuals; computer databases of individual profiles etc. One book worth reading is Daniel Solove's book entitled The Digital Person. Technology has moved on in great strides with legislation trailing behind. In any case, I'm not entirely convinced that legislation is necessarily the best approach to deal with the protection of privacy. In other words, let technology deal with technological problems. For example, if you find spyware on your computer, you use software to remove it. Laurence Lessig's book on Code and other laws of cyberspace is also another book worth reading!

Conference

Just a reminder that there will be the Privacy Laws & Business 19th Annual International Conference. The theme is:

Privacy Crisis Ahead?
Investing enough in data protection to strengthen and defend your reputation

July 3-5th, 2006, St. John's College, Cambridge, UK

Programme is available at www.privacylaws.com/pdfs/annualconference/ac19programme.doc

As I will be unable to attend, anyone who attends, let me know how it goes.

Monday, April 17, 2006

Further reading

As this is the bank holiday, I was reading through the latest developments on data protection and freedom of information. For those who want to do further reading, see:

Phishing

I received an email purporting to be from PayPal and asking for login details to PayPal account. Having researched and worked in the field of data protection, I decided to look at the link (see http://www.paypal.com/cgi-bin/webscr?cmd=login-run). This is an exact copy/replicate of PayPal website. You can email PayPal at spoof@paypal.com so that they can check whether this is genuine. Again, if you receive emails asking for personal details, it is always advisable to delete this and doublecheck with the company by forwarding the email to the company. Anyway, there are a few websites on phishing activities.

See

Wednesday, April 12, 2006

DTI Survey

In the latest UK DTI survey, it was found that UK businesses were still failing to protect an individual's personal information.

With increasing amounts of business being conducted online, data protection is ever more important, the DTI said. While most large organisations have adopted best practices regarding network and data protection, small companies have not. Fewer than a third of them encrypted the data they received.

This is particularly worrying for individuals who regularly use the internet, whether for buying goods, checking their bank statements etc. The UK Information Commissioner has provided guidance about the Data Protection Act 1998, but more needs to be done to raise awareness amongst the smaller businesses that it is vitally important to adhere to the Data Protection Act 1998. In particular, the seventh data protection principle (schedule 1 DPA 1998) requires that appropriate technical and organisational measures are taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.

For more details see:

Tuesday, April 11, 2006

Art. 29 Working Party's opinion on the retention of data

The Art. 29 Working Party (established under Art. 29 Data Protection Directive) has published its recent opinion on the retention of data. It takes the following view:


Therefore, the Art. 29 Working Party proposes a uniform, European-wide implementation of the Directive. This approach should guarantee a harmonized application of the provisions of the Directive whilst respecting the highest level possible of protecting personal data. This should also be done with a view to reducing the considerable costs to be borne by the service providers when complying with the provisions of the Directive. In order to transpose the provisions of the Directive in a uniform way and to comply with the requirements of Article 8 of the European Convention on Human Rights, Member States should implement adequate and specific safeguards.

We do not yet have the actual Directive, but here is the latest draft (pdf) to the retention of data. See also:

Friday, April 07, 2006

Photographs and privacy

Here is another press release about a photo published without the consent of the individual in the photo. According to the Press Complaints Commission, the photo was published in a newspaper article. I will not go into details of the case. The Press Complaints Commission has ruled, however, that the publication of a photo of the individual in his home without his consent was a breach of his privacy. It is interesting to note that the photo was taken in the complainant's home and not in public.
Although the Press Complaints Commission self-regulates the newspaper/magazine industry in the UK to ensure that they (newspapers/magazines) follow the codes of practice, we should not forget that there is the UK Data Protection Act 1998.
Some cases that came to mind (and may be of interest) are the decisions (by the House of Lords) in Campbell v MGN and the European Court of Human Rights in the Von Hannover v Germany. Both were concerned with the publication of details concerning the complainant's private lives. However, the European Court of Human Right's decision was far-reaching because it held that photos taken in public of public figures had to fulfil this condition: Pictures that were published in newspapers had to show that they were serving the 'public interest', there has to be some contribution towards a debate of general interest.
I could go on, but it would be more appropriate to have this written in an article. Food for thought!

Guidance from the ICO on buying and selling a database

I have been slightly pre-occupied over the last few days, having had to attend and chair a conference. I heard some very interesting papers and discussions.
Anyway, returning to my usual blog, I came across a few press releases on data protection. The UK Information Commissioner has published some guidance on buying and selling a database. The guidance is clear in stating that it is not a breach of the UK Data Protection Act 1998 to sell a database containing customers' details. However, companies/organisations (who plan to do this) must meet certain conditions/requirements. This includes obtaining the customer's consent and making sure that the customer understands the purpose for which the data was originally collected.
Guidance in this area is long overdue. However, it is still unclear the extent to which these databases are sold to other companies and whether customers know that their data are being transferred. More research and awareness in this area is much needed.
Guidance can be found here (pdf).

Monday, April 03, 2006

A good read!

I have almost finished reading the book entitled Just Law by Baroness Helena Kennedy and would recommend it to anybody who has not read this. Not only does the book cover issues such as the legal profession, criminal justice and police powers, there is even a section on "Big brother" (including ID cards). It is well-argued and written in such a way that anybody (without a legal background) is able to understand. Definitely worth reading!

