We have in the past received correspondence about data published on websites run by private individuals, such as amateur genealogy websites and personal home pages. Processing in these cases is often exempt from the DPA (Data Protection Act 1998) by virtue of the exemption at section 36 (which states that personal data processed by an individual only for the purposes of that individual's personal, family or household affairs (including recreational purposes) are exempt from the DPA.
Monday, May 08, 2006
FOI request
Sunday, May 07, 2006
Interesting developments
Anyway, returning to this, I received some interesting news about data protection developments. According to the Irish Times,
Ireland's Minister for Justice, Equality and Law Reform, Michael McDowell, is currently drafting the core elements of a new Privacy Bill. Rather than granting citizens new rights, the legislation will more clearly illustrate rights currently available under the Constitution and the European Convention on Human Rights.Secondly, a government committee in Singapore is studying how well Singapore laws protect the privacy of personal information. It aims to produce its recommendations by the middle of this year. To date, there is no Singapore data protection laws and it appears quite odd to me that there is no appetite to introduce legislation on data protection. There is one article written on the Singaporean developments in the International Journal of Law and Information Technology.
Thursday, April 27, 2006
Guidance on Outsourcing
Monday, April 24, 2006
Data Retention Directive
In the meantime, it will be worth reading the Data Retention Directive. At first glance, the Directive should be implemented by 15 September 2007 (Article 15). The application of the Directive to the retention of communications data relating to internet access, internet telephony and email can be postponed by each member state until 15 March 2009. Art. 15(3) provides as follows:
Until 15 March 2009, each Member State may postpone application of this Directive to the retention of communications data relating to Internet Access, Internet telephony and Internet e-mail. Any Member State that intends to make use of this paragraph shall, upon adoption of this Directive, notify the Council and the Commission to that effect by way of a declaration. The declaration shall be published in the Official Journal of the European Union.
Saturday, April 22, 2006
Panel discussion
We should not forget that privacy is not absolute and the law (Art. 8 of the European Convention of Human Rights) provides for exceptions to the protection of privacy. Has technology eroded privacy? To a greater extent - examples I can think of include RFIDs; mobile phones which have a camera facility as well as a possibility of revealing the location of individuals; computer databases of individual profiles etc. One book worth reading is Daniel Solove's book entitled The Digital Person. Technology has moved on in great strides with legislation trailing behind. In any case, I'm not entirely convinced that legislation is necessarily the best approach to deal with the protection of privacy. In other words, let technology deal with technological problems. For example, if you find spyware on your computer, you use software to remove it. Laurence Lessig's book on Code and other laws of cyberspace is also another book worth reading!
Conference
Privacy Crisis Ahead?
Investing enough in data protection to strengthen and defend your reputation
July 3-5th, 2006, St. John's College, Cambridge, UK
Programme is available at www.privacylaws.com/pdfs/annualconference/ac19programme.doc
As I will be unable to attend, anyone who attends, let me know how it goes.
Monday, April 17, 2006
Further reading
Phishing
See
- Anti-Phishing Working Group
- Guardian: Have the phishers had their chips?
- MailFrontier Phishing IQ Test
- Netcraft Anti-Phishing Tool - toolbar installed on your internet browser to detect suspicious websites.
- Honeynet Project and Research Alliance: Phishing
Wednesday, April 12, 2006
DTI Survey
In the latest UK DTI survey, it was found that UK businesses were still failing to protect an individual's personal information.With increasing amounts of business being conducted online, data protection is ever more important, the DTI said. While most large organisations have adopted best practices regarding network and data protection, small companies have not. Fewer than a third of them encrypted the data they received.
For more details see:
- Information Commissioner's website
- Business Link: Data Protection and Your Business - I shall add this link to my website
- Westbrook Data Protection Services
Tuesday, April 11, 2006
Art. 29 Working Party's opinion on the retention of data
Therefore, the Art. 29 Working Party proposes a uniform, European-wide implementation of the Directive. This approach should guarantee a harmonized application of the provisions of the Directive whilst respecting the highest level possible of protecting personal data. This should also be done with a view to reducing the considerable costs to be borne by the service providers when complying with the provisions of the Directive. In order to transpose the provisions of the Directive in a uniform way and to comply with the requirements of Article 8 of the European Convention on Human Rights, Member States should implement adequate and specific safeguards.
