Category: News

Party promises on Data Protection, FOI, Digital rights, Human Rights, Leveson and mass surveillance

At great risk to my mental health, I have extracted the relevant parts of the Party Manifestos.  Here they are without comment. URLs for each manifesto is at the end; address of my psychiatrist available on request.  CONSERVATIVE There is no explicit mention of data protection, freedom of information or privacy. “The next Conservative Government will scrap the Human Rights Act, and introduce a British Bill of Rights. This will break the formal link between British courts and the European Court

Read article

Confirmation that the Data Protection Regulation reduces protection for data subjects from Directive 95/46/EC

It appears that DAPIX civil servants are burning the midnight oil in an attempt to agree a draft text of the Data Protection Regulation which can be put before the Council of Ministers at its June meeting. Such a Ministerial agreement would then trigger tri-partite negotiations with the European Parliament and the Commission with the objective of producing a final text of the Regulation (my guess is still January-March 2016; implementation early 2018). To get to a June agreement, the

Read article

GCHQ to offer email services and obtain consent for mass communications data retention

One of the papers published by the Intelligence and Security Committee (ISC) with its report into “Privacy and Security” contained a five-page memo from GCHQ’s legal advisers (see last week’s blog and references).  It suggests that the secret organisation is about to offer email services to the public in order to allay concerns about the mass retention of communications data. I have checked with a leading domain name registration company, and it appears that the first steps have already been

Read article

Intelligence and Security Committee ignore the Data Protection Principles in its attempt to restore public trust in bulk data collection

Suppose you are on a jury in a case about tax evasion.  What would you think of a defence on the lines: “the accused did not seek to circumvent the law”?  Would you accept this statement and return a not-guilty verdict? Well this, in summary, is what the Intelligence and Security Committee (ISC) has done.  In its press release associated with its report ‘Privacy and Security: A modern and transparent legal framework’, the ISC states: “The UK’s intelligence and security

Read article

Development of a Scottish Population Register/ID Card Scheme is subject to ICO criticism

In January,  I published a blog on how the Scottish Government were consulting on plans to transform the current NHS Central Register (“NHSCR”) into a population register without much thought about the Data Protection Act (DPA). The ICO has just published a contribution to that consultation  process that, when you strip away the diplomatic language, comes to a similar conclusion. What I did not know at the time of writing the blog was that there was a flourishing “Entitlement Card”

Read article

Why the Data Protection Regulation is likely to provide a lower level protection than Directive 95/46/EC

This blog explains why I think the Italian text of the Regulation published just before Xmas is likely to provide data subjects with a lower level of protection than Directive 95/46/EC or even the current Data Protection Act 1998 (DPA). In the blog, I raise four areas to make the case: A carve out for the public sector (this allows Member States to legitimise processing that otherwise could be in breach of a data protection requirement). The “risk based” approach

Read article

When are personal data not personal data? The answer may be the solution for maintaining privacy in the Cloud?

Musing over the definitions again – there are worse habits you know! Suppose you have a data controller who holds personal data and uses an IT company to process the data and suppose further, the IT company does not have access to any identifying details (i.e. the controller retains ALL identifying data and the IT company has no identifying data or data that could lead to identification of data subjects). Clearly the data controller is processing personal data but is the

Read article

ECJ Ryneš ruling implies IP addresses are personal data in themselves

What better way to spend Data Protection Day (yesterday) than having a light-bulb moment; this is especially the case as, at my age, light bulbs tend to go in a different direction. My thoughts on IP addresses were triggered by the Ryneš ECJ case (domestic purposes exemption does not apply to surveillance of public places from a domestically installed CCTV). I think the Ryneš case strengthens the argument that an IP address is personal data in many instances. If I

Read article

Proposals to expand Central NHS Register creates a national population register and significant data protection/privacy risks

[Note added 17/3/2017: The proposal is no longer going ahead: See Question S5W-07384 of 21/02/2017 "Ministers have listened carefully to the arguments"   …and do not intend to take forward the proposal.] I thought the idea of a centralised, national population register was well and truly dead? Well the Holyrood SNP Government wants to resurrect a Scottish version. The Scottish Government’s plans are outlined in a document entitled “Consultation on proposed amendments to the National Health Service Central Register (Scotland) Regulations 2006”. The

Read article

Amberhawk Training Schedule Winter/Spring 2015

 1. DATA PROTECTION BCS PRACTITIONER QUALIFICATION: The next standard DP courses are in London (starts 20 January 2015) and in Leeds (starts 22 April);  the next intensive DP courses are in Edinburgh (starts 9th March 2015) and London (starts 28th April)  2. NEW DATA PROTECTION BCS FOUNDATION QUALIFICATION:  we are delivering the new BCS Foundation Course in Data Protection syllabus in London (16, 17 and 18 March). This 3 day course is intended to ensure that the team that supports

Read article
Search Hawktalk blogs by month :
Select Date
View blogs by category:
Hawktalk Taxonomy