Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Data Base question.

0 views
Skip to first unread message

Peter Turtill

unread,
Jan 9, 2011, 4:35:02 PM1/9/11
to
My local council likes to circulate information about choral events by a
local group which is not connected to the council.

When they mail me with information I can see everybody else's e-mail addy
they have circulated and naturally everybody else can see I have been
circulated.

The e-mail addresses must be coming from a Data Base somewhere, probably a
council department.

Is this a breach of the rules/laws governing council Data Bases?

pete


Percy Picacity

unread,
Jan 9, 2011, 4:55:01 PM1/9/11
to
"Peter Turtill" <petert...@gmail.com> wrote in
news:8ounps...@mid.individual.net:

It could be, but it rather depends on the terms under which they
originally collected the email addresses. It is probably bad practice
though, as at least one of the addressees is likely to want to misuse
the list for unwelcome commercial or political purposes. I don't think
it makes a difference whether the emails are stored on a computer
database, or on a set of vellum scrolls in the basement.

Why not ask them to use Bcc for the list?


--
Percy Picacity

Bernard Peek

unread,
Jan 9, 2011, 5:10:02 PM1/9/11
to

If you point out what they are doing wrong they will be in breach of the
rules if they don't then fix the problem. The law requires them to take
reasonable precautions to protect personal data. They can only do that
if they know what is reasonable. You should contact the sender and point
out their error.


--
Bernard Peek
b...@shrdlu.com

Peter Turtill

unread,
Jan 9, 2011, 5:10:02 PM1/9/11
to

"Percy Picacity" <k...@under.the.invalid> wrote in message
news:Xns9E68DEE428B...@208.90.168.18...

I have but all I am getting is a silly councillor sticking up for what she
regards as her staff and absolutely failing to address the issue.

pete


Geoff Berrow

unread,
Jan 9, 2011, 6:40:02 PM1/9/11
to
On Sun, 09 Jan 2011 22:10:02 +0000, Bernard Peek <b...@shrdlu.com>
wrote:

>> Is this a breach of the rules/laws governing council Data Bases?
>
>If you point out what they are doing wrong they will be in breach of the
>rules if they don't then fix the problem. The law requires them to take
>reasonable precautions to protect personal data. They can only do that
>if they know what is reasonable. You should contact the sender and point
>out their error.

More than reasonable precautions surely? The Act requires that
personal data be kept secure. Clearly they are not.
--
Geoff Berrow (Put thecat out to email)
It's only Usenet, no one dies.
My opinions, not the committee's, mine.
Simple RFDs www.4theweb.co.uk/rfdmaker

Percy Picacity

unread,
Jan 9, 2011, 7:25:01 PM1/9/11
to
Geoff Berrow <blth...@ckdog.co.uk> wrote in
news:cjhki650ofk5griab...@4ax.com:

> On Sun, 09 Jan 2011 22:10:02 +0000, Bernard Peek <b...@shrdlu.com>
> wrote:
>
>>> Is this a breach of the rules/laws governing council Data Bases?
>>
>>If you point out what they are doing wrong they will be in breach
>>of the rules if they don't then fix the problem. The law requires
>>them to take reasonable precautions to protect personal data. They
>>can only do that if they know what is reasonable. You should
>>contact the sender and point out their error.
>
> More than reasonable precautions surely? The Act requires that
> personal data be kept secure. Clearly they are not.

This is not certain. If for instance all the addressees were invited
to join a mailing list which allowed any of its members to communicate
directly with any or all others (not common nowadays for various
reasons) then the Council would have done exactly what they said they
were going to do with the data.

--
Percy Picacity

Graham Murray

unread,
Jan 10, 2011, 1:35:03 AM1/10/11
to
"Peter Turtill" <petert...@gmail.com> writes:

> "Percy Picacity" <k...@under.the.invalid> wrote in message

>> Why not ask them to use Bcc for the list?
>
> I have but all I am getting is a silly councillor sticking up for what she
> regards as her staff and absolutely failing to address the issue.

In which case maybe the next step should be to make a complaint to the
Information Commissioner.

Roland Perry

unread,
Jan 10, 2011, 3:55:02 AM1/10/11
to
In message <Xns9E68DEE428B...@208.90.168.18>, at 21:55:01 on
Sun, 9 Jan 2011, Percy Picacity <k...@under.the.invalid> remarked:

>Why not ask them to use Bcc for the list?