Friday, March 31, 2006

Compromise on ID Cards

A compromise has finally been reached on the UK ID cards bill. Anyone who applies for a passport will not need to apply for an ID card until 2011, but their details will be put on a national ID database. The House of Lords have finally supported this compromise by 287 votes to 60. What is still uncertain is how much these ID cards will cost and who has access to the national ID database?
Under clause 22 of the bill, a National Identity Scheme Commissioner will be appointed whose principal role will be to supervise the operation of this bill (once enacted). Clause 17-21 inclusive are relevant in determining the circumstances under which information about an individual can be provided. This includes a government department (under clause 17(5)) and where it was necessary in the public interest (clause 17(7)). One awaits to read the final version of the bill when it becomes law, but certainly, there are more questions that need to be answered.
Links:

Tuesday, March 28, 2006

ID cards rejected for the 5th time

I received a press release that the ID cards Bill has been rejected by the House of Lords for the 5th time. This time, it was by a majority of 28 (219-191). The main issue is whether ID cards should be linked to passport applications - the HL argue that this should be voluntary and not a compulsory measure. The Bill will now go back to the House of Commons.

Here are the links to:

Tor system

I was listening to the latest podcast and found an interesting development about anonymizing internet communications. The system is called Tor.
Tor is a toolset for a wide range of organizations and people that want to improve their safety and security on the Internet. Using Tor can help you anonymize web browsing and publishing, instant messaging, IRC, SSH, and other applications that use the TCP protocol. Tor also provides a platform on which software developers can build new applications with built-in anonymity, safety, and privacy features.
Anyway, for more details, visit their website or listen to the podcast!

Friday, March 24, 2006

Internet privacy case

I came across this latest press release about legal action being brought against Gratis, an internet company based in Washington DC. According to the reports, the New York Attorney General Eliot Spitzer has filed suit against Gratis on the grounds that it had sold personal information obtained from millions of consumers despite a promise of confidentiality. Allegations include selling access to lists of millions of Gratis’s customers to three independent email marketers.

For more, see:

Google

The court in California has ruled that Google should hand over some search data (including 50,000 web addresses) to the Department of Justice, but the Judge has denied request that a list of people's search requests should be handed over.

"The expectation of privacy by some Google users may not be reasonable," Judge Ware wrote, "but may nonetheless have an appreciable impact on the way in which Google is perceived, and consequently the frequency with which users use Google."

Questions should be raised over the extent in which Google holds the search requests of users. How long is it held and what are their policies? The Data Protection Directive 95/46/EC stipulates the conditions under which personal data are processed and applies within the European Union. The Directive on Privacy and Electronic Communications 2002/58/EC specifies the conditions under which "traffic data" (Art. 6) and "location data" (Art. 9) are held. More discussion and awareness is needed (whether academics, practitioners or the public) about the laws that apply to search engines.

See also:

Thursday, March 23, 2006

Freedom of Information Website

The freedom of information website has recently been revamped with a new design. It continues to provide useful information about this area. Certainly, it is relevant when we look at how the roles of the data protection commissioners have changed (to include oversight of freedom of information laws). The aim of the website is to provide a:

One-stop portal for critical resources about freedom of information laws and movements around the world. The site describes best practices and lessons learned, compares campaign strategies, and links the efforts of freedom of information advocates globally.

Anyway, well worth visiting!

Wednesday, March 22, 2006

Latest on ID Cards Bill

In this battle over the ID cards bill, the House of Commons have rejected the compromise by the House of Lords to make the scheme of ID cards voluntary until 2011. Therefore, anyone applying for a passport would be required to apply for an ID card from 2008. So the bill now returns to the House of Lords.

Tuesday, March 21, 2006

ID Cards - part 2

Further to my earlier blog on ID cards bill, the House of Lords (HL) had rejected the ID cards bill yesterday and have suggested a compromise proposal to keep the scheme voluntary until 2011 – after the next general election. I am including:

We await to see whether the House of Commons will accept this compromise.

ID cards - latest

I am beginning to lose count over the number of times the ID cards bill is being sent from one House to another. Today, we will expect more discussion about the ID cards in the House of Commons. If the latest news reports are correct, then we may see a compromise made by the Liberal Democrats and Conservative peers in the House of Lords should the amendments be rejected by the House of Commons. According to the reports, it is suggested that the Bill's requirement that people must get an ID card when applying for a passport is voluntary for five years and will become compulsory in 5 years ie. 2012. I am including a link to the progress of the ID cards. We'll have to wait and see what developments arises, but hopefully, the Parliament Act will not be invoked to force this Bill through.

See also the latest blog:

Thursday, March 16, 2006

ID cards - defeat in the House of Lords for the third time

The amendments to the ID cards bill have been rejected by the House of Lords by 218 to 183 (a majority of 35) for the third time and will return to the House of Commons for another debate. The main area of concern is that people should not be compulsorily added onto a national database and be required to apply for an ID card when they renew or apply for their passport. One awaits to see whether the Parliament Acts would be invoked. It raises questions however, about the government's initial idea that ID cards would be voluntary.

Wednesday, March 15, 2006

The latest on Google

There have been some press releases circulating about the likely verdict that the judge may give the Google case concerning the Justice Department's (DoJ) request to some search results by users. If the reports are correct, the demands by the DoJ have been reduced

The Department is now seeking only 50,000 web addresses, of which it says it will look at 10,000. It has also reduced the number of search queries sought – down to 5,000 from one million. Of these, the Department says it will only look at 1,000.


However, there was also a hint by the judge that Google may have to comply with the demand for requests.

