<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Matthew Arnold &#38; Baldwin LLP &#124; Giving you a lot more than just law... &#187; data protection</title>
	<atom:link href="http://www.mablaw.com/tag/data-protection/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mablaw.com</link>
	<description>MAB</description>
	<lastBuildDate>Wed, 08 Feb 2012 16:47:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
		<item>
		<title>Unite ordered to disclose details of its users for a second time after failing to do it properly first time round – Manish Patel v Unite, High Court</title>
		<link>http://www.mablaw.com/2012/02/unite-disclose-details-users-patel/</link>
		<comments>http://www.mablaw.com/2012/02/unite-disclose-details-users-patel/#comments</comments>
		<pubDate>Wed, 08 Feb 2012 11:20:47 +0000</pubDate>
		<dc:creator>Simon Weinberg</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[Upload-TMT]]></category>
		<category><![CDATA[Websites]]></category>
		<category><![CDATA[British Airways]]></category>
		<category><![CDATA[British airways cabin crew strike]]></category>
		<category><![CDATA[British Airways strike]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[data protection law]]></category>
		<category><![CDATA[defamation]]></category>
		<category><![CDATA[defamatory]]></category>
		<category><![CDATA[defamatory allegations]]></category>
		<category><![CDATA[defamatory posts]]></category>
		<category><![CDATA[disclose]]></category>
		<category><![CDATA[disclosure]]></category>
		<category><![CDATA[discussion forum]]></category>
		<category><![CDATA[expert]]></category>
		<category><![CDATA[expert report]]></category>
		<category><![CDATA[expert's report]]></category>
		<category><![CDATA[forum]]></category>
		<category><![CDATA[High Court]]></category>
		<category><![CDATA[identify]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[identity disclosure]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[intrusive]]></category>
		<category><![CDATA[intrusive Norwich Pharmacal order]]></category>
		<category><![CDATA[intrusive order]]></category>
		<category><![CDATA[Norwich Pharmacal]]></category>
		<category><![CDATA[Norwich Pharmacal Order]]></category>
		<category><![CDATA[online content]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[privacy law]]></category>
		<category><![CDATA[proportionality]]></category>
		<category><![CDATA[proportionate]]></category>
		<category><![CDATA[proportionate Norwich Pharmacal order]]></category>
		<category><![CDATA[proportionate order]]></category>
		<category><![CDATA[terms of use]]></category>
		<category><![CDATA[trade union]]></category>
		<category><![CDATA[Unite]]></category>
		<category><![CDATA[Unite trade union]]></category>
		<category><![CDATA[Unite union]]></category>
		<category><![CDATA[unlawful]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web site]]></category>
		<category><![CDATA[web sites]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[website content]]></category>
		<category><![CDATA[website forum]]></category>
		<category><![CDATA[website terms of use]]></category>
		<category><![CDATA[websites]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=19208</guid>
		<description><![CDATA[During the British Airways cabin crew strike, Mr Patel had acted as a volunteer cabin crew member. Allegedly as a result of his actions, he was the subject of defamatory allegations posted on a forum on the website of the British Airline Steward and Stewardesses Association (BASSA), which was operated by Unite, the trade union. [...]]]></description>
			<content:encoded><![CDATA[<p>During the British Airways cabin crew strike, Mr Patel had acted as a volunteer cabin crew member. Allegedly as a result of his actions, he was the subject of defamatory allegations posted on a forum on the website of the British Airline Steward and Stewardesses Association (BASSA), which was operated by Unite, the trade union. Mr Patel wanted to take action against the 42 users responsible for the postings, but the postings had been made under false names and he could not take action unless Unite disclosed their identities.</p>
<p>When Mr Patel complained to Unite about the postings, Unite took the forum offline and released a statement that the allegations against Mr Patel were unfounded; but Unite failed to respond to Mr Patel’s request for the identification of those responsible.</p>
<p>The BASSA website was subject to terms of use, which warned users that their personal data might be disclosed subject to data protection and privacy law.</p>
<p>Mr Patel successfully applied to the High Court for a “Norwich Pharmacal” order, which required Unite to provide the identities, addresses and Internet Protocol addresses of the users responsible. Instead, Unite provided an expert’s report to show that the information requested had in fact been deleted. Mr Patel and his solicitors pushed Unite to make further efforts to recover the information, without success. Mr Patel therefore sought a further Norwich Pharmacal order for an independent expert to be given access to Unite’s database on the grounds that the continued failure to provide the information must be, at best, as a result of incompetence or technical ignorance. Unite objected to a further order on data protection grounds.</p>
<p>The High Court ruled that Unite had not provided sufficient evidence that it had carried out the reasonable search required by the first Norwich Pharmacal order, and Unite had not shown that it had actually followed up the information provided by Mr Patel in order to carry out that search. The High Court noted that the additional order that Mr Patel was asking for was intrusive, but that it was proportionate and necessary to give the order so that Unite would comply with Mr Patel’s information request. The High Court considered the fact that the website terms of use warned users that Unite might disclose a user’s identity, subject to data protection and privacy law, and that, without the order, those responsible would not be identified. Whilst the order was given by the High Court, it was strictly limited to an expert appointed jointly by both parties and only to the disclosure of the information which would identify those responsible, or which explained why identification was not possible.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2012/02/unite-disclose-details-users-patel/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New data protection proposals announced for the EU</title>
		<link>http://www.mablaw.com/2012/02/data-protection-proposals-eu/</link>
		<comments>http://www.mablaw.com/2012/02/data-protection-proposals-eu/#comments</comments>
		<pubDate>Wed, 01 Feb 2012 22:20:43 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[Upload-Pharma]]></category>
		<category><![CDATA[Upload-TMT]]></category>
		<category><![CDATA[Websites]]></category>
		<category><![CDATA[consent]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data export]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[data processor]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[data retention]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[data subject]]></category>
		<category><![CDATA[data subject access]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[EU]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[European Commission]]></category>
		<category><![CDATA[European Union]]></category>
		<category><![CDATA[excessive]]></category>
		<category><![CDATA[express]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[implicit]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Internet protocol address]]></category>
		<category><![CDATA[Internet service provider]]></category>
		<category><![CDATA[Internet use]]></category>
		<category><![CDATA[Internet user]]></category>
		<category><![CDATA[IP address]]></category>
		<category><![CDATA[ISP]]></category>
		<category><![CDATA[misuse of data]]></category>
		<category><![CDATA[On-line]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[right to be forgotten]]></category>
		<category><![CDATA[sensitive personal data]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=19151</guid>
		<description><![CDATA[The European Union Justice Commissioner Viviane Reding has launched the European Commission’s proposals for the reform of the data protection regime in the EU, with the aim of increasing a person’s control of their data and cutting costs for businesses. The Commission has estimated that the changes will save an estimated €2.3bn per year for [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://ec.europa.eu/justice/data-protection/document/review2012/com_2012_11_en.pdf">The European Union Justice Commissioner Viviane Reding has launched the European Commission’s proposals for the reform of the data protection regime in the EU</a>, with the aim of increasing a person’s control of their data and cutting costs for businesses. The Commission has estimated that the changes will save an estimated €2.3bn per year for business by easing administrative burdens. The existing data protection regime dates back to 1995 and, given the technological advances made together with the impact of globalisation, the Commission says it is out of step with current techniques for data collection and use.</p>
<p><a href="http://ec.europa.eu/justice/newsroom/data-protection/news/120125_en.htm">In a press release, the EC outlined the main changes that will be made to the data protection regime in the EU</a>::</p>
<p>-          There will be one set of rules across the EU, rather than each EU Member State having its own rules.</p>
<p>-          The scope of the people caught by the data protection law will be increased. The rules will apply to data controllers who are not established within the EU if the data processing relates to offers of goods or services to data subjects within the EU or a monitoring of EU data subjects’ behaviour. Clearly, this is intended to cover large online players from the US such as Google.</p>
<p>-          In addition, what counts as personal data is being widened. Data will be personal data if it is not just data held by the data controller that can identify the individual but also data held by a third party which, in combination with the data held by the data controller, could identify. This could catch rights holders that hand over Internet Protocol addresses to Internet service providers for enforcement of copyright infringement under the Digital Economy Act 2010.</p>
<p>-          There will no longer be an obligation for organisations to notify (or register) all data protection activities to data protection regulators (such as the Information Commissioner’s Office (ICO) in the UK), but only data breaches will need to be notified; however, that will need to take place within 24 hours of becoming aware of the breach. Organisations will need to have continuous monitoring and reporting systems in place at all times. Security breaches must also be notified to data subjects “without undue delay”.</p>
<p>-          In place of general notification obligations, organisations will have to maintain documentation and records showing their processing activities, and be subject to strict audit requirements and produce that to the authorities on demand.</p>
<p>-          Data controllers will also have to comply with training requirements.</p>
<p>-          People will be able to access and transfer their own data more easily. They will have a right to be given their data in a convenient portable format such as a disk or MP3 file. They will also have a right to be told how long their data will be kept for.</p>
<p>-          Data subjects will have a right to be told where the data controller got their data from.</p>
<p>-          There will be a “right to be forgotten” where people will be able to delete their data if there are no grounds for it being retained. This will put a huge burden on Internet businesses in particular, which will have to do what they can to ensure links to the data is deleted by others even after they have deleted it.</p>
<p>-          Member State regulators, such as the ICO, will be strengthened to allow them to better enforce the rules, with possible fines of up to £1m or 2% of a company’s global turnover. The amount of the fine will depend on the nature, gravity and duration of the breach; whether the breach was deliberate or negligent; previous history of breaches; what security measures had been put in place; and the level of co-operation with the authorities.</p>
<p>-          All organisations will have to appoint data protection officers unless they have fewer than 250 employees, in which case they will be exempt from this requirement.</p>
<p>-          Clearer rules for the transfer of data across borders within multi-national organisations will be introduced. In addition, national data protection authorities will need to approve bespoke agreed clauses as an alternative to the standard contractual clauses for transfers between an organisation in one EU country and another organisation outside of the EU.</p>
<p>-          Any consent from a data subject will have to be explicit rather than implied. Any written consent such as a tick-box will need to be distinguishable from other consents. This would mark a change from current online acceptance practice.</p>
<p>-          Data access policies will have to be not only fair but also transparent.</p>
<p>-          The law will move from data being permitted if “not excessive” to effectively minimising the data as it will only be legitimate if the purpose cannot be fulfilled by processing non-personal data.</p>
<p>-          Data processors (people who process data on behalf of data controllers and do not take any decisions in respect of the data) are currently not subject to the data protection requirements. They are only caught under contract law when data controllers (as they are required to do) enter into a written agreement with the data processor to contain certain safeguards. That will change. Under the new regime, data processors will have specific direct obligations to maintain security of data under the law.</p>
<p>-          Data controllers will generally not be able to charge data subjects for data subject access requests.</p>
<p>The proposals will be sent to the European Parliament and the Council of Ministers for discussion, and will take effect two years after they have eventually been adopted.</p>
<p>Paul Gershlick, a Partner at Matthew Arnold &amp; Baldwin LLP, comments: “This proposed law makes depressing reading. The Commission has trumpeted the ease of cost to business, but such a statement totally ignores all the other increases in regulation that this law would introduce. On balance, this will involve much more red tape for business to have to comply with. At a time when SMEs need a helping hand to grow and help to rescue the EU’s economy, this development is not going to be welcomed. Instead of considering SMEs’s legitimate interests, the Commission seems to have been too focused on protecting EU citizens against big US Internet businesses.</p>
<p>“The one plus side is that the new data protection law will be implemented in one consistent way across the whole EU; the major downside, though, is that it will involve much stricter obligations than businesses currently face, including tougher internal programmes and records and quick reports to the regulators and data subjects of data breaches. And there will now be much bigger fines for breaches. Let’s hope some of the provisions are softened before the law is passed.”</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2012/02/data-protection-proposals-eu/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ICO fines Midlothian Council £140,000 for sending details about children and carers to wrong people</title>
		<link>http://www.mablaw.com/2012/02/ico-fines-midlothian-council/</link>
		<comments>http://www.mablaw.com/2012/02/ico-fines-midlothian-council/#comments</comments>
		<pubDate>Wed, 01 Feb 2012 22:19:49 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[Local Councils]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[Upload-Pharma]]></category>
		<category><![CDATA[Upload-TMT]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[fine]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[ICO fine]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[misuse of data]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[sensitive personal data]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=19153</guid>
		<description><![CDATA[The Information Commissioner’s Office has fined Midlothian Council £140,000 for sending sensitive personal data about children and carers to the wrong people on five separate occasions in the first six months of 2011. The Information Commissioner’s Office said that all of the breaches could have been avoided with the right protective measures and training. It [...]]]></description>
			<content:encoded><![CDATA[<p>The Information Commissioner’s Office has fined Midlothian Council £140,000 for sending sensitive personal data about children and carers to the wrong people on five separate occasions in the first six months of 2011. The Information Commissioner’s Office said that all of the breaches could have been avoided with the right protective measures and training. It said that the serious upset caused would have been obvious and it has sought to send out a strong message to other people to be careful to avoid making similar mistakes. The ICO has the power to fine data controllers up to £500,000 for breaches of the Data Protection Act, but until now its highest fine actually handed out has been £130,000. The ICO has ordered the Council to take better steps to keep personal data secure, and it has already sought to improve security measures including by making sure that more than one member of staff checks a letter before it goes out and improving training.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2012/02/ico-fines-midlothian-council/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sussex hospital facing £375,000 fine after hard drives with thousands of patient data ended up on eBay</title>
		<link>http://www.mablaw.com/2012/01/hospital-fine-data-hard-drives-ebay/</link>
		<comments>http://www.mablaw.com/2012/01/hospital-fine-data-hard-drives-ebay/#comments</comments>
		<pubDate>Fri, 13 Jan 2012 12:10:00 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Pharmaceutical]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[Websites]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[data processor]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[data subject]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[databases]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[eBay]]></category>
		<category><![CDATA[fine]]></category>
		<category><![CDATA[health]]></category>
		<category><![CDATA[healthcare]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[illegal]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[Information Commissioner’s Office]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[misuse of data]]></category>
		<category><![CDATA[National Health Service]]></category>
		<category><![CDATA[NHS]]></category>
		<category><![CDATA[On-line]]></category>
		<category><![CDATA[online content]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[pharma]]></category>
		<category><![CDATA[pharmaceutical sector]]></category>
		<category><![CDATA[sensitive personal data]]></category>
		<category><![CDATA[subcontractor]]></category>
		<category><![CDATA[unlawful]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web postings]]></category>
		<category><![CDATA[web site]]></category>
		<category><![CDATA[web site content]]></category>
		<category><![CDATA[web sites]]></category>
		<category><![CDATA[website content]]></category>
		<category><![CDATA[websites]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=18970</guid>
		<description><![CDATA[Following on from the Information Commissioner Office targeting the health sector for enforcement action for breaches of the Data Protection Act, the ICO has written to Brighton General Hospital proposing to fine it £375,000. This was due to a subcontractor of the Hospital, who was in charge of destroying hard drives containing thousands of patients’ [...]]]></description>
			<content:encoded><![CDATA[<p>Following on from the Information Commissioner Office targeting the health sector for enforcement action for breaches of the Data Protection Act, the ICO has written to Brighton General Hospital proposing to fine it £375,000. This was due to a subcontractor of the Hospital, who was in charge of destroying hard drives containing thousands of patients’ data, offered them up for sale on eBay in 2010. The hospital argues that it is the victims of crime and has challenged the proposed fine. The ICO has not publicly commented at this stage. Anyone processing data about living individuals must take appropriate measures to protect the security of it, particularly when it is sensitive personal data such as people’s health details. The ICO has the power to fine data controllers up to £500,000 for breaches of the Act, but until now its highest fine has been just over £100,000. A man had been arrested on suspicion of the theft, but police decided to take no further action for a prosecution.</p>
