Saturday, May 19, 2007

New book on Privacy and Technology

There is a recent book published by the National Academies Press entitled Engaging Privacy and Information Technology in a Digital Age:

Privacy is a growing concern in the United States and around the world. The spread of the Internet and the seemingly boundary less options for collecting, saving, sharing, and comparing information trigger consumer worries. Online practices of business and government agencies may present new ways to compromise privacy, and e-commerce and technologies that make a wide range of personal information available to anyone with a Web browser only begin to hint at the possibilities for inappropriate or unwarranted intrusion into our personal lives. Engaging Privacy and Information Technology in a Digital Age presents a comprehensive and multidisciplinary examination of privacy in the information age. It explores such important concepts as how the threats to privacy evolving, how can privacy be protected and how society can balance the interests of individuals, businesses and government in ways that omote privacy reasonably and effectively? This book seeks to raise awareness of the web of connectedness among the actions one takes and the privacy policies that are enacted, and provides a variety of tools and concepts with which debates over privacy can be more fruitfully engaged. Engaging Privacy and Information Technology in a Digital Age focuses on three major components affecting notions, perceptions, and expectations of privacy: technological change, societal shifts, and circumstantial discontinuities. This book will be of special interest to anyone interested in understanding why privacy issues are often so intractable.

The book is fairly lengthy, but a number of recommendations have been made including the establishment of a privacy commissioner. Here is a short extract from the executive summary, but worth reading the actual book:

Individuals can take a number of steps to enhance the privacy of their personal information and to become better informed about the extent to which their privacy has been compromised, although the effectiveness ofthese measures is bound to be limited. The committee thus recommends that if policy choices require that individuals shoulder the burden of protecting their own privacy, law and regulation should support theindividual in doing so. Firms and other organizations can design and implement self-regulatory regimes for protecting the privacy of the personal informationthey collect. Self-regulation is limited as a method for ensuring privacy,although it nevertheless offers protections that would not otherwise beavailable to the public. The committee offers a number of concrete recommendations to enhance the effectiveness of privacy policies. Specifically, organizations with self-regulatory privacy policies should take both technical and administrative measures to ensure their enforcement, routinely test whether their stated privacy policies are being fully implemented, produce privacy impact assessments when they are appropriate, strengthen their privacy policy by establishing a mechanism forrecourse if an individual or a group believes that they have been treated in a manner inconsistent with an organization’s stated policy, and establish an institutional advocate for privacy. The committee found that governmental bodies have important roles to play in protecting the privacy of individuals and or groups and in ensuring that decisions concerning privacy are made in an informedfashion. However, the U.S. legal and regulatory framework surrounding privacy is a patchwork that lacks consistent principles or unifying themes. Accordingly, the committee concluded that a less decentralized and moreintegrated approach to privacy policy in the United States could bring agreater degree of coherence to the subject of privacy. Two recommendationsf ollow from this conclusion. First, the committee recommends that the U.S. government should undertake a broad systematic review of national privacy laws and regulations. Second, the committee recommends that government policy makers should respect the spirit of privacy-related law.
See also

Friday, May 11, 2007

Privacy Enhancing Technologies

A recent press release from the European Commission on the promotion of Privacy enhancing technologies ("design information and communication systems and services in a way that minimises the collection and use of personal data and facilitate compliance with data protection rules") :

The Commission adopts today a Communication with the purpose of identifying the benefits of Privacy Enhancing Technologies (PETs) and laying down the Commission's objectives in this field, to be achieved by a number of specific actions supporting the development of PETs and their use by data controllers and consumers. The development of information and communication technologies is constantly offering new services which improve people's life. However, alongside these benefits, new risks also arise for the individual, such as identity theft, discriminatory profiling, continuous surveillance or deceit. Vice-President Frattini, Commissioner responsible for Justice, Freedom and Security, highlighted that: "To ensure that breaches of the data protection rules and violations of individual's rights are not only something forbidden and subject to sanctions under the existing legal provisions, but also technically more difficult, the Commission puts forward a set of actions aiming at developing and promoting the use of Privacy Enhancing Technologies." Viviane Reding, Commissioner for Information Society and Media added "On line services provide a lot of benefits and convenience to citizens and huge competitive advantages to European businesses. Yet for such services to enjoy large scale growth and so boost Europe's economy, people must have sufficient confidence that their personal privacy and legitimate business interests are being properly safeguarded".The use PETs can help to design information and communication systems and services in a way that minimises the collection and use of personal data and facilitate compliance with data protection rules. The use of PETs should result in making breaches of certain data protection rules more difficult and /or helping to detect them, therefore having a positive impact on consumer trust, in particular in cyberspace, all without losing the functionality of the information system. The Commission Communication adopted today reflects on the benefits of PETs, lays down the Commission's objective to promote these technologies and sets out clear actions to achieve them in the future by supporting the development of PETs and their use by data controllers and by consumers. To pursue the objective of enhancing the level of privacy and data protection in the Community, the Commission intends to clearly identify the need and technological requirements of PETs and further promote the development of these technologies (in particular through RTD projects and large-scale pilot demonstrations) and their use by industry and public authorities, involving a vast array of actors, including its own services, national authorities, industry and consumers. The aim is to provide the foundation for user-empowering privacy protection services reconciling legal and technical differences across Europe through public-private partnerships. To ensure respect for appropriate standards in the protection of personal data through PETs, standardization and coordination of national technical rules on security measures for data processing are envisaged.
See also:

Monday, May 07, 2007

European Data Protection Intensive Conference 24-25 May 2007

A two-day conference organised by Data Protection Law and Policy is being held in Amsterdam, 24-25 May 2007:

The European Data Protection Intensive is a unique event designed to solve the challenge faced by so many data protection professionals: to find authoritative information, and reliable advisors, on the data protection rules and regulations throughout Europe. Data Protection Law & Policy has organised this two-day Intensive to provide you with all the information and analysis on the legal and practical issues throughout Europe. The European Intensive is supported by the data protection specialists of Ecomlex, a network of 18 European law firms. This pan-european conference brings together leading data protection experts and a strong multinational representation. At the European Intensive you will find data protection experts from all twenty-seven EU states, plus Switzerland and Norway, who will be available to lead discussions as well as to meet for individual appointments. KEY ISSUES IN PLENARY SESSIONS The two-day Intensive will feature a day of Plenary Sessions which will focus on the key issues facing European data protection professionals, followed by a day of Group Interactive Sessions. SIX GROUP INTERACTIVE SESSIONS The Six Group Interactive Sessions will enable participants to ask experts directly about their particular concerns in any and every country in Europe. COVER EVERY COUNTRY The programme has been structured to enable participants to cover every single country, if they so choose, in the course of the second day of the Intensive.

