Category Archives: Uncategorized

ICO’s reasons for reducing BA’s fine – COVID not significant factor

Some media outlets who should know better have suggested COVID-19’s economic impact led to the ICO reducing its intended £183m fine for British Airways to the final £20m. In this piece on the Mishcon site, I point out that the initial figure was dropped after (and quite probably because of) strong representations from BA’s lawyers about the ICO’s reliance on a draft internal procedure for setting fine amounts.

Leave a comment

Filed under Uncategorized

Something is rotten in the state of FOI

By law, Freedom of Information Act 2000 (FOIA) requests must be responded to within 20 working days.

FOIA is regulated and (should be) enforced by the Information Commissioner’s Office (ICO).

As a public authority the ICO must also respond to FOIA requests.

So the ICO regulates (and should enforce) its own compliance with FOIA.

On 9 March 2020 I made a FOIA request to ICO, asking for the number of, and the recipients of “reprimands” issued by the ICO under Article 58(2)(b) of the General Data Protection Regulation (GDPR).

I didn’t receive a response within 20 working days (I did receive an acknowledgment of receipt on 31 March). However, I understood, and understand, the impact that COVID-19 has had on the ICO, so I realised and accepted that there might be a slight delay.

On 12 June I chased for a response.

On 16 June I was told the ICO was “working on a response”.

On 31 July I chased for a response.

On 12 August I received an apology and on 19 August a further email telling me I should receive a response by 28 August.

On 28 August I received some information: I was told how many Article 58 reprimands have been issued, but not who the recipients were. The latter would follow “shortly” as they were still “considering it”.

Despite chasing again, twice, I have heard nothing more.

So, nearly seven months after I made my FOIA request, and nearly half a year late, I still have no response from the office which is meant to regulate the law.

I really didn’t want to push this request too much. This period of pandemic has been beyond any normality, and I was very aware of the pressures the ICO must be under. But this was not a difficult request to deal with, in terms of finding the information (in fact, I would imagine they could find it in minutes). What presumably was difficult was the decision about whether to name and therefore shame the recipients of reprimands. I cannot see how COVID will have adversely affected the ability to take such a decision.

Ultimately, though, with an approach such as this from the regulator, one is left wondering – what’s the point in making FOIA requests?

The views in this post (and indeed most posts on this blog) are my personal ones, and do not represent the views of any organisation I am involved with.

Leave a comment

Filed under Uncategorized

New posts on EC 2 year review of GDPR and CCPA

A couple of new posts by me on the Mishcon de Reya website.

Commission evaluation report of GDPR: a good start, but areas for improvement
CCPA – California’s new data protection law is now enforceable

I’d note in particular the quote ICO gave us on the Commission’s GDPR review, to the effect that it doesn’t think it needs more resources:

We continually invest in strengthening the ICO in both number and expertise and presently employ nearly 800 staff. We have over 200 case officers working on issues raised by the public and over 100 staff in our enforcement department taking forward our investigations. We also have well resourced departments developing our information rights policies and guidance.

 

Leave a comment

Filed under Uncategorized

Further delays to ICO proposed fines for BA and Marriott

A post by me on the Mishcon de Reya website.

ICO is clearly not finding it easy to make the intended fines stick.

Leave a comment

Filed under Uncategorized

Event on collective redress for databreaches

Via the Mishcon de Reya website – an event run in association with the British Institute for International and Comparative Law on identifying, building, bringing and defending Group actions for data protection infringements.

Leave a comment

Filed under Uncategorized

Sign-up available for Mishcon Data Matters blog

Just a very quick post to say that it is now possible to subscribe to the Mishcon de Reya Data Matters blog. I often post on there, as do several of my colleagues.

Leave a comment

Filed under Uncategorized

Data protection and legal knowledge – it cuts both ways

In his recent annual COMBAR lecture, the Chancellor of the High Court, Sir Geoffrey Vos, said

an insight into the law relating to data and data protection should be one of the most important specialisms in the armoury of a modern commercial lawyer

To which I say, “spot on, Sir Geoffrey”. As he goes on to add

Whilst many glaze over at the mention of “data protection”, it will become something that every lawyer at all levels will need to understand and advise upon

Ignore the cruel jibe – he is right, or almost so: in fact lawyers at all levels should already be understanding and advising on data protection.