On a technical note... many anti-spam systems will reject emails with
the characteristics exhibited by a bcc list, but the real answer is for
the sender to "invest" in a proper list-mailing system.
--
Roland Perry

Chris R

unread,
Jan 10, 2011, 4:10:02 AM1/10/11
to
More than reasonable precautions surely? The Act requires that
personal data be kept secure. Clearly they are not.
-------------
An address alone is not personal data.

Chris R


Iain

unread,
Jan 10, 2011, 5:35:02 AM1/10/11
to

It may be personally identifiable information, if, for example, it is in the
format:
firstname...@business.co.uk
... or some people make up there own 'business' name, which also may make it
obvious and personally identifiable.

If they are considered personally identifiable then they would be covered by
the normally principles including security, confidentiality and disclosure.
And you can of course have your name and details removed from the list.

Even if it is not technically against the principles, it certainly seems to
be considered bad practice:
http://www.theregister.co.uk/2010/02/10/orange_shares_email/
"Orange overshares in bcc blunder"

This is quite a difficult area. Your best option would probably be to
contact the Information Commissioner's Office and ask them directly:
https://www.ico.gov.uk/Global/contact_us.aspx

It might also be useful if you posted their response.

IANAL
--
Iain

Roland Perry

unread,
Jan 10, 2011, 5:50:03 AM1/10/11
to
In message <JtidnXQRBuktUbfQ...@brightview.co.uk>, at
09:10:02 on Mon, 10 Jan 2011, Chris R <inv...@invalid.munge.co.uk>
remarked:

An email address can often be personal data.
--
Roland Perry

Peter Turtill

unread,
Jan 10, 2011, 6:05:02 AM1/10/11
to

"Geoff Berrow" <blth...@ckdog.co.uk> wrote in message
news:cjhki650ofk5griab...@4ax.com...

> On Sun, 09 Jan 2011 22:10:02 +0000, Bernard Peek <b...@shrdlu.com>
> wrote:
>
>>> Is this a breach of the rules/laws governing council Data Bases?
>>
>>If you point out what they are doing wrong they will be in breach of the
>>rules if they don't then fix the problem. The law requires them to take
>>reasonable precautions to protect personal data. They can only do that
>>if they know what is reasonable. You should contact the sender and point
>>out their error.
>
> More than reasonable precautions surely? The Act requires that
> personal data be kept secure. Clearly they are not.

I thought the same but IANAL so I checked here with folks who have an
interest in the law. Many thanks for your response.

pete


Bernard Peek

unread,
Jan 10, 2011, 6:10:02 AM1/10/11
to

That's true but the council is distributing additional information with
the addresses; in the body of the email. In aggregate this may
constitute personal data.

--
Bernard Peek
b...@shrdlu.com

Peter Turtill

unread,
Jan 10, 2011, 6:10:10 AM1/10/11
to

"Percy Picacity" <k...@under.the.invalid> wrote in message
news:Xns9E6938F914...@208.90.168.18...

Yes of course Percy and I would accept that but it isn't the case here. This
is just a case where a mail has been circulated to a number of folks who now
know each other are on the same list.

pete


Bernard Peek

unread,
Jan 10, 2011, 6:15:02 AM1/10/11
to

On its own it can't be. But if there is additional information provided
with it then in aggregate it may be. If for instance the email mentioned
that members of the list were expected to be in a particular place at a
particular time then it and the email addresses of everyone on the list
would become personal data.

--
Bernard Peek
b...@shrdlu.com

Peter Turtill

unread,
Jan 10, 2011, 6:55:03 AM1/10/11
to

"Bernard Peek" <b...@shrdlu.com> wrote in message
news:8p07se...@mid.individual.net...

That is also my understanding after much thought on the subject thanks.

pete


Roland Perry

unread,
Jan 10, 2011, 8:10:02 AM1/10/11
to
In message <8p07se...@mid.individual.net>, at 11:15:02 on Mon, 10 Jan
2011, Bernard Peek <b...@shrdlu.com> remarked:

>>> More than reasonable precautions surely? The Act requires that
>>> personal data be kept secure. Clearly they are not.
>>> -------------
>>> An address alone is not personal data.
>>
>> An email address can often be personal data.
>
>On its own it can't be.

If I could perhaps quote the law:

DPA 1988 1(1):

"personal data" means data which relate to a living individual who
can be identified—

(a) from those data, or
(b) from those data and other information which is in the possession
of, or is likely to come into the possession of, the data
controller,

In this case it may well be that the association with other email
addresses simultaneously 'leaked', and the body of the email, are both
relevant "other information", but they are not the sole source of such
other information. The existence of "other information" will make the
email address ["those data"] *on its own* personal data.