See:

Thursday, May 03, 2007

Revisiting the notion of "Processing" and the UK Court of Appeal's Decision in MDU v Johnson

Some who are working in the data protection field will be aware of the recent decision issued by the UK Court of Appeal over the notion of "processing" in MDU v Johnson. Without going too much into the details of the case, however, the decision by the CA, appears to run contrary to the spirit of the European Data Protection and in particular, the interpretation of what constitutes "processing" of personal data. Art. 2(b)of the Data Protection Directive 95/46/EC provides that:

(b) 'processing of personal data' ('processing') shall mean any operation or set of operations which is performed upon personal data, whether or not by automatic means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction;

Processing is given a wide definition by the Directive and this is again, followed by other EU Member States. Perhaps, a belated response on one's part, but given the UK's implementation of the Data Protection Directive 95/46/EC, the discussion by the Courts to the Lindqvist decision was not helpful. The Lindqvist judgment provides that:

25. According to the definition in Article 2(b) of Directive 95/46, the term processing of such data used in Article 3(1) covers any operation or set of operations which is performed upon personal data, whether or not by automatic means. That provision gives several examples of such operations, including disclosure by transmission, dissemination or otherwise making data available. It follows that the operation of loading personal data on an internet page must be considered to be such processing.

26. It remains to be determined whether such processing is wholly or partly by automatic means. In that connection, placing information on an internet page entails, under current technical and computer procedures, the operation of loading that page onto a server and the operations necessary to make that page accessible to people who are connected to the internet. Such operations are performed, at least in part, automatically.

27. The answer to the first question must therefore be that the act of referring, on an internet page, to various persons and identifying them by name or by other means, for instance by giving their telephone number or information regarding their working conditions and hobbies, constitutes the processing of personal data wholly or
partly by automatic means within the meaning of Article 3(1) of Directive 95/46.

The UK Court of Appeal in MDU v Johnson at paras. 33-34 stated that:

I should also note that reference was made to the decision of the European Court of Justice [ECJ] in Case C-101/01 [2004] QB 1014 (Lindqvist). A web page containing personal information about L and some of her fellow parishioners was composed by L on her home computer and placed on the internet. She was prosecuted for processing personal data by automatic means. The national court referred to the ECJ the question:

Does it constitute 'the processing of personal data wholly or partly by automatic means' to list on a self-made internet home page a number of persons with comments and statements about their jobs and hobbies etc?

The ECJ held that the listing of the parishioners was the processing of their personal data, and that the process had been "performed, at least in part, automatically" because of the loading of the page on to the server. The selection of the data had been purely manual, yet there was no suggestion that the processing taken as a whole was not automatic. It is, however, important to remind ourselves of the terms of the question that was asked in Lindqvist, which was limited to whether using the computer to place the list on the net was processing. Plainly it was, for the reason given by the ECJ. By the same token, when Dr Roberts caused the computer to transmit her conclusions to the RAG data was being processed. But it does not help [J] to establish the latter point, because what he complains of is unfair conduct in the reaching of those conclusions, before that processing of the conclusions took place. I think that in the end it was agreed by the appellant that Lindqvist does not assist in our present concerns. But [Counsel] has more formidable support from authority nearer home, the decision of this court in Campbell v MGN Ltd [2003] QB 633.

That case was regarded by the Judge as conclusive in [J's] favour on the processing issue, and it must therefore be analysed in some detail.

The judgment is slightly lengthy and warrants another article to be written. At this stage, however, much work is still needed (whether by academics, policy makers, lawyers etc) to inform not only the public about the European Data Protection Directive 95/46/EC and what it is intended (see also the UK Information Commissioner's Website), but that if the UK Data Protection Act 1998 continues to be narrowly construed (in the light of cases such as Durant and Johnson), data protection laws in the UK may, in all but name, be considered weak!

ONI Conference: The Future of Free Expression on the Internet

There is a conference being held on the 18th May and hosted at the Oxford Internet Institute, which judging by the website is well worth going:

The OpenNet Initiative is holding its first public conference to discuss the current state of play of Internet filtering worldwide. The conference will be hosted by the Oxford Internet Institute on May 18, 2007. The conference is free of charge and open to the public.

Results from the first global study of Internet filtering carried out by the OpenNet Initiative will be on the table for a day of discussion involving ICT development experts, speech and human rights advocates, journalists and bloggers, international laywers and scholars, and others interested in state responses to online information flows. We hope you will join us in exploring interpretations and implications of our data and helping to shape the OpenNet Initiative's evolving research agenda.

The day will conclude with a debate hosted by the Oxford Union - Resolved: the Internet is the greatest force for democracy around the world.

Further details can be found at:

Wednesday, May 02, 2007

House of Lords Decision in Douglas v Hello

As some may be aware, there has been a lot of press coverage about the House of Lords judgment on the Douglas v Hello case. This time, it is about the Hello and OK magazine. The judgment is fairly lengthy, but a good summary is provided by 5RB:

Facts: Michael Douglas and Catherine Zeta-Jones entered into an agreement with OK! magazine by which OK! were given exclusive rights to publish photographs of the Douglas-Zeta-Jones wedding. At the wedding and reception photography was prohibited; employees signed agreements not to take photographs and guests were searched for cameras. Shortly after the wedding OK! became aware that Hello! magazine planned to publish surreptitiously taken photographs of the wedding. OK! brought claims against Hello! for breach of confidence and causing loss by unlawful means (the Douglases also brought proceedings but these were no longer in issue).Lindsay J held Hello! liable for breach of confidence. The Court of Appeal reversed the judge’s decision on the ground that the obligation of confidence for the benefit of OK! attached only to the photographs which the Douglases authorized them to publish and not to any others. OK! appealed.

Issue (1) Whether Hello! were lable to OK! for breach of confidence;(2) Whether Hello! were liable to OK! for interfering with their business interests by unlawful means.

Held Allowing the appeal by a 3-2 majority:(1) Reversing the judgment of the Court of Appeal; OK! had paid £1m for the benefit of the obligation of confidence imposed upon all those present at the wedding in respect of any photographs of the wedding and were entitled to enforce that obligation. It had no claim to privacy nor could it make a claim parasitic on the Douglases rights. (Per Lord Nicholls and Lord Walker dissenting) The unapproved photographs contained nothing not in the approved photographs and therefore, once the latter had been published, there could be no breach of confidence. (Per Lord Walker dissenting) The law would not protect exclusivity in a ‘spectacle’.

(2) If it were necessary to consider this, Hello! had the necessary intention to cause loss but had not used unlawful means to interfere with the actions of the Douglases.
See also:

No doubt, there will be some academic discussion about the law of torts in this area (particularly, the protection of an individual's image). Commitments permitting, one will have to start writing an article on this.