I think we will will have to wait until the judge makes the final decision rather than speculate the outcome, but once again, one will question how long Google or any other search engine company stores search engine results and what their policies are with regard to the retention of data (such as internet search engine requests). This brings me to the Data Retention Directive, but I will return to this issue at a later date.

See also:

Tuesday, March 14, 2006

Google case

In the latest press release, Google is set to challenge the US's government's demands to hand over records and lists of data derived from Google's search engines today in court. Google argues the following:

Firstly, Google says it does not want to do the government's work for it, and secondly it says that it wants to protect its product. Thirdly, Google wants to show users that the company is serious about protecting their privacy.


In any case, questions are/will be raised on the extent Google holds users' data and whether users, as data subjects can request information held by Google either through their search engines or their email service. It would easier to make a data subject request if the user subscribed to Google's email service (now renamed Google mail) because there is the issue of proving one's identity for data inputted on a search engine. One will wait to see what the court's verdict will be.

Monday, March 13, 2006

Rome II regulation - amendments

I was reading through the latest blog, which referred to the recent amendments made to the proposed Rome II regulation on the law to be applicable to non-contractual relations. Several changes have been made to the proposed regulation.
For our purposes, however, it was the original Art. 6 on privacy violations that I was interested in. Just to recap, see my previous blog. However, reading through the relevant sections in the proposals, it was decided that the original Art. 6 would be deleted because the proposed amendments to Art. 6 would have been too favourable to the press:

Amendment 57 would change the substance of the rule applicable to violations of privacy, particularly by the press. The Commission cannot accept this amendment, which is too generous to press editors rather than the victim of alleged defamation in the press and does not reflect the solution taken by a large majority of Member States. Since it is not possible to reconcile the Council’s text and the text adopted by Parliament at first reading, the Commission considers that the best solution to this controversial question is to exclude all press offences and the like from the proposal and delete Article 6 of the original proposal. Other privacy violations would be covered by Article 5.

The proposed Article 5 now reads as follows:
1. Where no choice has been made under Article 4, the law applicable to a non-contractual obligation shall be the law of the country in which the damage arises or is likely to arise, irrespective of the country in which the event giving rise to the damage occurred and irrespective of the country or countries in which the indirect consequences of that event arise.
2. However, where the person claimed to be liable and the person sustaining damage both have their habitual residence in the same country when the damage occurs, the non-contractual obligation shall be governed by the law of that country.
3. Notwithstanding paragraphs 1 and 2, where it is clear from all the circumstances of the case that the non-contractual obligation is manifestly more closely connected with another country, the law of that other country shall apply. A manifestly closer connection with another country may be based in particular on a pre-existing relationship between the parties, such as a contract that is closely connected with the non-contractual obligation in question. For the purpose of assessing the existence of a manifestly closer connection with another country, account shall be taken inter alia of the expectations of the parties regarding the applicable law.
The proposed Art. 1(2)(h) excludes from the regulation violations of privacy and of personal rights by the media.
My initial reaction is one of disappointment because the original Art. 6 had to be abandoned on the basis of lack of consensus. However, we now have the proposed Art. 5. What is unclear to me is what the Commission means by other privacy violations. Violations committed by individuals other than the press? There will be a number of questions that need to be addressed or at least clarified. I think it is time for further discussion and reading...
Links to the proposed Rome Regulation II:

VoIP - data protection implications

I came across this recent article about Voice Internet Protocol (VoIP) and the data protection implications (pdf) arising from the use of this technology. Some of the concerns include the ease with which individuals can tap into VoIP. Users are reminded to update their VoIP firmware in their end devices. I think that with the gradual take up of VoIP services, there should be more awareness by users and the German Data Protection and Freedom of Information Officer, Peter Schaar is right to point these concerns.

Thursday, March 09, 2006

UK OIC issues updated guidance on Durant

Although the UK Information Commissioner has issued further guidance (pdf) concerning the Durant case, I do not think we should conclude that this is going to be the end of the matter (concerning the interpretation of "personal data"). The European Commission is currently looking at UK's implementation of the Data Protection Directive and Durant is considering of submitting an appeal to the European Court of Human Rights.
In short, the guidance provides that
  • A living individual must be able to be identified from the data in question. In the Durant case, the Court of Appeal did not focus on this element of the definition; and
  • The data must 'relate to' the individual identified. It is this issue with which the Court was most concerned, explaining ‘relate to’ as “information that affects [a person’s] privacy, whether in his personal or family life, business or professional capacity”.

Whatever the case may be, the ruling in Durant stands until we hear anything more.

Tuesday, March 07, 2006

Email tracking services

In the latest press release about email tracking services, Art. 29 Working Party has expressed its strongest disapproval of the service, didtheyreadit.com, from Florida-based Rampell Software, LLC. So, the question is what is the main problem arising under this service? Firstly, the service offers no opportunity to accept or refuse the tracking.

It also provides additional details to senders: the date and time when the email was opened; where, geographically, the email was opened; for how long; and whether it was forwarded.

Subscribers who use Yahoo!, Hotmail or AOL email services can simply add ".didtheyreadit.com" to the end of a recipient's e-mail address to have an email tracked. Users of Outlook simply download a piece of software to add the secret tracking ability.
The recipient's unambiguous consent should be obtained before senders use this type of email tracking service.

While services are being offered (such as the one above) to users, there is still a need for greater awareness by companies to ensure that they do not infringe data protection laws. Otherwise, we may find that recipients to such services invoking the data protection laws to protect their privacy rights!