Friday, April 07, 2006
Photographs and privacy
Guidance from the ICO on buying and selling a database
Monday, April 03, 2006
A good read!
Friday, March 31, 2006
Compromise on ID Cards
Tuesday, March 28, 2006
ID cards rejected for the 5th time
Here are the links to:
Tor system
Tor is a toolset for a wide range of organizations and people that want to improve their safety and security on the Internet. Using Tor can help you anonymize web browsing and publishing, instant messaging, IRC, SSH, and other applications that use the TCP protocol. Tor also provides a platform on which software developers can build new applications with built-in anonymity, safety, and privacy features.
Friday, March 24, 2006
Internet privacy case
For more, see:
"The expectation of privacy by some Google users may not be reasonable," Judge Ware wrote, "but may nonetheless have an appreciable impact on the way in which Google is perceived, and consequently the frequency with which users use Google."
Questions should be raised over the extent in which Google holds the search requests of users. How long is it held and what are their policies? The Data Protection Directive 95/46/EC stipulates the conditions under which personal data are processed and applies within the European Union. The Directive on Privacy and Electronic Communications 2002/58/EC specifies the conditions under which "traffic data" (Art. 6) and "location data" (Art. 9) are held. More discussion and awareness is needed (whether academics, practitioners or the public) about the laws that apply to search engines.
See also:
Thursday, March 23, 2006
Freedom of Information Website
One-stop portal for critical resources about freedom of information laws and movements around the world. The site describes best practices and lessons learned, compares campaign strategies, and links the efforts of freedom of information advocates globally.
Anyway, well worth visiting!
Wednesday, March 22, 2006
Latest on ID Cards Bill
Tuesday, March 21, 2006
ID Cards - part 2
Further to my earlier blog on ID cards bill, the House of Lords (HL) had rejected the ID cards bill yesterday and have suggested a compromise proposal to keep the scheme voluntary until 2011 – after the next general election. I am including:
We await to see whether the House of Commons will accept this compromise.
ID cards - latest
See also the latest blog:
Thursday, March 16, 2006
ID cards - defeat in the House of Lords for the third time
The amendments to the ID cards bill have been rejected by the House of Lords by 218 to 183 (a majority of 35) for the third time and will return to the House of Commons for another debate. The main area of concern is that people should not be compulsorily added onto a national database and be required to apply for an ID card when they renew or apply for their passport. One awaits to see whether the Parliament Acts would be invoked. It raises questions however, about the government's initial idea that ID cards would be voluntary.Wednesday, March 15, 2006
The latest on Google
The Department is now seeking only 50,000 web addresses, of which it says it will look at 10,000. It has also reduced the number of search queries sought – down to 5,000 from one million. Of these, the Department says it will only look at 1,000.
However, there was also a hint by the judge that Google may have to comply with the demand for requests.
I think we will will have to wait until the judge makes the final decision rather than speculate the outcome, but once again, one will question how long Google or any other search engine company stores search engine results and what their policies are with regard to the retention of data (such as internet search engine requests). This brings me to the Data Retention Directive, but I will return to this issue at a later date.
See also:
- LA Times: US cuts back request for Google data
- The Digital Collegian: Google: Court ruling would result in slippery slope
Tuesday, March 14, 2006
Google case
Firstly, Google says it does not want to do the government's work for it, and secondly it says that it wants to protect its product. Thirdly, Google wants to show users that the company is serious about protecting their privacy.
In any case, questions are/will be raised on the extent Google holds users' data and whether users, as data subjects can request information held by Google either through their search engines or their email service. It would easier to make a data subject request if the user subscribed to Google's email service (now renamed Google mail) because there is the issue of proving one's identity for data inputted on a search engine. One will wait to see what the court's verdict will be.
