podcast

A little bit about me...

I am a London-based lawyer specialising in privacy, data protection and data security law. My practice includes litigation and court-room advocacy. My client base includes major government departments, FTSE 100 companies and multi-nationals. I regularly undertake media work and am often quoted in the press. For example, I was the legal expert on the Channel 4 Dispatches documentary 'The Data Theft Scandal', which exposed security failings in the Indian call centre industry.

Twitter Weekly Updates for 2012-02-05

Posted on by Stewart
Posted in Twitter updates

Twitter Weekly Updates for 2012-01-29

Posted on by Stewart
  • EU Data Protection Regulation & Directive to be published tmrw. Watch this space for analysis. #privacy #
  • Today's the day we'll learn the EU's real intentions for data protection. Will the crazy stuff in the leaked Regulation be dropped? #privacy #
  • #ENISA report on #privacy risks of web reputation systems. So, how many stars did you give those items on Amazon & eBay http://t.co/nL1b1tzY #
  • Viviane Reding's latest on data protection reform. It has been drip-drip for 2 years now. Like Chinese water torture http://t.co/VYBVHaG3 #
  • The new EU data protection regime in all is glory here http://t.co/T0flUC9C #
  • DP Regulation confirms regulation of data processors; massive implications for #Cloud and #outsourcing #dataprotection #
  • DP Regulation contains parental consent rule for children below 13 yrs, mirroring US COPPA approach. #dataprotection #
  • DP Regulation contains modified #accountability approach. Now easier to enforce non-compliance. #dataprotection #
  • DP Regulation includes right to be forgotten and data portability principle. Major implications for social networking. #dataprotection #
  • DP Regulation includes Privacy by Design, putting compliance into project initiation and technical blue prints. #dataprotection #
  • #DP Regulation sets out 24 hrs breach notification rule; an unnecessary distraction during difficult incident response? #dataprotection #
  • DP Regulation mandates Privacy Impact Assessments for complex processing operations that pose special risks to privacy. #dataprotection #
  • #DP Regulation makes Data Protection Officers compulsory. #dataprotection #
  • #DP Regulation promotes #BCR for international transfers. #dataprotection #
  • #DP Regulation enhances the powers of the national regulators like ICO. #dataprotection #
  • DP Regulation established new Data Protection Board, to improve consistency of responses by national regulators. #dataprotection #
  • #FFW m-Payments conference – Nokia says Olympics are key driver for take up and use in UK in 2012 #
  • #FFW m-Payments conference, Nokia: massive adoption in Kenya, as few alternatives; Europe needs to make processes easier for customers #
  • DP Regulation may have unwittingly lessened the rights of individuals in UK – Art.17 restricts compensation to "damage", which is money here #
  • #EDPS response to DP Regulation; happy, but still not enough new regulation, apparently #dataprotection http://t.co/uodTopxi #
  • One way to cut budget deficit: ban Eurocrat PR spinning & vanity press conferences and give us money saved as rebate. #DPreformprocesswaste #
  • US strategy for global supply chain security published #infosec #cybersecurity http://t.co/Zzwj6riY #
  • Belated reference to US policy to protect electricity grid from #cybersecurity threats http://t.co/pz68eGiY #
  • Bill Gates at Deptford School. Brilliant! #notdataprotection http://t.co/8RIMuM6n #
  • Excellent Cyber Peace-keepers news report by Susan Watts, Newsnight – worth a read http://t.co/AUNFsB56 #
  • #ICO to have a pop at credit texters http://t.co/0Laka1pN #
Posted in Twitter updates

Breach reporting within 24 hours – what’s the rush?

Posted on by Stewart

Have you ever had the misfortune to be involved in the immediate aftermath of a serious security breach? If you haven’t, let me tell you something for free; even with the best contingency plans and support from the best experts, it can be a brutal environment of chaos and stress, which can test the patience of a Saint. You are focusing on understanding the angles, containment, recovery and mitigation and if you get lucky you may come out of the first day with your sanity intact.