European Data Protection Supervisor's Annual Report

The European Data Protection Supervisor's Annual Report 2006 has been published. For those who do not want to read the full report, Out-Law.com provides a summary:


The number of complaints to the European Data Protection Supervisor (EDPS) almost doubled in 2006, but only 20% were valid complaints for the privacy watchdog of the EU institutions, its annual report has said. The number of complaints remained small, rising from 27 in 2005 to 52 in 2006. All but 10 of the complaints should have been directed to national data protection authorities and not the European Supervisor. In 2005 all but five of the complaints were similarly misdirected. The EDPS is still a new body, having only been formed in 2004. It increased in size last year from having 19 staff to having 24, and its budget increased from €3 million to €4m. "A large majority of the complaints received continued to fall outside of the supervisory competences of the EDPS, for instance because they dealt exclusively with processing of personal data on the level of the member states, where national Data Protection Authorities are competent," said the report. The report revealed that the body is conducting an audit of Eurodac, the database of fingerprints of illegal immigrants and applicants for asylum. The in-depth security audit is due to report by the middle of this year, the EDPS said. The report acknowledged that the EDPS still has not managed to make data protection an automatic part of working life for EU bodies. "[One challenge] is the implementation of data protection rules and principles in the whole EU administration and to develop a data protection culture as part of good governance," said the report..

See also:

Tuesday, May 01, 2007

ICO to call for more powers

This is a recent press release from the UK's ICO office calling for new privacy safeguards against a surveillance society:


The Information Commissioner, Richard Thomas, is today proposing new safeguards – including privacy impact assessments and inspection powers –to ensure public confidence in initiatives and technologies which could otherwise accelerate the growth of a surveillance society.Giving evidence before the Home Affairs Select Committee the Information Commissioner will also call for stronger powers to allow his Office (the ICO) to carry out inspections and audits. Currently the Commissioner must gain consent before inspecting an organisation for compliance with the Data Protection Act. Information Commissioner, Richard Thomas, said: “People now understand that data protection is an essential barrier to excessive surveillance. But it is wrong that my Office cannot find out what is happening in practice without the consent of each organisation. The risks that arise from excessive surveillance affect both individuals and society as a whole. As well as risks such as identity mistakes and security breaches there can be unnecessary intrusion into people’s lives and loss of personal autonomy. There is also a concern that too much surveillance will create a climate of fear and suspicion. It is essential that before new surveillance technologies are introduced fullconsideration is given to the impact on individuals and that safeguards are inplace to minimise intrusion.”The introduction of privacy impact assessments will ensure organisations set out how they will minimise the threat to privacy and address all the risks of new surveillance arrangements prior to their implementation...

See also:

On Privacy Impact Assessments, see also:

Monday, April 30, 2007

Virtual conference on Negotiating Identities

There is a virtual conference on negotiating identities: E-Congress on Negotiating Identities, which is taking place online on the 15th and 16th of May:


Registration is free and focus is to bring together people who study and explore social identities in a variety of contexts. In particular, we aim to support people in thinking and moving beyond their and others’ social categorisation. Registration also allows you access to the weblinks in the library and the forum (cafe).


More details can be found at http://identityresearch.org/.

Friday, April 27, 2007

House of Lords Committee: Surveillance and Data Collection

The House of Lords Committee has launched a new inquiry into the impact that government surveillance and data collection have upon the privacy of citizens and their relationship with the State. See extract at:

The inquiry, which is set against a backdrop of increased use of CCTV, the creation of the national DNA database, the new NHS Spine and the proposals for ID cards, will seek to find out if increased surveillance and data collection by the state have fundamentally altered the way it relates to its citizens. Some of the questions the Committee will be seeking answers to include:

What forms of surveillance and data collection might be considered constitutionally proper or improper? Is there a line that should not be crossed? How could it be identified?

What effect do public and private sector surveillance and data collection have on a citizen’s liberty and privacy?

How have surveillance and data collection altered the nature of citizenship in the 21st century, especially in terms of citizens’ relationship with the state?

Is the Data Protection Act sufficient to protect citizens? Is there a need for additional constitutional protection for citizens in relation to surveillance and the collection of data?

Commenting ahead of the publication of the Committee’s call for evidence, Lord Holme of Cheltenham, Chairman of the Constitution Committee, said:

“The nature and extent of surveillance and data collection have changed dramatically in recent years. We now have close to 4.2 million CCTV cameras in the UK and with the introduction of the NHS Spine and the ID card database the government will hold more information about us than ever before. “The broad constitutional implications of these changes have not thus far been sufficiently closely scrutinised. As a Committee we hope to get to the bottom of how these changes are altering the relationship between individuals and the State, and to ascertain whether necessary protection is in place."

Perhaps, an interesting question to ask about the sufficiency of the DPA 1998 to protect citizens. The DPA 1998 provides safeguards for the collection of personal information. Whether the existing legislative data protection framework is sufficient to prevent the surveillance is questionable. Do we need toughter penalties? On the subject about additional constitutional protection for citizens in relation to surveillance and the collection of data, the first starting point would be to look at the Human Rights Act 1998, which incorporates the ECHR and includes the"'right to respect for private and family life." Although the right to privacy is not absolute, it would be a good starting point.

See also:

Thursday, April 26, 2007

DCA Consultation on Freedom of Information Regulations

The DCA has issued its consultation on the draft regulations for the Freedom of Infomation Regulations. The first consultation period has ended, so this is a consultation for a subsequent paper. See extract below:

The Government has drafted amended FOI fees regulations which will allow public authorities to take into account more comprehensively the work involved in dealing with an FOI request. This consultation asks for views on the draft Regulations. The initial consultation period closed on 8 March 2007. A supplementary paper opened a second period of consultation on 29 March 2007 inviting views on the principle of amending the 2004 Regulations and also any further views on the draft Regulations themselves as set out in the consultation paper of 14 December 2006.

Saturday, April 21, 2007

Interpretation of "Processing"

Another important case has reached the UK Court of Appeals, Johnson v MDU and examines the notion of "processing" personal data. Here is a short extract from Out-Law.com.

David Paul Johnson took a case against the Medical Defence Union (MDU), a non-profit body which provides indemnity policies for its members. The MDU had refused to renew Johnson's policy after it conducted a review of his case and Johnson argued that the organisation had not
processed his data fairly and had therefore breached the Data Protection Act. The MDU operates a scoring system of its own invention which allocates points to certain complaints or allegations made against a doctor, even if they are never proved or pursued. By 2002 Johnson, who had been an MDU member since 1986, had built up enough of these points to trigger a review of his policy by the MDU. He had built up points by consulting the MDU over professional issues, including complaints. He had never been the subject of a claim of professional negligence. His case had been judged after an MDU staff member had looked through his files and collated information from them into a new computer document. Most of the files were manual and fell outside the Data Protection Act's definition of a "relevant filing system". Three were computer based, though, and so their use was controlled by the Act. Johnson claimed that this task was processing, as defined and controlled by the Act's first principle, which says that processing of personal data must be fair and lawful. Johnson claimed that his data was unfairly processed, in breach of the Act. The High Court agreed that the activity carried out by the MDU was processing under the Act, but said that it was unfair only in a minor and inconsequential way, and that therefore there was no breach. Both parties appealed the judgment, Johnson arguing that the processing was unfair and the MDU arguing that the High Court was wrong to say that its actions counted as data processing. The Court of Appeal said that the actions were not data processing. "Mr Johnson, who agrees that he has no right in contract or in any other chapter of English law to challenge [MDU examiner] Dr Roberts's selection of the information contained in his personal data, asserts that he can nonetheless mount these proceedings because her act of analysis is covered by the First Data Protection Principle," said presiding judge Lord Justice Buxton in his ruling. "I would not be prepared to conclude that the 1998 Act has had that effect, and the other widespread effects suggested above, unless I was driven to it. Far from that being the case, neither the 1998 Act nor the Directive give any support to the appellant's case. I would therefore hold that the Judge was wrong to find that Dr Roberts's selection of the data amounted to processing of data in the terms of the Act," he said.