You can easily determine my identity from my email address, for example
(by looking up the Nominet registration for the domain, let alone
associating any content with it).

On a wider front, both the UK Information Commissioner and the EU's
Article 29 Committee both agree that email addresses can be personal
data.

But I am not claiming that all email addresses are personal data.
--
Roland Perry

Geoff Berrow

unread,
Jan 10, 2011, 5:45:02 AM1/10/11
to

An email address?

GB

unread,
Jan 10, 2011, 5:45:03 AM1/10/11
to

Bit of a sledgehammer etc. The council will have somewhere an IT compliance
officer, who will understand the problem and be able to fix it.

--
Murphy's ultimate law is that if something that could go wrong doesn't,
it turns out that it would have been better if it had gone wrong.


Geoff Berrow

unread,
Jan 10, 2011, 5:45:03 AM1/10/11
to
On Mon, 10 Jan 2011 00:25:01 +0000, Percy Picacity
<k...@under.the.invalid> wrote:

>> More than reasonable precautions surely? The Act requires that
>> personal data be kept secure. Clearly they are not.
>
>This is not certain. If for instance all the addressees were invited
>to join a mailing list which allowed any of its members to communicate
>directly with any or all others (not common nowadays for various
>reasons) then the Council would have done exactly what they said they
>were going to do with the data.

Well yes. I was assuming that this was not the case.

Peter Crosland

unread,
Jan 10, 2011, 6:05:10 AM1/10/11
to
>>> Why not ask them to use Bcc for the list?
>>
>> I have but all I am getting is a silly councillor sticking up for what
>> she
>> regards as her staff and absolutely failing to address the issue.
>
> In which case maybe the next step should be to make a complaint to the
> Information Commissioner.

Not really. The councillor is not directly responsible for the day to day
running of the council. It should be reported in writing to the Data
Protection Officer at the council with a copy to the chief executive. Only
if this fails shoul the ICO be involved.

Peter Crosland


Bernard Peek

unread,
Jan 10, 2011, 6:10:10 AM1/10/11
to
On 09/01/11 22:10, Peter Turtill wrote:

>> Why not ask them to use Bcc for the list?
>
> I have but all I am getting is a silly councillor sticking up for what she
> regards as her staff and absolutely failing to address the issue.

If the council have been informed of a fault in their procedures then
they are definitely at fault. You could find out who their data
protection officer is and raise a complaint, copied to the Information
Commissioner. You should name the councillor who has failed to implement
the required changes.

Alternatively you could write to the councillor again and point out that
they may be committing an offence by failing to correct the original
error, and that this may leave them personally liable to fines.

--
Bernard Peek
b...@shrdlu.com

Peter Turtill

unread,
Jan 10, 2011, 6:10:10 AM1/10/11
to

"Graham Murray" <news...@gmurray.org.uk> wrote in message
news:87k4idf...@newton.gmurray.org.uk...

Yes of course but that is such a waste of resources over something that
should be fixed as soon as it was pointed out. Thanks for your input which
just goes to show Usenet still has a useful function when moderated and used
sensibly.

pete


Peter Turtill

unread,
Jan 10, 2011, 6:15:09 AM1/10/11
to

"Chris R" <inv...@invalid.munge.co.uk> wrote in message
news:JtidnXQRBuktUbfQ...@brightview.co.uk...

Supposing it was a mailing list about abortion being circulated, (which it
wasn't) and by receiving that mail I saw the name of others I knew. Isn't
the fact the mail reads as mine petert...@gmail.com and identifies me a
dangerous route and also a breech of the Data Control provisions?

pete


Man at B&Q

unread,
Jan 10, 2011, 8:55:02 AM1/10/11
to
On Jan 10, 10:35 am, "Iain" <s...@smaps.net> wrote:
> Chris R wrote:
> > More than reasonable precautions surely?  The Act requires that
> > personal data be kept secure.  Clearly they are not.
> > -------------
> > An address alone is not personal data.
>
> > Chris R
>
> It may be personally identifiable information, if, for example, it is in the
> format:
> firstname.lastn...@business.co.uk

> ... or some people make up there own 'business' name, which also may make it
> obvious and personally identifiable.
>
> If they are considered personally identifiable then they would be covered by
> the normally principles including security, confidentiality and disclosure.
> And you can of course have your name and details removed from the list.
>
> Even if it is not technically against the principles, it certainly seems to
> be considered bad practice:http://www.theregister.co.uk/2010/02/10/orange_shares_email/
> "Orange overshares in bcc blunder"

Hah! That's the one!

