Category: News

Latest DAPIX leak of the Data Protection Regulation eases transfers and makes fining difficult

This blog reports the latest leak from "the DAPIX sieve" in the areas of transfers of personal data outside the EEA and fines from Data Protection Authorities (references below has the link to the leaked document). As is well known the Irish have published the first 40 Articles of the Commission’s Regulation (see previous blogs); this leak (at the end of the Irish Presidency) gives a good idea of the direction of travel in relation to the remaining 50 Articles.

Read article

Mr Hague can explain GCHQ interception of “external communications”

No doubt you have seen this weekend’s brouhaha about GCHQ and the Guardian’s allegation that it has intercepted communications on a gargantuan scale. Well I think Mr Hague can clear everything up with a public statement as to why he thinks such interception is proportionate without any nonsense such as: "I can't say anything because that could jeopardise national security”. Why? Because it is very likely that he has signed (or authorised) a warrant phrased in very general terms that

Read article

Member States divide over the protection offered by the Irish version of the data protection regulation

Do you know what? After watching a very turgid video covering the meeting of Ministers (June 6th) which discussed the Irish text of the Data Protection Regulation, I have concluded that there is a no agreement in sight. Indeed, I think the Regulation will not see the light of day unless there is a great “love-in” between Member States. As I explained in the last blog, some Member States want more “risk assessment”; a move which in combination with a

Read article

How the UK’s risk-based data protection policy can result in lower standards of data protection

Today’s blog deals with the UK position on the Irish text of the Regulation and is based on the statements of Chris Grayling MP, the Cabinet Minister responsible for data protection at a June’s Council of Ministers meeting (see references). Following these statements I have concluded that the current UK Government policy on data protection supports a level of protection below that established by Directive 95/46/EC. This arises because the Government want many more data protection obligations in the replacement

Read article

Irish data protection regulation text gives Google and Facebook the upper hand

Would you be surprised if the Irish text of the Regulation could allow a Member State, most likely Eire, to implement specific exemptions for companies like Google and Facebook from those data subject rights that involve accuracy, correction, erasure of personal data and the so-called “right to be forgotten”? In addition, would you be surprised if the definition of “main establishment” introduced by the Irish could mean that any enforcement action against such companies would be prolonged and could easily

Read article

Irish do a “hatchet job” on the Data Protection Regulation

The Irish Presidency has published the first 40 Articles of what it considers to be an acceptable Regulation; as I said with my DAPIX blog (see references) based on a leak of this document, my conclusion is: Irish text = old Directive 95/46/EC + tweaks In previous blogs on this subject, I have referred to the fact that there has been no agreement by Member States on the text. The DAPIX leak document (see references) is one of the few documents which explains why these disagreements arise. The

Read article

ICO needs a different strategy to deal with data protection offences

I have drawn the conclusion that the Government will not commence the custodial nature of Section 55 offence in the Data Protection Act this side of the General Election (and within the next few years). The reason is familiar: fear of upsetting the press. I also think that the ICO needs to adopt another strategy to deal with the problem of not having the custodial element available; for instance, by passing over suitable cases to the public prosecutors and/or using

Read article

Latest leak: the new Data Protection Regulation is looking more like the old Directive

Here is a swift “low-down” on the latest DAPIX leak (thanks to a friend of a friend who knows someone who received an email). I think the headline says it all; the Regulation is being softened and weakened from the data subject perspective. The DAPIX document (see references for a copy) only refers to some Articles so the general effect on the Regulation is not clear from the document. However the direction of travel is clear. That direction is; less

Read article

How Google lost the trust of Europe’s Data Protection Authorities

Over the last two years, various European Data Protection Commissioners have taken action against Google. Hardly a month goes by without something being reported: a €145,000 StreetView fine here or a court case about jurisdiction there. So it is important to understand: “why is Google on the receiving end all this enforcement action?”. Why now, and not five years ago? What has changed? From Europe’s Data Protection Commissioners perspective, there is a collective recognition that Google has given them the

Read article

Mrs Thatcher’s data protection legacy

Successive UK Governments have seen data protection more as a cost overhead to be minimised rather than as an essential protection for the individual in an electronic age. This view started with Mrs Thatcher’s first Government and has endured for over three decades. During the 1970s, there were a number of White Papers and Reports starting with the Younger Report on Privacy (in 1972) and ending with the Lindop’s Report on Data Protection (December 1978). So when Mrs Thatcher came

Read article
Search Hawktalk blogs by month :
Select Date
View blogs by category:
Hawktalk Taxonomy