Friday, April 13, 2007

Monitoring of Electronic Communications

A colleague had sent me some information about a recent case (Copland v UK) that has reached the European Court of Human Rights, which concerned an individual's personal communications (including e-mails) that were being monitored without her consent. The Court unanimously held that this was an infringement of her violation to her right to respect for private and family life under Art. 8(1) of the European Convention of Human Rights. Clearly, the monitoring of employees emails have important privacy and data protection implications.
Whilst the privacy of communications is not absolute (sufficient warning by the employer), it would be useful to consult the UK's ICO's employment practice code as a starting point. Plus, the ICO's recently commissioned report on surveillance (pdf).

Wednesday, April 11, 2007

DNA database

There is a case pending before the European Court of Human Rights concerning the storage of DNA. This is an interesting case as it concerns an individual who has not been charged with an offence. No doubt DNA of an individual is "personal data" within the meaning of the Data Protection Directive 95/46/EC ("sensitive data" if it relates to the health of the individual). See the extract below from Out-Law News:

The Government's DNA retention policy combined with increasingly sophisticated statistical techniques means that eventually most citizens in the UK will be linked to data stored on the police's DNA database, according to a privacy law expert. The outcome of an appeal to the European Court of Human Rights (ECHR) that challenges the UK's DNA retention policy will not limit the ultimate reach of the DNA database, only the speed of its compilation, says Dr Chris Pounder of Pinsent Masons. Under last year's Police and Justice Act, the police are allowed to retain DNA data on those arrested even if those arrested are not convicted of or even charged with any crime. Data derived from these samples are then added to the National DNA Database. Michael Marper's case before the ECHR could change this law. Marper was accused of harassment by his partner. He was arrested and DNA samples were taken. The charges were dropped when he reconciled with his partner, but police refused to destroy his DNA samples and related data. Marper exhausted his appeals through the English courts and then complained to the ECHR that the retention of his DNA is a breach of his rights to privacy under the European Convention on Human Rights. Earlier this year the ECHR decided that there was enough of importance in the case that it will hear it. "The Court finds that serious questions of fact and law arise, the determination of which should depend on an examination of the merits," said the ECHR in January. "The application cannot be regarded as manifestly ill-founded within the meaning of the Convention. No other grounds for declaring it inadmissible have been established." The ECHR has previously ruled in favour of the police's right to retain DNA, but that case involved a man who had been convicted of a crime. A Dutch bank robber, Mr Van der Velden, argued that police had failed to respect his private life by storing his DNA profile. The ECHR said that this interference with his privacy was proportionate.

See also:

Tuesday, April 10, 2007

ICO's response to proposed changes to the FOIA by the Government

The UK ICO has issued its response to the Government's proposals to introduce changes to the FOIA in reducing the number of FOI requests. The ICO is of the view that existing rules would enable the government to achieve its objectives without having to introduce further changes. The main points are:

a more robust application of section 14 (exclusion of vexatious requests) would, to a very significant extent, address the mischief at which the new cost proposals purport to be directed;
• there are grave doubts about the extent to which the aggregation of non-similar requests would be workable in practice, particularly if determined applicants took steps to circumvent the new provisions;
• the proposed concepts of reading, consultation and consideration time, will present very real difficulties for challenge and adjudication;
• the proposals will introduce new layers of procedural and bureaucratic complexity. There is likely - as feared by Frontier Economics - to be “a substantial increase in
requests for internal review and appeals to the ICO, with a substantial increase in costs”.
• there will certainly be a surge of difficult procedural complaints to ICO which can be predicted to start no less than two months after the new Regulations have been implemented. Unless further resources are made available, regrettably, the net effect – at least for the forthcoming year - has to be the prospect of more time taken to resolve difficult cases, an increase rather than a reduction in the backlog of complaints and the diversion of resources onto complaints about costs rather than substantive issues of disclosure of official information in the public interest....

5. The ICO believes that a more robust application of section 14, in line with the published guidance and decision notices, would, to a very significant extent, address the mischief at which the new cost proposals purport to be directed.

See also:

Monday, April 09, 2007

Telemedia Act 2007

The German Telemedia Act 2007 (Telemediengesetz) replaces the German Teleservices Act, the Teleservices Data Protection Act and the Federal Media Services Treaty. It takes effect on March 2007 and regulates all electronic information and communication services except pure telecommunication and broadcasting (so-called "Telemedia Services"). It covers webshops, mobile commerce, newsgroups, music download platforms, video on demand (VOD), internet search engines, emails and even simple company websites, but not to live-streaming of video, web-casting, IPTV (Internet Protocol TV) or VoIP (Voice Over Internet Protocol - internet telephony). The new Act has been criticised for not going far enough to protect the privacy of the user on the internet. There is no English translation available, but Wikipedia has an entry on this (in German). See also:

Saturday, April 07, 2007

Another paper

I have been away for the last few days attending the SLSA Conference 2007, hence the lack of blog posts. This is a jointly written paper, but may be of interest to those who have experience with this aspect of work. Here is the abstract:

Title: "All or nothing: this is the question?: the application of Art. 3(2) Data Protection Directive 95/46/EC to the internet"

The Data Protection Directive 95/46/EC (hereinafter the “Directive”) was passed in 1995 to harmonise the national data protection laws within the European Community with the aim of protecting the fundamental rights and freedoms of individuals including their privacy as set out under Art. 1 of the Data Protection Directive. The rules governing the processing of personal data are deemed to be inapplicable in the two instances outlined by Art.3(2). Processing of personal data taking place as part of activities falling outside of Community law are excluded from the DPD. The Directive is also deemed to be inapplicable if the processing of personal data is undertaken by a natural person in the course of a purely personal or household activity. It is the second part of Art. 3(2) which is examined in more detail. The ruling by the European Court of Justice in Lindqvist provides us with a fresh opportunity to re-examine whether the policy justifications for the exclusion under Art 3(2) continue to remain relevant in the light of widespread use of new technologies such as blogs, podcasts and web pages for processing and distributing information. Greater clarity regarding the implication of new communication technologies for DPD policy is necessary if the laws on data protection are to evolve in a coherent and principled manner.

Keywords: Data Protection Directive 95/46/EC; internet, private purposes, blogs, podcasts

Although this is still a work in progress, we hope to have this published by the end of the year. Any thoughts or views are welcome.