<p>Paul Gershlick, Head of Pharmaceuticals and Life Sciences at Partner at Matthew Arnold &amp; Baldwin LLP and a data protection law specialist, comments: “We need to understand the facts as the ICO sees them and then make a judgement, but such a large fine seems harsh given that the hospital appear to have been the victim and no data actually got into the public domain through the hospital’s action with the police when the items appeared on eBay. This action signals the tough intentions of the UK’s data protection regulator in dealing with data security breaches involving people’s health data.”</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2012/01/hospital-fine-data-hard-drives-ebay/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Health sector tops list for focus of data protection regulator&#8217;s enforcement</title>
		<link>http://www.mablaw.com/2012/01/health-sector-data-protection-enforcement/</link>
		<comments>http://www.mablaw.com/2012/01/health-sector-data-protection-enforcement/#comments</comments>
		<pubDate>Thu, 05 Jan 2012 22:36:51 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Pharmaceutical]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[data subject]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[enforcement]]></category>
		<category><![CDATA[enforcement notice]]></category>
		<category><![CDATA[health]]></category>
		<category><![CDATA[healthcare]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[ICO enforcement]]></category>
		<category><![CDATA[ICO enforcement action]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[Information Commissioner’s Office]]></category>
		<category><![CDATA[life sciences]]></category>
		<category><![CDATA[misuse of data]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[pharma]]></category>
		<category><![CDATA[pharmaceutical]]></category>
		<category><![CDATA[pharmaceutical industry]]></category>
		<category><![CDATA[pharmaceutical sector]]></category>
		<category><![CDATA[regulat]]></category>
		<category><![CDATA[sensitive personal data]]></category>
		<category><![CDATA[Upload-Pharma]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=18928</guid>
		<description><![CDATA[The health sector tops the list of areas targeted for enforcement by the Information Commissioner&#8217;s Office. This is in the ICO&#8217;s latest information rights strategy. As well as health are the credit and finance, criminal justice, Internet and mobile services, and security sectors. The ICO sets out a plan of 5 Es: eduate, empower, engage, [...]]]></description>
			<content:encoded><![CDATA[<p>The health sector tops the list of areas targeted for enforcement by the Information Commissioner&#8217;s Office. This is in the ICO&#8217;s latest information rights strategy. As well as health are the credit and finance, criminal justice, Internet and mobile services, and security sectors.</p>
<p>The ICO sets out a plan of 5 Es: eduate, empower, engage, enable and enforce. It is not purely about enforcement as it wants to educate and help too, but that is clearly the end result if there are problems. It wants to target its limited resources to the areas in which it perceives are the greatest need to act to protect individuals. It will consider the volume, nature and sensitivity of the data and the number of people affected. Ultimately, it will consider what is in the public interest.</p>
<p>The ICO wants to ensure that its activities are conducted transparently, proportionately, consistently, targeted and in an accountable way. It also wants to see a high proportion of the public aware of their privacy rights and how to enforce them.</p>
<p>The Information Rights Strategy can be found here: <a href="http://www.ico.gov.uk/about_us/plans_and_priorities/information_rights_strategy.aspx">http://www.ico.gov.uk/about_us/plans_and_priorities/information_rights_strategy.aspx</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2012/01/health-sector-data-protection-enforcement/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ICO gives verdict on implementation of new cookies rules: websites must do better</title>
		<link>http://www.mablaw.com/2011/12/ico-cookies-guidance-websites/</link>
		<comments>http://www.mablaw.com/2011/12/ico-cookies-guidance-websites/#comments</comments>
		<pubDate>Fri, 23 Dec 2011 16:16:49 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[Websites]]></category>
		<category><![CDATA[consent]]></category>
		<category><![CDATA[cookie]]></category>
		<category><![CDATA[cookie consent]]></category>
		<category><![CDATA[cookie law]]></category>
		<category><![CDATA[cookies]]></category>
		<category><![CDATA[cookies consent]]></category>
		<category><![CDATA[cookies policy]]></category>
		<category><![CDATA[cookies statement]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[e-privacy]]></category>
		<category><![CDATA[eprivacy]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[Information Commissioner’s Office]]></category>
		<category><![CDATA[On-line]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Privacy and Electronic Communications (EC Directive) (Amendment) Regulations]]></category>
		<category><![CDATA[privacy and electronic communications (ec directive) regulations]]></category>
		<category><![CDATA[Privacy and Electronic Communications Directive]]></category>
		<category><![CDATA[privacy and electronic communications regulations]]></category>
		<category><![CDATA[privacy issues]]></category>
		<category><![CDATA[privacy policy]]></category>
		<category><![CDATA[privacy principles]]></category>
		<category><![CDATA[privacy statement]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web content]]></category>
		<category><![CDATA[web site]]></category>
		<category><![CDATA[web sites]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[website content]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=18906</guid>
		<description><![CDATA[The Information Commissioner’s Office – the UK’s data protection regulator &#8211; has given a damming report on websites’ implementation of new cookies laws, under which website users must receive clear information of the cookies that are used on a site and their consent must be obtained for the use. The law changed in May this [...]]]></description>
			<content:encoded><![CDATA[<p>The Information Commissioner’s Office – the UK’s data protection regulator &#8211; has given a damming report on websites’ implementation of new cookies laws, under which website users must receive clear information of the cookies that are used on a site and their consent must be obtained for the use. The law changed in May this year, but the ICO gave websites a further year to make the changes. However, it said at the time that businesses must make the changes. The purpose of the year’s grace was to allow steps to be taken to be ready. The ICO is disappointed, though, that many businesses are doing nothing to address the new law and this is not acceptable. In the report, it has provided updated guidance on how to comply, including suggested wording for the information and how links should be used to the relevant wording. The guidance says that providing the information through a privacy policy is not normally enough.</p>
<p>The guidance advocates a cookie audit to identify the cookies used, distinguishing between session, persistent and third party cookies, look at how privacy-intrusive each cookie is and how clear information is provided to users.</p>
<p>The ICO has also given further guidance on obtaining consent. It says that website operators should have minimal use of cookies until users have consented. Implied consent is not a viable option at the moment, but as users become more aware of cookies, that could be used. It also advocates contractual obligations between third parties and website owners governing the collection of consent for the third party cookies.</p>
<p>The ICO’s report and the guidance can be found here:  <a href="http://www.ico.gov.uk/news/latest_news/2011/must-try-harder-on-cookies-compliance-says-ico-13122011.aspx">http://www.ico.gov.uk/news/latest_news/2011/must-try-harder-on-cookies-compliance-says-ico-13122011.aspx</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/12/ico-cookies-guidance-websites/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ticket exchange website loses as Court of Appeal orders disclosure of information about sellers for sale of tickets above face value – RFU v Viagogo, Court of Appeal</title>
		<link>http://www.mablaw.com/2011/12/rfu-viagogo-norwich-pharmacal/</link>
		<comments>http://www.mablaw.com/2011/12/rfu-viagogo-norwich-pharmacal/#comments</comments>
		<pubDate>Fri, 23 Dec 2011 11:29:02 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Commercial Contracts]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Sport]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[Websites]]></category>
		<category><![CDATA[B2C]]></category>
		<category><![CDATA[business-to-consumer]]></category>
		<category><![CDATA[consumer agreement]]></category>
		<category><![CDATA[consumer agreements]]></category>
		<category><![CDATA[consumer contract]]></category>
		<category><![CDATA[consumer contracts]]></category>
		<category><![CDATA[consumer law]]></category>
		<category><![CDATA[consumer laws]]></category>
		<category><![CDATA[Court of Appeal]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection law]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[disclose]]></category>
		<category><![CDATA[disclosure]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[High Court]]></category>
		<category><![CDATA[Norwich Pharmacal Order]]></category>
		<category><![CDATA[On-line]]></category>
		<category><![CDATA[online content]]></category>
		<category><![CDATA[online trading]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[trespass]]></category>
		<category><![CDATA[trespasser]]></category>
		<category><![CDATA[trespassing]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web content]]></category>
		<category><![CDATA[web site]]></category>
		<category><![CDATA[web sites]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[website content]]></category>
		<category><![CDATA[websites]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=18899</guid>
		<description><![CDATA[A ticket exchange website has been ordered to hand over to the Rugby Football Union details of people who have sold on its site England rugby tickets for above the ticket’s face value. Sales above face value contravened the RFU’s rules and meant that any purchaser would be trespassing on entering the rugby ground for [...]]]></description>
			<content:encoded><![CDATA[<p>A ticket exchange website has been ordered to hand over to the Rugby Football Union details of people who have sold on its site England rugby tickets for above the ticket’s face value. Sales above face value contravened the RFU’s rules and meant that any purchaser would be trespassing on entering the rugby ground for the game. The High Court initially and now the Court of Appeal have ruled that the RFU was entitled to have details about the sellers, as they would be jointly liable for the purchasers’ trespass.</p>
<p>Viagogo – the website – had objected to the hand over, saying that to do so would be disproportionate and infringe its users’ data protection rights. The Court of Appeal disagreed. The rights had to be balanced and the RFU was entitled to know about who was infringing its contract terms. The Court of Appeal therefore ruled that it was right to grant the RFU a “Norwich Pharmacal Order” against Viagogo to reveal the data. Whether or not the England rugby body used that data to take action against the sellers or the people who had provided the tickets to the sellers was irrelevant to the ruling.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/12/rfu-viagogo-norwich-pharmacal/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ICO advises communications providers to inform of data protection breaches every month</title>
		<link>http://www.mablaw.com/2011/12/ico-guidance-data-protection-communications-providers/</link>
		<comments>http://www.mablaw.com/2011/12/ico-guidance-data-protection-communications-providers/#comments</comments>
		<pubDate>Thu, 22 Dec 2011 11:08:56 +0000</pubDate>
		<dc:creator>Simon Weinberg</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[data protection breach]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[data protection regime]]></category>
		<category><![CDATA[electronic communication providers]]></category>
		<category><![CDATA[electronic communications providers]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[ICO guidance]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[online content]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[privacy and electronic communications regulations]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web site]]></category>
		<category><![CDATA[web sites]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[website content]]></category>
		<category><![CDATA[websites]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=18841</guid>
		<description><![CDATA[The Information Commissioner’s Office (ICO) has released updated guidance in which it advises electronic communication providers to inform the ICO of breaches to users’ personal data each month. The guidance also recommends that, if a breach is particularly serious, the ICO should be informed immediately by using a new standard notification form. The changes to [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.ico.gov.uk/for_organisations/privacy_and_electronic_communications/the_guide/security_breaches.aspx">The Information Commissioner’s Office (ICO) has released updated guidance in which it advises electronic communication providers to inform the ICO of breaches to users’ personal data each month</a>. The guidance also recommends that, if a breach is particularly serious, the ICO should be informed immediately by using a new standard notification form.</p>
<p>The changes to the guidance largely reflect the revisions made to the Privacy and Electronic Communications Regulations in May 2011, under which electronic communications providers must inform the ICO about all data protection breaches. The main difference is the recommendation to provide a monthly report rather than simply to maintain a record of breaches which can be audited by the ICO for compliance.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/12/ico-guidance-data-protection-communications-providers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Atos to provide service that will enable comparison of data across GP practices in England – but privacy campaigners complain again</title>
		<link>http://www.mablaw.com/2011/12/atos-data-comparison-gp-practices/</link>
		<comments>http://www.mablaw.com/2011/12/atos-data-comparison-gp-practices/#comments</comments>
		<pubDate>Wed, 21 Dec 2011 14:50:20 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Pharmaceutical]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[data subject]]></category>
		<category><![CDATA[GP]]></category>
		<category><![CDATA[misuse of data]]></category>
		<category><![CDATA[NHS]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[pharma]]></category>
		<category><![CDATA[pharmaceutical]]></category>
		<category><![CDATA[pharmaceutical industry]]></category>
		<category><![CDATA[pharmaceutical market]]></category>
		<category><![CDATA[pharmaceutical sector]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[sensitive personal data]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=18864</guid>
		<description><![CDATA[Atos has been engaged to provide an £8m service through a computer system so as to extract data about patients from GPs’ surgeries and enable comparable extractions across the NHS. The Department of Health has said that the service will lead to better patient care. It will also help GPs and clinical commissioning groups in [...]]]></description>
			<content:encoded><![CDATA[<p>Atos has been engaged to provide an £8m service through a computer system so as to extract data about patients from GPs’ surgeries and enable comparable extractions across the NHS. The Department of Health has said that the service will lead to better patient care. It will also help GPs and clinical commissioning groups in their proposed new processes. However, yet again, privacy campaigners are warning about protection of patient data. Big Brother Watch has criticised the Government’s healthcare strategy for moving too fast and without putting in place proper safeguards for patient data. It says the proposals pay only lip service to privacy and patients have no ability to prevent their medical information from being published if the people running the system regard it as having been properly safeguarded. However, the NHS Information Centre says that the system will provide an unprecedented standardised picture of primary care information across the country while protecting patient confidentiality.</p>
<p>Paul Gershlick, a Partner and Head of the Pharmaceutical and Life Sciences sector at Matthew Arnold &amp; Baldwin LLP, says, “It is absolutely crucial to protect patient data. However, privacy groups again appear to be pursuing a single concern agenda – ie privacy. What about improving patient care and improving or saving lives? Instead of criticising the Government’s healthcare data strategy for being pursued too fast, people worried about privacy should instead be working with the Government to make sure the privacy safeguards are in place so that the health benefits can be achieved as soon as possible. The longer any delays take, the fewer number of people who will benefit from any reforms. When people’s lives are at stake, there should be no time to lose.”</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/12/atos-data-comparison-gp-practices/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ICO fines Welsh council for data protection breach</title>
		<link>http://www.mablaw.com/2011/12/ico-fines-welsh-council-data-protection-breach/</link>
		<comments>http://www.mablaw.com/2011/12/ico-fines-welsh-council-data-protection-breach/#comments</comments>
		<pubDate>Wed, 21 Dec 2011 11:25:40 +0000</pubDate>
		<dc:creator>Simon Weinberg</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[child protection]]></category>
		<category><![CDATA[council]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[data protection breach]]></category>
		<category><![CDATA[data protection law]]></category>
		<category><![CDATA[data protection regime]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=18838</guid>
		<description><![CDATA[The Information Commissioner’s Office (ICO) has issued a fine of £130,000 to Powys County Council in Wales for data protection breaches. The council sent a child protection report to a member of the public following a mix-up in the printing process. The fine follows a similar incident last year where public parts of a document [...]]]></description>
			<content:encoded><![CDATA[<p>The Information Commissioner’s Office (ICO) has issued a fine of £130,000 to Powys County Council in Wales for data protection breaches. The council sent a child protection report to a member of the public following a mix-up in the printing process.</p>
<p>The fine follows a similar incident last year where public parts of a document about another child were sent to the same member of the public by the council. The ICO admonished the council, with the council promising to improve its processes.</p>
<p>In addition to the fine, the council has been ordered to retrain all staff in relation to data protection before the end of March 2012, with refresher training to follow every three years.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/12/ico-fines-welsh-council-data-protection-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Protection Board to be set up to oversee the changed data protection regime in Europe</title>
		<link>http://www.mablaw.com/2011/12/data-protection-board-europe/</link>
		<comments>http://www.mablaw.com/2011/12/data-protection-board-europe/#comments</comments>
		<pubDate>Mon, 19 Dec 2011 09:21:36 +0000</pubDate>
		<dc:creator>Simon Weinberg</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[Article 29]]></category>
		<category><![CDATA[Article 29 Working Party]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[data protection baord]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[data protection regime]]></category>