Monday, March 13, 2006
Rome II regulation - amendments
Amendment 57 would change the substance of the rule applicable to violations of privacy, particularly by the press. The Commission cannot accept this amendment, which is too generous to press editors rather than the victim of alleged defamation in the press and does not reflect the solution taken by a large majority of Member States. Since it is not possible to reconcile the Council’s text and the text adopted by Parliament at first reading, the Commission considers that the best solution to this controversial question is to exclude all press offences and the like from the proposal and delete Article 6 of the original proposal. Other privacy violations would be covered by Article 5.
1. Where no choice has been made under Article 4, the law applicable to a non-contractual obligation shall be the law of the country in which the damage arises or is likely to arise, irrespective of the country in which the event giving rise to the damage occurred and irrespective of the country or countries in which the indirect consequences of that event arise.
2. However, where the person claimed to be liable and the person sustaining damage both have their habitual residence in the same country when the damage occurs, the non-contractual obligation shall be governed by the law of that country.
3. Notwithstanding paragraphs 1 and 2, where it is clear from all the circumstances of the case that the non-contractual obligation is manifestly more closely connected with another country, the law of that other country shall apply. A manifestly closer connection with another country may be based in particular on a pre-existing relationship between the parties, such as a contract that is closely connected with the non-contractual obligation in question. For the purpose of assessing the existence of a manifestly closer connection with another country, account shall be taken inter alia of the expectations of the parties regarding the applicable law.
VoIP - data protection implications
I came across this recent article about Voice Internet Protocol (VoIP) and the data protection implications (pdf) arising from the use of this technology. Some of the concerns include the ease with which individuals can tap into VoIP. Users are reminded to update their VoIP firmware in their end devices. I think that with the gradual take up of VoIP services, there should be more awareness by users and the German Data Protection and Freedom of Information Officer, Peter Schaar is right to point these concerns.For more details about this, see:
- VoIP - guidance by the German Data Protection and Freedom of Information (in German)
- VoIP - Part 2 (in German)
- BFDI: Communications
Thursday, March 09, 2006
UK OIC issues updated guidance on Durant
- A living individual must be able to be identified from the data in question. In the Durant case, the Court of Appeal did not focus on this element of the definition; and
- The data must 'relate to' the individual identified. It is this issue with which the Court was most concerned, explaining ‘relate to’ as “information that affects [a person’s] privacy, whether in his personal or family life, business or professional capacity”.
Whatever the case may be, the ruling in Durant stands until we hear anything more.
Tuesday, March 07, 2006
Email tracking services
In the latest press release about email tracking services, Art. 29 Working Party has expressed its strongest disapproval of the service, didtheyreadit.com, from Florida-based Rampell Software, LLC. So, the question is what is the main problem arising under this service? Firstly, the service offers no opportunity to accept or refuse the tracking.
It also provides additional details to senders: the date and time when the email was opened; where, geographically, the email was opened; for how long; and whether it was forwarded.
Subscribers who use Yahoo!, Hotmail or AOL email services can simply add ".didtheyreadit.com" to the end of a recipient's e-mail address to have an email tracked. Users of Outlook simply download a piece of software to add the secret tracking ability.
While services are being offered (such as the one above) to users, there is still a need for greater awareness by companies to ensure that they do not infringe data protection laws. Otherwise, we may find that recipients to such services invoking the data protection laws to protect their privacy rights!
Monday, March 06, 2006
ID card bill defeated in the HL
I am including details of the latest press release, Parlimentlive TV (once the clip is available), the ID card bill and UK OIC's view on ID cards.
Although the bill is going through Parliament, we need to be reminded whether the bill is proportionate or goes further than what is necessary (ie. holding biometric data such as fingerprints/irises)? Similarly, it is hard to see how a database containing everyone's personal data could reconcile with the need to safeguard fundamental data protection principles such as fair processing? This is particularly the case if this data should become available to commercial organisations - no plans as yet, but the possibility is still there and we should not quickly dismiss this option!