Data Protection - a new website

Here is another website on data protection in the EU - Set up by Dr Jóri, Data protection.eu aims to 'carry out a comparative analysis of European data protection legislations, that can help the data protection community of Europe to answer them.'
Information on data protection laws is certainly needed and trying to find up-to-date sources can be difficult, so the website will indeed be useful to those who work in the data protection field. Other websites worth visiting include:

Friday, March 30, 2007

Enquiry into a "Surveillance Society"

An enquiry is being conducted by the UK Parliament into the surveillance of citizens by the Government. Here is a short extract from the latest press release.

The UK Parliament has launched an enquiry into the surveillance conducted on citizens by the Government. It will investigate the growing number and scope of government databases holding increasing amounts of information on citizens. The Home Affairs Committee will conduct the inquiry, called 'A Surveillance Society?', so that it can produce rules for Government to follow when building up increasing amounts of sensitive and private information on the general public. "The inquiry will consider the growth of numerous public and private databases and forms of surveillance," said a Committee statement. "They either derive directly from the work of the Home Office and its related public functions or are controversial because whilst they offer the potential to play a part in the fight against crime their use may impinge on individual liberty." "The inquiry will focus on Home Office responsibilities such as identity cards, the National DNA Database and CCTV, but where relevant will look also at other departments’ responsibilities in this area, for instance the implications of databases being developed by the Department of Health and the Department for Education and Skills for use in the fight against crime," it said.

Data Protection Resources: new URL

Just a reminder Data Protection Resources has a new URL address. It is now at http://freespace.virgin.net/r.wong253/. Please update your webpages.

Royal Academy of Engineers - Report on Privacy

The report on privacy (entitled Dilemmas on Privacy and Surveillance) has finally been published by the Royal Academy of Engineers and can be found here (pdf). The underlying theme is that engineers should design systems that protect the privacy of individuals. The report is about 64 pages long. Here is a short extract from the executive summary:
This study identifies likely developments in information technology in the near future, considers their impact on thecitizen, and makes recommendations on how to optimize their benefits to society. The report focuses on an area wherethe developments in IT have had a particularly significant impact in our everyday lives - the use of IT in surveillance,data-capture, and identity management. It looks at the threats that these technologies may pose and at the roleengineering can play in avoiding and managing these risks.

Tuesday, March 20, 2007

RFID - changes to the Directive on Privacy and Electronic Communications 2002/58/EC

There has been a lot of discussion surrounding the privacy implications through the use of RFID by companies, but in the latest press release, the European Commission is anticipated to introduce changes to the Directive on Privacy and Electronic Communications 2002/58/EC (pdf) to take account of RFID chips. Here is a short extract:

The European Commission will make changes to the Privacy and Electronic Communications Directive to take account of the exploding market in radio frequency identification (RFID) chips, it has said. Amendments will be proposed by the middle of this year. The Commission has published a Communication, intended as "a step towards a policy framework," for dealing with RFID chips, whose usefulness is seen by some to be at odds with privacy and data protection. RFID is a radio technology which allows chips to be identified at short distances by chip readers. The chips themselves are so cheap – just a few pence each – that they are useful in all sorts of commercial applications, from goods transit to stock management and even shop checkouts. It is the application of the chips to people and the things people do with the chipped goods, though, that has always worried privacy activists. Information Society and Media Commissioner Viviane Reding said that the advisory group she was forming to monitor RFID would work in conjunction with the Article 29 Data Protection Working Group, an existing, independent EU advisory body. Reding announced the creation of an RFID Stakeholder Group to help the Commission develop its RFID policy as part of an action plan to address the potential pitfalls and benefits of using RFID technology.

One has still to read the Communication (pdf) issued by the European Commission, but see:

Thursday, March 15, 2007

Search Engine results

Google has decided to anonymise personal data that it receives from its search engine. Whilst the discussion of search results derived from search engines is not new, the privacy implications are important. The types of data that could be held about a user include information such as the search term itself, the IP address, and details of how a user makes searches, such as the browser used and previous queries to Google. Perhaps the question is whether any individuals has put in a request to Google about information held about them from the search engines?
Here is a short extract from the BBC website:
Privacy bodies have welcomed Google's decision to anonymise personal data it receives from users' web searches. The firm previously held information about searches for an indefinite period but will now anonymise it after 18 to 24 months. "This is an extremely positive development," said Ari Schwartz, deputy director of the Center for Democracy and Technology, a US-based watchdog. "It's the type of thing we have been advocating for a number of years." However, governments could still force Google to hold onto data or hand it over to authorities. "By anonymising our server logs after 18 to 24 months, we think we're striking the right balance between two goals: continuing to improve Google's services for you, while providing more transparency and certainty about our retention practices," a statement from the search giant said. It's a step forward, but I would like to see them anonymising data in a much shorter period Richard Clayton, Cambridge University It added: "Unless we're legally required to retain log data for longer, we will anonymise our server logs after a limited period of time." Peter Fleischer, Google's privacy counsel for Europe, said the decision has been taken after consulting with privacy bodies in theUS and Europe. He said: "We believe that privacy is one of the cornerstones of trust. We will be retroactively going back into our log database and anonymising all the information there."

Thursday, March 08, 2007

Privacy law in the US?

I came across a press release whereby Microsoft Chairman Bill Gates urges Congress to pass legislation on privacy:

Microsoft Chairman Bill Gates has added to his legislative wish list, renewing his push for Congress to pass an "all-inclusive" consumer privacy and security law by year's end.

In his keynote speech at a dinner here Wednesday hosted by the advocacy group Center for Democracy and Technology, Gates shifted his focus away from the calls for education and immigration changes that dominated his appearance at a morning Senate hearing. There's a critical need for federal privacy rules that require transparency about data collection practices, grant users access to their own data and dictate what companies must do if a breach occurs, Gates told an audience of about 900 people in a cavernous ballroom at the Ritz-Carlton Hotel here. Microsoft isn't alone in requesting federal privacy legislation. The Windows maker is allied with a number of tech titans, including eBay, Hewlett-Packard, Google, Intel and Oracle, that have begun lobbying Congress to override what they deem a patchwork of disparate state laws.

Privacy in the US certainly seems to be patchy, but whereas the European Data Protection Framework is much stricter in protecting the privacy of individuals (Art. 1 states fundamental rights and freedoms of individuals), this cannot be said of the US. Whether the legislation will be framed along the lines of the European Data Protection Directive is not clear, but for anyone interested in the differences between the US/Europe protection of privacy, see:

  • Kang and Buchner. Privacy in Atlantis, Harvard Journal of Law and Technology, Vol. 18, No. 1, Fall 2004.
  • Reidenberg, R. and P. Schwartz. Data privacy Law (Michie, 1996).