		<category><![CDATA[EU]]></category>
		<category><![CDATA[EU Justice Commissioner]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[European Commission]]></category>
		<category><![CDATA[European data protection laws]]></category>
		<category><![CDATA[European data protection regime]]></category>
		<category><![CDATA[European Union]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[Member State]]></category>
		<category><![CDATA[Member States]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=18836</guid>
		<description><![CDATA[The recent proposals to update the data protection laws across the European Union (EU) have brought much comment and debate in the UK (see here and here). The EU Justice Commissioner has now announced that a “Data Protection Board” will be created to oversee the revised regime, monitor compliance and enforce its restrictions. The “Article [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.mablaw.com/2011/11/eu-data-protection-laws-overhaul-reding/">The recent proposals to update the data protection laws across the European Union (EU)</a> have brought much comment and debate in the UK (see <a href="http://www.mablaw.com/2011/11/culture-minister-queries-eu-data-protection-proposals/">here</a> and <a href="http://www.mablaw.com/2011/11/ico-briefing-future-data-protection-eu/">here</a>). The EU Justice Commissioner has now announced that a “Data Protection Board” will be created to oversee the revised regime, monitor compliance and enforce its restrictions.</p>
<p>The “Article 29 Working Party”, which is a committee of national regulators from each EU State (including the UK’s Information Commissioner’s Office), will provide the basis for the new board. The board will offer support to each country’s regulator and, it is hoped, will bring about more harmonisation between the data protection laws in each Member State.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/12/data-protection-board-europe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hospital pays data protection compensation after employee unlawfully accesses patient data – Grinyer v Plymouth Hospital NHS Trust, County Court</title>
		<link>http://www.mablaw.com/2011/12/hospital-data-protection-compensation-grinyer-plymouth/</link>
		<comments>http://www.mablaw.com/2011/12/hospital-data-protection-compensation-grinyer-plymouth/#comments</comments>
		<pubDate>Fri, 09 Dec 2011 08:21:22 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Pharmaceutical]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[life sciences]]></category>
		<category><![CDATA[mental health]]></category>
		<category><![CDATA[misuse of data]]></category>
		<category><![CDATA[NHS]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[pharma]]></category>
		<category><![CDATA[pharmaceutical]]></category>
		<category><![CDATA[pharmaceutical sector]]></category>
		<category><![CDATA[sensitive personal data]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=18705</guid>
		<description><![CDATA[Plymouth Hospital NHS Trust has been ordered to pay one of its patients damages for breach of the Data Protection Act after one of its staff had unlawfully accessed the patient’s details, contrary to the Data Protection Act. According to a blog post from the barrister who represented the successful claimant &#8211; http://www.unitystreetchambers.com/blog/?p=131 – the [...]]]></description>
			<content:encoded><![CDATA[<p>Plymouth Hospital NHS Trust has been ordered to pay one of its patients damages for breach of the Data Protection Act after one of its staff had unlawfully accessed the patient’s details, contrary to the Data Protection Act. According to a blog post from the barrister who represented the successful claimant &#8211; <a href="http://www.unitystreetchambers.com/blog/?p=131">http://www.unitystreetchambers.com/blog/?p=131</a> – the patient was awarded £12,500 for exacerbating his paranoid medical condition and £4,800 for loss of earnings. The person who had unlawfully accessed his personal data was a nurse at the hospital and his partner at the time.</p>
<p>Paul Gershlick, a Partner and Head of the Pharmaceutical and Life Sciences sector at Matthew Arnold &amp; Baldwin LLP, comments: “This case shows that any organisations involved with people’s health data must be careful to ensure that their employees do not misuse the data and that they take adequate safeguards to protect it. Health data about individuals falls within the category of sensitive personal data and is a higher class of data that is protected under data protection laws. That said, this outcome would probably have been the same regardless of the fact that the data misused was within the category of sensitive personal data.”</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/12/hospital-data-protection-compensation-grinyer-plymouth/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MAB Pharma sector leader welcomes new NHS data sharing plans</title>
		<link>http://www.mablaw.com/2011/12/mab-pharma-sector-nhs-data-sharing-plans/</link>
		<comments>http://www.mablaw.com/2011/12/mab-pharma-sector-nhs-data-sharing-plans/#comments</comments>
		<pubDate>Mon, 05 Dec 2011 08:25:16 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Pharmaceutical]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[anonymised data]]></category>
		<category><![CDATA[anonymised personal data]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[data protection regime]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[data sharing]]></category>
		<category><![CDATA[data subject]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[databases]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[life sciences]]></category>
		<category><![CDATA[NHS]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[pharma]]></category>
		<category><![CDATA[pharma products]]></category>
		<category><![CDATA[pharmaceutical]]></category>
		<category><![CDATA[pharmaceutical business]]></category>
		<category><![CDATA[pharmaceutical company]]></category>
		<category><![CDATA[pharmaceutical industry]]></category>
		<category><![CDATA[pharmaceutical market]]></category>
		<category><![CDATA[pharmaceutical products]]></category>
		<category><![CDATA[pharmaceutical sector]]></category>
		<category><![CDATA[sensitive personal data]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=18542</guid>
		<description><![CDATA[At this time of financial uncertainty, it is great to see politicians thinking outside of the box to develop solutions to protect UK industry and improve people&#8217;s lives.  According to plans announced by David Cameron, the NHS should be opened up to business in the pharmaceutical and life sciences sector and this could include sharing [...]]]></description>
			<content:encoded><![CDATA[<p>At this time of financial uncertainty, it is great to see politicians thinking outside of the box to develop solutions to protect UK industry and improve people&#8217;s lives.  According to plans announced by David Cameron, the NHS should be opened up to business in the pharmaceutical and life sciences sector and this could include sharing anonymous patient data to help research and development, innovation and carrying out clinical trials inside hospitals.  The Prime Minister wants to see new treatments reach patients faster and the UK to be a world leader in life sciences including by being the fastest adopter of new ideas in the world.  He sees this initiative as acting as a magnet to pull new innovations through and develop the pharma and life sciences sector.</p>
<p>Some have raised privacy concerns over the proposals.  Big Brother Watch has said it should be for patients to decide what happens with their medical information rather than governments.  Meanwhile, Patient Concern warns that the plans would be the death of patient confidentiality.</p>
<p>However, Paul Gershlick, a Partner and Head of the Pharmaceutical and Life Sciences sector at Matthew Arnold &amp; Baldwin LLP, disagrees with those concerns and welcomes the Government&#8217;s initiative.  He says: &#8221;It is clear from the Government plans that patient data will be anonymous so that any one individual will not be identified during the data sharing.  If that is the case, why should there be any fuss from privacy campaigners? Under UK data protection law, people lose rights over &#8220;their&#8221; data if that data is anonymised. </p>
<p>&#8220;Surely, as long as patient data is protected through anonymity, the main objective must be to improve patient care and make people&#8217;s lives better.  As a society, we must do all we can to improve the quality of care through helping to achieve faster drug development and introduction. If the NHS works together with the private sector to help to develop or bring out new drugs quicker, that has got to be a good thing if it saves anyone&#8217;s lives or makes them more comfortable.  And if this has the added bonus of generating more business in the UK by making it a more attractive place to do business in the pharmaceutical and life sciences sector particularly in these economic uncertain times, so much the better.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/12/mab-pharma-sector-nhs-data-sharing-plans/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Councils need counselling for better data protection</title>
		<link>http://www.mablaw.com/2011/11/councils-data-protection-big-brother-watch/</link>
		<comments>http://www.mablaw.com/2011/11/councils-data-protection-big-brother-watch/#comments</comments>
		<pubDate>Mon, 28 Nov 2011 17:58:45 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[Local Councils]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[councils]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[data subject]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[FOIA]]></category>
		<category><![CDATA[freedom of information]]></category>
		<category><![CDATA[Freedom of Information Act 2000]]></category>
		<category><![CDATA[freedom of information request]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[Information Commissioner’s Office]]></category>
		<category><![CDATA[Local Council]]></category>
		<category><![CDATA[misuse of data]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[request for information]]></category>
		<category><![CDATA[sensitive personal data]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=17875</guid>
		<description><![CDATA[There have been 1,035 cases of personal data loss by 132 councils in the past three years. These are the findings of Big Brother Watch, after it had submitted a freedom of information request to ascertain the scale of the problem. Only 55 of the incidents had been reported to the Information Commissioner’s Office, leaving [...]]]></description>
			<content:encoded><![CDATA[<p>There have been 1,035 cases of personal data loss by 132 councils in the past three years. These are the findings of Big Brother Watch, after it had submitted a freedom of information request to ascertain the scale of the problem. Only 55 of the incidents had been reported to the Information Commissioner’s Office, leaving the conclusion that most of the data losses had been unannounced. The data losses related to children, the old, the sick, women and men and involved the usual suspects of things going wrong &#8211; laptops and mobile devices without adequate encryption as well as information being posted on Facebook.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/11/councils-data-protection-big-brother-watch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ICO publishes briefing on the future of data protection in the EU</title>
		<link>http://www.mablaw.com/2011/11/ico-briefing-future-data-protection-eu/</link>
		<comments>http://www.mablaw.com/2011/11/ico-briefing-future-data-protection-eu/#comments</comments>
		<pubDate>Fri, 25 Nov 2011 09:45:57 +0000</pubDate>
		<dc:creator>Simon Weinberg</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[data protection framework]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[data protection regime]]></category>
		<category><![CDATA[EC]]></category>
		<category><![CDATA[EU]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[European Commission]]></category>
		<category><![CDATA[European Union]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[Intellectual property]]></category>
		<category><![CDATA[intellectual property rights]]></category>
		<category><![CDATA[IP]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=17246</guid>
		<description><![CDATA[The Information Commissioner’s Office (ICO) has published a briefing outlining the European Commission’s (EC) proposals to reform the Data Protection Directive, and sets out its views on a number of those proposals. The ICO expects the EC to publish its proposal early next year. The ICO highlights that it believes the new framework must: -          [...]]]></description>
			<content:encoded><![CDATA[<p>The Information Commissioner’s Office (ICO) has published a briefing outlining the European Commission’s (EC) proposals to reform the Data Protection Directive, and sets out its views on a number of those proposals. The ICO expects the EC to publish its proposal early next year.</p>
<p>The ICO highlights that it believes the new framework must:</p>
<p>-          be clear and easy to understand and provide a cost-effective means of individuals exercising their rights;</p>
<p>-          set out a clear structure with overarching high-level principles based on risk, context and purpose with flexibility for enforcement bodies, rather than a prescriptive approach based on lists;</p>
<p>-          involve an obligation on organisations to carry out a private impact assessment where processing could have a significant or adverse effect on an individual, uses intrusive technology or creates a particular risk.</p>
<p>-          ensure that data processors are responsible and accountable, with the emphasis on the maintenance of standards rather than simply having a ‘process’ that complies with the law; and</p>
<p>-          allow the ICO more inspection and enforcement powers in both the private and public sectors with less emphasis on prior approval and authorisation of a data processor’s activities.</p>
<p>The ICO was critical of recent statements suggesting that consumers should have a “right to be forgotten” as it could mislead and create false expectations and be impossible to implement in practice.</p>
<p>The full text of the briefing can be found <a title="Opens in new window" href="http://www.ico.gov.uk/news/~/media/documents/library/Data_Protection/Research_and_reports/ico_stakeholder_briefing_-_the_future_of_dp_in_the_eu.ashx" target="_blank">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/11/ico-briefing-future-data-protection-eu/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Culture Minister queries EU data protection proposals</title>
		<link>http://www.mablaw.com/2011/11/culture-minister-queries-eu-data-protection-proposals/</link>
		<comments>http://www.mablaw.com/2011/11/culture-minister-queries-eu-data-protection-proposals/#comments</comments>
		<pubDate>Fri, 25 Nov 2011 09:42:40 +0000</pubDate>
		<dc:creator>Simon Weinberg</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[Websites]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[Culture Minister]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[data protection principles]]></category>
		<category><![CDATA[data protection regime]]></category>
		<category><![CDATA[Ed Vaizey]]></category>
		<category><![CDATA[EU]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[European Commission]]></category>
		<category><![CDATA[European Union]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[right to be forgotten]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web site]]></category>
		<category><![CDATA[web sites]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[website content]]></category>
		<category><![CDATA[websites]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=17234</guid>
		<description><![CDATA[The Government’s Culture Minister, Ed Vaizey, has given a statement on the development of European Union (EU) data protection laws. The statement was made in a speech to the Internet Advertising Bureau in London. The EU has proposed several changes to the current data protection regime, including granting individuals a “right to be forgotten” by [...]]]></description>
			<content:encoded><![CDATA[<p>The Government’s Culture Minister, Ed Vaizey, has given a statement on the development of European Union (EU) data protection laws. The statement was made in a speech to the Internet Advertising Bureau in London.</p>
<p>The EU has proposed several changes to the current data protection regime, including granting individuals a “right to be forgotten” by allowing them to force organisations to delete personal data they hold and making non-EU based organisations subject to EU data protection law if they store personal data of EU citizens in the “cloud” (i.e. storing the data on an Internet-based network rather than on local servers).</p>
<p>The Culture Minister responded that:</p>
<p>-          A “right to be forgotten” would give the public false expectations. His argument was based on the ease and speed with which data can be copied and circulated on the Internet, to the extent that the Government would be unlikely to pass a law into force that it was impossible to enforce.  After all, how could one organisation promise that someone’s photos had been permanently deleted when someone else may have copied them from that original site?</p>
<p>-          It was questionable how feasible it would be to enforce EU law against non-EU organisations and there was the possibility that the law would stifle innovation and economic growth in the sector.</p>
<p>The full text of the speech can be found <a href="http://www.culture.gov.uk/news/ministers_speeches/8592.aspx">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/11/culture-minister-queries-eu-data-protection-proposals/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ENISA expresses concern over loss of Internet user control</title>
		<link>http://www.mablaw.com/2011/11/enisa-concern-loss-internet-user-control/</link>
		<comments>http://www.mablaw.com/2011/11/enisa-concern-loss-internet-user-control/#comments</comments>
		<pubDate>Fri, 18 Nov 2011 08:45:38 +0000</pubDate>
		<dc:creator>Simon Weinberg</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[Websites]]></category>
		<category><![CDATA[cookie]]></category>
		<category><![CDATA[cookie consent]]></category>
		<category><![CDATA[cookie law]]></category>
		<category><![CDATA[cookies]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[ENISA]]></category>
		<category><![CDATA[EU]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[European Commission]]></category>
		<category><![CDATA[European Network and Information Security Agency]]></category>
		<category><![CDATA[European Union]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Internet preferences]]></category>
		<category><![CDATA[Internet privacy]]></category>
		<category><![CDATA[Internet security]]></category>
		<category><![CDATA[online content]]></category>
		<category><![CDATA[online preferences]]></category>
		<category><![CDATA[online privacy]]></category>
		<category><![CDATA[online security]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[privacy preferences]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[social network]]></category>
		<category><![CDATA[social networks]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web operator]]></category>
		<category><![CDATA[web personalisation]]></category>
		<category><![CDATA[web preferences]]></category>
		<category><![CDATA[web privacy]]></category>
		<category><![CDATA[web security]]></category>
		<category><![CDATA[web site]]></category>
		<category><![CDATA[web sites]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[website content]]></category>
		<category><![CDATA[website operator]]></category>
		<category><![CDATA[website personalisation]]></category>
		<category><![CDATA[websites]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=17167</guid>
		<description><![CDATA[The European Network and Information Security Agency (ENISA), an agency of the European Union, has published a report on the storage of personal data by social networks in order to provide a personalised profile to users. When a user visits, for example, a shopping website, the products they view may be tracked so that, the [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.enisa.europa.eu/act/rm/emerging-and-future-risk/deliverables/life-logging-risk-assessment/">The European Network and Information Security Agency (ENISA), an agency of the European Union, has published a report on the storage of personal data by social networks in order to provide a personalised profile to users</a>. When a user visits, for example, a shopping website, the products they view may be tracked so that, the next time they visit the site, they see a personalised view of that website based on their previous activity, rather than the full website. ENISA have expressed concern that this can lead to users not realising that they have only been provided with filtered, personalised information and making decisions without having fully researched their options.</p>