Monday, March 06, 2006

ID card bill defeated in the HL

Further to my earlier posting, the House of Lords (HL) has defeated the ID card bill by a majority of 61 (227 to 166 against the government). The main area of disagreement is the requirement to have ID cards if anyone applies to renew their passport (or apply for a passport). So, where does that leave us? The bill will now return to the House of Commons for another round of debate. If there is no compromise between the two Houses, then we may see the Parliament Act being invoked.

I am including details of the latest press release, Parlimentlive TV (once the clip is available), the ID card bill and UK OIC's view on ID cards.

Although the bill is going through Parliament, we need to be reminded whether the bill is proportionate or goes further than what is necessary (ie. holding biometric data such as fingerprints/irises)? Similarly, it is hard to see how a database containing everyone's personal data could reconcile with the need to safeguard fundamental data protection principles such as fair processing? This is particularly the case if this data should become available to commercial organisations - no plans as yet, but the possibility is still there and we should not quickly dismiss this option!

ID cards in the House of Lords

The ID cards Bill expected to be debated in the House of Lords (HL) today. The question is whether the HL will accept the amendments agreed by the House of Commons (HC)? Just to recap, the ministers have decided against the need for the government to carry out a report on ID cards (despite uncertainty about the actual costs for ID cards). The HC also agreed that people who apply for their passports (on renewal or first time) are also given ID cards (costs still undecided. However, the 'Home Secretary Charles Clarke had said that a stand-alone ID card would cost £30, while one linked to a passport would cost £93') and have their personal information held on a database. We await to see whether the HL will oppose these amendments.

Thursday, March 02, 2006

Court records online

This latest press release came to my attention, which raises interesting perspectives about how we view personal information online. According to the report, the Administrative Office of Pennsylvania Courts is formulating a policy to govern which records - and what case information - will be available over the Internet.

Larry Frankel, the Pennsylvania legislative director for the American Civil Liberties Union, was among several people who argued that criminal case records should not be on the Internet before a defendant is adjudicated guilty. Frankel said many people wrongly consider an arrest equivalent to a conviction.

The report raises broader issues about the general publication of personal information online. It should be added that the US does not have data protection laws, but have an arrangement known as Safe Harbor between the US and the EU. It is unclear at this stage how much personal information should be included in a court record, but there was some discussion about whether to include date of births. However, there is some concern (see below):

The 13,000-lawyer Philadelphia Bar Association believes posting information about someone who has not been found guilty could unfairly tarnish their reputation, said Alan M. Feldman, the association's chancellor.

Certainly, the potential of confusion between individuals (without further detailed information such as d.o.b) may arise, but at the same time, one is wary about the amount of personal data that should be available in a court record online. This is certainly a difficult area, but it would be interesting to see what kind of policy is formulated.

Wednesday, March 01, 2006

UK IOC publishes Good Practice Note for professionals

Just received a press release that the UK OIC has published a good practice notice (about 3 pages long) for professionals when complying with the Data Protection Act 1998.
The Data Protection Act gives everyone a right to see information that is held about them including any opinions,” said David Smith, Deputy Information Commissioner. “Professionals need to be aware of this and understand what action is required when an individual challenges one of their opinions."
For more on this, see here (pdf).

Tuesday, February 28, 2006

ID cards

I came across the latest press release about ID cards bill in the UK, which (if it is correct) is likely to be opposed by the Tories and Lib Dems in the House of Lords. If this is the case, we are likely to see a delay in the introduction of ID cards, if and when the Bill goes through. As I reiterated in my previous posting, I still cannot see how such an expensive measure (ID cards) could be justified, when there are other proportionate, cost effective ways that could be used. I do not know what the latest public poll is to ID cards, but even if we rely on the last survey back in November, the public is still divided over the issue. See more here.

Saturday, February 25, 2006

Data Retention Directive - latest developments

The latest developments on the Data Retention Directive is that the EU justice and interior ministers have approved the controversial Directive. The storage of data (be it telephone calls or internet) is between 6 to 24 months. It should be added that it is not details about the content of the telephone calls that are stored but rather a record that a telephone call was made. More information of the latest press release can be found here.
As a starting point, see:

Not heard the last of Durant!

I have finally finished writing my paper, but in the process of doing so, there was a press release about the latest saga to the case of Durant.
For those who are unaware of the case of Durant, please see here for more information. Anyway, Durant is expected to submit an application to the ECHR against the UK government. The principle ground is that Durant had suffered a breach of Art. 8(1) ECHR which states that 'everyone has the right to respect for his private and family life, his home and his correspondence.' Once the application is submitted, the Court in Strasbourg has to decide whether Durant has a case and a decision is not expected until several years.
If the court decides to listen to Durant's case, I would be interested to see whether Durant would contend that the state had failed to take positive measures to protect D's right under Art. 8(1) ECHR. For more on privacy and its legal interpretation, I would refer you to a chapter I wrote a few years ago on privacy.

Thursday, February 23, 2006

Photographs and other things....

Still trying to finish writing a paper, but I came across this press release about fining three photographers the equivalent of $1.37 Cdn each for invasion of privacy by taking pictures of Diana, Princess of Wales, and boyfriend Dodi Fayed the night of their fatal 1997 car crash, officials said yesterday. See here for further details.

Sunday, February 19, 2006

Privacy Officer


A report that was recently published by Marketing Improvement found that most firms within the FTSE 100 were unable to respond properly to a request to speak to the company’s Privacy Officer. Only 28% of companies were able to direct the query to the correct person. The recommendation from the report is that companies appoint a Chief Privacy Officer who can deal with queries relating to privacy and data protection. However, the appointment would also assist the company in the compliance of the relevant data protection laws. Much more work still needs to be done to raise the awareness about data protection in companies and the UK Information Commissioner has gone some way to redress this.