ID cards in the House of Lords
Thursday, March 02, 2006
Court records online
Larry Frankel, the Pennsylvania legislative director for the American Civil Liberties Union, was among several people who argued that criminal case records should not be on the Internet before a defendant is adjudicated guilty. Frankel said many people wrongly consider an arrest equivalent to a conviction.
The report raises broader issues about the general publication of personal information online. It should be added that the US does not have data protection laws, but have an arrangement known as Safe Harbor between the US and the EU. It is unclear at this stage how much personal information should be included in a court record, but there was some discussion about whether to include date of births. However, there is some concern (see below):
The 13,000-lawyer Philadelphia Bar Association believes posting information about someone who has not been found guilty could unfairly tarnish their reputation, said Alan M. Feldman, the association's chancellor.
Certainly, the potential of confusion between individuals (without further detailed information such as d.o.b) may arise, but at the same time, one is wary about the amount of personal data that should be available in a court record online. This is certainly a difficult area, but it would be interesting to see what kind of policy is formulated.
Wednesday, March 01, 2006
UK IOC publishes Good Practice Note for professionals
The Data Protection Act gives everyone a right to see information that is held about them including any opinions,” said David Smith, Deputy Information Commissioner. “Professionals need to be aware of this and understand what action is required when an individual challenges one of their opinions."
Tuesday, February 28, 2006
ID cards
Saturday, February 25, 2006
Data Retention Directive - latest developments
Not heard the last of Durant!
I have finally finished writing my paper, but in the process of doing so, there was a press release about the latest saga to the case of Durant. Thursday, February 23, 2006
Photographs and other things....
Sunday, February 19, 2006
Privacy Officer

For more details about the report, see the link (pdf) here.
Thursday, February 16, 2006
Papers to write
Diverging from this slightly, Art. 29 Working Party (established under the Data Protection Directive 95/46/EC) has issued a paper on whistleblowing compliance.
The Working Party reported that cultural differences around the EU have made it impractical to issue general guidance at this stage. It has therefore chosen to focus on those areas that need guidance most – especially those affected by new legislation such as the US Sarbanes-Oxley Act, which penalises firms that do not comply with whistleblowing rules.
More details can be found here.
Wednesday, February 15, 2006
Annual report on data protection published
Singapore to look at laws on privacy
Information, Communications and The Arts Minister Lee Boon Yang admits that wider protection for personal information is definitely needed. Dr Lee told Parliament, "We also recognise the need to protect personal data and personal information and the possible misuse of personal information or even identity thefts. This is especially critical as infocomm technology can be misused and distributed with potentially adverse impact on the individuals concerned. MICA appreciates the need to take a wider perspective on data protection. We recognise that an effective data protection regime will be an important pillar to develop Singapore's position as a trusted IT hub."
Tuesday, February 14, 2006
Phone records
Monday, February 13, 2006
ID cards - latest developments

Insights
What was perhaps surprising was that there was less attention given about privacy on the internet. I say this because there appears to be a focus on the mainstream media such as newspapers (online/offline) and television but nothing on blogging and podcasting (where users do rely as their alternative source of information). Although the conference was both informative and interesting, I would have liked more discussion in these areas.
I would definitely recommend the book entitled Genetic privacy by Graeme Laurie. The book touches on the issues of genetics and its implications on privacy. Worth reading!
Thursday, February 09, 2006
Proposed Rome II Regulation
Art. 6
1. The law applicable to a non-contractual obligation arising out of a violation of privacy or rights relating to the personality shall be the law of the forum where the application of the law designated by Article 3 would be contrary to the fundamental principles of the forum as regards freedom of expression and information.
2. The law applicable to the right of reply or equivalent measures shall be the law of the country in which the broadcaster or publisher has its habitual residence.
Art. 3 provides that
1. The law applicable to a non-contractual obligation shall be the law of the country in which the damage arises or is likely to arise, irrespective of the country in which the event giving rise to the damage occurred and irrespective of the country or countries in which the indirect consequences of that event arise.