<p>ENISA also expressed concern in relation to security and privacy risks from such practices. The report suggests that users are becoming increasingly dependent on websites storing their personal information to make their future visits quicker and easier; whilst this is a benefit to a user, it makes fraud and unauthorised access easier, with the potential for not only financial loss but also possible reputational harm, discrimination and even exclusion from websites altogether.</p>
<p>The report suggests that the other effect of the practice is that website operators are being put under increasing pressure to store and protect personal information in a legally compliant way, which they may not have the knowledge or financial means to undertake.</p>
<p>ENISA suggested that privacy-friendly mechanisms should be incorporated into new websites and software, with clear instructions for users explaining the risks involved in a personalised service.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/11/enisa-concern-loss-internet-user-control/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W3C developments as to how web-surfers can protect their data</title>
		<link>http://www.mablaw.com/2011/11/w3c-web-users-protect-data/</link>
		<comments>http://www.mablaw.com/2011/11/w3c-web-users-protect-data/#comments</comments>
		<pubDate>Fri, 18 Nov 2011 08:44:42 +0000</pubDate>
		<dc:creator>Mark Weston</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[Websites]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[cookie]]></category>
		<category><![CDATA[cookie law]]></category>
		<category><![CDATA[cookies]]></category>
		<category><![CDATA[cookies consent]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Internet preferences]]></category>
		<category><![CDATA[Internet privacy]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[online content]]></category>
		<category><![CDATA[online preferences]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[preference tracking]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Privacy and Electronic Communications (EC Directive) (Amendment) Regulations 2011]]></category>
		<category><![CDATA[privacy preferences]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[user]]></category>
		<category><![CDATA[W3C]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web preferences]]></category>
		<category><![CDATA[web site]]></category>
		<category><![CDATA[web sites]]></category>
		<category><![CDATA[web standards]]></category>
		<category><![CDATA[web tracking]]></category>
		<category><![CDATA[web user]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[website content]]></category>
		<category><![CDATA[website operator]]></category>
		<category><![CDATA[website operators]]></category>
		<category><![CDATA[website user]]></category>
		<category><![CDATA[websites]]></category>
		<category><![CDATA[World Wide Web Consortium]]></category>
		<category><![CDATA[Yahoo]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=17165</guid>
		<description><![CDATA[Changes to the law in relation to cookies have resulted in an increasingly intense spotlight on the use of cookies by website operators. The Privacy and Electronic Communications (EC Directive) (Amendment) Regulations 2011 came into force on 26 May 2011 and mean that, in basic terms, consent must be obtained from a website user before [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.mablaw.com/2011/05/new-law-comes-into-force-requiring-user-consent-when-using-cookies/">Changes to the law in relation to cookies have resulted in an increasingly intense spotlight on the use of cookies by website operators</a>. The Privacy and Electronic Communications (EC Directive) (Amendment) Regulations 2011 came into force on 26 May 2011 and mean that, in basic terms, consent must be obtained from a website user before a website operator can place a cookie on the user’s machine – other than for limited exceptions, if a user refuses to give their consent, the cookie cannot be placed.</p>
<p>The World Wide Web Consortium (W3C) has published two draft standards to allow users to express privacy preferences in relation to cookies.  W3C released details of:</p>
<ol>
<li>the “Tracking Preference Expression”, which defines mechanisms for users to express cross-site tracking preferences, and for websites to indicate whether these preferences are complied with; and</li>
<li>the “Tracking Compliance and Scope Specification”, which defines the meaning of a “Do Not Track” mechanism for notifying websites of a preference and set out best practice for website compliance.</li>
</ol>
<p>It is hoped that the documents will culminate in the development of software that can be used and developed further by browser operators to protect users from cookies and tracking mechanisms. It is intended that the new standards will allow a user to express a preference for how their data is collected for tracking purposes and alert users as to whether a website honours their preferences or not.</p>
<p>The documents have been developed by a working group within W3C which includes representatives of Apple, Facebook, Google, IBM, Microsoft and Yahoo.</p>
<p>W3C is hopeful that the standards will be in operation in 2012.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/11/w3c-web-users-protect-data/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>EU Justice Minister signals massive overhaul towards far stricter data protection laws for business</title>
		<link>http://www.mablaw.com/2011/11/eu-data-protection-laws-overhaul-reding/</link>
		<comments>http://www.mablaw.com/2011/11/eu-data-protection-laws-overhaul-reding/#comments</comments>
		<pubDate>Thu, 17 Nov 2011 21:59:37 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[Websites]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[consent]]></category>
		<category><![CDATA[consumer]]></category>
		<category><![CDATA[consumer rights]]></category>
		<category><![CDATA[consumers]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[data protection principles]]></category>
		<category><![CDATA[data protection regime]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[data subject]]></category>
		<category><![CDATA[data subject access]]></category>
		<category><![CDATA[delete]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[EU]]></category>
		<category><![CDATA[EU law]]></category>
		<category><![CDATA[EU laws]]></category>
		<category><![CDATA[European Commission]]></category>
		<category><![CDATA[European Union]]></category>
		<category><![CDATA[explicit consent]]></category>
		<category><![CDATA[explicit prior consent]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Internet use]]></category>
		<category><![CDATA[Internet user]]></category>
		<category><![CDATA[misuse of data]]></category>
		<category><![CDATA[On-line]]></category>
		<category><![CDATA[online content]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[prior consent]]></category>
		<category><![CDATA[sensitive personal data]]></category>
		<category><![CDATA[social network]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[social networking site]]></category>
		<category><![CDATA[social networking website]]></category>
		<category><![CDATA[UGC]]></category>
		<category><![CDATA[user-generated content]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web content]]></category>
		<category><![CDATA[web postings]]></category>
		<category><![CDATA[web site]]></category>
		<category><![CDATA[web site content]]></category>
		<category><![CDATA[web sites]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[website content]]></category>
		<category><![CDATA[websites]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=17132</guid>
		<description><![CDATA[Businesses will need to obtain explicit prior consent from individuals before processing data about them and give them the right to have their data deleted at any time especially if they post data on the Internet themselves, according to a statement from European Union Justice Commissioner, Viviane Reding. There has been expectation for some time [...]]]></description>
			<content:encoded><![CDATA[<p>Businesses will need to obtain explicit prior consent from individuals before processing data about them and give them the right to have their data deleted at any time especially if they post data on the Internet themselves, according to a statement from European Union Justice Commissioner, Viviane Reding. There has been expectation for some time that the EU’s data protection laws are about to be overhauled. That step is imminent. Reding expects to introduce proposals for the new rules by the end of January 2012.</p>
<p>In her statement, Reding said consumers should be more “empowered”. She also issued a warning that cloud computing service providers would face stricter provisions. Cloud computing refers to the making available of software and data on a network such as the Internet rather than on the user’s own servers.</p>
<p>Paul Gershlick, a Partner at Matthew Arnold &amp; Baldwin LLP and editor of Upload-IT, comments: “This statement will send shockwaves through businesses. Currently, there are a number of grounds on which organisations can process data. They include if it is for their legitimate interests and it does not cause the data subject unwarranted harm. The statement is short so something may be lost in the translation, but at face value it suggests that the only grounds for processing data will be with explicit consent and that consent must be given in advance. That could prevent many businesses from functioning efficiently if they need to obtain explicit consent first every time.</p>
<p>“The new laws will also look to address the problem of social media site users saying something embarrassing and then never being able to remove it later, leaving them in an awkward position when a prospective interviewer checks them out on the web before a job interview. There has not yet been any clarity over users’ position when someone else posts a comment, photo or video clip about them on the web without their consent – if someone is featured in someone else’s posted content, will the subject be able to pull it?</p>
<p>“Further, the statement issues a warning for cloud computing service providers, but does not give any indication about how exactly their businesses may be affected.</p>
<p>“Overall, the statement leaves more questions than answers and is not particularly helpful for businesses looking to plan ahead to the new regime. They will have to watch this space over the next few weeks to see what the impact will be.”</p>
<p>The statement can be found here: <a href="http://europa.eu/rapid/pressReleasesAction.do?reference=MEMO/11/762&amp;type=HTML">http://europa.eu/rapid/pressReleasesAction.do?reference=MEMO/11/762&amp;type=HTML</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/11/eu-data-protection-laws-overhaul-reding/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Midata collaboration between large private sector groups, BIS and Information Commissioner hands back control of data to consumers</title>
		<link>http://www.mablaw.com/2011/11/midata-consumer-data-empowerment/</link>
		<comments>http://www.mablaw.com/2011/11/midata-consumer-data-empowerment/#comments</comments>
		<pubDate>Wed, 16 Nov 2011 19:54:06 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[BIS]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[data sharing]]></category>
		<category><![CDATA[data subject]]></category>
		<category><![CDATA[data subject access]]></category>
		<category><![CDATA[databases]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[Information Commissioner’s Office]]></category>
		<category><![CDATA[Midata]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[sensitive personal data]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=17134</guid>
		<description><![CDATA[A new scheme in which consumers will be empowered to manage data held about them by large private sector organisations such as Google and British Gas is going to be launched in 2012. Midata is the result of collaboration between the Department for Business, Innovation and Skills, the Information Commissioner’s Office (the UK’s data protection [...]]]></description>
			<content:encoded><![CDATA[<p>A new scheme in which consumers will be empowered to manage data held about them by large private sector organisations such as Google and British Gas is going to be launched in 2012. Midata is the result of collaboration between the Department for Business, Innovation and Skills, the Information Commissioner’s Office (the UK’s data protection regulator) and some of the largest consumer-facing organisations in the UK. The scheme is an innovation that turns the tables so that it will give consumers the opportunity to access and manage their data and take decisions such as the best deal for them based on it. At its core is protection of the data and adherence by the businesses to data protection laws. The data will be provided in a portable, electronic format in a safe and secure way. Although this is not being introduced in conjunction with the proposed new European Union data protection laws, there is a consistent theme of empowerment for consumers over their data running through both proposals.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/11/midata-consumer-data-empowerment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Justice Committee joins Information Commissioner in call for blaggers to face jail</title>
		<link>http://www.mablaw.com/2011/11/justice-committee-information-commissioner-blaggers-jail/</link>
		<comments>http://www.mablaw.com/2011/11/justice-committee-information-commissioner-blaggers-jail/#comments</comments>
		<pubDate>Thu, 10 Nov 2011 08:07:03 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[blag]]></category>
		<category><![CDATA[blagger]]></category>
		<category><![CDATA[blagging]]></category>
		<category><![CDATA[Criminal Justice and Immigration Act]]></category>
		<category><![CDATA[Criminal Justice and Immigration Act 2008]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[fine]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[illegal]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[jail]]></category>
		<category><![CDATA[Justice Committee]]></category>
		<category><![CDATA[misuse of data]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[unlawful]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=17030</guid>
		<description><![CDATA[The Justice Committee has called for data blaggers to be jailed. Under the Data Protection Act, it is unlawful for someone to knowingly or recklessly obtain or disclose personal data without the data controller’s consent. The Information Commissioner has long been concerned with blaggers – people who obtain personal data by deception. He recently said: [...]]]></description>
			<content:encoded><![CDATA[<p>The Justice Committee has called for data blaggers to be jailed. Under the Data Protection Act, it is unlawful for someone to knowingly or recklessly obtain or disclose personal data without the data controller’s consent. The Information Commissioner has long been concerned with blaggers – people who obtain personal data by deception. He recently said: “It beggars belief that the penalties for seriously abusing the system still do not include the possibility of a prison sentence, even in the most serious cases.” The Criminal Justice and Immigration Act allows the Secretary of State to introduce new laws that would allow jail sentences to be handed out to people who unlawfully obtain or use personal data, but that power has not yet been exercised. The Justice Committee is now following the Information Commissioner’s call for prison sentences to be introduced, especially as fines were often so low in cases where the offender’s ability to pay are taken into account. </p>
<p>The report can be found here: <a href="http://www.publications.parliament.uk/pa/cm201012/cmselect/cmjust/1473/147302.htm">http://www.publications.parliament.uk/pa/cm201012/cmselect/cmjust/1473/147302.htm</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/11/justice-committee-information-commissioner-blaggers-jail/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Personal data breaches in private sector rise by 60%</title>
		<link>http://www.mablaw.com/2011/11/personal-data-breaches-ico/</link>
		<comments>http://www.mablaw.com/2011/11/personal-data-breaches-ico/#comments</comments>
		<pubDate>Sun, 06 Nov 2011 20:39:42 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[misuse of data]]></category>
		<category><![CDATA[personal data]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=17028</guid>
		<description><![CDATA[The number of data security breaches in the private sector has risen by nearly 60% in one year, the Information Commissioner’s Office has announced following a survey of 800 organisations. Christopher Graham, the Information Commissioner, has said that businesses not keeping data safe could face fines of up to £500,000 as well as suffering reputation [...]]]></description>
			<content:encoded><![CDATA[<p>The number of data security breaches in the private sector has risen by nearly 60% in one year, the Information Commissioner’s Office has announced following a survey of 800 organisations. Christopher Graham, the Information Commissioner, has said that businesses not keeping data safe could face fines of up to £500,000 as well as suffering reputation damage. Meanwhile, in a separate survey of over 1,000 individuals, the ICO has found that nearly 60% lack confidence in the way their personal data is protected.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/11/personal-data-breaches-ico/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ECJ case confirms that Internet publishers responsible for breach of privacy in every country where the material is accessible – eDate Advertising v X, Oliver Martinez &amp; Robert Martinez v MGN Limited, ECJ</title>
		<link>http://www.mablaw.com/2011/11/ecj-internet-publisher-breach-privacy-country-accessible/</link>
		<comments>http://www.mablaw.com/2011/11/ecj-internet-publisher-breach-privacy-country-accessible/#comments</comments>
		<pubDate>Sat, 05 Nov 2011 23:39:04 +0000</pubDate>
		<dc:creator>Mark Weston</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[Websites]]></category>
		<category><![CDATA[breach of privacy]]></category>
		<category><![CDATA[claim]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[ECJ]]></category>
		<category><![CDATA[EU]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[European Commission]]></category>
		<category><![CDATA[European Court of Justice]]></category>
		<category><![CDATA[European Union]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Internet age]]></category>
		<category><![CDATA[national courts]]></category>
		<category><![CDATA[online content]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[private life]]></category>
		<category><![CDATA[publish]]></category>
		<category><![CDATA[publishers]]></category>
		<category><![CDATA[right to private life]]></category>
		<category><![CDATA[Sunday Mirror]]></category>
		<category><![CDATA[unlawful]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web site]]></category>
		<category><![CDATA[web sites]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[website content]]></category>
		<category><![CDATA[websites]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=17032</guid>
		<description><![CDATA[The European Court of Justice (ECJ) has ruled that individuals can sue publishers of content on the Internet which they believe has harmed their image. The ECJ considered two cases, one from France and the other from Germany, where publishers had been sued for alleged breaches of privacy. The Sunday Mirror was the alleged breaching [...]]]></description>
			<content:encoded><![CDATA[<p>The European Court of Justice (ECJ) has ruled that individuals can sue publishers of content on the Internet which they believe has harmed their image. The ECJ considered two cases, one from France and the other from Germany, where publishers had been sued for alleged breaches of privacy. <em>The Sunday Mirror</em> was the alleged breaching party in the French case.</p>