For more details about the report, see the link (pdf) here.

Thursday, February 16, 2006

Papers to write

I have been busy trying to write a paper which I hope to submit to a conference in Germany. As it raises some vital questions about data protection and its direction, I am keen that the paper is accepted, so that I am given the opportunity to discuss about this. I can't say anything more on this, but if accepted, I will make this available at some point later in the year.

Diverging from this slightly, Art. 29 Working Party (established under the Data Protection Directive 95/46/EC) has issued a paper on whistleblowing compliance.

The Working Party reported that cultural differences around the EU have made it impractical to issue general guidance at this stage. It has therefore chosen to focus on those areas that need guidance most – especially those affected by new legislation such as the US Sarbanes-Oxley Act, which penalises firms that do not comply with whistleblowing rules.

More details can be found here.

Wednesday, February 15, 2006

Annual report on data protection published

Just a quick note that the latest annual report on data protection by Art. 29 Working Party has been published. It also includes latest caselaw from each country and developments from countries outside the EEA (including Canada and the US).

Singapore to look at laws on privacy

I came across this latest press release about Singapore looking at laws to protect an individual's privacy. A report is expected by October this year, which will not only consider guidelines but also legislation in this area.

Information, Communications and The Arts Minister Lee Boon Yang admits that wider protection for personal information is definitely needed. Dr Lee told Parliament, "We also recognise the need to protect personal data and personal information and the possible misuse of personal information or even identity thefts. This is especially critical as infocomm technology can be misused and distributed with potentially adverse impact on the individuals concerned. MICA appreciates the need to take a wider perspective on data protection. We recognise that an effective data protection regime will be an important pillar to develop Singapore's position as a trusted IT hub."

It is certainly a step in the right direction. I am hoping to present a paper on Asian laws of privacy, so I would be interested to see what developments arise.

Tuesday, February 14, 2006

Phone records

In the latest saga to the sale of cell phone records of users in the US, the House Energy and Commerce Committee leaders are demanding answers from operators of Internet sites like "phonebust.com" and"datafind.org" that offer criminals, stalkers and any other paying customer the detailed records of a person's private calls made on cellular, wire line or Internet-based phones. More details can be found in this latest press release. I don't think we will hear the last of this matter, but if it will halt these illegitimate activities, then it will have achieved something. Whatever outcome, there is a need for stronger legal protection in the US.

Monday, February 13, 2006

ID cards - latest developments


According to the latest report, MPs have voted against making the government carry out a report on costs before introducing identity cards. However, a report is expected on costs every six months for the first 10 years of the scheme being in place. Furthermore, MPs also supported the idea that it would be compulsory for people to be given cards - and put on a register - when they apply for passports. I will say more on this later this week.


Insights

I recently attended a conference on privacy and the discussions that arose made me think about the recent cases of Campbell (supermodel) and Von Hannover case.

What was perhaps surprising was that there was less attention given about privacy on the internet. I say this because there appears to be a focus on the mainstream media such as newspapers (online/offline) and television but nothing on blogging and podcasting (where users do rely as their alternative source of information). Although the conference was both informative and interesting, I would have liked more discussion in these areas.

I would definitely recommend the book entitled Genetic privacy by Graeme Laurie. The book touches on the issues of genetics and its implications on privacy. Worth reading!

Thursday, February 09, 2006

Proposed Rome II Regulation

I was reading through the press release, which seemed to indicate that there is some support by the UK government to the 'country of origin' proposal under the Rome Regulation II. The draft Rome Regulation II deals with non-contractual disputes and includes a provision on privacy. The draft proposal can be found here (pdf). Art. 6 of the proposed regulation provides for the violation of privacy and rights relating to personality:

Art. 6

1. The law applicable to a non-contractual obligation arising out of a violation of privacy or rights relating to the personality shall be the law of the forum where the application of the law designated by Article 3 would be contrary to the fundamental principles of the forum as regards freedom of expression and information.
2. The law applicable to the right of reply or equivalent measures shall be the law of the country in which the broadcaster or publisher has its habitual residence.


Art. 3 provides that

1. The law applicable to a non-contractual obligation shall be the law of the country in which the damage arises or is likely to arise, irrespective of the country in which the event giving rise to the damage occurred and irrespective of the country or countries in which the indirect consequences of that event arise.

2. However, where the person claimed to be liable and the person sustaining damage both have their habitual residence in the same country when the damage occurs, the noncontractual obligation shall be governed by the law of that country.

3. Notwithstanding paragraphs 1 and 2, where it is clear from all the circumstances of the case that the non-contractual obligation is manifestly more closely connected with another country, the law of that other country shall apply. A manifestly closer connection with another country may be based in particular on a pre-existing relationship between the parties, such as a contract that is closely connected with the non-contractual obligation in question.

The provision is significant because if it goes through then theoretically if an applicant suffers damage in a country that has stronger privacy rights, he/she could use their laws rather than rely on the UK, which does not have a common law to privacy but has to rely on the Data Protection Act 1998, law of confidentiality and where relevant the Human Rights Act 1998 (Art. 8 of the ECHR). It might be worthwhile for me to write an article on the implications of the proposed regulation.

For more details on the Rome Regulation II, see Diane Wallis's (MEP) website as a starting point.