MBQ


Man at B&Q

unread,
Jan 10, 2011, 8:31:48 AM1/10/11
to
On Jan 9, 10:10 pm, "Peter Turtill" <peterturt...@gmail.com> wrote:
> "Percy Picacity" <k...@under.the.invalid> wrote in message
>
> news:Xns9E68DEE428B...@208.90.168.18...
>
>
>
> > "Peter Turtill" <peterturt...@gmail.com> wrote in

An employee at a large mobile phone operator did this with 100s of
customer e-mail addresses in cc instead of bcc. A number of the
recipients registered complaints with the Information commissioner and
it hasn't happened again. Never did get a satisfactory apology from
the company concerned.

MBQ

Geoff Berrow

unread,
Jan 10, 2011, 6:55:02 AM1/10/11
to
On Mon, 10 Jan 2011 11:05:02 +0000, "Peter Turtill"
<petert...@gmail.com> wrote:

>> More than reasonable precautions surely? The Act requires that
>> personal data be kept secure. Clearly they are not.
>
>I thought the same but IANAL so I checked here with folks who have an
>interest in the law. Many thanks for your response.


In my experience government bodies tend to take their responsibilities
too seriously, rather than the other way round but in this instance it
seems careless to distribute the email addresses like this.

Whether it contravenes the act or not, it's clearly not good practice.

Goldenwight

unread,
Jan 10, 2011, 9:20:02 AM1/10/11
to
An email address is most definitely NOT personal data. Even if it
reads JoeB...@joebloggs.co.uk, it does not identify an individual-
merely an email account. In any event, there may be two or three Joe
Bloggs's at that company. Or none at all, for that matter

Regarding the Information Commissioner, any complaint to them will be
thrown straight back with a request that you put your complaint in
writing to the Council concerned. There's no point in sending the
Commissioner a copy of a letter to the Council.

Write to the Council's Data Protection Officer, give them 28 days to
reply, THEN write to the Information Commissioner but it won't do you
any good, because they will simply write back to you and say that
there has been no disclosure of personal data.

Better still, send an email to everyone on the list explaining the
situation, making sure that everyone else sees everyone else's name,
and then sit back and watch the fireworks!

D.M. Procida

unread,
Jan 10, 2011, 9:25:02 AM1/10/11
to
Geoff Berrow <blth...@ckdog.co.uk> wrote:

> On Mon, 10 Jan 2011 11:05:02 +0000, "Peter Turtill"
> <petert...@gmail.com> wrote:
>
> >> More than reasonable precautions surely? The Act requires that
> >> personal data be kept secure. Clearly they are not.
> >
> >I thought the same but IANAL so I checked here with folks who have an
> >interest in the law. Many thanks for your response.
>
>
> In my experience government bodies tend to take their responsibilities
> too seriously, rather than the other way round but in this instance it
> seems careless to distribute the email addresses like this.
>
> Whether it contravenes the act or not, it's clearly not good practice.

It's easy enough to do. I did it once to dozens of clients, and I was
sufficiently flustered and embarrassed that when I sent out an apology,
I did exactly the same thing again.

Daniele

Geoff Berrow

unread,
Jan 10, 2011, 10:35:02 AM1/10/11
to
On Mon, 10 Jan 2011 14:25:02 +0000,
real-not-anti...@apple-juice.co.uk (D.M. Procida) wrote:

>> In my experience government bodies tend to take their responsibilities
>> too seriously, rather than the other way round but in this instance it
>> seems careless to distribute the email addresses like this.
>>
>> Whether it contravenes the act or not, it's clearly not good practice.
>
>It's easy enough to do. I did it once to dozens of clients, and I was
>sufficiently flustered and embarrassed that when I sent out an apology,
>I did exactly the same thing again.

I've done worse but it won't help to talk about it. :(

Roland Perry

unread,
Jan 10, 2011, 11:40:10 AM1/10/11
to
In message
<7d0fff16-8bd4-427c...@15g2000vbz.googlegroups.com>, at
14:20:02 on Mon, 10 Jan 2011, Goldenwight <prostetn...@hotmail.com>
remarked:

>An email address is most definitely NOT personal data. Even if it
>reads JoeB...@joebloggs.co.uk, it does not identify an individual-
>merely an email account.

I do hate threads which turn into a pantomime ("oh yes I do!") but the
data protection authorities are quite clear that email addresses can
often be.

