Category Archives: Uncategorized

ICO applies public sector fine approach to charity

The Information Commissioner’s Office has fined the CENTRAL YOUNG MEN’S CHRISTIAN ASSOCIATION (YMCA) of London £7500.

The penalty notice is not published at the time of writing (nor anything else yet on the ICO website), although the fine is said to have already been paid, and the press release issued by the ICO says the fine was issued for “a data breach where emails intended for those on a HIV support programme were sent to 264 email addresses using CC instead of BCC, revealing the email addresses to all recipients. This resulted in 166 people being identifiable or potentially identifiable”.

The press release also says that the fine was reduced from an initially-recommended £300,000, “in line with the ICO’s public sector approach”. When I queried the rather obvious point that a charity is not a public authority, an ICO spokesman initially told me that “as Central YMCA is a charity that does a lot of good work, they engaged with us in good faith after the incident happened, recognised their mistake immediately and have made amends to their processing activities and they paid the fine in full straight away, we applied the spirit of the public sector approach to them even though they’re not strictly a public sector body”.

This led to a further follow-up query from me because as a matter of logic and timing, how could the fact that a controller “paid the fine in full straight away” be a mitigating factor in reducing the amount of the fine to be paid? The further response was “The point was that they engaged fully and subsequently paid the fine in full, thus confirming our position that they were engaging and taking the breach seriously. The calculation comes before the payment which has no bearing on the assessed amount.”

I’m not quite sure what to make of this. Can any controller which “does a lot of good work”, engages with the ICO in good faith and remedies processing activities also benefit from a 3900% decrease in fine from an originally-recommended sum? What does “a lot of good work” mean? Is it something only charities do? What about private companies with a strong ESG ethos, or who make significant charitable contributions?

[this post was originally published on my LinkedIn page.]

The views in this post (and indeed most posts on this blog) are my personal ones, and do not represent the views of any organisation I am involved with.

Leave a comment

Filed under Data Protection, fines, Information Commissioner, LinkedIn Post, monetary penalty notice, Uncategorized

8000% in people affected by central government data breaches

Yes, you read that correctly. Here’s what we’ve just published on the Mishcon de Reya website:

https://www.mishcon.com/news/data-breach-crisis-in-central-government-time-for-ico-to-act

Leave a comment

Filed under Uncategorized

Princess Kate and data protection

I’ve written a piece on the Mishcon de Reya website on the data protection implications of reports that staff at the London might have inappropriately accessed her patient notes.

https://www.mishcon.com/news/the-princess-of-wales-and-possible-data-protection-offences-and-infringements

Leave a comment

Filed under Uncategorized

NADPO January webinar – a focus on the DPDI Bill

As we hurtle into an election year there may be a rush to get parliamentary bills over the line. The signs are that there is a) a momentum behind the Data Protection and Digital Information Bill*, and b) little notable opposition opposition, so I’m expecting it to pass.

Accordingly, the NADPO executive have asked two experts to speak about the Bill at our next webinar, on Tuesday 23 January: Dr Chris Pounder and Ibrahim Hasan are preeminent in the field, and will be talking, respectively, about “New Data Sharing rules under the DPDI Bill” and “Proposed changes to UK GDPR”.

As always, attendance is free for NADPO members, and Data Protection Forum members can also attend for free under our mutual agreement with the Forum. If anyone else fancies testing the NADPO waters please drop me a line at chair at nadpo dot co dot uk and I’ll see if we can accommodate you.

[*the Bill is no longer titled “No.2”, despite what I’ve seen from many experts, including *cough* myself, albeit a few months ago now]

Leave a comment

Filed under Uncategorized

NADPO September webinar

The monthly NADPO lunchtime webinars resume today at 12:30 to 14:00, with talks by Robin Hopkins of 11KBW on ‘Insights from recent High Court judgments’ and Ashley Winton of Mishcon de Reya LLP on ‘DPIA => AIIA, a look at the wider laws that will apply to AI’.

NADPO members should have the joining details in their inboxes, but if anyone would like a free guest place, to test the NADPO waters, as it were, do either message me here, or on chair at NADPO dot co dot uk, as we have a couple available.

2 Comments

Filed under Uncategorized

UK-US Data Bridge now constructed

Traffic to start moving next month…

A short piece by me on the Mishcon de Reya website:

https://www.mishcon.com/news/uk-us-data-bridge-agreed

Leave a comment

Filed under Uncategorized

ECtHR case with “profound consequences for digital archives”

A piece in The Times by me and my Mishcon de Reya colleague Emma Woollcott, on the recent Hurbain v Belgium “right to be forgotten” case:

https://www.thetimes.co.uk/article/588d0282-523f-11ee-a518-203f78f24415?shareToken=e340610d08c71fe41d2602e066339071

Leave a comment

Filed under Uncategorized

ICO and reprimands – unfair to recipients?

I’ve written on the Mishcon de Reya website about the Information Commissioner’s Office’s use of reprimands for data protection infringements, despite the absence of any published guidance or procedure. Coupled with the lack of any way of appealing a reprimand, does this risk putting recipients in an unfair position?

https://www.mishcon.com/news/icos-regulatory-use-of-reprimands-does-it-need-a-rethink

Leave a comment

Filed under Uncategorized

NADPO June Webinar

NADPO’s next webinar is tomorrow, June 27, featuring 

Lucas Amin, Open Democracy – “the NHS Federated Data Platform – risks and opportunities”
Dr Luc Rocher, Oxford Internet Institute – “The hazards of proxy data sets

Members should already have (just) been sent the link, and it is also available in the members’ zone on our website. As usual, there are one or two free spaces if anyone wants to test the waters. Contact me at chair at nadpo dot co dot uk if you’d like to request one.

https://nadpo.co.uk/event/nadpo-june-webinar/

Leave a comment

Filed under Uncategorized

ICO to issue fines for non-compliant cookie banners?

That is what they are warning. Let’s see what transpires. New post by me on the Mishcon de Reya website:

https://www.mishcon.com/news/ico-warns-of-fines-for-companies-who-do-not-get-cookie-banners-right

Leave a comment

Filed under Uncategorized