Against this backdrop of prior experience, I want to reflect on the new EU Data Protection Regulation proposal that serious personal data breaches must be reported to national data regulators within 24 hours of discovery. I kid you not. You read this right.

I’m at a loss as to what is going on within the EU’s thinking. Why is this stringent timetable being proposed? Seriously, what will be the benefit to data protection and privacy of this requirement? What will the regulator actually be able to add, other than providing some hyperlinks to website regulatory policies? Or does someone know something that I don’t, perhaps that regulators are experts on security breach handling? If you look at the ICO guidance on security breaches, you’ll see that it is fine as far as it goes, but it doesn’t add anything to that which a Chief Security Officer, or an expert security consultant, or an IT Co, or a GovCERT already knows. And there’s no criticism here, because ICO isn’t meant to be expert in these things and doesn’t pretend to be.

This new requirement adds an unnecessary compliance obligation that will be an unnecessary diversion and distraction from the key objectives of incident response. Why not continue with the requirement for telecos and ISPs, which is still not even 12 months old, namely that serious data breaches shall be notified to the regulators without “undue delay”? Surely, it would be better to see how that regime beds in before we start tinkering around with things in this way? And doesn’t the shift undermine all the assertions of confidence that the EU published in 2009, when they were saying that the without undue delay approach was the right thing to do?

I reflect also on the fact that in the summer last year the EU published a call for comments from telcos and ISPs on how to handle breach disclosure. The fruits of that work haven’t been published yet, which renders the new position thoroughly immature.

Hopefully, this proposal will be canned once the implications sink in.

Posted in Breach disclosure, Data Protection Directive, Data Protection Regulation, Law reform

New Data Protection Regulation – less divergences? Hmm

Posted on by Stewart

After prolonged teasers and tasters the European Commission has finally published its proposal for a Data Protection Regulation, which will replace the 1995 Data Protection Directive.

The first thing that you notice is the density of the document, which is four times as fat as the current Directive. It occurs to me that if this is intended to simplify data protection compliance then it’s a funny way to go about this. Ah well …

The principle case for a Regulation is that it will help to reduce the differences in national legislations. That’s a fair ambition, but I recall that they said that about the original Directive. So let’s examine this a bit further. Will the Regulation achieve this objective?

Well, the fact that the Regulation will remove the need for national legislations means that we will be faced with just one legal framework, which is good. The new “Data Protection Board”‘ which will replace the Article 29 Working Party, should also help with consistency of regulatory approaches – because that is the Board’s role – so we have more reason to feel positive.

Yet, there is an Emperor’s New Clothes sense to the Regulation, because despite the innovations just identified we are still left with the fact that operationally-speaking the national regulators have day to day freedoms to deal with problems in their countries the way that they want to. This means that the scope for national divergences has not been fully eradicated by the new approach. And this leaves us with considerable uncertainty. Add to this the fact that national courts and tribunals also retain their own discretions, then it seems that the scope for continuing divergences seems massive.

Of course, only time will tell, but my guess is that despite the legal and political tinkering we will still have different rules in different countries, or, at least, different practices on the ground.

Posted in Data Protection Directive, Data Protection Regulation, Law reform

Twitter Weekly Updates for 2012-01-22

Posted on by Stewart
  • #Cookie compliance jobs still coming in, but most websites won't hit the May deadline. #privacy #
  • Great free website tracking tool showing what you disclose by browsing. #privacy #dataprotection http://t.co/Pde9E533 #
Posted in Twitter updates