<p><a href="http://curia.europa.eu/jurisp/cgi-bin/form.pl?lang=EN&amp;Submit=rechercher&amp;numaff=C-509/09">The ECJ ruled</a> that those individuals that were the subject of stories published online not only had the choice of suing the publisher either in the country where the publisher is based or in the country where the individual had their “centre of interests”, but they also had the choice of bringing the claim in a country where the story or content was accessible (although only for the damage suffered in that country). In such an instance, the ECJ ruled that the relevant national courts could not apply a stricter law to the case than that applied by the courts in the country where the publisher was actually based.</p>
<p>In an age where content spreads so easily on the Internet, the waters have suddenly become more muddied for a publisher – it is now much easier than previously thought for a person who is the subject of a story to take action.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/11/ecj-internet-publisher-breach-privacy-country-accessible/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rise in requests for content removal from Google</title>
		<link>http://www.mablaw.com/2011/11/rise-in-requests-content-removal-google/</link>
		<comments>http://www.mablaw.com/2011/11/rise-in-requests-content-removal-google/#comments</comments>
		<pubDate>Wed, 02 Nov 2011 17:04:54 +0000</pubDate>
		<dc:creator>Mark Weston</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[Websites]]></category>
		<category><![CDATA[content]]></category>
		<category><![CDATA[content removal]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[defamation]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[illegal]]></category>
		<category><![CDATA[infringement]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[national security]]></category>
		<category><![CDATA[online content]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[removal of content]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[unauthorised]]></category>
		<category><![CDATA[unlawful]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web site]]></category>
		<category><![CDATA[web sites]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[website content]]></category>
		<category><![CDATA[websites]]></category>
		<category><![CDATA[YouTube]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=17016</guid>
		<description><![CDATA[As part of it bi-annual transparency report, Google has revealed that, for the period of January to June of this year, there has been a 71% increase in requests for content to be removed from its services, including Google’s search service and YouTube, when compared to the previous six months. Google stated that it has [...]]]></description>
			<content:encoded><![CDATA[<p>As part of it bi-annual transparency report, Google has revealed that, for the period of January to June of this year, there has been a 71% increase in requests for content to be removed from its services, including Google’s search service and YouTube, when compared to the previous six months. Google stated that it has complied with 82% of requests, either in full or in part.</p>
<p>The 65 requests received in that period covered more than 300 individual items, and came from the UK government and courts. Six of the requests related to videos that raised national security concerns on YouTube, and several other were court orders relating to defamation and privacy.</p>
<p>Details of the requests can be found <a href="http://www.google.com/transparencyreport/governmentrequests/GB/?p=2011-06&amp;t=CONTENT_REMOVAL_REQUEST"><span style="text-decoration: underline;">here</span></a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/11/rise-in-requests-content-removal-google/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Information Commissioner calls for compulsory data protection audits</title>
		<link>http://www.mablaw.com/2011/10/information-commissioner-compulsory-data-protection-audits/</link>
		<comments>http://www.mablaw.com/2011/10/information-commissioner-compulsory-data-protection-audits/#comments</comments>
		<pubDate>Sun, 30 Oct 2011 18:15:09 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[Pharmaceutical]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection audit]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[local government]]></category>
		<category><![CDATA[National Health Service]]></category>
		<category><![CDATA[NHS]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[pharma]]></category>
		<category><![CDATA[pharmaceutical]]></category>
		<category><![CDATA[pharmaceutical business]]></category>
		<category><![CDATA[pharmaceutical company]]></category>
		<category><![CDATA[pharmaceutical industry]]></category>
		<category><![CDATA[pharmaceutical market]]></category>
		<category><![CDATA[pharmaceutical products]]></category>
		<category><![CDATA[pharmaceutical sector]]></category>
		<category><![CDATA[private sector]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=16967</guid>
		<description><![CDATA[The Information Commissioner has reiterated his stance that compulsory data protection audits should take place for the private sector, local government and the NHS in order to improve how personal data is handled. At present, the Information Commissioner’s Office (ICO) must obtain consent from the data controller before an audit can take place unless the [...]]]></description>
			<content:encoded><![CDATA[<p>The Information Commissioner has reiterated his stance that compulsory data protection audits should take place for the private sector, local government and the NHS in order to improve how personal data is handled. At present, the Information Commissioner’s Office (ICO) must obtain consent from the data controller before an audit can take place unless the audit is for a central government department (in which case an audit can take place without the need for consent). Up to July 2011, only 19% of businesses contacted by the ICO had agreed to be audited.</p>
<p>Of particular concern in the pharmaceutical sector is that out of 47 undertakings that the ICO has agreed with organisations that have breached the Data Protection Act since April, 40% of those have been in the healthcare sector.</p>
<p>The ICO’s press release can be found <a href="http://www.ico.gov.uk/news/latest_news/2011/compulsory-audit-powers-needed-for-local-government-nhs-and-private-sector-13102011.aspx"><span style="text-decoration: underline;">here</span></a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/10/information-commissioner-compulsory-data-protection-audits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>EC publishes report on child safety on social-networking websites</title>
		<link>http://www.mablaw.com/2011/10/ec-report-child-safety-social-networking/</link>
		<comments>http://www.mablaw.com/2011/10/ec-report-child-safety-social-networking/#comments</comments>
		<pubDate>Wed, 19 Oct 2011 13:48:10 +0000</pubDate>
		<dc:creator>Mark Weston</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[Websites]]></category>
		<category><![CDATA[child protection]]></category>
		<category><![CDATA[child safety]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[EC]]></category>
		<category><![CDATA[EU]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[European Commission]]></category>
		<category><![CDATA[European Union]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[social network]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[social networking site]]></category>
		<category><![CDATA[social networking website]]></category>
		<category><![CDATA[unauthorised]]></category>
		<category><![CDATA[unlawful]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web site]]></category>
		<category><![CDATA[web sites]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[website content]]></category>
		<category><![CDATA[websites]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=16889</guid>
		<description><![CDATA[The European Commission (EC) has published a report on child safety on social-networking websites. It is the second report since an agreement was reached with social networking website providers in 2009 called “Safer Social Networking Principles for the EU”, and is a progress report on the achievements made to date. The first report considered how [...]]]></description>
			<content:encoded><![CDATA[<p><span style="text-decoration: underline;"><a href="http://europa.eu/rapid/pressReleasesAction.do?reference=IP/11/1124&amp;format=HTML&amp;aged=0&amp;language=EN&amp;guiLanguage=en">The European Commission (EC) has published a report on child safety on social-networking websites</a></span>. It is the second report since an agreement was reached with social networking website providers in 2009 called “Safer Social Networking Principles for the EU”, and is a progress report on the achievements made to date.</p>
<p><span style="text-decoration: underline;"><a href="http://europa.eu/rapid/pressReleasesAction.do?reference=IP/11/762&amp;format=HTML&amp;aged=0&amp;language=EN&amp;guiLanguage=en">The first report </a></span>considered how 14 social networking websites had implemented the 2009 agreement. This second report considered nine social networking websites, which included a range of blogging, gaming, file-sharing and personal social-networking functionality, and found that only two of the websites had default settings which made a child’s information visible only to approved contacts; the other websites shared a large amount of that information beyond a child’s approved contacts.</p>
<p>The EC has said that it will take into account the two reports when it undertakes a comprehensive initiative to empower and protect children when using new technologies, which is set to take place later this year.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/10/ec-report-child-safety-social-networking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>School and Union sign undertakings with Information Commissioner after unencrypted laptops with sensitive personal data on them are stolen</title>
		<link>http://www.mablaw.com/2011/10/ico-ascl-holly-park-school-encryption/</link>
		<comments>http://www.mablaw.com/2011/10/ico-ascl-holly-park-school-encryption/#comments</comments>
		<pubDate>Mon, 17 Oct 2011 21:10:30 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Schools]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[data subject]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[encrypt]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[information]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[misuse of data]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[sensitive personal data]]></category>
		<category><![CDATA[undertaking]]></category>
		<category><![CDATA[undertakings]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=16926</guid>
		<description><![CDATA[The Association of School and College Leaders and Holly Park School have signed separate undertakings with the Information Commissioner’s Office after laptops containing sensitive personal data had been stolen. The sensitive personal data in each case included details of health, including trade union members and school pupils respectively. The laptops were unencrypted. The School did [...]]]></description>
			<content:encoded><![CDATA[<p>The Association of School and College Leaders and Holly Park School have signed separate undertakings with the Information Commissioner’s Office after laptops containing sensitive personal data had been stolen. The sensitive personal data in each case included details of health, including trade union members and school pupils respectively. The laptops were unencrypted. The School did not even have a data protection policy in place. The ICO – the UK’s data protection regulator – has once again emphasised the importance of taking appropriate security measures to protect data, particularly with encrypting portable devices. The organisations at the centre of the breaches have agreed to take better steps to encrypt, as well as raising awareness and training amongst its users. The undertakings can be found here: <a href="http://www.ico.gov.uk/news/latest_news/2011/laptop-thefts-highlight-the-need-for-encryption-05102011.aspx">http://www.ico.gov.uk/news/latest_news/2011/laptop-thefts-highlight-the-need-for-encryption-05102011.aspx</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/10/ico-ascl-holly-park-school-encryption/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NHS Trust accidentally leaves 10,000 patients’ records in waste disposal room for shredding</title>
		<link>http://www.mablaw.com/2011/10/nhs-trust-patients-records-data-protection/</link>
		<comments>http://www.mablaw.com/2011/10/nhs-trust-patients-records-data-protection/#comments</comments>
		<pubDate>Tue, 11 Oct 2011 20:21:59 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Pharmaceutical]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[hospital]]></category>
		<category><![CDATA[hospitals]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[misuse of data]]></category>
		<category><![CDATA[NHS]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[pharma]]></category>
		<category><![CDATA[pharmaceutical]]></category>
		<category><![CDATA[pharmaceutical industry]]></category>
		<category><![CDATA[pharmaceutical market]]></category>
		<category><![CDATA[pharmaceutical sector]]></category>
		<category><![CDATA[sensitive personal data]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=16855</guid>
		<description><![CDATA[Over 10,000 records of hospital patients and staff were presumed to have been accidentally destroyed after Dartford and Gravesham NHS Trust had temporarily stored them in a waste disposal room and then forgot about them. By the time they looked for the records where they had last been left a few months later, the records [...]]]></description>
			<content:encoded><![CDATA[<p>Over 10,000 records of hospital patients and staff were presumed to have been accidentally destroyed after Dartford and Gravesham NHS Trust had temporarily stored them in a waste disposal room and then forgot about them. By the time they looked for the records where they had last been left a few months later, the records were no longer there. They were taken there temporarily after their normal dedicated storage areas had become temporarily unavailable. The data involved sensitive personal data, as it reflected people’s health records. In all likelihood, the data would have been destroyed securely, but that did not stop the Information Commissioner’s Office – the UK’s data protection regulator – from requiring the Trust to sign up to written undertakings that promised to improve its care over personal data and the training of staff.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/10/nhs-trust-patients-records-data-protection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Police did not need to disclose information on sexual offender stats at schools because it was only in the public interest and not substantial public interest – Smith v Information Commissioner’s Office, Information Tribunal</title>
		<link>http://www.mablaw.com/2011/10/police-smith-substantial-public-interest-personal-data/</link>
		<comments>http://www.mablaw.com/2011/10/police-smith-substantial-public-interest-personal-data/#comments</comments>
		<pubDate>Fri, 07 Oct 2011 13:32:44 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[anonymised data]]></category>
		<category><![CDATA[anonymised personal data]]></category>
		<category><![CDATA[confidential information]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[data protection principles]]></category>
		<category><![CDATA[data protection regime]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data subject]]></category>
		<category><![CDATA[databases]]></category>
		<category><![CDATA[disclosure]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[FOIA]]></category>
		<category><![CDATA[freedom of information]]></category>
		<category><![CDATA[freedom of information act]]></category>
		<category><![CDATA[Freedom of Information Act 2000]]></category>
		<category><![CDATA[freedom of information request]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[information]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[Information Commissioner’s Office]]></category>
		<category><![CDATA[Information Tribunal]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[police]]></category>
		<category><![CDATA[public]]></category>
		<category><![CDATA[public authority]]></category>
		<category><![CDATA[public bodies]]></category>
		<category><![CDATA[public body]]></category>
		<category><![CDATA[public interest]]></category>
		<category><![CDATA[public interest disclosure]]></category>
		<category><![CDATA[public sector]]></category>
		<category><![CDATA[publication]]></category>
		<category><![CDATA[request for information]]></category>
		<category><![CDATA[sensitive personal data]]></category>
		<category><![CDATA[substantial public interest]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=16812</guid>
		<description><![CDATA[Ms Smith made a request to Devon and Cornwall Constabulary to disclose the number of teaching staff in schools and colleges in Torbay, Teignbridge and South Hams who had been investigated, cautioned and charged with a sexual offence. Ms Smith had made the request under the Freedom of Information Act, which requires public authorities to [...]]]></description>
			<content:encoded><![CDATA[<p>Ms Smith made a request to Devon and Cornwall Constabulary to disclose the number of teaching staff in schools and colleges in Torbay, Teignbridge and South Hams who had been investigated, cautioned and charged with a sexual offence. Ms Smith had made the request under the Freedom of Information Act, which requires public authorities to provide data in response to a request for information, unless they are exempt from making the disclosure. One such exemption is where there is a duty not to disclose personal data under the Data Protection Act. The police said that the data requested, if disclosed, together with other information in the public domain could have enabled the people who had been charged with the offence to be identified. The police therefore said that the information was exempt from disclosure.</p>
<p>The Information Commissioner’s Office and, now on appeal, the Information Tribunal agreed with the police. The Tribunal also discounted Ms Smith’s claims that sensitive personal data can be disclosed if it is in the substantial public interest to do so. The Tribunal ruled that although there was public interest in establishing data on sexual offences, the higher threshold of substantial public interest had not been surmounted. There was public interest in establishing sexual offences by teachers and others in positions of trust. Substantial public interest could have been for something like prevalence of sexual offender activity or police incompetence in dealing with the issue. The Tribunal decided that although the decision was finely balanced, the police were right not to reveal the information that could have led to identifying individuals in this case.</p>
<p>The ruling can be found here: <a href="http://www.bailii.org/uk/cases/UKFTT/GRC/2011/2011_0006.html">http://www.bailii.org/uk/cases/UKFTT/GRC/2011/2011_0006.html</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/10/police-smith-substantial-public-interest-personal-data/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Information Commissioner calls for new custodial sentences to tackle blagging</title>
		<link>http://www.mablaw.com/2011/10/information-commissioner-custodial-sentences-blagging/</link>
		<comments>http://www.mablaw.com/2011/10/information-commissioner-custodial-sentences-blagging/#comments</comments>
		<pubDate>Sun, 02 Oct 2011 16:26:24 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[blagging]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[data subject]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[databases]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[fine]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[Information Commissioner’s Office]]></category>
		<category><![CDATA[misuse of data]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[prison]]></category>
		<category><![CDATA[sensitive personal data]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=16730</guid>
		<description><![CDATA[The Information Commissioner’s Office has called for the introduction of custodial sentences for blaggers – which is where people use deceptive means to obtain personal data from data controllers. Christopher Graham – the UK’s data protection regulator &#8211; says that blagging is routinely used in financial services, debt collection and claims management, but he argues [...]]]></description>