Monday, February 06, 2006

Report on Identity Fraud

A report has recently been published by Council of Better Business Bureaus and Javelin Strategy & Research involving 5000 interviews with consumers. In brief, it found that identity fraud had decreased amongst adult victims between 2003 and 2006 from 10.1 million to 8.9 million people in the US. The average fraud amount per case has increased from $5,249 to $6,383, over 2 years. The report also highlighted four misperceptions:
Misperception #1: "Consumers are helpless to protect themselves"
Misperception #2: "Consumers bear the brunt of the financial losses from identity fraud"
Misperception #3: "Internet use increases the risks of identity fraud"
Misperception #4: " Seniors are most frequent targets of fraud operators"
Although the report is not free, more information can be found from this link to the BBB website.

Wednesday, February 01, 2006

Surveillance Society

Last night, I was listening to the recent discussion on Newsnight about whether UK (with all its legal measures) was sleep walking into a surveillance society. The interview was between Shami Chakrabarti, Director of Liberty and John Denham, Minister of State for the Home Office. What was interesting was the discussion about consumers being willing to give over their information to companies (reward cards), but possibly not the case when we talk about large DNA databases of information. Although it was acknowledged by the interviewees that there was no absolute right to privacy, there was still a need for open debate (even for DNA databases). The idea of a surveillance society is not far from people's mind. See the UK Information Commissioner's website on this subject and the Surveillance and Society webpage.

Monday, January 30, 2006

ICO decision notices

I had a look at the UCL' website which was recently updated to include a search facility for ICO Decision notices. The website had also translated two articles about Germany's freedom of information laws. Worth visiting!

Wednesday, January 25, 2006

Search engines

There has been some concern over the last few day about search engines (in particular, the news concerning Google and whether it will hand over the search engine results to the DOJ) and privacy in general. It was not really surprising (certainly for privacy scholars, data protection experts etc) that google search results could be of use to official authorities (particularly as it contains personal information of individuals albeit indirectly).

However, what would be more of interest is the consequences of such use, particularly in the context of online profiling - users' habits, what they read, do etc. being collected.

From a data protection perspective, the Directive on Privacy and Electronic Communications 2002/58/EC have been very clear about the collection of personal information online (see Art. 5 on confidentiality of communications and Art. 6 on traffic data).

The Data Protection Directive (particularly Art. 8 on sensitive data) is also relevant. Art. 8(1) expressly prohibits the processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership and the processing of data concerning health or sex life. There are then a list of exemptions provided under Art. 8(2). The point is that search engine results can and may show that personal information relate to the specific categories (political, philosopical beliefs etc.) Unless the exemptions apply, search engines would find itself at fault with the Data Protection Directive.

I have included a list for those who want follow up on online profiling:

CDT

FTC: Report into Online profiling
EPIC: Online profiling (pdf)

Monday, January 23, 2006

Outsourcing


I was reading through the latest article on outsourcing about concerns that some of the key services by the UK government, Department of Work and Pensions may be transferred abroad. What is unclear is where there are transferring these services and whether the UK government have really considered the implications of the Data Protection Act 1998 (see also the eight data protection principle). Security aside, perhaps the question that arises, is how "adequate" are the laws abroad to protect the personal information of individuals?
I recall one instance in which an investigative reporter was able to obtain personal details belonging to UK bank customers from a call centre in Delhi. Although, this matter has been investigated by the Information Commissioner (see another article) with the conclusion that the security procedures of call centres in India were robust, it raises serious issues about the extent of offshoring activities - I raise these questions because India does not currently have data protection laws, but have been planning to do so (how long, one awaits to see).
For more information on data protection however, see the UK Information Commissioner website.

Friday, January 20, 2006

Online Brokers

Well, what can I say? There have been some press releases circulating about the practice of online brokers, who manage to obtain the personal information and cell phone records of users. These are then sold onto anybody who requests this (see also
this press release).

The US Federal Communications Commission is currently investigating this practice. Perhaps, what is surprising to me (if it is correct) is the lack of powers on the part of the Privacy Commissioner in Canada to investigate this. The main reason is that the current Canadian legislation PIPEDA does not intend to apply outside of Canada. While it is acknowledged that there may be potential enforcement problems, it raises serious issues about the current PIPEDA.

As for the European side, Art. 5 of the Directive on Privacy and Electronic Communications 2002/58/EC provides for the confidentiality of communications and with the exceptions from the processing of such data, the consent of the user is required (see Art. 5(1)).

For anyone interested in examining the subject of online brokers, see the Canadian Internet Policy and Public Interest Clinic as a starting point. They are due to issue a report in the Spring on the Canadian data-brokerage industry.

Wednesday, January 18, 2006

ID cards debate

As some of you may be aware, the UK government has been pushing through ID cards Bill this week, which was recently blocked by the House of Lords. The main concern has been the cost, which keeps fluctuating every time I read a press release.
However, leaving aside the costs, the biometric passports is currently being rolled out this year with the possibility of fingerprints from 2008 (date not yet decided). Why waste the money on ID Cards that duplicates what the passport does, lacks robustness (or potential if we look at the LSE report), flawed (in terms of the cost) and is far too complex? I have my reservations (of course, data protection issues comes into this), but for more information, see the following websites:

Monday, January 16, 2006

Online mapping - privacy concerns

I came across a recent posting in Boston.com about mapping services introduced by companies such as Microsoft and Google, which raised potential privacy concerns.