>In any event, there may be two or three Joe
>Bloggs's at that company. Or none at all, for that matter

Unless you look at the Nominet registry entry, you can't tell that
joebloggs.co.uk is registered to a company or to a person.

Very frequently it will be a person. And that must be your assumption
for DPA purposes.

And even if the domain is registered to a company, there can be "other
information" available, which confirms the identity of a person and
makes the email personal data because of that.
--
Roland Perry

Peter Turtill

unread,
Jan 10, 2011, 12:10:03 PM1/10/11
to

"Roland Perry" <rol...@perry.co.uk> wrote in message
news:VwaO4$rogvK...@perry.co.uk...

In message <8p07se...@mid.individual.net>, at 11:15:02 on Mon, 10 Jan
2011, Bernard Peek <b...@shrdlu.com> remarked:
>>> More than reasonable precautions surely? The Act requires that
>>> personal data be kept secure. Clearly they are not.
>>> -------------
>>> An address alone is not personal data.
>>
>> An email address can often be personal data.
>
>On its own it can't be.

If I could perhaps quote the law:

DPA 1988 1(1):

"personal data" means data which relate to a living individual who

can be identified-

(a) from those data, or
(b) from those data and other information which is in the possession
of, or is likely to come into the possession of, the data
controller,

In this case it may well be that the association with other email
addresses simultaneously 'leaked', and the body of the email, are both
relevant "other information", but they are not the sole source of such
other information. The existence of "other information" will make the
email address ["those data"] *on its own* personal data.

You can easily determine my identity from my email address, for example
(by looking up the Nominet registration for the domain, let alone
associating any content with it).

On a wider front, both the UK Information Commissioner and the EU's
Article 29 Committee both agree that email addresses can be personal
data.

But I am not claiming that all email addresses are personal data.

Thank you for a very informative post Roland.

pete


Peter Turtill

unread,
Jan 10, 2011, 12:15:03 PM1/10/11
to

"Goldenwight" <prostetn...@hotmail.com> wrote in message
news:7d0fff16-8bd4-427c...@15g2000vbz.googlegroups.com...

Yes indeed. That sounds like a good idea:-)

pete


Peter Turtill

unread,
Jan 10, 2011, 12:20:05 PM1/10/11
to

"Roland Perry" <rol...@perry.co.uk> wrote in message
news:p4aB6X7p...@perry.co.uk...

In this case the local council (Ipswich) likes to employ a team of community
workers who send out "good news" and they control the news. They never send
out news about anything they do wrong or when they get fined etc. I believe
they use this method to claim they have consulted Ipswich residents.

pete
> --
> Roland Perry


Iain

unread,
Jan 10, 2011, 12:31:13 PM1/10/11
to
Goldenwight wrote:
> An email address is most definitely NOT personal data. Even if it
> reads JoeB...@joebloggs.co.uk, it does not identify an individual-
> merely an email account. In any event, there may be two or three Joe
> Bloggs's at that company. Or none at all, for that matter

According to the Information Commissioner's Office helpline, you are wrong.
What you and I quoted is specifically the example that she gave me.
Apparently it is probably a breach of the DPA as they should have used the
BCC (if it is available).

The Act iteself defines personal data in its very first section - data which
relates to a living individual who could be identified from those data. Not
using the BCC facility is likely to be a breach of the first principle -
processing data fairly and lawfully.

If that organisation is going to do something with that individual's
personal data that they might not reasonably expect, then they should
provide them with some fair processing information. She added that it does
not actually say that within the first principle, but that is how they
interpret it [which is what we would need to go on].

She went on to say that if someone gave an email address to a company, they
wouldn't normally expect it to be disclosed to a third party if they hadn't
been told that that was going to be the case. If they had been given fair
processing information that they were going to disclose it to all those
people, then fine. If they haven't been and it's accidentally disclosed in
that way, then it's like to be a breach of the first principle of the Act.

(This is a summary from a recorded conversation)

IANAL, but but I telephoned to check up!
--
Iain

Peter Turtill

unread,
Jan 10, 2011, 3:30:56 PM1/10/11
to

"Iain" <sp...@smaps.net> wrote in message
news:8p0tue...@mid.individual.net...