Twitter Weekly Updates for 2012-01-15

Posted on by Stewart
  • Interesting judgment in #GPS tracking case reviewing US authorities on search and seizure http://t.co/necXGh3e #privacy #surveillance #
  • #EDPS data protection priorities for 2012 published #privacy #law http://t.co/3Ysf6C0c #
  • #EDPS promises to issue a pile of opinions this year – check out the table #privacy #dataprotection http://t.co/rpdAVIqj #
  • #ICO planning to fine Brighton & Sussex NHS £375k for unsafe decommissioning of hard drives #privacy #dataprotection #
  • leaked draft Data Protection Regulation in Dec – key EU Institutions didn't like the proposals apparently. Expect leaked v.57 soon … #
  • Major new EU M-Payments initiative – one of my top 10 predictions for 2012! #spookyforesight http://t.co/1nFWqm1F #
  • And the EU M-Payments Green Paper http://t.co/4p0HACNF #
  • EU e-commerce growth plan http://t.co/XIWAHSo6 #
  • M-Payments conference at #FFW 25 Jan. Super speakers inc Vodafone & Nokia. Some places left for industry. Free. Contact me. #
  • @DanRaywood @danworthV3 @Warwick_Ashford @iblametom @bryanglick – gents, M-Payments Conf at our office 25 Jan. Hear from Vodafone Nokia FFW #
  • @quentynblog – hi! it's the NFC piece that's the differentiator between the earlier African revolution and what's hitting Europe now Quentyn #
  • @quentynblog @njp7 – yes, £375k would be the highest DPA fine so far. Quantum-wise, it would be one to appeal. #
  • MPs call for introduction of data protection gaol sentence to curb whiplash claims. #privacy #dataprotection #law http://t.co/EiRDEOJV #
  • #FFW privacy team all received their #IAPP CIPP/E certs and badges today. Euro privacy pros, you should take the course! See @jtrevorhughes #
  • @Privacymatters @jtrevorhughes – learning & CPD great for lawyers & our firm keen to promote professionalism in privacy hence support IAPP #
Posted in Twitter updates

#ICO fines – what’s the plan exactly?

Posted on by Stewart

The most interesting piece of data protection news today is the story that the Information Commissioner has informed Brighton and Sussex NHS Hospitals that he is planning to fine them £375k. We don’t know from the news reports whether this is one data controller or two, or, if two, whether they are to be fined £375k each, or if this is the total amount of two separate fines, but if we are talking about one single fine of £375k, then this really is big news.

So far the highest single fine has been £120k (or £200k, if you treat the Crossley case as such), so in that sense this is big news. But what interests me the most – and why I actually consider this to be big news – is the fact that ICO is getting perilously close to the £500k cap, which cannot be exceeded.

And so this raises the question has ICO got its fining scale right? If we are to take £500k as being reserved for the extreme end of seriousness (which, surely, must be right) then does the insecure decommissioning of NHS computers get close to that level? Or can we imagine a security breach situation that would make such insecure decommissioning pale into insignificance in a relative sense? If we can, then these events get pushed down the scale of seriousness and the quantum, £375k, becomes difficult to justify.

You can argue the point both ways; after all, patient data is sensitive and it’s easy to see real distress being caused, perhaps even real “damage” (in the sense of pecuniary loss, including personal injury). So in the eyes of some, the insecure decommissioning of hospital computers might be the worst thing that can be imagined. And I know I wouldn’t be happy if my health records were affected. Yet these points on their own do not justify the quantum. Instead, you need the additional justifications of punishment, deterrent effect etc.

And all of this takes you to the key point of this blog, which is simply this – what is ICO’s plan? By this I mean, how does ICO arrive at its figures and how are they justified?

We’re probably not going to get to the bottom of this until someone takes a case on to appeal, but as we are nearly two years into the fining regime I think we’ve arrived at the point when we can legitimately expect ICO to explain where it is heading with the fine and what has driven it’s decisions so far.

Posted in Fines, ICO cases

Twitter Weekly Updates for 2012-01-08

Posted on by Stewart
Posted in Twitter updates

Twitter Weekly Updates for 2011-12-18

Posted on by Stewart
Posted in Twitter updates

Twitter Weekly Updates for 2011-12-18

Posted on by Stewart
Posted in Twitter updates
← Older posts

Terms and Conditions Privacy Policy © Copyright 2010 All Rights Reserved