2. However, where the person claimed to be liable and the person sustaining damage both have their habitual residence in the same country when the damage occurs, the noncontractual obligation shall be governed by the law of that country.
3. Notwithstanding paragraphs 1 and 2, where it is clear from all the circumstances of the case that the non-contractual obligation is manifestly more closely connected with another country, the law of that other country shall apply. A manifestly closer connection with another country may be based in particular on a pre-existing relationship between the parties, such as a contract that is closely connected with the non-contractual obligation in question.
For more details on the Rome Regulation II, see Diane Wallis's (MEP) website as a starting point.
Monday, February 06, 2006
Report on Identity Fraud
Wednesday, February 01, 2006
Surveillance Society
Monday, January 30, 2006
ICO decision notices
Wednesday, January 25, 2006
Search engines
However, what would be more of interest is the consequences of such use, particularly in the context of online profiling - users' habits, what they read, do etc. being collected.
From a data protection perspective, the Directive on Privacy and Electronic Communications 2002/58/EC have been very clear about the collection of personal information online (see Art. 5 on confidentiality of communications and Art. 6 on traffic data).
The Data Protection Directive (particularly Art. 8 on sensitive data) is also relevant. Art. 8(1) expressly prohibits the processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership and the processing of data concerning health or sex life. There are then a list of exemptions provided under Art. 8(2). The point is that search engine results can and may show that personal information relate to the specific categories (political, philosopical beliefs etc.) Unless the exemptions apply, search engines would find itself at fault with the Data Protection Directive.
I have included a list for those who want follow up on online profiling:
CDT
FTC: Report into Online profiling
EPIC: Online profiling (pdf)
Monday, January 23, 2006
Outsourcing

Friday, January 20, 2006
Online Brokers
this press release).
The US Federal Communications Commission is currently investigating this practice. Perhaps, what is surprising to me (if it is correct) is the lack of powers on the part of the Privacy Commissioner in Canada to investigate this. The main reason is that the current Canadian legislation PIPEDA does not intend to apply outside of Canada. While it is acknowledged that there may be potential enforcement problems, it raises serious issues about the current PIPEDA.
As for the European side, Art. 5 of the Directive on Privacy and Electronic Communications 2002/58/EC provides for the confidentiality of communications and with the exceptions from the processing of such data, the consent of the user is required (see Art. 5(1)).
For anyone interested in examining the subject of online brokers, see the Canadian Internet Policy and Public Interest Clinic as a starting point. They are due to issue a report in the Spring on the Canadian data-brokerage industry.
Wednesday, January 18, 2006
ID cards debate
Monday, January 16, 2006
Online mapping - privacy concerns
The images are so detailed you can tell whether a neighbor's hedge was recently trimmed or whether the car parked in front of a local eatery might belong to a friend....The companies' newly evolving search and mapping services make it easier than ever to scout out everything from vacation destinations to a new hairdresser.Never before have searchable databases of detailed pictures covering wide swaths of urban areas been readily available.
(a) 'personal data' shall mean any information relating to an identified
or identifiable natural person ('data subject'); an identifiable person
is one who can be identified, directly or indirectly, in particular by reference
to an identification number or to one or more factors specific to his physical,
physiological, mental, economic, cultural or social identity.
The Commission recognises that high profile individuals may be exposed to security problems if their precise addresses are published. Indeed, the newspaper itself noted that the complainant had ‘gained her fair share of stalkers and obsessive fans’. The Commission was satisfied that the photograph and its caption contained sufficient information to identify the exact location of the property. It did not consider that the newspaper had demonstrated that the information was in the public domain to such an extent as to justify publishing it in this way. There was therefore a breach of Clause 3 on this point.
Friday, January 13, 2006
Another case of privacy invasion

The new music software includes a 'MiniStore' window, which provides recommended links to Apple's music download service when a listener actively clicks on a song in their personal playlist, including songs that haven't been purchased from the iTunes store.