			<content:encoded><![CDATA[<p>The Information Commissioner’s Office has called for the introduction of custodial sentences for blaggers – which is where people use deceptive means to obtain personal data from data controllers. Christopher Graham – the UK’s data protection regulator &#8211; says that blagging is routinely used in financial services, debt collection and claims management, but he argues that the current penalties are not sufficient deterrent. In theory, blaggers could face unlimited fines in the Crown Court, but in reality the average fine is about £100. He would like to see the Justice Secretary introduce custodial sentences as he is permitted to do under the Criminal Justice and Immigration Act.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/10/information-commissioner-custodial-sentences-blagging/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lib Dems concern about cloud computing</title>
		<link>http://www.mablaw.com/2011/09/lib-dems-concern-about-cloud-computing/</link>
		<comments>http://www.mablaw.com/2011/09/lib-dems-concern-about-cloud-computing/#comments</comments>
		<pubDate>Wed, 28 Sep 2011 16:19:57 +0000</pubDate>
		<dc:creator>Mark Weston</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[Websites]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data hosting]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[information technology]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[LibDems]]></category>
		<category><![CDATA[Liberal Democrats]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[public data]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web site]]></category>
		<category><![CDATA[web sites]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[websites]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=16744</guid>
		<description><![CDATA[The Liberal Democrats have said that the use of cloud computing in public services needs to be investigated urgently to protect the public against the risks of storing data outside of the UK. In a paper entitled “Making IT Work: Policies for Information Technology”, the party argued that the Government should investigate the potential for [...]]]></description>
			<content:encoded><![CDATA[<p>The Liberal Democrats have said that the use of cloud computing in public services needs to be investigated urgently to protect the public against the risks of storing data outside of the UK. In a paper entitled “Making IT Work: Policies for Information Technology”, the party argued that the Government should investigate the potential for abuse of the rights of data owners if public data is hosted outside the UK.</p>
<p>The paper states that the principles of cloud computing, where file and programs are stored effectively on the Internet, must comply with the strictest principles of data protection and privacy. It goes on to argue that a watchdog body should be formed to regulate cloud computing services, with an emphasis on transparency of cloud computing operations.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/09/lib-dems-concern-about-cloud-computing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sony requires PlayStation Network users to sign up to terms and conditions that waive their collective rights of redress</title>
		<link>http://www.mablaw.com/2011/09/sony-playstation-network-terms-conditions-waiver/</link>
		<comments>http://www.mablaw.com/2011/09/sony-playstation-network-terms-conditions-waiver/#comments</comments>
		<pubDate>Tue, 27 Sep 2011 15:24:40 +0000</pubDate>
		<dc:creator>Mark Weston</dc:creator>
				<category><![CDATA[Commercial Contracts]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[Websites]]></category>
		<category><![CDATA[B2C]]></category>
		<category><![CDATA[business-to-consumer]]></category>
		<category><![CDATA[class action]]></category>
		<category><![CDATA[consumer]]></category>
		<category><![CDATA[consumer contract]]></category>
		<category><![CDATA[consumer contracts]]></category>
		<category><![CDATA[consumer law]]></category>
		<category><![CDATA[consumer laws]]></category>
		<category><![CDATA[consumers]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[data subject]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[database right infringement]]></category>
		<category><![CDATA[databases]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[fair]]></category>
		<category><![CDATA[fairness]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Internet use]]></category>
		<category><![CDATA[Internet user]]></category>
		<category><![CDATA[law suit]]></category>
		<category><![CDATA[lawsuit]]></category>
		<category><![CDATA[legal action]]></category>
		<category><![CDATA[liability]]></category>
		<category><![CDATA[limited liability]]></category>
		<category><![CDATA[misuse of data]]></category>
		<category><![CDATA[On-line]]></category>
		<category><![CDATA[online content]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[reasonable]]></category>
		<category><![CDATA[sensitive personal data]]></category>
		<category><![CDATA[site terms]]></category>
		<category><![CDATA[standard terms]]></category>
		<category><![CDATA[standard terms and conditions]]></category>
		<category><![CDATA[standard trading terms]]></category>
		<category><![CDATA[term]]></category>
		<category><![CDATA[terms]]></category>
		<category><![CDATA[Terms & conditions]]></category>
		<category><![CDATA[terms of use]]></category>
		<category><![CDATA[Ts & Cs]]></category>
		<category><![CDATA[Ts and Cs]]></category>
		<category><![CDATA[UCTA]]></category>
		<category><![CDATA[unenforceable]]></category>
		<category><![CDATA[unfair]]></category>
		<category><![CDATA[unfair contract terms]]></category>
		<category><![CDATA[unfair contract terms act]]></category>
		<category><![CDATA[Unfair Contract Terms Act 1977]]></category>
		<category><![CDATA[unfair terms]]></category>
		<category><![CDATA[Unfair Terms Directive]]></category>
		<category><![CDATA[Unfair Terms in Consumer Contracts Directive]]></category>
		<category><![CDATA[Unfair Terms in Consumer Contracts Regulation 1999]]></category>
		<category><![CDATA[Unfair Terms in Consumer Contracts Regulations]]></category>
		<category><![CDATA[UTCCR]]></category>
		<category><![CDATA[void]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web content]]></category>
		<category><![CDATA[web database]]></category>
		<category><![CDATA[web site]]></category>
		<category><![CDATA[web site content]]></category>
		<category><![CDATA[web sites]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[website content]]></category>
		<category><![CDATA[websites]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=16723</guid>
		<description><![CDATA[Sony has required its PlayStation Network users to sign up to new terms and conditions that would amount to their waiver of the right to take part in collective legal action, or so-called “class action lawsuits”. Class action lawsuits are more common in the US than the UK, but Sony is concerned over its exposure [...]]]></description>
			<content:encoded><![CDATA[<p>Sony has required its PlayStation Network users to sign up to new terms and conditions that would amount to their waiver of the right to take part in collective legal action, or so-called “class action lawsuits”. Class action lawsuits are more common in the US than the UK, but Sony is concerned over its exposure after collective legal actions have been issued over the theft of tens of millions of its customers’ personal data following a data hack of its customer database earlier in the year. The legal action could leave Sony with billions of pounds of liability if it loses. The exclusion of class action clause is a novel idea by Sony, but its attempt to stop UK consumers from having an effective legal right of remedy may breach UK consumer laws such as the Unfair Contract Terms Act and the Unfair Terms in Consumer Contracts Regulations.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/09/sony-playstation-network-terms-conditions-waiver/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hospital agrees to improve data protection procedures after medical student loses dozens of patients’ sensitive health records on unencrypted memory stick</title>
		<link>http://www.mablaw.com/2011/09/hospital-sensitive-personal-data-protection-memory-stick/</link>
		<comments>http://www.mablaw.com/2011/09/hospital-sensitive-personal-data-protection-memory-stick/#comments</comments>
		<pubDate>Fri, 16 Sep 2011 11:20:10 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Pharmaceutical]]></category>
		<category><![CDATA[Schools]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breach notification]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[data protection principles]]></category>
		<category><![CDATA[data protection regime]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[data subject]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[health]]></category>
		<category><![CDATA[healthcare]]></category>
		<category><![CDATA[hospital]]></category>
		<category><![CDATA[hospitals]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[Information Commissioner’s Office]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[pharma]]></category>
		<category><![CDATA[pharmaceutical]]></category>
		<category><![CDATA[pharmaceutical industry]]></category>
		<category><![CDATA[pharmaceutical market]]></category>
		<category><![CDATA[pharmaceutical sector]]></category>
		<category><![CDATA[school]]></category>
		<category><![CDATA[sensitive personal data]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=16664</guid>
		<description><![CDATA[The University Hospital of South Manchester NHS Foundation Trust has given formal undertakings to the Information Commissioner’s Office – the UK’s data protection regulator – to improve its data protection practices after a medical student lost an unencrypted memory stick containing 87 patients’ health records.  Data controllers are obliged under data protection law to take [...]]]></description>
			<content:encoded><![CDATA[<p>The University Hospital of South Manchester NHS Foundation Trust has given formal undertakings to the Information Commissioner’s Office – the UK’s data protection regulator – to improve its data protection practices after a medical student lost an unencrypted memory stick containing 87 patients’ health records.  Data controllers are obliged under data protection law to take appropriate steps to keep personal data secure, but even greater steps are needed if it involves sensitive personal data such as health records. The University Hospital has agreed to ensure that all students now have appropriate data security training and there will also be regular monitoring to ensure compliance with the data policies. The ICO sent out a warning to people who are involved with use of health data.  It said: “Medics handle some of the most sensitive personal information possible and it is vital that they understand the need to keep it secure at all times.”  It added that it would continue to work with healthcare bodies and education providers to ensure that data protection training is a mandatory part of people’s education.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/09/hospital-sensitive-personal-data-protection-memory-stick/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Information Commissioner’s Office advocates students to examine the examiner’s comments</title>
		<link>http://www.mablaw.com/2011/08/information-commissioner%e2%80%99s-office-students-subject-access-request/</link>
		<comments>http://www.mablaw.com/2011/08/information-commissioner%e2%80%99s-office-students-subject-access-request/#comments</comments>
		<pubDate>Sat, 27 Aug 2011 15:27:37 +0000</pubDate>
		<dc:creator>Simon Weinberg</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Schools]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data subject]]></category>
		<category><![CDATA[data subject access]]></category>
		<category><![CDATA[data subject access request]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[Information Commissioner’s Office]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[school]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=15399</guid>
		<description><![CDATA[Exam results were generally very good again this year. But the Information Commissioner’s Office has offered hope for people whose results were not quite as desired. The ICO has issued a statement encouraging students or their parents to obtain information about what the examiner thought about their work. Under the Data Protection Act, data controllers [...]]]></description>
			<content:encoded><![CDATA[<p>Exam results were generally very good again this year. But the Information Commissioner’s Office has offered hope for people whose results were not quite as desired. The ICO has issued a statement encouraging students or their parents to obtain information about what the examiner thought about their work. Under the Data Protection Act, data controllers must provide people’s personal data if they request it. Accessing the information may help students and their parents decide on whether to go through a re-sit or go through a different path. The ICO’s statement can be found here: <a href="http://www.ico.gov.uk/news/latest_news/2011/students_can_request_examiners_comments_under_data_protection_laws_18082011.aspx">http://www.ico.gov.uk/news/latest_news/2011/students_can_request_examiners_comments_under_data_protection_laws_18082011.aspx</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/08/information-commissioner%e2%80%99s-office-students-subject-access-request/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ICO says Google doing reasonably in private</title>
		<link>http://www.mablaw.com/2011/08/ico-google-privacy/</link>
		<comments>http://www.mablaw.com/2011/08/ico-google-privacy/#comments</comments>
		<pubDate>Fri, 26 Aug 2011 15:27:11 +0000</pubDate>
		<dc:creator>Mark Weston</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[Websites]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[eprivacy]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Google Street View]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[privacy audit]]></category>
		<category><![CDATA[privacy policies]]></category>
		<category><![CDATA[privacy policy]]></category>
		<category><![CDATA[privacy procedures]]></category>
		<category><![CDATA[Street View]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web site]]></category>
		<category><![CDATA[web sites]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[websites]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=15635</guid>
		<description><![CDATA[In November 2010 Google signed an undertaking with the Information Commissioner’s Office (ICO) for the ICO to conduct audits of its privacy procedures after it was reported that Google’s ‘Street View’ cars had collected Wi-Fi data from members of the public whilst collecting the information necessary to map the ‘Street View’ product. The ICO has [...]]]></description>
			<content:encoded><![CDATA[<p><strong><span style="text-decoration: underline;"><a href="http://www.mablaw.com/2010/11/ico-google-significant-breach-dpa/"><span style="text-decoration: underline;">In November 2010 Google signed an undertaking with the Information Commissioner’s Office (ICO) for the ICO to conduct audits of its privacy procedures after it was reported that Google’s ‘Street View’ cars had collected Wi-Fi data from members of the public whilst collecting the information necessary to map the ‘Street View’ product.</span></a></span></strong><strong></strong></p>
<p>The ICO has now completed the audit and has said that Google has taken ‘reasonable steps’ to improve its privacy policies and that it has taken action in all the areas in which it had agreed to do so. The ICO has now asked Google to continue its improvements and to better inform its users of its privacy policies.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/08/ico-google-privacy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Housing associations agree to ensure data about tenants protected under lock and key after data breach involving 20,000 tenants</title>
		<link>http://www.mablaw.com/2011/08/housing-associations-tenants-data-breach/</link>
		<comments>http://www.mablaw.com/2011/08/housing-associations-tenants-data-breach/#comments</comments>
		<pubDate>Fri, 26 Aug 2011 15:24:20 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[data subject]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[Information Commissioner’s Office]]></category>
		<category><![CDATA[misuse of data]]></category>
		<category><![CDATA[personal data]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=15439</guid>
		<description><![CDATA[Lewisham Homes and Wandle Housing Association have signed undertakings with the Information Commissioner’s Office promising to take better care of personal data after a contractor who had worked for both housing associations had left an unencrypted memory stick containing data concerning 20,000 of their tenants in a pub. The ICO criticised the housing associations for [...]]]></description>
			<content:encoded><![CDATA[<p>Lewisham Homes and Wandle Housing Association have signed undertakings with the Information Commissioner’s Office promising to take better care of personal data after a contractor who had worked for both housing associations had left an unencrypted memory stick containing data concerning 20,000 of their tenants in a pub. The ICO criticised the housing associations for a failure to have proper processes and conduct training. From now on, they will have to ensure that all personal portable devices are encrypted when they contain personal data and that employees and external workers who provide them with services are made aware of their data protection processes. The ICO’s statement on this case can be found here: <a href="http://www.ico.gov.uk/news/latest_news/2011/thousands_of_tenants_details_found_on_memory_stick_left_in_pub_04082011.aspx">http://www.ico.gov.uk/news/latest_news/2011/thousands_of_tenants_details_found_on_memory_stick_left_in_pub_04082011.aspx</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/08/housing-associations-tenants-data-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ICO tells school to learn lesson of avoiding passwords for duplicate purposes after 20,000 people’s personal data compromised by hack attack</title>
		<link>http://www.mablaw.com/2011/08/ico-school-passwords-duplicate/</link>
		<comments>http://www.mablaw.com/2011/08/ico-school-passwords-duplicate/#comments</comments>
		<pubDate>Thu, 25 Aug 2011 15:26:34 +0000</pubDate>
		<dc:creator>Mark Weston</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Schools]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[data subject]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[databases]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[Information Commissioner’s Office]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[school]]></category>
		<category><![CDATA[sensitive personal data]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=15412</guid>
		<description><![CDATA[Personal data belonging to 20,000 pupils, parents and teachers have been hacked after hackers (including one school pupil) on a school website managed to access the rest of the school’s systems. This was achieved by gaining entry after discovering that one user had used the same password for both systems. The data included names, addresses, [...]]]></description>
			<content:encoded><![CDATA[<p>Personal data belonging to 20,000 pupils, parents and teachers have been hacked after hackers (including one school pupil) on a school website managed to access the rest of the school’s systems. This was achieved by gaining entry after discovering that one user had used the same password for both systems. The data included names, addresses, photographs and medical history (and therefore included sensitive personal data). Although the school had advised users to avoid duplicate passwords, no checks were put in place to check that this recommendation was followed. Bay House School in Hampshire has now signed undertakings promising to the Information Commissioner’s Office that it will separate and encrypt sensitive personal data from basic identification and contact details, and to use different passwords for accessing different parts of the system. The ICO said that although it was hard to remember more than one password, it was vitally important to use different passwords to access different systems so that the databases can be kept secure. This is particularly important when young people are involved. The ICO’s statement can be found here: <a href="http://www.ico.gov.uk/news/latest_news/2011/hampshire_school_breached_data_protection_rules_08082011.aspx">http://www.ico.gov.uk/news/latest_news/2011/hampshire_school_breached_data_protection_rules_08082011.aspx</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/08/ico-school-passwords-duplicate/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Article 29 Working Party gives concerning definition of consent</title>