But it cuts both ways – those who are not qualified lawyers, but who practise in the area of data protection, need to understand its basis in law. Too often one sees non-lawyer practitioners failing to ground their advice in the legal definitions and statutory principles, and being unaware of prior court decisions, or the concept of stare decisis itself, or even how to navigate a statute.

I’m not here to recommend any particular provider, or offering, but I will say that all lawyers could benefit from good training in at least data protection, and all data protection practitioners could benefit from good training in the basics of the law.

The views in this post (and indeed all posts on this blog) are my personal ones, and do not represent the views of any organisation I am involved with.

Leave a comment

Filed under Data Protection, Uncategorized

Computer says “no”

I have another piece up on the Mishcon de Reya Data Matters site:

Computer says no – data protection and reasonable adjustments

Leave a comment

Filed under Uncategorized

Regulatory cooperation and information sharing

I have a new piece up on the Mishcon de Reya Data Matters pages. You can read it here.

2 Comments

Filed under Uncategorized

The wheels of the Ministry of Justice

do they turn so slowly that they’ll lead to the Lord Chancellor committing a criminal offence?

On 21 December last year, as we were all sweeping up the mince piece crumbs, removing our party hats and switching off the office lights for another year, the Information Commissioner’s Office (ICO) published, with no accompanying publicity whatsoever, an enforcement notice served on the Secretary of State for Justice. The notice drew attention to the fact that in July 2017 the Ministry of Justice (MoJ) had had a backlog of 919 subject access requests from individuals, some of which dated back to 2012. And by November 2017 that had barely improved – to 793 cases dating back to 2014.

I intended to blog about this at the time, but it’s taken me around nine months to retrieve my chin from the floor, such was the force with which it dropped.

Because we should remember that the exercise of the right of subject access is a fundamental aspect of the fundamental right to protection of personal data. Requesting access to one’s data enables one to be aware of, and verify the lawfulness of, the processing. Don’t take my word for it – look at recital 41 of the-then applicable European data protection directive, and recital 63 of the now-applicable General Data Protection Regulation (GDPR).

And bear in mind that the nature of the MoJ’s work means it often receives subject access requests from prisoners, or others who are going through or have been through the criminal justice system. I imagine that a good many of these horrendously delayed requests were from people with a genuinely-held concern, or grievance, and not just from irritants like me who are interested in data controllers’ compliance.

The notice required MoJ to comply with all the outstanding requests by 31 October 2018. Now, you might raise an eyebrow at the fact that this gave the MoJ an extra eight months to respond to requests which were already incredibly late and which should have been responded to within forty days, but what’s an extra 284 days when things have slipped a little? (*Pseuds’ corner alert* It reminds me of Larkin’s line in The Whitsun Weddings about being so late that he feels: “all sense of being in a hurry gone”).

Maybe one reason the ICO gave MoJ so long to sort things out is that enforcement notices are serious things – a failure to comply is, after all, a criminal offence punishable on indictment by an unlimited fine. So one notes with interest a recent response to a freedom of information request for the regular updates which the notice also required MoJ to provide.

This reveals that by July this year MoJ had whittled down those 793 delayed cases to 285, with none dating back further than 2016. But I’m not going to start hanging out the bunting just yet, because a) more recent cases might well be more complex (because the issues behind them will be likely to be more current, and therefore potentially more complex, and b) because they don’t flaming well deserve any bunting because this was, and remains one of the most egregious and serious compliance failures it’s been my displeasure to have seen.

And what if they don’t clear them all by 31 October? The notice gives no leeway, no get-out – if any of those requests extant at November last year remains unanswered by November this year, the Right Honourable David Gauke MP (the current incumbent of the position of Secretary of State for Justice) will, it appears, have committed a criminal offence.

Will he be prosecuted?

The views in this post (and indeed all posts on this blog) are my personal ones, and do not represent the views of any organisation I am involved with.

1 Comment

Filed under access to information, Data Protection, Directive 95/46/EC, GDPR, human rights, Information Commissioner, Ministry of Justice, Uncategorized