Thursday, April 27, 2006

Guidance on Outsourcing

The UK Information Commissioner has issued some guidance on outsourcing. This is particularly important if companies intend to outsource their operations to countries outside the EEA because Art. 25 of the Data Protection Directive 95/46/EC (DPD) prohibits the transfer of personal data to third countries (outside the EEA) unless it satisfies the adequacy requirement under Art. 25 DPD. This is implemented under the 8th data protection principle of Schedule 1, Data Protection Act 1998. There are exemptions to Art. 25 under Art. 26 including obtaining consent from the data subject (customers/staff etc); transfer is necessary for the conclusion or performance of a contract and so forth. For more details, see:

Monday, April 24, 2006

Data Retention Directive

The Data Retention Directive 2006/24/EC (pdf) is now available. However, according to latest news reports, the US has taken an interest in the Directive. What is unclear is whether they will follow the EU's example.

In the meantime, it will be worth reading the Data Retention Directive. At first glance, the Directive should be implemented by 15 September 2007 (Article 15). The application of the Directive to the retention of communications data relating to internet access, internet telephony and email can be postponed by each member state until 15 March 2009. Art. 15(3) provides as follows:

Until 15 March 2009, each Member State may postpone application of this Directive to the retention of communications data relating to Internet Access, Internet telephony and Internet e-mail. Any Member State that intends to make use of this paragraph shall, upon adoption of this Directive, notify the Council and the Commission to that effect by way of a declaration. The declaration shall be published in the Official Journal of the European Union.

Saturday, April 22, 2006

Panel discussion

With two weeks to go before I present (at a conference on privacy), there is a panel discussion that I will be involved in with two other academics. The theme of the panel discussion is Privacy: inroads and threats to privacy. One is reminded of Scott McNealy's famous words back in 1999 "You have zero privacy anyway--Get over it".

We should not forget that privacy is not absolute and the law (Art. 8 of the European Convention of Human Rights) provides for exceptions to the protection of privacy. Has technology eroded privacy? To a greater extent - examples I can think of include RFIDs; mobile phones which have a camera facility as well as a possibility of revealing the location of individuals; computer databases of individual profiles etc. One book worth reading is Daniel Solove's book entitled The Digital Person. Technology has moved on in great strides with legislation trailing behind. In any case, I'm not entirely convinced that legislation is necessarily the best approach to deal with the protection of privacy. In other words, let technology deal with technological problems. For example, if you find spyware on your computer, you use software to remove it. Laurence Lessig's book on Code and other laws of cyberspace is also another book worth reading!

Conference

Just a reminder that there will be the Privacy Laws & Business 19th Annual International Conference. The theme is:

Privacy Crisis Ahead?
Investing enough in data protection to strengthen and defend your reputation

July 3-5th, 2006, St. John's College, Cambridge, UK

Programme is available at www.privacylaws.com/pdfs/annualconference/ac19programme.doc

As I will be unable to attend, anyone who attends, let me know how it goes.

Monday, April 17, 2006

Further reading

As this is the bank holiday, I was reading through the latest developments on data protection and freedom of information. For those who want to do further reading, see:

Phishing

I received an email purporting to be from PayPal and asking for login details to PayPal account. Having researched and worked in the field of data protection, I decided to look at the link (see http://www.paypal.com/cgi-bin/webscr?cmd=login-run). This is an exact copy/replicate of PayPal website. You can email PayPal at spoof@paypal.com so that they can check whether this is genuine. Again, if you receive emails asking for personal details, it is always advisable to delete this and doublecheck with the company by forwarding the email to the company. Anyway, there are a few websites on phishing activities.

See

Wednesday, April 12, 2006

DTI Survey

In the latest UK DTI survey, it was found that UK businesses were still failing to protect an individual's personal information.

With increasing amounts of business being conducted online, data protection is ever more important, the DTI said. While most large organisations have adopted best practices regarding network and data protection, small companies have not. Fewer than a third of them encrypted the data they received.