		<link>http://www.mablaw.com/2011/08/article-29-working-party-opinion-consent/</link>
		<comments>http://www.mablaw.com/2011/08/article-29-working-party-opinion-consent/#comments</comments>
		<pubDate>Wed, 03 Aug 2011 17:50:54 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[Websites]]></category>
		<category><![CDATA[Article 29 Working Party]]></category>
		<category><![CDATA[consent]]></category>
		<category><![CDATA[cookie]]></category>
		<category><![CDATA[cookie law]]></category>
		<category><![CDATA[cookies]]></category>
		<category><![CDATA[cookies consent]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data subject]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[EU]]></category>
		<category><![CDATA[EU law]]></category>
		<category><![CDATA[Europea]]></category>
		<category><![CDATA[European Union]]></category>
		<category><![CDATA[European Union Directive]]></category>
		<category><![CDATA[European Union law]]></category>
		<category><![CDATA[explicit consent]]></category>
		<category><![CDATA[express]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[Information Commissioner’s Office]]></category>
		<category><![CDATA[informed consent]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Internet business]]></category>
		<category><![CDATA[Internet businesses]]></category>
		<category><![CDATA[Internet use]]></category>
		<category><![CDATA[Internet user]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[tick box]]></category>
		<category><![CDATA[unambiguous]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web content]]></category>
		<category><![CDATA[web site]]></category>
		<category><![CDATA[web site content]]></category>
		<category><![CDATA[web sites]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[website content]]></category>
		<category><![CDATA[website operator]]></category>
		<category><![CDATA[website operators]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=13249</guid>
		<description><![CDATA[The Article 29 Working Party – a European Union data protection advisory body consisting of national data protection regulators – has issued concerning an opinion as to its interpretation on the definition of the key data protection concept of “consent” under European Union data protection laws. Contradicting pronouncements in the UK by the Information Commissioner’s [...]]]></description>
			<content:encoded><![CDATA[<p>The Article 29 Working Party – a European Union data protection advisory body consisting of national data protection regulators – has issued concerning an opinion as to its interpretation on the definition of the key data protection concept of “consent” under European Union data protection laws. Contradicting pronouncements in the UK by the Information Commissioner’s Office and Government, it says that consent should be made in advance of any processing to be valid – otherwise, any prior processing would be unlawful unless it satisfies other permitted data protection grounds. The body added that passive behaviour such as failing to un-tick default boxes on websites of failure to respond to an email or letter would not amount to consent, as active behaviour would be needed. The advice can apply just as much to the Data Protection Act as the new rules on obtaining consent to cookies.</p>
<p>The Article 29 Working Party’s opinions are not legally binding and they only represent the body’s own interpretation of data protection laws. However, they can be very persuasive and should not be ignored. It will be interesting to see what changes are made by the UK’s regulator, the Information Commissioner’s Office, to its stance on consent following this opinion. This can potentially affect a lot of businesses, particularly Internet ones.</p>
<p>The Article 29 Working Party opinion can be found here: <a href="http://ec.europa.eu/justice/policies/privacy/docs/wpdocs/2011/wp187_en.pdf">http://ec.europa.eu/justice/policies/privacy/docs/wpdocs/2011/wp187_en.pdf</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/08/article-29-working-party-opinion-consent/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nearly 1,000 police officers disciplined for unlawful use of personal data in last three years</title>
		<link>http://www.mablaw.com/2011/08/police-unlawful-personal-data-big-brother-watch/</link>
		<comments>http://www.mablaw.com/2011/08/police-unlawful-personal-data-big-brother-watch/#comments</comments>
		<pubDate>Mon, 01 Aug 2011 17:48:38 +0000</pubDate>
		<dc:creator>Simon Weinberg</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[data subject]]></category>
		<category><![CDATA[databases]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[FOIA]]></category>
		<category><![CDATA[freedom of information]]></category>
		<category><![CDATA[Freedom of Information Act 2000]]></category>
		<category><![CDATA[freedom of information request]]></category>
		<category><![CDATA[illegal]]></category>
		<category><![CDATA[misuse of data]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[police]]></category>
		<category><![CDATA[public sector]]></category>
		<category><![CDATA[sensitive personal data]]></category>
		<category><![CDATA[unauthorised]]></category>
		<category><![CDATA[unlawful]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=13243</guid>
		<description><![CDATA[Staggering figures have emerged that show that hundreds of police officers have been snooping on people’s personal information without permission. Nearly 1,000 police officers have been disciplined for unlawful snooping contrary to data protection laws over a three year period, following a requests for information with 36 police forces under the Freedom of Information Act [...]]]></description>
			<content:encoded><![CDATA[<p>Staggering figures have emerged that show that hundreds of police officers have been snooping on people’s personal information without permission. Nearly 1,000 police officers have been disciplined for unlawful snooping contrary to data protection laws over a three year period, following a requests for information with 36 police forces under the Freedom of Information Act by Big Brother Watch. The Act enables people to request information from public data bodies for free. Nearly 100 staff had been forced to leave the police because of their mis-doings. For example, officers have been looking up information about their partners, neighbours and friends. Much of the information is sensitive personal data as it relates to criminal convictions. According to Big Brother Watch, some of the information had even been passed to criminal gangs and drug dealers. 243 officers were prosecuted for illegal access of data under the Data Protection Act.</p>
<p>Big Brother Watch’s statement can be found here: <a href="http://www.bigbrotherwatch.org.uk/Police_databases.pdf">http://www.bigbrotherwatch.org.uk/Police_databases.pdf</a>.</p>
<p>These figures are astonishing. Everyone would reasonably expect there to be the odd bad apple or two. But the scale of wrongdoing is incredible. The police need to carry out a root and branch review to ensure that their staff more effectively do what they should be doing – protecting the public. Anyone arguing that this demonstrates that we live in a police state, however, need to remember this &#8211; we only found out about these figures because of the Freedom of Information Act and the investigative work carried out by Big Brother Watch.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/08/police-unlawful-personal-data-big-brother-watch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ICO urges health sector culture shift on data protection</title>
		<link>http://www.mablaw.com/2011/07/ico-health-sector-data-protection/</link>
		<comments>http://www.mablaw.com/2011/07/ico-health-sector-data-protection/#comments</comments>
		<pubDate>Fri, 29 Jul 2011 10:25:52 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Pharmaceutical]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[data subject]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[Information Commissioner’s Office]]></category>
		<category><![CDATA[misuse of data]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[pharma]]></category>
		<category><![CDATA[pharmaceutical]]></category>
		<category><![CDATA[sensitive personal data]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=12956</guid>
		<description><![CDATA[The Information Commissioner’s Office – the regulator in charge of enforcing UK data protection laws. – has urged health sector organisations to better protect personal data. It claims that there are systemic problems with how data protection policies are followed, or not as the case may be. The ICO says that health workers are routinely [...]]]></description>
			<content:encoded><![CDATA[<p>The Information Commissioner’s Office – the regulator in charge of enforcing UK data protection laws. – has urged health sector organisations to better protect personal data. It claims that there are systemic problems with how data protection policies are followed, or not as the case may be. The ICO says that health workers are routinely keeping sensitive personal data about patients on unencrypted memory sticks or they are faxing it to the wrong number. He has urged the sector to undergo a cultural shift in how they treat data.</p>
<p>The ICO highlighted one case where a member of staff left 29 patient records in a public place after taking them from the NHS premises. In another case, one NHS Trust sent details about a vulnerable adult to an engineering company. Five health organisations have signed undertakings, promising to improve their standards, but the ICO wants the rest of the health industry to take note.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/07/ico-health-sector-data-protection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ICO advocates more organisations to agree to consensual data protection audits</title>
		<link>http://www.mablaw.com/2011/07/ico-consensual-data-protection-audits/</link>
		<comments>http://www.mablaw.com/2011/07/ico-consensual-data-protection-audits/#comments</comments>
		<pubDate>Tue, 26 Jul 2011 18:24:02 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[data protection regime]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[Information Commissioner’s Office]]></category>
		<category><![CDATA[personal data]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=12942</guid>
		<description><![CDATA[The Information Commissioner’s Office – the regulator in charge of enforcing UK data protection laws. – has called on private sector organisations to agree to consensual data protection audits. The ICO said that the purpose of the audits was not to name and shame but to work with data controllers to ensure that personal data [...]]]></description>
			<content:encoded><![CDATA[<p>The Information Commissioner’s Office – the regulator in charge of enforcing UK data protection laws. – has called on private sector organisations to agree to consensual data protection audits. The ICO said that the purpose of the audits was not to name and shame but to work with data controllers to ensure that personal data is being properly protected. More than seven out of 10 public sector organisations agree to work with the ICO, whereas fewer than two in 10 private sector organisations do so. The ICO said that after its audits, 92% of its recommendations were acted upon. These are the findings in the ICO’s latest annual report, which can be found here: <a href="http://www.ico.gov.uk/about_us/performance/~/media/documents/library/Corporate/Research_and_reports/annual_report_2011.ashx">http://www.ico.gov.uk/about_us/performance/~/media/documents/library/Corporate/Research_and_reports/annual_report_2011.ashx</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/07/ico-consensual-data-protection-audits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>European Commission consults on harmonised data breach notification rules</title>
		<link>http://www.mablaw.com/2011/07/european-commission-data-breachnotification-rules/</link>
		<comments>http://www.mablaw.com/2011/07/european-commission-data-breachnotification-rules/#comments</comments>
		<pubDate>Thu, 21 Jul 2011 21:01:35 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[communications]]></category>
		<category><![CDATA[communications service providers]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breach notification]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data subject]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[Directive]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[EU]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[European Commission]]></category>
		<category><![CDATA[European Union]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[misuse of data]]></category>
		<category><![CDATA[notification]]></category>
		<category><![CDATA[On-line]]></category>
		<category><![CDATA[personal data]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=12616</guid>
		<description><![CDATA[The revision to the E-Privacy Directive – which was recently implemented in the UK with the Privacy and Electronic Communications (EC Directive) Amendment Regulations 2011 – has introduced European Union rules for public communications services providers to notify regulators, subscribers and individuals if there has been a data breach. However, there has been a lack [...]]]></description>
			<content:encoded><![CDATA[<p>The revision to the E-Privacy Directive – which was recently implemented in the UK with the Privacy and Electronic Communications (EC Directive) Amendment Regulations 2011 – has introduced European Union rules for public communications services providers to notify regulators, subscribers and individuals if there has been a data breach. However, there has been a lack of certainty as to the circumstances in which people would be notified and how that would take place. The UK’s privacy regulator – the Information Commissioner’s Office – has issued guidance on the format and procedure of breach notification to it here: <a href="http://www.ico.gov.uk/~/media/documents/library/Data_Protection/Practical_application/BREACH_REPORTING.ashx">http://www.ico.gov.uk/~/media/documents/library/Data_Protection/Practical_application/BREACH_REPORTING.ashx</a>.</p>
<p>The European Commission is now consulting with communications service providers, consumer groups, Member States and others on practical guidelines that would harmonise the rules across the EU. It has asked the following questions:</p>
<ul>
<li>How would organisations comply with the new notification obligation?</li>
<li>What types of breaches should trigger individuals being notified?</li>
<li>What means of notification should take place and what procedure should be followed?</li>
<li>What information should be in the notification to the regulator and the affected individuals?</li>
</ul>
<p>The consultation is open until 9 September and can be found here: <a href="http://europa.eu/rapid/pressReleasesAction.do?reference=IP/11/887&amp;format=HTML&amp;aged=0&amp;language=EN&amp;guiLanguage=en">http://europa.eu/rapid/pressReleasesAction.do?reference=IP/11/887&amp;format=HTML&amp;aged=0&amp;language=EN&amp;guiLanguage=en</a>..</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/07/european-commission-data-breachnotification-rules/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Freedom of information journal- Disclosing anonymised data</title>
		<link>http://www.mablaw.com/2011/07/freedom-of-information-journal-disclosing-anonymised-data/</link>
		<comments>http://www.mablaw.com/2011/07/freedom-of-information-journal-disclosing-anonymised-data/#comments</comments>
		<pubDate>Wed, 20 Jul 2011 14:07:28 +0000</pubDate>
		<dc:creator>Simon Weinberg</dc:creator>
				<category><![CDATA[IT]]></category>
		<category><![CDATA[Intellectual Property]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[Websites]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[information]]></category>
		<category><![CDATA[intellectual property rights]]></category>
		<category><![CDATA[web site]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=12159</guid>
		<description><![CDATA[Freedom of Information journal has published an article I’ve written on the disclosure of anonomous data. The article covers some key areas including the ruling on anonymised, notification of the right to refuse, and the effect of the judgment. This article was borne out of a blog I posted in June. Click here to view [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.pdpjournals.com/overview-freedom-of-information">Freedom of Information journal</a> has published an article I’ve written on the disclosure of anonomous data. The article covers some key areas including the ruling on anonymised, notification of the right to refuse, and the effect of the judgment. This article was borne out of a <a href="http://www.mablaw.com/2011/06/disclosing-anonymised-data-under-the-freedom-of-information-act-would-not-breach-data-protection/">blog</a> I posted in June.</p>
<p><a href="http://www.mablaw.com/wp-content/uploads/2011/07/Freedom-of-Information-Journal-Personal-data-exemption-1-anonymised-data-given-the-OK-by-Simon-Weinberg.pdf">Click here</a> to view the article in full.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/07/freedom-of-information-journal-disclosing-anonymised-data/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lancashire Police given caution for publishing sensitive data about alleged criminal offence on website for all to see</title>
		<link>http://www.mablaw.com/2011/07/lancashire-police-sensitive-data-website/</link>
		<comments>http://www.mablaw.com/2011/07/lancashire-police-sensitive-data-website/#comments</comments>
		<pubDate>Sat, 16 Jul 2011 20:55:58 +0000</pubDate>
		<dc:creator>Mark Weston</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[data subject]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[Information Commissioner’s Office]]></category>
		<category><![CDATA[misuse of data]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[sensitive personal data]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web content]]></category>
		<category><![CDATA[web postings]]></category>
		<category><![CDATA[web site]]></category>
		<category><![CDATA[web site content]]></category>
		<category><![CDATA[web sites]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[website content]]></category>
		<category><![CDATA[websites]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=12637</guid>
		<description><![CDATA[The Information Commissioner’s Office – the regulator in charge of enforcing data protection laws in the UK – has given Lancashire Police a stern talking to after the police had published sensitive personal data relating to the alleged commission of an offence on its website. The publication of a complaint that it had received surrounding [...]]]></description>
			<content:encoded><![CDATA[<p>The Information Commissioner’s Office – the regulator in charge of enforcing data protection laws in the UK – has given Lancashire Police a stern talking to after the police had published sensitive personal data relating to the alleged commission of an offence on its website. The publication of a complaint that it had received surrounding the offence breached the Data Protection Act. The ICO said that publishing the complaint was fine as long as the relevant information was redacted such that the people’s names were removed so that no living individuals could be identified. The mistake was compounded when the police had been informed about it but failed to take sufficient action for four days.</p>
<p>Lancashire Police has agreed to take appropriate security measures to prevent data being accessed without authorisation, and it has also promised to conduct quality assurance checks before material is published on its website. It has further decided to implement a new policy for staff emphasising the importance of taking appropriate action to safeguard data.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/07/lancashire-police-sensitive-data-website/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cookie law gives ICO food for thought</title>
		<link>http://www.mablaw.com/2011/07/cookie-law-ico-food-for-thought/</link>
		<comments>http://www.mablaw.com/2011/07/cookie-law-ico-food-for-thought/#comments</comments>
		<pubDate>Sun, 03 Jul 2011 07:20:23 +0000</pubDate>
		<dc:creator>Mark Weston</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[Websites]]></category>
		<category><![CDATA[analytics]]></category>
		<category><![CDATA[cookie law]]></category>
		<category><![CDATA[cookies]]></category>
		<category><![CDATA[cookies consent]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[FOIA]]></category>
		<category><![CDATA[freedom of information]]></category>