To provide those recommendations, the software sends information about the selected song, such as artist, title and genre, back to Apple. But the software also transmits a string of data that is linked to a computer user's unique iTunes account ID, computer experts have found.
Because iTunes users typically sign up for the music store with an email address and a credit card number, the account ID number could in theory be linked to that information, as well as a user's purchase history, said Apple expert Kirk McElhearn, who has published several books on Macintosh computers.
If one looks at the data protection principles under the Data Protection Directive (Art. 6), this provides that:
1. Member States shall provide that personal data must be:
(a) processed fairly and lawfully;
(b) collected for specified, explicit and legitimate purposes and not further processed in a way incompatible with those purposes. Further processing of data for historical, statistical or scientific purposes shall not be considered as incompatible provided that Member States provide appropriate safeguards;
(c) adequate, relevant and not excessive in relation to the purposes for which they are collected and/or further processed;
(d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that data which are inaccurate or incomplete, having regard to the purposes for which they were collected or for which they are further processed, are erased or rectified;
(e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the data were collected or for which they are further processed. Member States shall lay down appropriate safeguards for personal data stored for longer periods for historical, statistical or scientific use.
2. It shall be for the controller to ensure that paragraph 1 is complied with.
What is unclear is why users were not informed about the fact that information about their playlist could be sent back to Apple. Irrespective of whether consent has been given, it certainly appears that information collected about its users and redirected to the company goes against some of the data protection principles.
Furthermore, the Directive on Privacy and Electronic Communications 2002/58/EC provides that such use should only be allowed for legitimate purposes with the knowledge of the user concerned. Art. 5(3) states that:
Member States shall ensure that the use of electronic communications networks to store information or to gain access to information stored in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned is provided with clear and comprehensive information in accordance with Directive 95/46/EC, inter alia about the purposes of the processing, and is offered the right to refuse such processing by the data controller. This shall not prevent any technical storage or access for the sole purpose of carrying out or facilitating the transmission of a communication over an electronic communications network, or as strictly necessary in order to provide an information society service explicitly requested by the subscriber or user.Recital 24 of the same Directive provides that:
Terminal equipment of users of electronic communications networks and any information stored on such equipment are part of the private sphere of the users requiring protection under the European Convention for the Protection of Human Rights and Fundamental Freedoms. So-called spyware, web bugs, hidden identifiers and other similar devices can enter the user's terminal without their knowledge in order to gain access to information, to store hidden information or to trace the activities of the user and may seriously intrude upon the privacy of these users. The use of such devices should be allowed only for legitimate purposes, with the knowledge of the users concerned.
The UK Information Commissioner has also issued some guidance on the Privacy and Electronic Communications (EC Directive) Regulations 2003 that implements the Directive on Privacy and Electronic Communications 2002/58/EC.
Wednesday, January 11, 2006
Journals worth reading!

Provide information rights practitioners with a round up of the latest developments in the information rights field. The journal will provide information on a wide range of issues across information rights as a whole, uniting freedom of information, data protection and the environmental information regulations. It will provide reports of emerging case law from decisions of the information commissioner and tribunal, and will serve as a useful reference tool for practitioners in central government and beyond.Another journal I would recommend reading is opengovjournal.org. I have still yet to go through the articles, but quick skim read of the contents shows interesting perspectives to the UK Freedom of Information Act including:
- First pulse check on UK FOI community indicates good health by Sarah Holsen.
- The role of the information tribunal under the UK Freedom of Information Act 2000 by Timothy Pitt-Payne.
- The UK’s openness watchdog lacks teeth and transparency by Heather Brooke.
Monday, January 09, 2006
Another Cause for Concern

The Information Commissioner's Office (ICO) said the hotel may also have breached the Data Protection Act by wrongly disposing of the cards, understood to include those completed by a number of MPs.
I agree that there was certainly a procedural lapse to ensure the security/confidentiality of customer's personal details. I cannot overemphasise the need to comply with the Data Protection Act 1998. In particular, the seventh data protection principle states that:
Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.
To see further guidelines, see the Information Commissioner's website.