Tuesday, March 06, 2007

Art. 29 Working Party: Opinion on transfer of PNR to US Authorities

The Art. 29 Working Party has issued its opinion aimed at travel agents/airlines that provide travel services to passengers flying to and from the United States. Here is the executive summary:
This opinion and its annexes (frequently asked questions and model notices) are aimed attravel agents, airlines, and any other organisations providing travel services to passengersflying to and from the United States of America. This opinion and the annexes update andreplace the previous opinion of 30 September 2004 (WP97).The current legal framework for transferring PNR information to the US authorities iscovered by the interim agreement of 16 October 2006. Negotiations for a new agreementare expected to start in 2007.There remain obligations on travel agents, airlines and other organisations to provideinformation to passengers about the processing of their personal information, and thisopinion aims to give advice and guidance on who needs to provide what information, how and when. Information should be provided to passengers when they agree to buy a flight ticket, andwhen they receive confirmation of this ticket.The opinion gives advice on providing information by phone, in person and on theinternet. The Art. 29 Working Party has established the model information notices (the annexes tothis opinion) to make providing this information easier for organisations, and to makesure the information provided is consistent across the European Union.The shorter information notice gives passengers summary information about transfers oftheir data to the US authorities, and how to find out more information.The longer notice is in the form of frequently asked questions and has more details aboutthe processing. It explains passenger data more widely, before focusing on PNR data. It also includes links to the interim agreement and other relevant documents.

See:

Monday, March 05, 2007

Data Protection Resources: New URL

Just a note that I have a new URL for my website on Data Protection Protection Resources. It is now http://freespace.virgin.net/r.wong253/. Please update your links.

Freedom of information

Some of you may be aware that there are likely to be changes to the UK Freedom of Information Act 2000 and introduce restrictions on information to be requested. In the Times today:
The Information Commissioner will tomorrow demolish one of the main arguments being used by Government to introduce restrictions on people’s right to know about the State. Richard Thomas, who will be appearing before MPs on the Constitutional Affairs Committee, is expected to say that public bodies already have wide-ranging powers to ignore requests that are designed to waste civil servants’ time. The Government believes that laws introduced in 2005 requiring much greater disclosure of information from the public sector place an unfair burden on civil servants. However campaigners say that the proposed restrictions are unnecessary and designed to save the Government from embarrassment after a series of damaging disclosures.
The Freedom of Information Act 2000 already has a provision that does not allow for "vexatious or malicious requests". Are the changes necessary? I leave this with you to decide.

Saturday, March 03, 2007

File Sharing and Privacy

I came across a news report from Sky News yesterday on file sharing and identity theft. Trying to find a repeat of the report (podcast) on Sky News website has proven difficult, but there is a short piece asking for views on file-sharing worries. On the report, though, one user on a peer-to-peer networking found, to his surprise that he was not merely downloading files, but also downloaded personal details belonging to individuals. Although he notified Sky News on this, it raises questions about personal data and protection of individuals' personal information online. No doubt, identity theft is a problem, but is the UK Data Protection Act 1998 or even the European Data Protection Directive 95/46/EC satisfactory in dealing with these difficult issues?
The UK Data Protection Act 1998 places a responsibility on "data controllers" (those who hold our personal information) to make sure that our personal information is carefully safeguarded (not the actual legal terminology, but see Schedule 1 of the DPA 1998 for a start). However, with file sharing, is it always identifiable who the data controller is? Probably technological means such as the data controller's IP address (of their computer) is one way of ascertaining the identity of the data controller, but even then, there is the question of being certain that the IP address belongs to the filesharer. No doubt, these will be issues that will have to be considered by the ICO.

Tuesday, February 27, 2007

First UK case on Spyware

There was a recent case R v Waters, that reached the Court of Appeal about a man who had conspired to install spyware software on his wife's computer. He was sentenced to four months imprisonment and the Court of Appeal upheld the ruling:

Computers are an established part of modern life. An increasing amount of personal and private information is kept on computers, not only by the State and large organisations but also by individuals. The privacy of that information must be protected and it is vulnerable to the kind of unauthorised interference and intrusion that occurred in this case. The judge correctly identified deterrence as an element of sentencing in this case. In our judgment, a sentence of imprisonment for offences such as this was not wrong in principle.


For further reading, see also:

  • Deterrent sentence appropriate for "computer spying" [2007] Justice of the Peace & Local Government Law 171(7),
    115



Thursday, February 22, 2007

Data Protection Act 1998

I received a recent press release about changes to be made to the UK Data Protection Act 1998 to strengthen the penalties against those who misuse personal information.


Following the results of a consultation paper launched last summer, the Department of Constitutional Affairs has announced that much tougher powers to sentence those found guilty of breaching Data Protection principles will be given to courts. For the first time, this will mean that courts may impose prison sentences for individuals who trade in, or deliberately misuse personal data. The change is intended to combat the illegal trade in personal information which has become highly profitable in recent years. Several reports by the Information Commissioner have highlighted the inadequacy of current penalties, as the fines imposed on those who breach the provisions of the Data Protection Act do not appear to have deterred others from participating in the trade. In the worst cases, judges will have the power to impose prison sentences of up to two years in addition to unlimited fines.

This follows a recent report from the ICO who called for tougher penalties against those who are involved in the illegal trade of personal information. See:

Thursday, February 15, 2007

Data snooping

There was a recent press release from the BBC on the confusion surrounding data snooping laws.
Balancing the needs of the police to investigate crimes online with the privacy of individual web users has become controversial as governments seek to extend their snooping rights in cyberspace. Already European ISPs and phone companies are in the process of implementing an EU directive which forces them to retain a variety of communication data for up to two years. Now, a republican congressman, Lamar Smith, has put forward a bill for discussion in the US Congress that could see a similar regime operating Stateside. Experts think it is unlikely that the US will introduce draconian data retention laws any time soon, not because they do not want to but because similar European legislation is currently in varying degrees of disarray.
The Data Retentions Directive 2006/24/EC (pdf) amends the Data Protection Directive 95/46/EC and Directive on Privacy and Electronic Communications 2002/58/EC. It will require organisations to store data of up to 2 years (Art. 6). However, some provisions continue to remain unclear when considering how the Directive (when implemented) will work in practice. For example, the Directive draws a distinction between retaining "traffic data" and "location data", but is it always necessarily clear how this is applied to the internet? Some articles/websites worth reading:

Friday, January 26, 2007

Data protection/privacy bloggers

For those interested in data protection/privacy, there are a few blogs that are worth following:

PIPEDA Blog - Written by a Canadian Lawyer, this contains information related to the Personal Information Protection and Electronic Documents Act (aka PIPEDA) and other Canadian and international laws.
Privacy Podcast - By Aaron Titus, with a US bias on keeping identity secure.
Marketing by Permission - By Tim Trent with a UK focus on data protection developments
SpyBlog - Need no further explanation.

Let me know if there are any new blogs that have a data protection/privacy focus.

Tuesday, January 23, 2007

Sensitive data

I have been doing a lot of writing lately, hence the lack of any blog posts recently. Anyway, the latest article that I recently wrote is on sensitive data which examines the current data protection framework and in particular, the Data Protection Directive 95/46/EC and its categorisation of sensitive data under Art. 8 as applied to the internet. The article can be found here. Any views on this subject are welcome.