This is particularly worrying for individuals who regularly use the internet, whether for buying goods, checking their bank statements etc. The UK Information Commissioner has provided guidance about the Data Protection Act 1998, but more needs to be done to raise awareness amongst the smaller businesses that it is vitally important to adhere to the Data Protection Act 1998. In particular, the seventh data protection principle (schedule 1 DPA 1998) requires that appropriate technical and organisational measures are taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.

For more details see:

Tuesday, April 11, 2006

Art. 29 Working Party's opinion on the retention of data

The Art. 29 Working Party (established under Art. 29 Data Protection Directive) has published its recent opinion on the retention of data. It takes the following view:


Therefore, the Art. 29 Working Party proposes a uniform, European-wide implementation of the Directive. This approach should guarantee a harmonized application of the provisions of the Directive whilst respecting the highest level possible of protecting personal data. This should also be done with a view to reducing the considerable costs to be borne by the service providers when complying with the provisions of the Directive. In order to transpose the provisions of the Directive in a uniform way and to comply with the requirements of Article 8 of the European Convention on Human Rights, Member States should implement adequate and specific safeguards.

We do not yet have the actual Directive, but here is the latest draft (pdf) to the retention of data. See also:

Friday, April 07, 2006

Photographs and privacy

Here is another press release about a photo published without the consent of the individual in the photo. According to the Press Complaints Commission, the photo was published in a newspaper article. I will not go into details of the case. The Press Complaints Commission has ruled, however, that the publication of a photo of the individual in his home without his consent was a breach of his privacy. It is interesting to note that the photo was taken in the complainant's home and not in public.
Although the Press Complaints Commission self-regulates the newspaper/magazine industry in the UK to ensure that they (newspapers/magazines) follow the codes of practice, we should not forget that there is the UK Data Protection Act 1998.
Some cases that came to mind (and may be of interest) are the decisions (by the House of Lords) in Campbell v MGN and the European Court of Human Rights in the Von Hannover v Germany. Both were concerned with the publication of details concerning the complainant's private lives. However, the European Court of Human Right's decision was far-reaching because it held that photos taken in public of public figures had to fulfil this condition: Pictures that were published in newspapers had to show that they were serving the 'public interest', there has to be some contribution towards a debate of general interest.
I could go on, but it would be more appropriate to have this written in an article. Food for thought!

Guidance from the ICO on buying and selling a database

I have been slightly pre-occupied over the last few days, having had to attend and chair a conference. I heard some very interesting papers and discussions.
Anyway, returning to my usual blog, I came across a few press releases on data protection. The UK Information Commissioner has published some guidance on buying and selling a database. The guidance is clear in stating that it is not a breach of the UK Data Protection Act 1998 to sell a database containing customers' details. However, companies/organisations (who plan to do this) must meet certain conditions/requirements. This includes obtaining the customer's consent and making sure that the customer understands the purpose for which the data was originally collected.
Guidance in this area is long overdue. However, it is still unclear the extent to which these databases are sold to other companies and whether customers know that their data are being transferred. More research and awareness in this area is much needed.
Guidance can be found here (pdf).

Monday, April 03, 2006

A good read!

I have almost finished reading the book entitled Just Law by Baroness Helena Kennedy and would recommend it to anybody who has not read this. Not only does the book cover issues such as the legal profession, criminal justice and police powers, there is even a section on "Big brother" (including ID cards). It is well-argued and written in such a way that anybody (without a legal background) is able to understand. Definitely worth reading!

Friday, March 31, 2006

Compromise on ID Cards

A compromise has finally been reached on the UK ID cards bill. Anyone who applies for a passport will not need to apply for an ID card until 2011, but their details will be put on a national ID database. The House of Lords have finally supported this compromise by 287 votes to 60. What is still uncertain is how much these ID cards will cost and who has access to the national ID database?
Under clause 22 of the bill, a National Identity Scheme Commissioner will be appointed whose principal role will be to supervise the operation of this bill (once enacted). Clause 17-21 inclusive are relevant in determining the circumstances under which information about an individual can be provided. This includes a government department (under clause 17(5)) and where it was necessary in the public interest (clause 17(7)). One awaits to read the final version of the bill when it becomes law, but certainly, there are more questions that need to be answered.
Links:

Tuesday, March 28, 2006

ID cards rejected for the 5th time

I received a press release that the ID cards Bill has been rejected by the House of Lords for the 5th time. This time, it was by a majority of 28 (219-191). The main issue is whether ID cards should be linked to passport applications - the HL argue that this should be voluntary and not a compulsory measure. The Bill will now go back to the House of Commons.

