When they mail me with information I can see everybody else's e-mail addy
they have circulated and naturally everybody else can see I have been
circulated.
The e-mail addresses must be coming from a Data Base somewhere, probably a
council department.
Is this a breach of the rules/laws governing council Data Bases?
pete
It could be, but it rather depends on the terms under which they
originally collected the email addresses. It is probably bad practice
though, as at least one of the addressees is likely to want to misuse
the list for unwelcome commercial or political purposes. I don't think
it makes a difference whether the emails are stored on a computer
database, or on a set of vellum scrolls in the basement.
Why not ask them to use Bcc for the list?
--
Percy Picacity
If you point out what they are doing wrong they will be in breach of the
rules if they don't then fix the problem. The law requires them to take
reasonable precautions to protect personal data. They can only do that
if they know what is reasonable. You should contact the sender and point
out their error.
--
Bernard Peek
b...@shrdlu.com
I have but all I am getting is a silly councillor sticking up for what she
regards as her staff and absolutely failing to address the issue.
pete
>> Is this a breach of the rules/laws governing council Data Bases?
>
>If you point out what they are doing wrong they will be in breach of the
>rules if they don't then fix the problem. The law requires them to take
>reasonable precautions to protect personal data. They can only do that
>if they know what is reasonable. You should contact the sender and point
>out their error.
More than reasonable precautions surely? The Act requires that
personal data be kept secure. Clearly they are not.
--
Geoff Berrow (Put thecat out to email)
It's only Usenet, no one dies.
My opinions, not the committee's, mine.
Simple RFDs www.4theweb.co.uk/rfdmaker
> On Sun, 09 Jan 2011 22:10:02 +0000, Bernard Peek <b...@shrdlu.com>
> wrote:
>
>>> Is this a breach of the rules/laws governing council Data Bases?
>>
>>If you point out what they are doing wrong they will be in breach
>>of the rules if they don't then fix the problem. The law requires
>>them to take reasonable precautions to protect personal data. They
>>can only do that if they know what is reasonable. You should
>>contact the sender and point out their error.
>
> More than reasonable precautions surely? The Act requires that
> personal data be kept secure. Clearly they are not.
This is not certain. If for instance all the addressees were invited
to join a mailing list which allowed any of its members to communicate
directly with any or all others (not common nowadays for various
reasons) then the Council would have done exactly what they said they
were going to do with the data.
--
Percy Picacity
> "Percy Picacity" <k...@under.the.invalid> wrote in message
>> Why not ask them to use Bcc for the list?
>
> I have but all I am getting is a silly councillor sticking up for what she
> regards as her staff and absolutely failing to address the issue.
In which case maybe the next step should be to make a complaint to the
Information Commissioner.
>Why not ask them to use Bcc for the list?
On a technical note... many anti-spam systems will reject emails with
the characteristics exhibited by a bcc list, but the real answer is for
the sender to "invest" in a proper list-mailing system.
--
Roland Perry
Chris R
It may be personally identifiable information, if, for example, it is in the
format:
firstname...@business.co.uk
... or some people make up there own 'business' name, which also may make it
obvious and personally identifiable.
If they are considered personally identifiable then they would be covered by
the normally principles including security, confidentiality and disclosure.
And you can of course have your name and details removed from the list.
Even if it is not technically against the principles, it certainly seems to
be considered bad practice:
http://www.theregister.co.uk/2010/02/10/orange_shares_email/
"Orange overshares in bcc blunder"
This is quite a difficult area. Your best option would probably be to
contact the Information Commissioner's Office and ask them directly:
https://www.ico.gov.uk/Global/contact_us.aspx
It might also be useful if you posted their response.
IANAL
--
Iain
An email address can often be personal data.
--
Roland Perry
I thought the same but IANAL so I checked here with folks who have an
interest in the law. Many thanks for your response.
pete
That's true but the council is distributing additional information with
the addresses; in the body of the email. In aggregate this may
constitute personal data.
--
Bernard Peek
b...@shrdlu.com
Yes of course Percy and I would accept that but it isn't the case here. This
is just a case where a mail has been circulated to a number of folks who now
know each other are on the same list.
pete
On its own it can't be. But if there is additional information provided
with it then in aggregate it may be. If for instance the email mentioned
that members of the list were expected to be in a particular place at a
particular time then it and the email addresses of everyone on the list
would become personal data.
--
Bernard Peek
b...@shrdlu.com
That is also my understanding after much thought on the subject thanks.
pete
If I could perhaps quote the law:
DPA 1988 1(1):
"personal data" means data which relate to a living individual who
can be identified—
(a) from those data, or
(b) from those data and other information which is in the possession
of, or is likely to come into the possession of, the data
controller,
In this case it may well be that the association with other email
addresses simultaneously 'leaked', and the body of the email, are both
relevant "other information", but they are not the sole source of such
other information. The existence of "other information" will make the
email address ["those data"] *on its own* personal data.