Thursday, January 05, 2006
One year on: the Freedom of Information Act
Writing in the Guardian on the first anniversary of the Freedom of Information Act, Lord Falconer, the constitutional affairs secretary, signals his intention to end what ministers regard as abuses of a system that is generally working well.
His move will anger the tabloid press and cause concern among freedom of information campaigners suspicious that wider restrictions will be imposed under the cover of protecting individuals. Lord Falconer writes: "Freedom of information is about giving power to the people, not about declaring open season for the wilder fevers of journalistic wish lists".
One awaits to see what proposals arise to amend the FOIA. However, one main concern is the continued backlog of complaints arising from the FOIA and are dealt with by the Information Commissioner. In a special report on the FOIA, it found that 'the commissioner has so far received more than 2,200 complaints, mainly about Whitehall and local councils. Of these, he has yet to deliver a verdict on 1,300 of them. His staff are only now starting to consider complaints which were submitted to his office in May.' How can these problems be remedied? More staffing? Staffing is only one part of the solution. According to the same report, what is being is considered is as follows:
The government is now reviewing at least two aspects of the act. The first is the issue of fees that can be charged by government bodies to members of the public when they make requests to recover the costs of, for example, finding and photocopying documents. So far, the public has been charged very little. However charging would almost certainly reduce the number of requests made.Secondly, Charles Falconer, the constitutional affairs secretary responsible for the act, is looking to clamp down on what he believes are "wilder" and irresponsible requests, particularly from the tabloid press. He cited as examples requests for the number of windows at the department for education and skills, and the amount of money that departments spend on toilet paper.
Although there are concerns about potential misuse arising from the FOIA, it is questionable whether the proposed changes has the counter-effect of defeating the very purpose of the FOIA - transparency, accountability etc. We await (with bated breath). For more information about the FOIA, see the DCA website.
Wednesday, January 04, 2006
Radio Interview about DNA
I was listening to the Today programme and came across this interesting discussion (realplayer) on DNA and privacy between Lord Mackenzie and Simon Davies from Privacy International. The introduction to the interview was about the following:What was interesting was the discussion about potential mistakes that could be made from contaminated DNA? It was defended on the grounds that such opposition (not the actual words used) could apply to fingerprints. What needed to be tightened were the procedural aspects when collecting the DNA of individuals.
Another area of discussion was the use of DNA collected. One example given by Davies was the reluctance by many police officers to volunteer their own DNA in a National DNA database on the grounds that this would be used for other purposes such as paternity testing.
Looking at this subject from a data protection perspective, it is disconcerting to find potential misuses arising from the collection of DNA ie. collected and used for purposes other than that which was originally intended. The Data Protection Principles (under Art. 6 of the Data Protection Directive 95/46/EC) states that:
1. Member States shall provide that personal data must be:
(a) processed fairly and lawfully;
(b) collected for specified, explicit and legitimate purposes and not further
processed in a way incompatible with those purposes. Further processing of
data for historical, statistical or scientific purposes shall not be considered as incompatible
provided that Member States provide appropriate safeguards;
The data protection principles can be found in Schedule 1 of the UK Data Protection Act 1998. Although, we cannot ignore the potential benefits that have arisen through the use of DNA testing, we must also guard against the potential misuse from the DNA collected. The UK Data Protection Act 1998 and the Data Protection Directive 95/46/EC goes some way to address this, but more awareness (in my view) of this legislation in the context of genetic information is required.(c) adequate, relevant and not excessive in relation to the purposes for which they are collected and/or further processed;
(d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that data which are inaccurate or incomplete, having regard to the purposes for which they were collected or for which they are further processed, are erased or rectified;
(e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the data were collected or for which they are further processed. Member States shall lay down appropriate safeguards for personal data stored for longer periods for historical, statistical or scientific use.
2. It shall be for the controller to ensure that paragraph 1 is complied with.
For more information about genetic information, see the Human Genetics Commission website and a report (pdf) published back in 2000 on the public attitudes to the use of genetic information.