The images are so detailed you can tell whether a neighbor's hedge was recently trimmed or whether the car parked in front of a local eatery might belong to a friend....
The companies' newly evolving search and mapping services make it easier than ever to scout out everything from vacation destinations to a new hairdresser.
Never before have searchable databases of detailed pictures covering wide swaths of urban areas been readily available.

Well, should we sound alarmed or not? Before I consider the Data Protection Directive (DPD), I should say that I have no objection with a general map showing roads, motorways etc. My main concern is the level of detail contained in a map, which will inevitably raise privacy concerns under the Data Protection Directive. More specifically, Art. 2(a) of the DPD:

(a) 'personal data' shall mean any information relating to an identified
or identifiable natural person ('data subject');
an identifiable person
is one who can be identified, directly or indirectly, in particular by reference
to an identification number or to one or more factors specific to his physical,
physiological, mental, economic, cultural or social identity.

This is where we get to the crux of the issue. Can a home be related to an identifiable person? This is not an easy question, but it really comes down to whether the home in question relates to an identified or identifiable individual. Leaving aside the exemptions, it is arguable that if someone can identify the home as belonging to X, then it is personal data.
Probably, a pertinent example I could think of is the recent ruling by the Press Complaints Commission (PCC) which upheld the complaint by JK Rowling when a national newspaper had published a picture of the author's London home together with the name of the road on which it was located. According to the PCC, this was "sufficient information to identify the exact location of the property".

The Commission recognises that high profile individuals may be exposed to security problems if their precise addresses are published. Indeed, the newspaper itself noted that the complainant had ‘gained her fair share of stalkers and obsessive fans’. The Commission was satisfied that the photograph and its caption contained sufficient information to identify the exact location of the property. It did not consider that the newspaper had demonstrated that the information was in the public domain to such an extent as to justify publishing it in this way. There was therefore a breach of Clause 3 on this point.

Well, one awaits to see what legal developments arise on this issues!

Friday, January 13, 2006

Another case of privacy invasion


I came across this recent press release about Apple's popular iTunes software. It was disconcerting to find that the software could send information about computer users' playlists back to Apple.

The new music software includes a 'MiniStore' window, which provides recommended links to Apple's music download service when a listener actively clicks on a song in their personal playlist, including songs that haven't been purchased from the iTunes store.

To provide those recommendations, the software sends information about the selected song, such as artist, title and genre, back to Apple. But the software also transmits a string of data that is linked to a computer user's unique iTunes account ID, computer experts have found.

Because iTunes users typically sign up for the music store with an email address and a credit card number, the account ID number could in theory be linked to that information, as well as a user's purchase history, said Apple expert Kirk McElhearn, who has published several books on Macintosh computers.

If one looks at the data protection principles under the Data Protection Directive (Art. 6), this provides that:

1. Member States shall provide that personal data must be:

(a) processed fairly and lawfully;

(b) collected for specified, explicit and legitimate purposes and not further processed in a way incompatible with those purposes. Further processing of data for historical, statistical or scientific purposes shall not be considered as incompatible provided that Member States provide appropriate safeguards;

(c) adequate, relevant and not excessive in relation to the purposes for which they are collected and/or further processed;

(d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that data which are inaccurate or incomplete, having regard to the purposes for which they were collected or for which they are further processed, are erased or rectified;

(e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the data were collected or for which they are further processed. Member States shall lay down appropriate safeguards for personal data stored for longer periods for historical, statistical or scientific use.

2. It shall be for the controller to ensure that paragraph 1 is complied with.

What is unclear is why users were not informed about the fact that information about their playlist could be sent back to Apple. Irrespective of whether consent has been given, it certainly appears that information collected about its users and redirected to the company goes against some of the data protection principles.

Furthermore, the Directive on Privacy and Electronic Communications 2002/58/EC provides that such use should only be allowed for legitimate purposes with the knowledge of the user concerned. Art. 5(3) states that:

Member States shall ensure that the use of electronic communications networks to store information or to gain access to information stored in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned is provided with clear and comprehensive information in accordance with Directive 95/46/EC, inter alia about the purposes of the processing, and is offered the right to refuse such processing by the data controller. This shall not prevent any technical storage or access for the sole purpose of carrying out or facilitating the transmission of a communication over an electronic communications network, or as strictly necessary in order to provide an information society service explicitly requested by the subscriber or user.
Recital 24 of the same Directive provides that:

Terminal equipment of users of electronic communications networks and any information stored on such equipment are part of the private sphere of the users requiring protection under the European Convention for the Protection of Human Rights and Fundamental Freedoms. So-called spyware, web bugs, hidden identifiers and other similar devices can enter the user's terminal without their knowledge in order to gain access to information, to store hidden information or to trace the activities of the user and may seriously intrude upon the privacy of these users. The use of such devices should be allowed only for legitimate purposes, with the knowledge of the users concerned.

I do not want to dwell on this too much, but for those interested in this area, see Spyware watch and Wikipedia's definition of spyware.

The UK Information Commissioner has also issued some guidance on the Privacy and Electronic Communications (EC Directive) Regulations 2003 that implements the Directive on Privacy and Electronic Communications 2002/58/EC.

Wednesday, January 11, 2006

Journals worth reading!