You can easily determine my identity from my email address, for example
(by looking up the Nominet registration for the domain, let alone
associating any content with it).
On a wider front, both the UK Information Commissioner and the EU's
Article 29 Committee both agree that email addresses can be personal
data.
But I am not claiming that all email addresses are personal data.
--
Roland Perry
An email address?
Bit of a sledgehammer etc. The council will have somewhere an IT compliance
officer, who will understand the problem and be able to fix it.
--
Murphy's ultimate law is that if something that could go wrong doesn't,
it turns out that it would have been better if it had gone wrong.
>> More than reasonable precautions surely? The Act requires that
>> personal data be kept secure. Clearly they are not.
>
>This is not certain. If for instance all the addressees were invited
>to join a mailing list which allowed any of its members to communicate
>directly with any or all others (not common nowadays for various
>reasons) then the Council would have done exactly what they said they
>were going to do with the data.
Well yes. I was assuming that this was not the case.
Not really. The councillor is not directly responsible for the day to day
running of the council. It should be reported in writing to the Data
Protection Officer at the council with a copy to the chief executive. Only
if this fails shoul the ICO be involved.
Peter Crosland
>> Why not ask them to use Bcc for the list?
>
> I have but all I am getting is a silly councillor sticking up for what she
> regards as her staff and absolutely failing to address the issue.
If the council have been informed of a fault in their procedures then
they are definitely at fault. You could find out who their data
protection officer is and raise a complaint, copied to the Information
Commissioner. You should name the councillor who has failed to implement
the required changes.
Alternatively you could write to the councillor again and point out that
they may be committing an offence by failing to correct the original
error, and that this may leave them personally liable to fines.
--
Bernard Peek
b...@shrdlu.com
Yes of course but that is such a waste of resources over something that
should be fixed as soon as it was pointed out. Thanks for your input which
just goes to show Usenet still has a useful function when moderated and used
sensibly.
pete
Supposing it was a mailing list about abortion being circulated, (which it
wasn't) and by receiving that mail I saw the name of others I knew. Isn't
the fact the mail reads as mine petert...@gmail.com and identifies me a
dangerous route and also a breech of the Data Control provisions?
pete
Hah! That's the one!
MBQ
An employee at a large mobile phone operator did this with 100s of
customer e-mail addresses in cc instead of bcc. A number of the
recipients registered complaints with the Information commissioner and
it hasn't happened again. Never did get a satisfactory apology from
the company concerned.
MBQ
>> More than reasonable precautions surely? The Act requires that
>> personal data be kept secure. Clearly they are not.
>
>I thought the same but IANAL so I checked here with folks who have an
>interest in the law. Many thanks for your response.
In my experience government bodies tend to take their responsibilities
too seriously, rather than the other way round but in this instance it
seems careless to distribute the email addresses like this.
Whether it contravenes the act or not, it's clearly not good practice.
Regarding the Information Commissioner, any complaint to them will be
thrown straight back with a request that you put your complaint in
writing to the Council concerned. There's no point in sending the
Commissioner a copy of a letter to the Council.
Write to the Council's Data Protection Officer, give them 28 days to
reply, THEN write to the Information Commissioner but it won't do you
any good, because they will simply write back to you and say that
there has been no disclosure of personal data.
Better still, send an email to everyone on the list explaining the
situation, making sure that everyone else sees everyone else's name,
and then sit back and watch the fireworks!
> On Mon, 10 Jan 2011 11:05:02 +0000, "Peter Turtill"
> <petert...@gmail.com> wrote:
>
> >> More than reasonable precautions surely? The Act requires that
> >> personal data be kept secure. Clearly they are not.
> >
> >I thought the same but IANAL so I checked here with folks who have an
> >interest in the law. Many thanks for your response.
>
>
> In my experience government bodies tend to take their responsibilities
> too seriously, rather than the other way round but in this instance it
> seems careless to distribute the email addresses like this.
>
> Whether it contravenes the act or not, it's clearly not good practice.
It's easy enough to do. I did it once to dozens of clients, and I was
sufficiently flustered and embarrassed that when I sent out an apology,
I did exactly the same thing again.
Daniele
>> In my experience government bodies tend to take their responsibilities
>> too seriously, rather than the other way round but in this instance it
>> seems careless to distribute the email addresses like this.
>>
>> Whether it contravenes the act or not, it's clearly not good practice.
>
>It's easy enough to do. I did it once to dozens of clients, and I was
>sufficiently flustered and embarrassed that when I sent out an apology,
>I did exactly the same thing again.
I've done worse but it won't help to talk about it. :(
I do hate threads which turn into a pantomime ("oh yes I do!") but the
data protection authorities are quite clear that email addresses can
often be.
>In any event, there may be two or three Joe
>Bloggs's at that company. Or none at all, for that matter
Unless you look at the Nominet registry entry, you can't tell that
joebloggs.co.uk is registered to a company or to a person.