Thursday, December 14, 2006

League table of media's trade in personal information

The Information Commissioner is due to present a report today to Parliament naming some of the UK's newspapers and magazines that have bought people's personal information in search of a story. According to the latest press release,

The list was assembled following the Operation Motorman raid at premises in Hampshire which led to prosecutions of private investigators. In that operation, the Information Commissioner’s staff uncovered numerous invoices addressed to newspapers and magazines detailing prices for providing their journalists with pieces of personal information. Altogether, 305 journalists were identified as recipients of a wide range of information.

It reinforces the importance of protecting personal information and stronger penalties for those that trade in personal information. As for freedom of expression, the DPA 1998 does provide an exemption to the processing of personal information under s 32:

32. - (1) Personal data which are processed only for the special purposes are exempt from any provision to which this subsection relates if-

(a) the processing is undertaken with a view to the publication by any person of any journalistic, literary or artistic material,

(b) the data controller reasonably believes that, having regard in particular to the special importance of the public interest in freedom of expression, publication would be in the public interest, and

(c) the data controller reasonably believes that, in all the circumstances, compliance with that provision is incompatible with the special purposes.
There will be the public interest defence available, so claims about curtailing freedom of speech seems to be slightly far-fetched. The Information Commissioner also gave a recent interview on this. See

Thursday, November 30, 2006

Why spam is still a problem

The European Commission has published a report into the growth of spam showing that it accounts for between 50 and 80 per cent of all e-mails, at a worldwide cost of €39 billion (£26 billion). According to its latest press release:

The new Communication on Spam acknowledges that legislative tools to fight these threats already exist, in particular the EU-wide “ban on spam” adopted in 2002 as part of the ePrivacy Directive (see IP/03/1015). However, implementation is still a problem in most EU Member States. To improve, they should now lay down clear lines of responsibility to use the tools available under EU law effectively. Because of the criminal trend in spam and its cross border aspects, good cooperation between enforcement authorities is paramount. In the Commission's view, spam fighters should have sufficient resources. The Dutch fall in spam was achieved through prosecutions by spam fighter OPTA, with just 5 full-time employees and €570,000 invested in equipment. Although we have the Directive on Privacy and Electronic Communications 2002/58/EC, more still needs to be done to tackle this problem.
See also:

Saturday, November 04, 2006

Surveillance Society

Whilst there has been much debate about living in a surveillance society (particularly as highlighted in the 28th International Conference on Data Potection Commissioners), and the strategies that could be adopted in regulating such surveillance, one of the interesting aspects that arose from the report (pdf) commissioned by the Information Commissioner is the idea of a privacy impact assessment test (PIA) and even a surveillance impact assessment test. There is quite a lot to digest from this report, but here is an excerpt on the PIA:

‘an assessment of any actual or potential effects that an activity or proposal may have on individual privacy and the ways in which any adverse effects may be mitigated’;
• ‘a process. The fact of going through this process and examining the options will bring forth a host of alternatives which may not otherwise have been considered’;
• an approach and a philosophy that holds promise by instilling a more effective culture of understanding and practice within organisations that process personal data;
• a form of risk-assessment, which therefore cannot escape the uncertainties of identifying and estimating the severity and likelihood of the various risks that may appear, to privacy, life-chances, discrimination equality and so on;
• a tool for opening up the proposed technologies or applications to in-depth scrutiny, debate and precautionary action within the organisation(s) involved;
• like PETs, premised on the view that it is better to build safeguards in than to bolt them on;
• an early-warning technique for decision-makers and operators of systems that process personal information, enabling them to understand and resolve conflicts between their aims and practices, and the required protection of privacy above or the control of surveillance;
• ideally, a public document, leading to gains in transparency and in the elevation of public awareness of surveillance issues and dangers may be realised; in turn, it may assist regulatory bodies in carrying out their work effectively.

A further point that should be added and noted in the report is that a PIA is not a compliance audit.


PIA should not be confused with compliance audits and the like, which are usually ex post facto and legally-oriented; as with environmental impact assessment, PIA assesses the likely impact of technology applications or new systems in the future, and considers a wider range of criteria.

For further reading, see pages 89 onwards in the report. Some countries such as Canada and Australia already have PIAs, but it remains to be seen whether PIAs will be adopted in the UK. See also:

Monday, October 23, 2006

Podcasts

Some of the podcasts that I find useful when keeping myself updated on freedom of information/data protection developments include:
  1. FOI Podcast service - a monthly series by Ibrahim Hasan, solicitor and information law expert on the latest developments on freedom of information law.
  2. Out-law radio - updated every Thursday, free 10 minute podcast produced by Out-Law.
  3. Privacy podcast - produced by Aaron Titus and more directed towards the protection of an individual's identity.

Tuesday, October 17, 2006

Data protection law for India?

I was reading through an article this morning about India's Information Technology Act 2000 which is likely to be amended to take account of data protection concerns. What is unclear at this stage is what these amendments will consist of and when they are likely to take effect. However, addressing data protection concerns in India have long been overdue, particularly with the recent Channel 4 documentary highlighting the security failures in a number of commercial call centres which allow detailed financial data on individuals to be gathered and sold on with ease.
Art. 25 of the Data Protection Directive 95/46/EC clearly provides that personal data is not transferred to countries outside the EEA without satisfying an adequate level of protection.
Art. 25
1. The Member States shall provide that the transfer to a third country of personal data which are undergoing processing or are intended for processing after transfer may take place only if, without prejudice to compliance with the national provisions adopted pursuant to the other provisions of this Directive, the third country in question ensures an adequate level of protection.

2. The adequacy of the level of protection afforded by a third country shall be assessed in the light of all the circumstances surrounding a data transfer operation or set of data transfer operations; particular consideration shall be given to the nature of the data, the purpose and duration of the proposed processing operation or operations, the country of origin and country of final destination, the rules of law, both general and sectoral, in force in the third country in question and the professional rules and security measures which are complied with in that country.
These provisions have been implemented in the UK Data Protection Act, Schedule 1, 8th data protection principle:

8. Personal data shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.

It remains to be seen whether India's laws will be sufficiently vigorous to deal with data protection breaches, but at least, it is a move towards the right direction.

Thursday, October 05, 2006

How much is your personal information?

I was reading through an article where the leader of leader of Bracknell Forest BC has suggested that people who allow their data to be sold to marketing firms could receive council tax cuts. There is more to this:
Paul Bettison told a Conservative party conference fringe meeting that the information from the council's smartcard system could be sold if controls on government databases were loosened."If I could use the information on the 45,000 residents who carry cards, I believe I could be the first council in the country to have a zero council tax," Bettison, e-champion of the Local Government Association (LGA), told the Conservative Technology Forum on 2 October 2006.Such use of the data gathered through the E+ cards, previously known as Edge smartcards, would be voluntary for residents – but for those who did not wish to take part, "it will be £1,400 for a band D," Bettison said.He added that the data held by the council, such as library books borrowed, indications of income and family, could allow companies to target direct mail with enough accuracy to stop it being annoying, as it would present people with offers that were of genuine interest. "Targeted junk mail isn't junk mail," he said. "It's welcome if it's relevant to me.
According to the same article, the Council has indicated that it has no plans to follow up on the idea, but it raises broader questions not only on the privacy of individuals to control their personal information, but also their right to use their information for a commercial incentive. Certainly, supermarkets have already started this line where you sign up for their store cards and build up points on the card in exchange for discounts such as money off coupons etc... I should add one does not have any objection with anyone signing up for a store card. However, if we ponder about the profiles that are being formed about consumers' shopping habits, then this information is certainly valuable to any marketer.