Thank you very much for taking the trouble and for providing the answer too.

pete


Mark

unread,
Jan 11, 2011, 5:35:03 AM1/11/11
to
On Mon, 10 Jan 2011 11:55:02 +0000, Geoff Berrow
<blth...@ckdog.co.uk> wrote:

>On Mon, 10 Jan 2011 11:05:02 +0000, "Peter Turtill"
><petert...@gmail.com> wrote:
>
>>> More than reasonable precautions surely? The Act requires that
>>> personal data be kept secure. Clearly they are not.
>>
>>I thought the same but IANAL so I checked here with folks who have an
>>interest in the law. Many thanks for your response.
>
>
>In my experience government bodies tend to take their responsibilities
>too seriously, rather than the other way round but in this instance it
>seems careless to distribute the email addresses like this.
>
>Whether it contravenes the act or not, it's clearly not good practice.

Indeed and it is a real risk. Everyone who had received this email
will have all those email addresses stored on their computer and, if
any one of those computers gets infected with malware, then you will
start receiving spam, viruses and all sorts of other nasties.
--
(\__/) M.
(='.'=) Due to the amount of spam posted via googlegroups and
(")_(") their inaction to the problem. I am blocking some articles
posted from there. If you wish your postings to be seen by
everyone you will need use a different method of posting.

Roland Perry

unread,
Jan 11, 2011, 6:15:10 AM1/11/11
to
In message <20coi65jhcjnhub78...@4ax.com>, at 10:35:03 on
Tue, 11 Jan 2011, Mark <i...@dontgetlotsofspamanymore.invalid> remarked:

>>Whether it contravenes the act or not, it's clearly not good practice.
>
>Indeed and it is a real risk. Everyone who had received this email
>will have all those email addresses stored on their computer and, if
>any one of those computers gets infected with malware, then you will
>start receiving spam, viruses and all sorts of other nasties.

Depending on which email client they use, and how they have it set up
(for example, mine can be set up to add, or not-add, incoming email
addresses to the address book).

If they use webmail (corporate or public), that may also be proof
against such attacks.

To some extent, keeping faith with the 7th Principle[1] means using an
email facility that's not especially prone to such issues. After all,
the user has other email addresses under his control, not just those
received via the cc: mailings.

[1] Appropriate technical and organisational measures shall be taken
against unauthorised or unlawful processing of personal data and against
accidental loss or destruction of, or damage to, personal data.
--
Roland Perry

Percy Picacity

unread,
Jan 11, 2011, 9:10:03 AM1/11/11
to
Roland Perry <rol...@perry.co.uk> wrote in
news:zC0nUMRV...@perry.co.uk:

Most of us are not data controllers and therefore proabably don't
need principles.

--
Percy Picacity

Steve Walker

unread,
Jan 13, 2011, 7:00:04 PM1/13/11
to
Chris R wrote:
> More than reasonable precautions surely? The Act requires that
> personal data be kept secure. Clearly they are not.
> -------------
> An address alone is not personal data.

Presumably that might be different if the context of the message implied
other personal information. If it was a circular for the HIV Support Group
rather than the Choral Society, for example?


Iain

unread,
Jan 13, 2011, 9:05:02 PM1/13/11
to

It has been proven that the above comment about it not being personal data
is incorrect - it can be personal data (S.1).

What you seem to want to point out is the potential effect (damage and/or
distress S.13) it could have by implying an association with a particular
group, assuming a breach of the first principle had occured.

--
Iain

Full text of the Data Protection Act (1998):
http://www.statutelaw.gov.uk/legResults.aspx?LegType=All+Legislation&title=Data+Protection&searchEnacted=0&extentMatchOnly=0&confersPower=0&blanketAmendment=0&TYPE=QS&NavFrom=0&activeTextDocId=3190610&PageNumber=1&SortAlpha=0

Roland Perry

unread,
Jan 14, 2011, 2:50:17 PM1/14/11
to
In message <8p9p2f...@mid.individual.net>, at 02:05:02 on Fri, 14 Jan
2011, Iain <sp...@smaps.net> remarked:

>> > More than reasonable precautions surely? The Act requires that
>> > personal data be kept secure. Clearly they are not.
>> > -------------
>> > An address alone is not personal data.
>>
>> Presumably that might be different if the context of the message
>> implied other personal information. If it was a circular for the
>> HIV Support Group rather than the Choral Society, for example?
>
>It has been proven that the above comment about it not being personal
>data is incorrect - it can be personal data (S.1).
>
>What you seem to want to point out is the potential effect (damage
>and/or distress S.13) it could have by implying an association with a
>particular group, assuming a breach of the first principle had occured.

There's also the issue that if health-related it could well be
sensitive[tm] personal data, not just personal data.
--
Roland Perry

0 new messages