		<category><![CDATA[freedom of information act]]></category>
		<category><![CDATA[freedom of information request]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Google Analytics]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Internet business]]></category>
		<category><![CDATA[Internet businesses]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[The Privacy and Electronic Communications (EC Directive) (Amendment) Regulations 2011]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web site]]></category>
		<category><![CDATA[web sites]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[website operator]]></category>
		<category><![CDATA[website operators]]></category>
		<category><![CDATA[website traffic]]></category>
		<category><![CDATA[websites]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=11018</guid>
		<description><![CDATA[The Privacy and Electronic Communications (EC Directive) (Amendment) Regulations 2011 (the Regulations) came into force on 26 May 2011, and there has been confusion in many quarters as to how exactly to comply. However, a recent Freedom of Information Act request made to the Information Commissioner’s Office (ICO) has shown the answer to another question [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.mablaw.com/2011/05/new-law-comes-into-force-requiring-user-consent-when-using-cookies/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+upload-it+%28Matthew+Arnold+%26+Baldwin+LLP+%7C+Upload-IT%29&amp;utm_content=FeedBurner">The Privacy and Electronic Communications (EC Directive) (Amendment) Regulations 2011 (the Regulations) came into force on 26 May 2011</a>, and there has been confusion in many quarters as to how exactly to comply. However, a recent Freedom of Information Act request made to the Information Commissioner’s Office (ICO) has shown the answer to another question that many business are asking – what effect will compliance with the Regulations have on website traffic and information?</p>
<p>The Regulations mean that, in basic terms, consent must be obtained from a website user before a website operator can place a cookie on the user – if a user refuses to give their consent, the cookie cannot be placed. Various means of obtaining consent have been suggested, but the ICO went for the straightforward route on its own website – a tick-box when you arrive on the website homepage telling you that, unless you give your consent, certain parts of the website will not work properly.</p>
<p>Under the Freedom of Information Act, a member of the public can request that certain information be disclosed by a public body. In this instance, a member of the public asked the ICO to disclose figures of who was giving their consent to the placement of the cookie. The information disclosed showed that 90% of users refused to give their consent. The cookie was a Google Analytics cookie and, as a result, 90% of users disappeared from the ICO’s analytics.</p>
<p>It’s easy to ignore this information – what would the ICO want this information for anyway? The importance, however, is in the fact that other websites who use cookies and have to ask for consent are likely to see a similar pattern, and those websites might use the information collected for advertising purposes – analytics for advertising may see the information they have to use drastically reduced, and many Internet businesses that rely on advertising for revenue may be operating at a handicap.</p>
<p>Information is key to the ongoing development of the advertising-run Internet, but also to the business that rely on the Internet for revenues, whether advertising based or not. A commercially viable option for obtaining consent to place cookies is an essential tool going forward for any Internet-dependent business.</p>
<p>The new law has been attacked for providing little privacy benefits to users, whilst adversely affecting their online experience and adding red tape and cost to website operators as well as potentially operating their viability with advertising revenue affected. This development will surely only add to those concerns.</p>
<p>The ICO has recently given website operators a one year window to comply with the new law, but has warned of action against anyone not taking appropriate steps to prepare. Meanwhile, the European Commission has now thrown down the gauntlet to industry to create industry standards by June 2012 that will create standard ways of gaining user consent to cookies. Neelie Kroes, a European Commissioner, has threatened to use all available means to protect citizens’ privacy if this does not happen. So far, only six countries (including the UK) across the European Union have implemented the new cookies opt-in law.</p>
<p>If you would like to discuss what options you have in order for your business to comply with the Regulations, please contact us on <span style="text-decoration: underline;"><a href="mailto:mark.weston@mablaw.com">mark.weston@mablaw.com</a></span>, <span style="text-decoration: underline;"><a href="mailto:paul.gershlick@mablaw.com">paul.gershlick@mablaw.com</a></span> or <span style="text-decoration: underline;"><a href="mailto:simon.weinberg@mablaw.com">simon.weinberg@mablaw.com</a></span>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/07/cookie-law-ico-food-for-thought/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hackers obtain personal data of 1.3 million Sega Pass users</title>
		<link>http://www.mablaw.com/2011/06/hackers-personal-data-sega-pass/</link>
		<comments>http://www.mablaw.com/2011/06/hackers-personal-data-sega-pass/#comments</comments>
		<pubDate>Thu, 30 Jun 2011 10:25:18 +0000</pubDate>
		<dc:creator>Mark Weston</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[Websites]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybercriminals]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[data subject]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[databases]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Internet security]]></category>
		<category><![CDATA[Internet use]]></category>
		<category><![CDATA[Internet user]]></category>
		<category><![CDATA[misuse of data]]></category>
		<category><![CDATA[On-line]]></category>
		<category><![CDATA[online content]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web content]]></category>
		<category><![CDATA[web site]]></category>
		<category><![CDATA[web site content]]></category>
		<category><![CDATA[web sites]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[website content]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=10983</guid>
		<description><![CDATA[Sega has admitted that 1.3 million users of its Sega Pass online game service have had their personal data obtained by website hackers. The details include names, email addresses, dates of birth and encrypted passwords. No payment card details have been stolen. As soon as Sega became aware of the breach, it suspended access to [...]]]></description>
			<content:encoded><![CDATA[<p>Sega has admitted that 1.3 million users of its Sega Pass online game service have had their personal data obtained by website hackers. The details include names, email addresses, dates of birth and encrypted passwords. No payment card details have been stolen. As soon as Sega became aware of the breach, it suspended access to the service. It is the latest gaming business to be affected by hackers after similar events affected Sony, Nintendo, Epic Games and Square Enix.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/06/hackers-personal-data-sega-pass/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CCTV monitoring website told to change by ICO</title>
		<link>http://www.mablaw.com/2011/06/cctv-monitoring-website-ico-order/</link>
		<comments>http://www.mablaw.com/2011/06/cctv-monitoring-website-ico-order/#comments</comments>
		<pubDate>Wed, 29 Jun 2011 13:59:26 +0000</pubDate>
		<dc:creator>Mark Weston</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[Websites]]></category>
		<category><![CDATA[CCTV]]></category>
		<category><![CDATA[CCTV footage]]></category>
		<category><![CDATA[CCTV images]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[disclose]]></category>
		<category><![CDATA[disclosure]]></category>
		<category><![CDATA[encrypt]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[illegal]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[infringement]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[streaming]]></category>
		<category><![CDATA[unauthorised]]></category>
		<category><![CDATA[unlawful]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web site]]></category>
		<category><![CDATA[web sites]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[websites]]></category>
		<category><![CDATA[YouTube]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=10500</guid>
		<description><![CDATA[A CCTV monitoring website, Internet Eyes, has been forced to change the way it operates by the Information Commissioner’s Office (ICO). The website streams CCTV images from its retailer clients to its signed up membership, and members can then gain £1,000 rewards for reviewing the footage and seeing and reporting any crimes that take place. [...]]]></description>
			<content:encoded><![CDATA[<p>A CCTV monitoring website, Internet Eyes, has been forced to change the way it operates by the Information Commissioner’s Office (ICO). The website streams CCTV images from its retailer clients to its signed up membership, and members can then gain £1,000 rewards for reviewing the footage and seeing and reporting any crimes that take place.</p>
<p>CCTV images can be considered as personal data, and the ICO’s action came after CCTV footage of a shopper from the website was posted on YouTube. The ICO has made it clear that such disclosure of personal data should take place only where ‘necessary’ i.e. for the purposes of crime detection, rather than just for entertainment, as it was here.</p>
<p>The ICO criticised Internet Eyes for not encrypting CCTV images it shared with its members, and it was also not tracking member activity meaning that it could not trace who had posted the video on YouTube. The ICO has made sure that the website has signed an undertaking to ensure encryption and sufficient tracking, and has also requested that the website not allow a member to access CCTV footage taken within a 30 mile radius of the member’s registered location, in an attempt to decrease the likelihood that those people visible in the footage are identifiable to a particular member.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/06/cctv-monitoring-website-ico-order/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Former T-Mobile employees given record fine for illegal trade in customer data – R v Hames and Turley, Chester Crown Court</title>
		<link>http://www.mablaw.com/2011/06/t-mobile-employees-customer-personal-data-hames-turley/</link>
		<comments>http://www.mablaw.com/2011/06/t-mobile-employees-customer-personal-data-hames-turley/#comments</comments>
		<pubDate>Sun, 26 Jun 2011 18:32:50 +0000</pubDate>
		<dc:creator>Paul Gershlick</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[consent]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[data protection regime]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[database right]]></category>
		<category><![CDATA[databases]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[fine]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[illegal]]></category>
		<category><![CDATA[Information Commissioner]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[Information Commissioner’s Office]]></category>
		<category><![CDATA[misuse of data]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[sensitive personal data]]></category>
		<category><![CDATA[unauthorised]]></category>
		<category><![CDATA[unauthorised use]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=10447</guid>
		<description><![CDATA[Two former employees of the T-Mobile have been fined £73,000 and given suspended prison sentences for the illegal trade in the phone giant’s customer data. Hames sold personal data to another Turley, a colleague at the time, who sold that data to a third party for a profit. The Information Commissioner’s Office praised the mobile [...]]]></description>
			<content:encoded><![CDATA[<p>Two former employees of the T-Mobile have been fined £73,000 and given suspended prison sentences for the illegal trade in the phone giant’s customer data. Hames sold personal data to another Turley, a colleague at the time, who sold that data to a third party for a profit. The Information Commissioner’s Office praised the mobile phone firm for working with it to uncover the illegal deal.</p>
<p>It is an offence under the Data Protection Act to knowingly or recklessly obtain personal data without consent. The data was important to T-Mobile and its competitors as it contained details of names, addresses, telephone numbers and customer contract end dates. This is the first time the Information Commissioner has sought a confiscation order under the Proceeds of Crime Act. That is where an order is made to deprive the wrong-doer from any benefit he has received from the crime.</p>
<p>The Information Commissioner has hailed the result in this case as marking a new chapter in deterrents against misuse of personal data. This case proves that there will be an audit trail and his office will try to find what has happened to it, and will take appropriate action, according to the Commissioner. The fine is the largest ever for employees who have stolen personal data for their own gain.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/06/t-mobile-employees-customer-personal-data-hames-turley/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Man fined for getting girlfriend to supply patient data so he could contact them to launch personal injury legal claims</title>
		<link>http://www.mablaw.com/2011/06/patient-data-protection-health/</link>
		<comments>http://www.mablaw.com/2011/06/patient-data-protection-health/#comments</comments>
		<pubDate>Fri, 24 Jun 2011 08:54:32 +0000</pubDate>
		<dc:creator>Mark Weston</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Pharmaceutical]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[blagging]]></category>
		<category><![CDATA[confidential information]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[data protection laws]]></category>
		<category><![CDATA[Data Provider]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[data subject]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[databases]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[fine]]></category>
		<category><![CDATA[health]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[illegal]]></category>
		<category><![CDATA[information]]></category>
		<category><![CDATA[Information Commissioner's Office]]></category>
		<category><![CDATA[Information Commissioner’s Office]]></category>
		<category><![CDATA[misuse of data]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[pharmaceutical]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[privacy issues]]></category>
		<category><![CDATA[right to privacy]]></category>
		<category><![CDATA[sensitive personal data]]></category>
		<category><![CDATA[unauthorised]]></category>
		<category><![CDATA[unauthorised use]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=10411</guid>
		<description><![CDATA[A man has been fined £2,000 for obtaining details about 29 hospital patients and the treatment they were receiving. His girlfriend worked at the hospital. He had been employed by Direct Assist, a personal injury business, and he had been seeking to contact those people to see if they wanted to launch a personal injury [...]]]></description>
			<content:encoded><![CDATA[<p>A man has been fined £2,000 for obtaining details about 29 hospital patients and the treatment they were receiving. His girlfriend worked at the hospital. He had been employed by Direct Assist, a personal injury business, and he had been seeking to contact those people to see if they wanted to launch a personal injury claim. Obtaining the data in this way is illegal, contrary to the Data Protection Act.</p>
<p>This case shows that some people in the personal injury industry are taking “ambulance chasing” to another level. It is one thing to take part in activity that may leave a bad taste in the mouth.  It is another to break the law when doing so.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/06/patient-data-protection-health/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>European Data Protection Supervisor critical of Data Retention Directive</title>
		<link>http://www.mablaw.com/2011/06/european-data-protection-supervisor-data-retention-directive/</link>
		<comments>http://www.mablaw.com/2011/06/european-data-protection-supervisor-data-retention-directive/#comments</comments>
		<pubDate>Tue, 21 Jun 2011 16:22:04 +0000</pubDate>
		<dc:creator>Mark Weston</dc:creator>
				<category><![CDATA[Data Protection & Privacy (Other Sectors)]]></category>
		<category><![CDATA[Data Providers]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Upload-IT]]></category>
		<category><![CDATA[communications]]></category>
		<category><![CDATA[communications data]]></category>
		<category><![CDATA[communications service providers]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[data retention]]></category>
		<category><![CDATA[data retention legislation]]></category>
		<category><![CDATA[data retention periods]]></category>
		<category><![CDATA[data retention requirement]]></category>
		<category><![CDATA[Directive]]></category>
		<category><![CDATA[EC]]></category>
		<category><![CDATA[EDPS]]></category>
		<category><![CDATA[EU]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[European Commission]]></category>
		<category><![CDATA[European Data Protection Supervisor]]></category>
		<category><![CDATA[European Union]]></category>
		<category><![CDATA[harmonisation]]></category>
		<category><![CDATA[Member State]]></category>
		<category><![CDATA[Member States]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[telecommunications]]></category>
		<category><![CDATA[telecoms]]></category>

		<guid isPermaLink="false">http://www.mablaw.com/?p=10246</guid>
		<description><![CDATA[The European Data Protection Supervisor (EDPS) has criticised the Data Retention Directive in an opinion published in relation to the European Commission’s evaluation report on the Directive. The opinion is critical of the Directive for failing to achieve harmonisation in national data retention legislation and because it does not meet the requirements imposed by fundamental [...]]]></description>
			<content:encoded><![CDATA[<p>The European Data Protection Supervisor (EDPS) has criticised <strong><span style="text-decoration: underline;"><a href="http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2006:105:0054:0063:EN:PDF"><span style="text-decoration: underline;">the Data Retention Directive</span></a></span></strong> in an opinion published in relation to the European Commission’s evaluation report on the Directive. The opinion is critical of the Directive for failing to achieve harmonisation in national data retention legislation and because it does not meet the requirements imposed by fundamental rights to data protection and privacy, in particular by:</p>
<ul>
<li>the necessity for data retention as provided in the Directive has not been sufficiently demonstrated;</li>
<li>data retention could have been regulated in a less privacy-intrusive way;</li>
<li>the Directive leaves too much scope for member states to decide on the purposes for which the data might be used, and also for establishing who can access the data and under which conditions.</li>
</ul>
<p>The Directive provides that communications service providers must retain various communications data for a period of between six and 24 months for the purposes of investigation, detection and prosecution of serious crime. In April 2011, the European Commission reviewed the Directive, and criticised its effectiveness in a report due to the fact that it had been interpreted in different ways in different Member States, leading to inconsistency and confusion for telecoms operators.</p>
<p>The EDPS has called on the European Commission to consider repealing the Directive in order to harmonise data retention laws across Europe, which was the primary intention of the Directive. Data retention periods currently differ across Europe, benefitting some communications service providers but not being a disadvantage to others. Privacy lobbyists are also likely to respond well to the EDPS’s opinion as they have long argued that the blanket data retention requirement infringes a data subject’s right to privacy.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mablaw.com/2011/06/european-data-protection-supervisor-data-retention-directive/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