The DCA has recently launched its journal entitled Information Rights Journal (pdf). A quick glance of the journal will show recent developments of data protection and decisions of the UK Information Commissioner to Freedom of Information Requests. As stated on the DCA website, the purpose of the journal is to:
Provide information rights practitioners with a round up of the latest developments in the information rights field. The journal will provide information on a wide range of issues across information rights as a whole, uniting freedom of information, data protection and the environmental information regulations. It will provide reports of emerging case law from decisions of the information commissioner and tribunal, and will serve as a useful reference tool for practitioners in central government and beyond.
Another journal I would recommend reading is opengovjournal.org. I have still yet to go through the articles, but quick skim read of the contents shows interesting perspectives to the UK Freedom of Information Act including:

  • First pulse check on UK FOI community indicates good health by Sarah Holsen.
  • The role of the information tribunal under the UK Freedom of Information Act 2000 by Timothy Pitt-Payne.
  • The UK’s openness watchdog lacks teeth and transparency by Heather Brooke.
Enjoy!

Monday, January 09, 2006

Another Cause for Concern


I was reading through a press release that slightly alarmed me after it emerged that credit card details of hundreds of guests at an exclusive hotel were found dumped in a skip.
The Information Commissioner's Office (ICO) said the hotel may also have breached the Data Protection Act by wrongly disposing of the cards, understood to include those completed by a number of MPs.

I agree that there was certainly a procedural lapse to ensure the security/confidentiality of customer's personal details. I cannot overemphasise the need to comply with the Data Protection Act 1998. In particular, the seventh data protection principle states that:


Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.

To see further guidelines, see the Information Commissioner's website.

Thursday, January 05, 2006

One year on: the Freedom of Information Act

There was an article recently on the Freedom of Information Act (FOIA). It provides as follows:

Writing in the Guardian on the first anniversary of the Freedom of Information Act, Lord Falconer, the constitutional affairs secretary, signals his intention to end what ministers regard as abuses of a system that is generally working well.

His move will anger the tabloid press and cause concern among freedom of information campaigners suspicious that wider restrictions will be imposed under the cover of protecting individuals. Lord Falconer writes: "Freedom of information is about giving power to the people, not about declaring open season for the wilder fevers of journalistic wish lists".


One awaits to see what proposals arise to amend the FOIA. However, one main concern is the continued backlog of complaints arising from the FOIA and are dealt with by the Information Commissioner. In a special report on the FOIA, it found that 'the commissioner has so far received more than 2,200 complaints, mainly about Whitehall and local councils. Of these, he has yet to deliver a verdict on 1,300 of them. His staff are only now starting to consider complaints which were submitted to his office in May.' How can these problems be remedied? More staffing? Staffing is only one part of the solution. According to the same report, what is being is considered is as follows:

The government is now reviewing at least two aspects of the act. The first is the issue of fees that can be charged by government bodies to members of the public when they make requests to recover the costs of, for example, finding and photocopying documents. So far, the public has been charged very little. However charging would almost certainly reduce the number of requests made.

Secondly, Charles Falconer, the constitutional affairs secretary responsible for the act, is looking to clamp down on what he believes are "wilder" and irresponsible requests, particularly from the tabloid press. He cited as examples requests for the number of windows at the department for education and skills, and the amount of money that departments spend on toilet paper.


Although there are concerns about potential misuse arising from the FOIA, it is questionable whether the proposed changes has the counter-effect of defeating the very purpose of the FOIA - transparency, accountability etc. We await (with bated breath). For more information about the FOIA, see the DCA website.



Wednesday, January 04, 2006

Radio Interview about DNA

I was listening to the Today programme and came across this interesting discussion (realplayer) on DNA and privacy between Lord Mackenzie and Simon Davies from Privacy International. The introduction to the interview was about the following:

The number of crimes solved by DNA has quadrupled in five years. But what if there are mistakes?

What was interesting was the discussion about potential mistakes that could be made from contaminated DNA? It was defended on the grounds that such opposition (not the actual words used) could apply to fingerprints. What needed to be tightened were the procedural aspects when collecting the DNA of individuals.

Another area of discussion was the use of DNA collected. One example given by Davies was the reluctance by many police officers to volunteer their own DNA in a National DNA database on the grounds that this would be used for other purposes such as paternity testing.

Looking at this subject from a data protection perspective, it is disconcerting to find potential misuses arising from the collection of DNA ie. collected and used for purposes other than that which was originally intended. The Data Protection Principles (under Art. 6 of the Data Protection Directive 95/46/EC) states that:

1. Member States shall provide that personal data must be:

(a) processed fairly and lawfully;

(b) collected for specified, explicit and legitimate purposes and not further
processed in a way incompatible with those purposes.
Further processing of
data for historical, statistical or scientific purposes shall not be considered as incompatible
provided that Member States provide appropriate safeguards;

(c) adequate, relevant and not excessive in relation to the purposes for which they are collected and/or further processed;

(d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that data which are inaccurate or incomplete, having regard to the purposes for which they were collected or for which they are further processed, are erased or rectified;

(e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the data were collected or for which they are further processed. Member States shall lay down appropriate safeguards for personal data stored for longer periods for historical, statistical or scientific use.

2. It shall be for the controller to ensure that paragraph 1 is complied with.

The data protection principles can be found in Schedule 1 of the UK Data Protection Act 1998. Although, we cannot ignore the potential benefits that have arisen through the use of DNA testing, we must also guard against the potential misuse from the DNA collected. The UK Data Protection Act 1998 and the Data Protection Directive 95/46/EC goes some way to address this, but more awareness (in my view) of this legislation in the context of genetic information is required.

For more information about genetic information, see the Human Genetics Commission website and a report (pdf) published back in 2000 on the public attitudes to the use of genetic information.