Very frequently it will be a person. And that must be your assumption
for DPA purposes.
And even if the domain is registered to a company, there can be "other
information" available, which confirms the identity of a person and
makes the email personal data because of that.
--
Roland Perry
If I could perhaps quote the law:
DPA 1988 1(1):
"personal data" means data which relate to a living individual who
can be identified-
(a) from those data, or
(b) from those data and other information which is in the possession
of, or is likely to come into the possession of, the data
controller,
In this case it may well be that the association with other email
addresses simultaneously 'leaked', and the body of the email, are both
relevant "other information", but they are not the sole source of such
other information. The existence of "other information" will make the
email address ["those data"] *on its own* personal data.
You can easily determine my identity from my email address, for example
(by looking up the Nominet registration for the domain, let alone
associating any content with it).
On a wider front, both the UK Information Commissioner and the EU's
Article 29 Committee both agree that email addresses can be personal
data.
But I am not claiming that all email addresses are personal data.
Thank you for a very informative post Roland.
pete
Yes indeed. That sounds like a good idea:-)
pete
In this case the local council (Ipswich) likes to employ a team of community
workers who send out "good news" and they control the news. They never send
out news about anything they do wrong or when they get fined etc. I believe
they use this method to claim they have consulted Ipswich residents.
pete
> --
> Roland Perry
According to the Information Commissioner's Office helpline, you are wrong.
What you and I quoted is specifically the example that she gave me.
Apparently it is probably a breach of the DPA as they should have used the
BCC (if it is available).
The Act iteself defines personal data in its very first section - data which
relates to a living individual who could be identified from those data. Not
using the BCC facility is likely to be a breach of the first principle -
processing data fairly and lawfully.
If that organisation is going to do something with that individual's
personal data that they might not reasonably expect, then they should
provide them with some fair processing information. She added that it does
not actually say that within the first principle, but that is how they
interpret it [which is what we would need to go on].
She went on to say that if someone gave an email address to a company, they
wouldn't normally expect it to be disclosed to a third party if they hadn't
been told that that was going to be the case. If they had been given fair
processing information that they were going to disclose it to all those
people, then fine. If they haven't been and it's accidentally disclosed in
that way, then it's like to be a breach of the first principle of the Act.
(This is a summary from a recorded conversation)
IANAL, but but I telephoned to check up!
--
Iain
Thank you very much for taking the trouble and for providing the answer too.
pete
>On Mon, 10 Jan 2011 11:05:02 +0000, "Peter Turtill"
><petert...@gmail.com> wrote:
>
>>> More than reasonable precautions surely? The Act requires that
>>> personal data be kept secure. Clearly they are not.
>>
>>I thought the same but IANAL so I checked here with folks who have an
>>interest in the law. Many thanks for your response.
>
>
>In my experience government bodies tend to take their responsibilities
>too seriously, rather than the other way round but in this instance it
>seems careless to distribute the email addresses like this.
>
>Whether it contravenes the act or not, it's clearly not good practice.
Indeed and it is a real risk. Everyone who had received this email
will have all those email addresses stored on their computer and, if
any one of those computers gets infected with malware, then you will
start receiving spam, viruses and all sorts of other nasties.
--
(\__/) M.
(='.'=) Due to the amount of spam posted via googlegroups and
(")_(") their inaction to the problem. I am blocking some articles
posted from there. If you wish your postings to be seen by
everyone you will need use a different method of posting.
Depending on which email client they use, and how they have it set up
(for example, mine can be set up to add, or not-add, incoming email
addresses to the address book).
If they use webmail (corporate or public), that may also be proof
against such attacks.
To some extent, keeping faith with the 7th Principle[1] means using an
email facility that's not especially prone to such issues. After all,
the user has other email addresses under his control, not just those
received via the cc: mailings.
[1] Appropriate technical and organisational measures shall be taken
against unauthorised or unlawful processing of personal data and against
accidental loss or destruction of, or damage to, personal data.
--
Roland Perry
Most of us are not data controllers and therefore proabably don't
need principles.
--
Percy Picacity
Presumably that might be different if the context of the message implied
other personal information. If it was a circular for the HIV Support Group
rather than the Choral Society, for example?
It has been proven that the above comment about it not being personal data
is incorrect - it can be personal data (S.1).
What you seem to want to point out is the potential effect (damage and/or
distress S.13) it could have by implying an association with a particular
group, assuming a breach of the first principle had occured.
--
Iain
Full text of the Data Protection Act (1998):
http://www.statutelaw.gov.uk/legResults.aspx?LegType=All+Legislation&title=Data+Protection&searchEnacted=0&extentMatchOnly=0&confersPower=0&blanketAmendment=0&TYPE=QS&NavFrom=0&activeTextDocId=3190610&PageNumber=1&SortAlpha=0
There's also the issue that if health-related it could well be
sensitive[tm] personal data, not just personal data.
--
Roland Perry