Thursday, September 07, 2006

Information Commissioner's website

The UK Information Commissioner's website has recently been revamped. There is information about dealing with nuisance calls and spam and environmental information. What is unclear is why put emphasis on environmental information? Anyway, the website also contains details about the upcoming Data Protection Commissioners' conference, which will be held on 2-3rd November 2006 and there will be an open session on the theme "a surveillance society." Finally, on the topic of surveillance, the European Commission has issued a consultation paper (pdf) on the use of surveillance technology in civil society.

Friday, August 11, 2006

Russian Data Protection Law

Not being an expert in Russian law, but this brief article (pdf) did catch my attention. Two new laws, About Personal Data 2006 and (160-03) and About Information, Information Technologies and Protection of Information 2006 (No. 149-03) were signed by the President Vladimir Putin on July 27, 2006. This would mean that the law on personal data will take effect in February 2007, bringing Russia into line with the other European countries that have enacted data protection laws.
The laws are meant to give effect to the European Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, ratified by Russia last year....

About Personal Data (The Personal Data Act) regulates the processing of personal data by Russia’s federal and regional governments, municipal authorities, legal entities and natural persons. It applies to both automatically and manually processed data. The aim is to protect an individual’s rights and freedoms, in particular the right to privacy, and private and family secrets...

The data protection laws are certainly beginning to make its headway. May it long continue...

Wednesday, August 02, 2006

28th International Data Protection and Privacy Commissioner's Conference

The 28th International Data Protection and Privacy Commissioners' Conference will be held in London on the 2 and 3 November 2006 and hosted by the Information Commissioner. One of the main themes of discussion will be surveillance. The ICO has commissioned a report into the the theme "Are we sleep walking into a surveillance society? The threats to individuals and the challenges for data protection authorities."

One of the challenges facing us today is the amount of personal information that can be collected, be it on the internet, supermarket or at our place of work. The Data Protection Act 1998, which implements the Data Protection Directive 95/46EC goes some way to regulate the collection of personal data. With the subject of ID cards raising its head again and the possibility of a national ID card database, the question is not so much about whether we are sleep walking into a surveillance society, but the implications (socially or politically) about the personal information that are collected of an individual/group of individuals? There is much scope for debate, but for an interesting read, see David Brin's work The Transparent Society.

Wednesday, July 19, 2006

UK Spam laws

I came across an article about strengthening the UK anti-spam laws introduced back in 2003. The Privacy and Electronic Communications Regulations was introduced to implement the Directive on Privacy and Electronic Communications 2002/58/EC. Yet, three years on, the law has been criticised for its weakness in not stopping spam being sent to businesses. From a legal standpoint, this is interesting given that the regulations were originally intended to prevent spam being sent to individuals. In its latest annual report (pdf), the UK Information Commissioner's Office took the view that the powers confered under the Privacy and Electronic Communications Regulations were insufficient to deal with the problem of spam. This is particularly the case when spam originates from countries outside the EU. Certainly, more can be done, but one will wait and see whether the government consider revising its laws.

Tuesday, July 04, 2006

ICO E-Newsletter

The UK Information Commissioner has published its first e-newsletter (April 2006). Certainly, a good idea and raises more awareness of data protection issues. Also includes a link to the report arising from the one-day conference "Data protection: the next 21 years".

Interesting Reading

I came across a recent article that described the current state of developments on data protection in Singapore. The article is entitled European Union Data Protection Directive: Adequacy of Data Protection in Singapore. My initial thoughts when reading this was that Singapore did not have any data protection laws as yet and even though there has been some discussion about whether to introduce such laws, to date, this has not yet materialised. In any case, the article is well worth reading and in some respects, I do agree that with the suggestions for introducing a framework to meet the requirements of the European Data Protection Directive. As a taster, here is the abstract:

The European Union Data Protection Directive requires member states to place restrictions on transfers of personal data to countries that cannot guarantee an adequate level of data protection. Countries that do guarantee adequate protection enjoy a smooth business environment and an enhanced ability to participate in trade. In this paper I examine the adequacy of Singapore’s data protection regime, and in particular the Model Data Protection Code. I suggest various amendments to the regime to enable Singapore to meet the Directive requirements. To carry out the assessment,I use a framework developed by the Article 29Working Party, the body that in practice carries outthe official adequacy assessments for the EU.

Friday, June 23, 2006

US privacy laws

Well, I have been taking a break from this, having been putting my head down with writing. Anyway, returning to my usual blog, I came across a recent press release that caught my attention. According to the this press release, some of the major tech companies including Google and Microsoft are calling for stronger privacy laws in the US.

The time has come for a serious process to consider comprehensive harmonized federal privacy legislation to create a simplified, uniform but flexible legal framework," said the CPL Forum's statement. "The legislation should provide protection for consumers from inappropriate collection and misuse of their personal information and also enable legitimate businesses to use information to promote economic and social value.

Whilst such efforts for stronger privacy laws in the US should be commendable, it is unclear whether the laws will in anyway be modelled on the European model on data protection. One can only await to see whether their calls are brought to fruition!

Saturday, June 10, 2006

Data Protection Award

This is the first time I have heard, but there is a European award for best practice in data protection. According to the press release, the UK Information Commissioner is encouraging the public sector organisations to put in an application which must be received by 5 October 2006. The criteria is as follows:

  • procedures in place for ensuring quality of the personal data processed
  • design of an efficient system for furnishing mandatory information to citizens
  • respectful and efficient procedures to manage consent
  • existence of specific rules or procedures for processing sensitive data
  • security measures in place
  • procedures for the communication or disclosure of data to third parties
  • arrangements in place for access to the data by third parties
  • the planning and design of procedures which enable people to access and challenge content, and seek any correction or deletion
More information can be obtained from the Information Commissioner. Well, it is another way of raising awareness of data protection laws and promoting good practice! Why not!

Wednesday, June 07, 2006

ECJ judgment available

Following the ruling by the European Court of Justice (ECJ) on the joined Cases C-317/04 and C-318/04 European Parliament v Council and Commission on 30 May 2006 concerning the EU-US agreement that required airlines to transfer the personal data of their passengers to the US authorities, the judgment is now available.

The ECJ held that the Council Decision 2004/496/EC of 17 May 2004 on the conclusion of an Agreement between the European Community and the USA on the processing and transfer of Passenger Name Record ("PNR") data by Air Carriers to the US Department of Homeland Security, Bureau of Customs and Border Protection (see the Department's fact sheet on the agreement), and Commission Decision 2004/535/EC of 14 May 2004 on the adequate protection of personal data contained in the PNR of air passengers transferred to the United States Bureau of Customs and Border Protection, should be annulled.

Well, time to read up on the judgment!