Here are the links to:

Tor system

I was listening to the latest podcast and found an interesting development about anonymizing internet communications. The system is called Tor.
Tor is a toolset for a wide range of organizations and people that want to improve their safety and security on the Internet. Using Tor can help you anonymize web browsing and publishing, instant messaging, IRC, SSH, and other applications that use the TCP protocol. Tor also provides a platform on which software developers can build new applications with built-in anonymity, safety, and privacy features.
Anyway, for more details, visit their website or listen to the podcast!

Friday, March 24, 2006

Internet privacy case

I came across this latest press release about legal action being brought against Gratis, an internet company based in Washington DC. According to the reports, the New York Attorney General Eliot Spitzer has filed suit against Gratis on the grounds that it had sold personal information obtained from millions of consumers despite a promise of confidentiality. Allegations include selling access to lists of millions of Gratis’s customers to three independent email marketers.

For more, see:

Google

The court in California has ruled that Google should hand over some search data (including 50,000 web addresses) to the Department of Justice, but the Judge has denied request that a list of people's search requests should be handed over.

"The expectation of privacy by some Google users may not be reasonable," Judge Ware wrote, "but may nonetheless have an appreciable impact on the way in which Google is perceived, and consequently the frequency with which users use Google."

Questions should be raised over the extent in which Google holds the search requests of users. How long is it held and what are their policies? The Data Protection Directive 95/46/EC stipulates the conditions under which personal data are processed and applies within the European Union. The Directive on Privacy and Electronic Communications 2002/58/EC specifies the conditions under which "traffic data" (Art. 6) and "location data" (Art. 9) are held. More discussion and awareness is needed (whether academics, practitioners or the public) about the laws that apply to search engines.

See also:

Thursday, March 23, 2006

Freedom of Information Website

The freedom of information website has recently been revamped with a new design. It continues to provide useful information about this area. Certainly, it is relevant when we look at how the roles of the data protection commissioners have changed (to include oversight of freedom of information laws). The aim of the website is to provide a:

One-stop portal for critical resources about freedom of information laws and movements around the world. The site describes best practices and lessons learned, compares campaign strategies, and links the efforts of freedom of information advocates globally.

Anyway, well worth visiting!

Wednesday, March 22, 2006

Latest on ID Cards Bill

In this battle over the ID cards bill, the House of Commons have rejected the compromise by the House of Lords to make the scheme of ID cards voluntary until 2011. Therefore, anyone applying for a passport would be required to apply for an ID card from 2008. So the bill now returns to the House of Lords.

Tuesday, March 21, 2006

ID Cards - part 2

Further to my earlier blog on ID cards bill, the House of Lords (HL) had rejected the ID cards bill yesterday and have suggested a compromise proposal to keep the scheme voluntary until 2011 – after the next general election. I am including:

We await to see whether the House of Commons will accept this compromise.

ID cards - latest

I am beginning to lose count over the number of times the ID cards bill is being sent from one House to another. Today, we will expect more discussion about the ID cards in the House of Commons. If the latest news reports are correct, then we may see a compromise made by the Liberal Democrats and Conservative peers in the House of Lords should the amendments be rejected by the House of Commons. According to the reports, it is suggested that the Bill's requirement that people must get an ID card when applying for a passport is voluntary for five years and will become compulsory in 5 years ie. 2012. I am including a link to the progress of the ID cards. We'll have to wait and see what developments arises, but hopefully, the Parliament Act will not be invoked to force this Bill through.

See also the latest blog: