Skip to content
Sep 10 14

Irish Water Data Protection Notice – An Alternative Version

by Daragh

So, I appear to have caused some consternation with my post over the weekend. To help clarify things, I’ve put together an alternative reality version of the Irish Water Data Protection Notice based on information that has been included in recent media coverage and which is fragmented across a number of documents produced by Irish Water. This is effectively free consultancy for Irish Water and is an incomplete first pass that is intended to illustrate the benefits of layout and structure of Data Protection Notices to improve clarity and communication of purposes for processing of data.

However, the content of this post is (c) 2014 Daragh O Brien and cannot be reused for commercial purposes other than news reporting without prior written permission.

+++++++

Who we are

Irish Water is the new national water utility, which is responsible for providing and managing public water services throughout Ireland. Irish Water is a State-owned company, established under the Water Services Acts 2007–2013.

Irish Water replaces the previous system of 31 Local Authority Water Services departments.

Registered Office

Our registered office is:

 Colvill House,
24-26 Talbot Street,
Dublin 1.

Address for Data Protection Queries

Data Protection queries, such as Subject Access requests or requests for data correction, should be sent to:

Data Protection Officer
P.O. Box 860,
South City Delivery Office,
Cork City,
Cork.

You can email queries to us care of dataprotection[AT]water[dot]ie  ==>(This email address doesn’t currently exist)

What Data are we processing?

We process a range of data about customers of public water services (Customers) and other users of private water services (Non-Customers).

Data about your property and water services

If your property is connected either a Public water main supply or Public Sewer you are a customer of Irish Water. We will ask you to confirm what kind of water or sewage system you are connected to in order to identify if you are a customer of Irish Water or not.

If you are a customer, we will confirm if you are receiving a bill for a water service from your Local Authority and if the property is used as a private residence or not, and if you are a property owner or a tenant.

We will also seek information about the number of people residing in your property.

Personal Data

The personal data we process about you includes:

  • Names of account holders,
  • PPSN numbers for account holders and any resident children (17 years or under)
  • Customer property address
  • Customer preferred billing address (if different from property address)
  • Home land line telephone number
  • Mobile telephone number
  • email address
  • Billing language preference

We will also record calls between Irish Water customer service staff and customers for purposes including quality assurance and training.

Sensitive Personal Data

Irish Water processes sensitive personal data about customers who indicate they wish to avail of special and/or priority services.

This information may include data relating to physical or mental health. In these circumstances we may also process personal data relating to a nominated carer or other person who will deal with correspondence on your behalf.

Personal Financial Data

We will process bank account details for the purposes of establishing recurring direct debits for the payment of Water Services bills.

Other than data you provide to us, what other data do we process about you?

Under Section 26 of the Water Services Act 2013, Irish Water is empowered to seek data from a number of different bodies. As of September 2014, these bodies include:

  • The Revenue Commissioners
  • The Residential Property Tenancies Board
  • The Property Services Regulatory Authority
  • Local Authorities
  • The Local Government Management Agency
  • Electricity Service providers
  • The Department of Social Protection
  • Gas service providers

Other bodies or data providers may be specified by the Minister after consultation with the Data Protection Commissioner.

Irish Water may make use of data from 3rd party data service providers for some of the purposes set out below.

Why are we processing it?

Irish Water has a number of specific purposes for processing your personal and sensitive personal data, and for seeking data about you from other sources.

Confirming if you are a Customer of Irish Water

We will process information about your household, its water supply and sewage services, and other related household data to confirm if you are a customer of Irish Water.

Confirming eligibility for allowances

  • To apply for the Household Water Services Allowance we process your PPS Number to verify your identity and your entitlement.
  • To apply for the Children’s Water Services Allowance, we process the PPS Numbers of resident children (under the age of 17) to verify the age and identity of the children.

This is a control check process that ensures correct and appropriate allowances are claimed to help ensure accurate application of credits to customer water service bills. For more information on our processing of PPSN please see the relevant section below.

[note: This is the purpose for which PPS Numbers is being obtained. It is good to note that Irish Water are not asking for PPSN for non customers, however that assumes that people won't fill it in in error. I assume Irish Water have a process to purge PPSN details they don't require?]

To generate and distribute customer water service bills and collect monies owed

We will use the name of the registered account holder and the property address, or the alternative billing address, for the purposes of sending Water Service bills to customers.

This data will also be used to support our credit control processes. In the event of non-payment of bills, your data may be passed to debt collection agencies for the purposes of debt recovery, up to and including legal proceedings for non-payment.

Data about language preferences will be used to ensure you receive a bill in the language you select. Sensitive personal data will be processed to allow us to issue braille bills or to arrange for “talking bill” services to be provided to visually impaired customers.

Where a customer availing of special services or priority services has indicated that a carer or other person should receive correspondence on their behalf we will process that person’s data as required.

For Fraud Detection and Prevention and Credit Scoring

Irish Water will use data obtained from various bodies as outlined above to allow us to operate prudent fraud detection and prevention  controls.

We may also use data from data services providers for the purposes of customer credit scoring as part of our prudent management of risk.

Marketing

Subject to specific consents, Irish Water may use contact data provided by customers for the purposes of marketing products and services to customers related to their Water Service. This will be subject to specific consents which will be obtained.

For non-customers, Irish Water may use contact data provided to send information about water service availability and to market relevant products and services. Again, this will be subject to specific consents.

Call Recordings

Calls between Irish Water Customer Service staff and customers will be recorded for quality assurance and training purposes, and to confirm details of the conversation if required.

Maintenance and Construction Activity

Irish Water may process your personal data for the purposes of conducting visits to premises, arranging for required works to be carried out at premises, and other construction and maintenance activities necessary to ensure the delivery of a public water service.

Health and Safety and Risk Assessment

Irish Water may process your personal and sensitive personal data for the purposes of ensuring compliance with Health and Safety obligations, ensuring appropriate water supplies for people with certain medical conditions, and the conducting of risk assessments associated with the management of the public water supply.

Your PPSN – what we will do with it

Irish Water is entitled to request your PPS Number and the PPS Numbers of  under Schedule 5 of the Social Welfare Consolidation Act 2005. PPS Numbers provided will be stored securely by Irish Water.

Your PPS Number will only be used to determine if you are entitled to water services allowances. PPS Numbers will be verified with the Department of Social Protection and a simple confirmation of entitlements will be received from them. No other data will be exchanged or processed for this purpose.

PPS Numbers will be retained by Irish Water for [NEEDS A RETENTION PERIOD AND PURPOSE POST VALIDATION OF DATA AT APPLICATION]

Only customers of Irish Water are required to provide us with their PPSN. Users of private water services should not submit this data to us as we do not have a purpose for processing it.

[note: I've flagged this already, but an exception handling process to ensure ppsn is not processed for non-customers by mistake would be a good control here.]

Sharing Data/Disclosure of Data

Irish Water may share data with companies who provide services to Irish Water for the purpose of carrying out our business functions as outlined above. Companies providing data processing services to Irish Water do so under a formal contract and are required to process data only for the purposes specified by Irish Water and must ensure they have appropriate organisational and technical measures to prevent unauthorised access to, alteration of, or disclosure of your data.

Irish Water may disclose or transfer data to a third party in the event of the business being purchased in part or entirely by that third party.

Irish Water may also disclose data if required to do so  in order to comply with a legal obligation, or to protect the rights, property, or safety of Irish Water, its customers, or other relevant third parties, or if required to do so on foot of a search warrant, court order, or where required under a Statutory duty.

Irish Water may share data with third parties for the purposes of fraud detection and prevention and as part of credit risk reduction.

Transfer of Data Outside the European Economic Area

Personal Data held by Irish Water may be transferred to or accessed from countries outside the European Economic Area. The reasons for data to be transferred may include, but are not limited to:

  • Outsource Customer Support services
  • IT Technical support services
  • Software development and support
  • Data hosting and back up services
  • Fraud Detection, Prevention, and Credit risk management

Transfers to countries outside the European Economic Area will be carried out subject to specific contract terms and other relevant controls, such as transfer to appropriate countries on the European Commission Safe Countries List or alternative  appropriate mechanism under the Data Protection Acts.

[note: The original Irish Water Data Protection notice forces consent to this EEA transfer provision. The Data Protection Commissioner is clear that relying on consent in this case requires the consent to be unambiguous and freely given. In the original form, the consent was not unambiguous as it didn't specify any purpose or what data. Also, given that Irish Water is a monopoly and we have no option but to fill out the registration form, the consent being sought was not freely given].

Data Retention

Irish Water has a defined Data Retention Policy.

[note: I assume they have a defined retention policy. What I would suggest here is that for each key purpose a time period be established]

 

Exercising your Data Protection Rights

Under the Data Protection Acts you have the right to:

  1. Request a copy of personal data held about you by Irish Water (Subject Access Request)
  2. Request Irish Water correct or delete incorrect or inaccurate data about you
  3. Request Irish Water cease processing your data for specific purposes, such as Direct Marketing

Subject Access Requests

To request a copy of your data you should send a request in writing to:

Data Protection Officer
PO Box 860
South Delivery Office
Cork City
Cork

Irish Water may request additional proof of identity from applicants for the purposes of verification to ensure data is disclosed only to the relevant individual.

Irish Water may charge a fee of up to €6.35 for Subject Access requests.

Change Direct Marketing Preferences

To change your Direct Marketing preferences you should send your request to:

FREEPOST,
Irish Water,
Data Protection Opt-out,
PO Box 860,
South City Delivery Office,
Cork City

Alternatively you can phone Irish Water on 1890 278 278 to update your marketing communications preferences.

Other Requests

Other requests should be sent to:

Data Protection Officer
PO Box 860
South Delivery Office
Cork City
Cork

Marketing Consents & Permissions

  • email:             I would like to receive marketing communications by email (YES/NO) [this is an opt-in consent]
  • SMS:               I would like to receive marketing communications by Text message (YES/NO) [this is an opt-in consent]
  • Mobile Call: I would like to receive marketing calls on my mobile phone (YES/NO) [needs to default to NO as this is an opt-in consent]
  • Landline:      I would like to receive marketing calls on my land line phone (YES/NO) [this can be an opt-opt consent]
  • Postal Mail: I would like to receive marketing material by post (YES/NO) [this can be an opt-out consent]

[note: The Article 29 Working group and the DPC have indicated that preticked boxes on web forms are not valid consent as the consent is not freely given. Including them here is possibly not ideal given that the form isn't online. 

The application form contains only one single Opt-out tick box for both electronic and postal marketing. This does not meet the requirements of SI336. As I haven't received my pack yet I can't comment on the on-line application process and whether it has better compliance with the ePrivacy regulations requirements (SI336)

Also it is important to note that the application form for Irish Water does not capture any electronic contact data for non-customers, therefore non-customers will be marketable to only via postal mail at this point on an opt-out basis]

Sep 6 14

Irish Water Data Protection Notice: A review…

by Daragh

circle of trustIrish Water have published their Data Protection notice on their website. This document is a key element in any organisation’s data protection compliance. It is the way in which the organisation demonstrates “fair obtaining” of personal data and sets out the specific lawful purposes for which they are processing data.  It is essential that these documents are as clear as possible, particularly for audiences who may have literacy difficulties. This is why I strongly recommend to clients that they do not let their legal team write these. Ultimately, data protection compliance is about ensuring you don’t have a surprised customer. It’s also about ensuring you establish and maintain a “Circle of Trust” about why you are asking for data and how you will process it.
In this post I’ll go through the Irish Water Data Protection notice and parse each paragraph and explain what it means and, where necessary, point you to the relevant legal justification for the processing that is taking place.

Irish Water Data Protection Notice

(sourced from https://www.water.ie/data-protection-notice/ 05/09/2014)

Irish Water may share the Customer’s data with agents or third parties who act on behalf of Irish Water in connection with the activities referred to above. Such agents or third parties are only permitted to use the Customer’s data as instructed by Irish Water. They are also required to keep the Customer’s data safe and secure. The data that we collect from you may be transferred to, and stored at, a destination outside the European Economic Area (“EEA”). In the event that the data is stored outside of the EEA, Irish Water shall procure that all relevant laws are complied with to secure the data. It may also be processed by staff operating outside the EEA who works for us or for one of our suppliers. Such staff maybe engaged in, among other things, the processing of your request for information and the provision of support services. By submitting data to Irish Water, the Customer agrees to this transfer, storing or processing. Irish Water will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Clause 19.

[comment:

This clause should have a "data sharing" heading. It repeats a bit of what was in the previous section. "Such agents or third parties are only permitted to use the Customer's data as instructed by Irish Water" is a reasonable sentence. Of course, it must be assumed that those agents and third parties have contracts with Irish Water that specify the purposes and controls for processing. 

This section also tells us that data "may be transferred to, and stored at, a destination outside the European Economic Area". This suggests use of outsourced data centres or data processors that are outside the EEA. There is nothing wrong with this in and of itself, but the problem comes with the next statement: "Irish Water shall procure that all relevant laws are complied with to secure the data". This is problematic, apart from the awkward use of the word "procure". Cross border data transfer outside the EEA requires either that the destination country is either a Safe Country , be covered by Safe Harbor (i.e. the US), or be undertaken using model contracts.

Why is our data being transferred? Staff outside the EEA working for Irish Water or a supplier will be processing data if we request information or to provide support services. This sounds like either IT support services being provided outside of the EEA or direct customer support call-centre type services being provided outside of the EEA. Question: Is Irish Water planning to outsource call centre operations to India? Also: What countries are they intending to transfer data to, and under what controls?

Apparently, by submitting data to Irish Water we will have agreed to the transfer. This is probably not valid consent under EU Data Protection law. While it is specific and informed, it is not freely given. Individuals have to provide data to Irish Water. While I am heartened to see that Irish Water will take all steps reasonably necessary to ensure data is treated securely, I'm bloody confused where "Clause 19" comes from (I suspect this Data Protection notice is an extract from a longer T&Cs document). Unfortunately, Irish Water are not required to take all "reasonably necessary steps". They  are required to ensure appropriate organisational and technical controls.

And as for processing "in accordance with this Clause 19"? Well, without knowing what that Clause 19 actually is (it might be this paragraph *shudder* or it could be something else) I can't add anything about the impact or meaning of that sentence.]

Irish Water may disclose the Customer’s data to third parties in the event that it sells or buys any business or assets, in which case it may disclose Customer data to the prospective seller or buyer or such business or assets; if Irish Water or substantially all of its assets are acquired by a third party, in which case Customer data held by it about its Customer will be one of the transferred assets. Irish Water may also disclose Customer data if it is under a duty to disclose or share Customer data in order to comply with any legal obligation, or in order to protect the rights, property, or safety of Irish Water, its customers or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction. Irish Water will also disclose Customer data if it believes in good faith that it is required to disclose it in order to comply with any applicable law, a summons, a search warrant, a court or regulatory order, or other valid legal process.

[comment: 

The inclusion of a disclosure purpose covering sale or transfer of assets is normal and common sense for any business. The biggest asset in most businesses now is its customer data. Disclosure of data when buying an asset is a question mark purpose, but one scenario might be due diligence when buying another water services business serving the Irish market to validate the size of the additional customer base being acquired. I'd question the legitimacy of disclosing data when buying a non-water sector business however. 

This clause also says that Irish Water will disclose data if required to do so under any legal obligation or to protect rights, property, or safety of Irish Water, its customers, or others. This is allowable under the Data Protection Acts, but should not be read as a blanket provision allowing any kind of disclosure. Appropriate governance controls would need to be in place to ensure that the "legal obligation" is valid and to ensure that the decision about protecting rights, property, and safety is taken under appropriate guidelines and controls.  Of course, we can't ignore the last sentence here which basically restates in a different way the kinds of legal obligation under which data might be disclosed. The "believes in good faith" clause suggests to me that IW will not contest any order requiring disclosure of data. My reading: If you are drinking tea while engaged in illegal downloading, IW will tell IRMO if asked.

This paragraph reiterates the exchange of and disclosure of data to third parties for fraud prevention and credit control. I've already raised an eyebrow about that earlier.]

From time to time the Customer may speak to employees of Irish Water (or agents acting on its behalf) by telephone. To ensure that Irish Water provides a quality service, the telephone conversations may be recorded. Irish Water will treat the recorded information as confidential and will only use it for staff training/quality control purposes, confirming details of the conversations with Irish Water or any other purposes mentioned in this Clause 19.

[comment: 

This actually a reasonably good provision, at least in part. It provides for the recording of calls with their employees or sub-contractors (i.e. customer service staff in call centres - see my question re: where those call centres might be in the future earlier).

The problems with this clause are that it starts with specific statements of purpose ("staff training/quality control") and then degenerates quickly into catch-all vagueness ("or any other purposes mentioned in this Clause 19"). Firstly: Clause 19 is not numbered or identified in this document. Secondly, I'm a Data Protection professional and I can't say that, even after a number of readings, I could list what specific purposes are mentioned in this document. There are a lot of "reasonable", "as necessary", and "because we're worth it" type phrases. I can't scan quickly and directly to a single section that says: "These are the purposes for which we are processing information".]

The Customer has a right to ask for a copy of the Customer’s data (Irish Water is entitled to charge a nominal administration fee for this) which is held by Irish Water about the Customer. If the Customer wishes to avail of this right, a request must be submitted in writing to: Irish Water, Data Protection Officer, PO Box 860, South City Delivery Office, Cork City. In order to protect the Customer’s privacy, the Customer may also be asked to provide suitable proof of identification. If any of the Customer’s details are incorrect the Customer is entitled to notify Irish Water to amend such details. Where the Customer has any queries in respect of Customer data it should contact Irish Water using the details provided in Clause 20.2.

[comment:

This paragraph tells us we have a right to ask for a copy of our data and we have to submit the request in writing. Correct thus far, this is as required under Section 4 DPA). They say they are entitle to charge an administration fee. This is correct. It’s €6.35 maximum. They don’t tell us how to pay that (postal orders, 10 €0.65 stamps, 635 1-cent coins…). They provide a postal address to send our requests to. It’s worth bearing  in mind that the Data Protection Acts only require that the request is in writing and organisations are not actually allowed to prescribe a standard form or mechanism for sending in Subject Access Requests. Personally, I’d have used an email address for this in addition to the postal address to ensure capture of SARs early in the process. I also hope their processes for handling requests that come in are better defined and resourced than this classic example.

That Irish Water are telling us they may ask for proof of identification for a Section 4 request is not a bad thing. It is good practice to verify the identity of a requester and is a basic organisational control practice to prevent unauthorised disclosure. Of course, once identification information is provided (e.g. passport copy) and the identification process has been met, the data should not be retained. The DPC looked at this in Case Study 16 of this year’s Annual Report.

This paragraph also requires us to address any queries in respect of data to a different address. We’re told the contact details are in Clause 20.2. Out of context, that is utterly meaningless – they might as well have asked us to send our requests attached to an Owl care of Hogwarts. It is important to note that queries in respect of customer data are most likely Section 3 requests – requests to confirm if data is being processed, and why, or requests to have data rectified or erased under Section 6 of the DPA. The use of two different addresses for Data Protection related processes strikes me as potentially inefficient and an inevitable cause for confusion. I always recommend to clients that they have a single “Data Protection request” funnel and have well defined back-office processes to sort the requests and process them effectively and efficiently.

If the Customer signs up for any of the Irish Water online services and Irish Water communicate with the Customer by email, the Customer is solely responsible for the security and integrity of the Customer’s own email account. The Customer accepts that electronic mail passing over the Internet may not be free from interference by third parties. Consequently, while Irish Water will take all reasonable security measures, Irish Water cannot guarantee the privacy or confidentiality of information relating to the Customer when passing over the Internet. Unfortunately, the transmission of information via the internet is not completely secure. Although Irish Water will do its best to protect Customer data, it cannot guarantee the security of Customer data transmitted via the internet; any transmission is entirely at the Customer’s own risk.

[comment: Summary of this is that Irish Water accept no responsiblity for the security of email communications. This is true. They can’t be responsible for external malicious attacks on your email account. This is a limitation of liability clause. It is not unreasonable. Of course, IW could give the option of using encrypted email communication…

Marketing [note: this is where some fun starts]

Irish Water and/or authorised agents acting on behalf of Irish Water, may wish to contact the Customer by text message, email, post, landline or in person about water related with products or services which may be of interest to the Customer (“Marketing Purpose”).

[Comment: 

This paragraph does not meet the requirements of SI336.

  1. Marketing by SMS requires opt-in consent under Section 13(1) of SI336. Given there is no alternative water service provider, any implied consent that might be argued would likely be invalid on grounds of it not being freely given. This basically amounts to a pre-ticked box on a web-form, which the Article 29 Working Party has already said doesn’t meet the requirement for informed opt-in consent.
  2. The same goes for marketing by email.. (SI336 lumps email and SMS messages in under the same term – electronic message).
  3. Post is OK for an opt-out mechanism under SI336
  4. Landline calls are also OK for an opt-out mechanism under SI336 (Section 13(5))

The “in person” provision is door to door selling. 

The catch all “related with products or services which may be of interest to the Customer” clause here is very wide. The service being offered does not have to be related to your water service – This is sufficiently broad that Irish Water could call you to sell Andalusian Time Share units if they so desired.

I note that their consent landgrab does not extend to mobile phones. If I was mischievious, I’d suggest that people enter their mobile phone number as a contact number as SI336 requires prior, explicit, opt-in consent for calls to mobile numbers (SI336, Section 6). 

If the Customer does not wish to be contacted for Marketing Purposes as set out above, the Customer may exercise a right of opt-out by either writing to Irish Water at FREEPOST, Irish Water, Data Protection Opt-out, PO Box 860, South City Delivery Office, Cork City or by calling Irish Water on 1890 278 278.

[comment: You can send your opt-out requests by a freepost letter or by ringing their call centre. Another address, another set of processes. It is clear that there is a strong presumption that opt-out is a sufficient mechanism for their marketing. This is incorrect.]

Conclusion

There are some good things about this Data Protection notice. However, they are outweighed by:

  1. Poor structure and layout that makes it very difficult to find relevant information and understand what is being done with data
  2. Some extremely vague and non-specific provisions, as well as some “kitchen sink” “just-in-casery” in terms of what is being addressed
  3. Some simply unsupportable approaches to obtaining consent
  4. An appearance of a fragmented and not properly thought through approach to governance of Data and management of Data Protection obligations.

The upshot:

  • Tinfoil hat brigade will have wriggle room to misunderstand potentially valid and allowable processing purposes, which will lead to more nonsense and noise.
  • The rest of us will find our data being processed in a range of vague and unspecified ways to which we will be told “you consented”, which we actually didn’t as consent needs to be freely given and meaningful and it is difficult to see how one can consent to take -it-or -leave-it provisions in the terms and conditions of a monopoly organisation.
  • Irish Water will wind up dealing with Data Protection complaints, some groundless but many with a strong basis.
  • Irish Water will engage in activities that will actually breach Data Protection rules when they engage in marketing, and will attempt to argue that customers consented. This will result in investigations by the DPC, and avoidable legal costs in defending prosecutions.

My rating: 5/10 – close, but no cigar.

Jul 25 14

Roll Up, Roll Up – see the amazing psychic dog! (minor update)

by Daragh
Roll up Roll Up, meet the new DPC!

Roll up Roll Up, meet the new DPC! (says Irish Times)

Every so often I read things in the newspaper that make me go “Yay!”. More frequently I read things that make me go “Boo!”. Today, as with other days, I read something that made me go “WHAT THE F….?!?!”.

Over the past few weeks the Irish Times has done a bang up job breaking some excellent stories about Data Protection issues in Ireland. Karlin Lillington, Elaine Edwards, and others have sought to “Tell the Story of Why” and push past the usual soundbites and bullshit gloss that usually passes for data-related journalism in Ireland.

One great example of this was the work done on a story about how the Dept of Arts Heritage and the Gaeltacht had erred in exposing data on living people (whose data privacy rights are protected under the Data Protection Acts and the Treaty for the Formation of the European Union, as well as the Irish Constitution – and if you want a potted guide to all of that Gerard Hogan gives a great summary here) on the IrishGenealogy.ie website. This was despite having had consultation with the Office of the Data Protection Commissioner and having had guidance on what was and was not acceptable from a Data Protection perspective.

The various pieces written by Elaine Edwards were detailed, explained the core of the issues well, and generally added to the quality of discourse.

On the 23rd of July, in their Online edition, the Irish Times ran this piece of utter nonsense dressed up as journalism. It’s such a poorly researched and written piece that I can understand why the author felt it best to leave their name off the byline [update- unfair to author, it was a leader piece, but if so my comments below are even more relevant - /update].

It is true that the DPC raised issue regarding a property price register. The issue was that the sharing of data between different entities that would be required to create such a register, while of interest to the public, lacked a legislative basis and therefore risked breaching the Data Protection Acts. Legislation was passed two years ago that provided the “air cover” for the sharing of data to build a property register and lo and behold there is a property price register in place now, linked to the LPT process.

Comparisons between Irish law and UK law are often as valid as comparing an apple and orange, and complaining about the bitterness of the orange skin as you try to bite into it, on the basis that they are both fruit.

But the doozy in this article for me is the challenge to the DPC as to why they didn’t spot that the Dept of Arts Heritage and the Gaeltacht were in breach of the Data Protection Acts for a year. The anonymous author of this article asserts that the DPC’s job is to ensure compliance with the Data Protection Acts.

Actually no. That is not their job. To make the Regulator responsible for ensuring compliance breaches a number of concepts in Governance, such as segregation of duties.

Their job is to enforce the Act, to provide advice on how to not be non-compliant (which they did in this case), and investigate and prosecute offences under the legislation (albeit with a role in relation to education and awareness building as well).

The responsibility for ensuring compliance rests with the Data Controller doing the processing, in this case the Dept of Arts, Heritage and the Gaeltacht, who were non-compliant because they did the very thing they were told not to do by the DPC. Responsibility for ensuring compliance rests with the IT project team who developed interfaces that shared too much data, the testers who didn’t spot it, and the Data Controller in the Dept who didn’t double check that the business rules were followed.

The DPC’s job is to hold the Data Controller ACCOUNTABLE.

The bizarre logic of the writer of the article simply makes no sense. Are the Gardai responsible for ensuring compliance with the Road Traffic Acts? No. Their job is the detection of, investigation of, and prosecution of offences. Just like the DPC in this context – when the Office was made aware of a possible breach of the Acts, they investigated and took action immediately.  (Ensuring compliance with the Road Traffic Acts is the responsibility of the road user).

For all the sense that is in the article, the anonymous scribe [update-anonymous as it is a leader piece-/update] might as well have advocated that the soon to depart Mr Hawkes be replaced with a Psychic Dog who would detect all the potential future crimes, just like Tom Cruise in Minority Report.

Lazy, sloppy, and brain numbingly dumb hackery dressed up as journalism, an article of this low quality has no place in a paper of merit such as the Irish Times.

Good, informed, and informative journalism on Data protection issues must be encouraged however.

Jul 17 14

An anniversary post (of sorts)

by Daragh

A little under a year ago I wrote two posts on this blog regarding the Irish DPC, Facebook, and Safe Harbor.

The blog posts in question are here and here

Those posts were written under less than ideal conditions; sitting at train stations or in cramped train carriages, eyes streaming with hayfever (or perhaps I was weeping for the death of privacy.. sometimes it’s hard to tell),  typing furiously on an iphone, with limited access to internet, so were rattled off essentially off the top of my head at the time based solely on the information that was in the public domain.

The gist of what I wrote in those posts was as follows:

  1. The Data Protection Commissioner’s Office has to enforce the law that is in front of them.
  2. The law that is in front of them says that transfers to Facebook are OK under Safe Harbor
  3. To conduct an investigation would mean the DPC would have to challenge a decision of the European Commission (specifically the Safe Harbor decision).
  4. That was probably the reason why other Data Protection Authorities, while complaining about Facebook, PRISM, and Safe Harbor hadn’t actually done anything to suspend transfers, because they too were not able to directly challenge a decision of the European Commission.

In June we received the judgement of Hogan J. in Schrems vs DPCThis case was initiated as a judicial review of the decision of the DPC not to launch a full blown investigation in to Safe Harbor and Facebook.

In that judgement, Hogan J. held that:

  1. The DPC had correctly interpreted and enforced the law that was in front of them. Transfers from Facebook Ireland to Facebook US were permitted as a result of Safe Harbor.
  2. A question needed to go to the ECJ as to whether the DPC could actually ignore or look beyond the Commission Decision on Safe Harbor when looking at whether processing was lawful. (In essence this is a question that is asking the ECJ to rule on Safe Harbor in light of the changes in EU Data Protection law since it was implemented a decade and a half ago. Since then Data Privacy has become clearly recognised as a fundamental right and the Digital Rights Ireland case has clarified the need for proportionality in data processing, particularly on-line surveillance).

And with that he sent a question to the European Court of Justice that potentially will have echoes as profound as Gavrilo Princip’s revolver shot on a side street in Sarajevo a century ago.

It was particularly heartening to me to read paragraphs 80 and 81 of Hogan J.’s judgement when it came out. In those paragraphs he basically says exactly what I said a year ago: the EU Commission had decided that Safe Harbor was an appropriate mechanism for cross border data transfer and the DPC was tied t the findings of the Commission under the Irish Data Protection Acts and the underlying Directive. That’s pretty much what I said in this blog post.

I am loathe to engage in precognition on the ECJ case that we are presented with now. However, I will venture the following for now:

  1. This is no longer a case about an Austrian law postgrad taking on an administrative functionary in on the western spiral arm of the EU.
  2. This has become a case about information flows and fundamental rights (thanks in no small part by some deft adjudication by Hogan J).
  3. This has become a question of information society (the ethics, rights, rules, and benefits of information processing) versus information economy (individuals as units of production, and surveillance of the drones by Big Brother). It will have a profound impact no matter what the outcome.
  4. While Max Schrems has taken his case against the Irish Data Protection Commissioner, ultimately it is the Safe Harbor mechanism that is on trial now at the ECJ.
  5. If Safe Harbor is found to be not fit for purpose as a result of the disproportionate threats to data privacy rights of EU citizens, we will move into a very interesting era. If it turns out that national Data Protection Authorities can second guess decisions of the EU Commission when the surrounding laws or social environment changes, that will have ripples out far beyond the world of Data Protection law and practice.

The role of Digital Rights Ireland as amicus curae in this case is to be welcomed. They add no baggage to the wagon train, but having been to the ECJ already on a data protection issue they are familiar with the winding trail ahead.

It is to be hoped that politicians and functionaries in the civil services of Member States and the Commission, as well as the media and the general public, wake up to the issues here and start paying attention. In the absence of a global drive to establish functioning and balanced frameworks for effective cross border data transfer we may find ourselves with exactly the same problems that gave rise over three decades ago to the need for the OECD Guidelines , and in turn Council of Europe Convention 108 and the entire framework of EU Data Protection laws in the first place.

Interesting times indeed.

Jul 10 14

Arise DeskZilla

by Daragh

I use a standing desk when working in my office (and if I could find a light weight portable option I’d use one on client sites as well). Many of the greatest leaders have used standing desks.

There are proven medical benefits to getting off your backside when working. It’s worth bearing in mind that sitting for a living is an invention of the late 19th and early 20th century. Prior to that most people did have to move around a lot. But standing desks can be expensive. So a theme has developed over the past few years of hacking functional standing desks that are ergonomically aligned using a low capital investment model (for which we must read “it don’t cost much if you make a mess of it”). The source of raw materials is a certain Swedish home improvements store famed for their meatballs that I won’t name here because they are very protective of their brand name. But a good source of ideas for how to repurpose their stuff can be found here.

About 18 months ago, after a flare up of back trouble, I did a bit of research (using the hacks site linked to above and a few others) to see how I might best build a standing desk on a near-zero budget. I started with a few basic design principles:

  1. Aim for “minimum viable product” – it had to meet ergonomic requirements for me and my height, but I guessed it how I worked, laid out my work, and how the desk would need to function would evolve as I changed from sitting on my ass to moving around.
  2. Reuse or recycle things I already had – I had a desk already. I wasn’t going to junk that. I also had a pretty cool laptop stand with cooling fan and USB ports.
  3. Kaizen principles – I’d look to find ways to reduce waste of effort and time when working, and accept that the desk would not be perfect as I’d always find something else to improve how it works for me and with me.
  4. MacGyver rocks.

Ergonomics

Some basics. If you don’t have your standing desk set up correctly you will simply make things worse for yourself. Do some research. Buy a measuring tape. Think about posture, stance and positioning. I train (as often as I can, which isn’t often enough) in Aikido so I am very concious of my centre point (hara) and the need to have hips and back aligned correctly for good movement and energy flow.

Some good resources for standing desk ergonomics I found during my research are here, here, and here. A recent resource that covers off some good “dos and don’ts” can be found here.

Introducing DeskZilla

DeskZilla was the result of my research and my design principles. It was built entirely from parts purchased from Ikea (oops I’ve named them), with a few extra bits thrown in to make minor adjustments.

Picture of deskzilla standing desk

First iteration of DeskZilla.

The parts I used were:

  1. A Vika/Amon desktop (no longer available). It is 100cm wide and 50 cm deep. For alternative table tops, see here: Ikea TableTops
  2. An Ekby Jarpen shelf for the monitor and laptop level, with three Ekby Tore clamp brackets (3 ensures shelf doesn’t bow in the middle). Ikea actually illustrate the use of the brackets on a desktop on their website now.
  3. Capita legs for the desk (which require a little MacGyvering with a drill to make some new screw holes for them as they are not meant as desk legs). I went for these as they could be adjusted up to 17cm high. Note that the Capita legs aren’t MASSIVELY extendy, they adjustable to compensate for uneven floors in the furniture they are supposed to be used on. But a centimetre or two can make all the difference.
  4. Two power blocks from Aldi that bolted onto the desk. I put them on the rear edge to stop DeskZilla from sliding backwards.

Total cost, a little over €70.

A key point… it is really important to measure your existing desk and the height/depth of each component to make sure things are going to be at the right height.

What I have with Deskzilla is a modular system where I can move the monitor and laptop down on to the lower level and move the keyboard and mouse down to the lower desk and use it as a sitting desk. The monitor is almost exactly perfectly positioned for a sitting desk when on the first level.

I had to add a pencil box under the keyboard to move it up a centimetre and a half or so for better ergonomics when typing. The monitor is now raised up on a hardback books to improve positioning (more on that in a moment).

Evolution, Phase 1

Almost immediately DeskZilla began to evolve. While the monitor was almost perfectly aligned, I found that video conferencing was a great way to double check.

Rule of thumb: if you have a webcam in your monitor your eyes should be in line with the lens. A hardback book fixed that.

After a few weeks of use I noticed I was getting stiffness. Some gym mats from Argos on the floor provides an anti-fatigue feature, and I still have my chair and can switch to sitting if I get too stiff and sore any day. The body is a bugger and some days you can stand without issue for hours (I pulled a 27 hour straight working day on a project last year… standing almost the entire time) and other days it hurts like heck after a few hours.

Second rule of thumb: listen to your body and adapt each day.

Evolution Phase 2

DeskZilla will evolve again soon. Experience with the monitor, and the hassle of bending to get pens, post-it notes etc,  tells me that it might make sense to swap the Ekby shelf for one with drawers that has the same length and a bit more height. The Ekby Alex shelf looks like a contender. The only reason I rejected it in Phase 1 was cost – it would have been over 50% additional on the budget.

I also need to think about raising the desktop a little to remove the need for a pencil case under the keyboard. That could be achieved through castor guards or something like that (the things that you put on furniture that is going on a wooden floor), another option is some half-inch wooden blocks  between the Ekby desktop and the Capita legs to give a small height boost. That last option would be a good call for anyone over 6ft 2″ who wanted to use this recipe, and could be a way to incrementally tweak the height to what you need rather than relying on just the leg extendibility.

Finally, I’ll probably invest in a folding bar stool type chair, or an ironing board chair to use when fatigue kicks in to take the weight off my ankles and knees.

Some key lessons about standing while working

  1. Think zen and do yoga. Simple stretching movements keeps fatigue at bay and helps strengthen core.
  2. Don’t stand still… move around and shift posture.
  3. Get used to working in shorter bursts and then changing position. I used to sit motionless for hours, now I work in 10 to 15 minute bursts and then switch posture or position… any longer and I stiffen up, which can hurt and break concentration any way. Movement keeps the brain awake!
  4. Two monitors makes a massive difference, but only if you aren’t having to crane your neck to see it.
  5. Your workspace will evolve around you. Find a natural movement and flow for you and settle into it. If you force it you’ll find it just doesn’t click for you.
  6. Breathe. Take advantage of your posture and position to take deep breaths and relax into your work.
  7. Each day you will need to improvise something to tweak a factor to improve comfort and flow. Accept that and get on with it
  8. The Desk is NEVER finished if you are building your own, (and it’s never perfect if you bought it off the shelf)
Jul 9 14

TV Licences, Data Protection, and the comments of the DPC

by Daragh

It was great to hear the Data Protection Commissioner on Newstalk this afternoon explaining the situation regarding the proposed TV License data slurp. I’ll post a link to the podcast when it is available.

A quick summary of key points that he made is as follows:

  1. The Government must pass legislation to allow for any access to data.
  2. The accessing of subscriber data is an interference with fundamental rights so, while Public Interest (e.g. maximising revenue from TV licence to keep Fair City on the air), the Government must convince the Oireachtas that the levels of access proposed are justified. The DPC specifically said that “the Oireachtas need to think about this”.
  3. He went on later to restate the importance of the Public Interest needing to out weigh and justify the interference in fundamental rights.
  4. He specifically flagged that whatever mechanism and process is proposed in legislation, it needs to be a “reasonable and proportionate measure”
  5. An Post should only have access to the minimum amount of information necessary to confirm if there is use of a TV service.

Hmmm.. I’ve heard comments like that somewhere else recently

A slight difference of opinion…

The DPC compared the access of data from TV service providers as being similar to the legislation that was brought in to establish the Property Register for the LPT tax.

I respectfully have to disagree a little on this. The LPT register required a completely new database to be created from scratch for the purposes of effectively, efficiently, and fairly levying a new tax. Data was drawn from multiple State and private sector data sets to create the best possible register for that purpose [disclosure: my company was involved in some preliminary work around the establishment of the LPT Register].

What is proposed in the case of the TV licence is to supplement an existing private sector database (An Post’s) with data from potential competitors for the purpose of detecting non-compliance with an existing tax/levy. It is a subtle difference and should affect the determination of what is proportionate. There is already an investigation and detection function for TV licence enforcement. Any level of access other than on a case by case basis for the investigation of and prosecution of non-payment would require a clear justification in my view to pass a proportionality test. Rather than comparing to the LPT establishing something new, a more appropriate comparison would be to existing Revenue powers to request data from banks in the course of an investigation, not as a general blanket bulk extraction.

The Thin End of the Wedge

The DPC is “concious of making sure that this won’t be the thin end of the wedge”. In that case attention needs to be paid to how the legislation evolves. As I pointed out yesterday, Sky and UPC are both also providers of telecommunications services. In defining what data is being accessed for what purpose, it needs to be clarified if this legislative data grab will be constrained just to television service packages or to a wider range of product offerings. And within that there then needs to be consideration as to how An Post would verify that a broadband subscriber was or was not using their service to stream TV to a laptop or handheld device, a scenario that is currently not covered by the TV licence, but is proposed to form part of a Household Broadcasting Charge in the not too distant future.

This is where there is another key difference between this proposed legislation and the LPT. The LPT legislation, from the very beginning, made clear that data would be obtained from private sector organisations to enrich and validate data on the Register obtained from existing State sources. While some thought that it was the tightening of Big Brother’s grubby mitts around our data, it was at least an open and transparent initiative.

If the intent here is to build a Household Broadcasting Charge Register by enriching the existing An Post data sets with 3rd party data, then the Minister and Department should come out and state that and place the Public Interest question around this proposed legislation on a more transparent footing, which in turn may affect the consideration of what form of mechanisms and measures would be reasonable and proportionate to achieve that end. That will ensure that the legislation that the Oireachtas may eventually pass will be fit-for-purpose, that the correct balance of rights between the individual, the organisation, and the State will be considered, and there can be a proper debate and provision of information about what constitutes a “reasonable and proportionate measure” in that context.

If the data is required to support existing investigation and detection processes for the current TV licence, I would suggest that what is reasonable and proportionate is more in line with Revenue’s powers of access to bank records on a case by case basis then the mass integration of data required to create the infrastructure for an entirely new tax head, and it is on that basis that the assessment of “reasonable and proportionate” should be made.

The de minimis principle

The DPC was clear that only the minimum necessary amount of information for the specific purpose could or should be shared. Hear hear!

Of course, his comment presumes a bulk sharing obligation is required or is proportionate. As I wrote yesterday, and as I mention above, if the proportionate response is to improve evidence gathering in investigation of suspected non-payment of a licence fee then An Post (or any other collecting agency) could simply ask, on a case by case basis, “Does X address have a television service” and receive a simple yes or no response.

The Commissioner’s comments don’t rule that approach out however.

Of course, de minimis is a principle that applies to the purpose and intent of the processing. If the intent or purpose is to ensure that everyone who has a Sky or UPC subscription has paid their TV licence, it would be quicker, easier, and cheaper, to make them collecting authorities for their customers and leave An Post with the rump, with the Department managing a reconciliation process on an annual basis. It would add €13 or so to a Sky TV subscription, and it would ensure that every location where a single customer had a Sky TV box installed was paying the fee.

The Prickly Problem of Proportionality

It is good to see the DPC making positive comments about how the Oireachtas needs to reflect on how any legislation that might emerge would impact on fundamental rights. The Government must convince the Oireachtas (but with a majority, that is a fudge), but the Oireachtas has to act in accordance with the Constitution and with our obligations under EU Treaties. The ECJ has ruled on the Data Retention Directive and has made it clear that for serious offences that the interference in data privacy rights through retention of or bulk access to communications data must be proportionate. Digital Rights Ireland have yet to return to the High Court for the next round of their challenge to the Communications Retention of Data Act 2011, but it defines a “serious offence” as being one carrying a prison sentence of at least 5 years.

For a €160 licence fee and a summary offence with a €1000 fine on first offence or €2000 on subsequent offences (people go to jail for non-payment of fine, not non-payment of TV licence) it will be interesting to see how proportionality will be established.

It may be that the Government will need to consider alternative mechanisms for enforcement of the TV Licence (or future Broadcasting Charge) that does not require the sharing of data. The key objective, after all, is to maximise the cash inflow for the State to support development of indigenous broadcasting while at the same time minimising enforcement costs and minimising the extent to which data is being shared and processed between private sector organisations, albeit on behalf of the State.

Of course, any reliance on full and frank debate in the Oireachtas has to recognise that the Government has a majority and we operate a whip system in our parliament. Government TDs will vote with the Government line. Which means that legislation might get passed that is actually a disproportionate response to the problem. Gerard Cunningham (@faduda) kindly reminded me of this on twitter.

Ultimately, the Minister needs to be clear in his Problem Statement before rushing to a solution, and the Oireachtas needs to think outside the box when assessing the reasonableness and proportionality of the legislative response to the realities of the telecommunications and broadcasting markets.

Jul 8 14

TV Licence checks and “Data Protection Principles” [updated]

by Daragh

This morning’s Irish Times reports this morning that the (current) Irish Communications Minister  is seeking cabinet approval for powers to enable the agency that collects TV Licences (currently An Post, the Irish post office) to access subscriber data from subscription TV providers such as Sky or UPC to crack down on TV licence evasion. We are assured by the Minister that the whole thing will be done ” in accordance with strict data protection guidelines”. Ignoring for a moment that “Data Protection” is not a guideline but is a fundamental right of EU citizens enshrined in law and derived from both the TFEU and the European Charter on Fundamental Rights and implemented in Irish law as a result of an EU Directive (ergo… not a guideline but kind of a big thing to keep an eye on), what might those guidelines be?

[Update] TheJournal.ie are reporting that this proposal has passed the Cabinet. The mechanism that is to be applied is reported as being:

“An Post will be allowed access the subscription data held by the likes of UPC and Sky to cross-reference their subscriber databases with its own data on TV licence fee payers”

I address the implications of this below in an update paragraph inserted in the original text. [/update]

Guidelines

In general Data Protection terms, once there is a statutory basis for processing (and access to data is processing) then the processing is lawful. What appears to be being proposed here is legislation that will allow subscriber data of one group of companies to be accessed by another company for the purposes of checking if someone is getting moving pictures on a telly box or similar device. So that’s the box ticked and we can move on, right? Oh, so long as we have protocols around the how, when, and why of access to the data right (because they are always followed)? And of course, the legislation will prevent scope creep in terms of  the use of the data and the potential sources of data that might be accessed using the legislation (e.g. telecommunications service providers who might have broadband going into a home or onto a device). Well, since April (and thanks to the great work of Digital Rights Ireland) we actually have some guidance from the Court of Justice of the European Union.

This is guidance that Minister Rabbitte’s department should be distinctly aware of as it affected legislation that they are responsible for, the Communications Data Retention Directive (from which the Irish Communications Data Retention Act got its authority). In that case, the ECJ was very clear: any processing of personal data needs to be a proportionate for the outcome required. In the Digital Rights Ireland case, the ECJ felt that requiring the retention of call traffic and internet usage data on the off chance it might be useful to authorities to counter terrorism was a disproportionate response. Access to specific data would not be disproportionate, but wholesale data slurping was a breach of fundamental rights to data privacy as enshrined in the EU Charter of Fundamental Rights. This reasoning was followed by Hogan J in the recent case of Schrems vs The Data Protection Commissioner in the High Court where Hogan deftly summarises the constitutional, statutory, and EU Treaty bases for Data Privacy rights in Ireland and the EU.

The upshot is that, regardless of the existence of a statutory authority to do a particular piece of processing, the processing itself must be a proportionate invasion of an individual’s right to Personal Data Privacy and their right to Privacy – two distinctly separate rights now under EU law. So, what would be a proportionate response in this context? How big is the problem?

The Proportionality Conundrum

According to the Minister, 16% of households don’t pay for a TV licence. According to ComReg 73% of households receive TV services via a subscription service. So 27% of people don’t pay for a TV service subscription and 16% don’t have a TV license, so there are more people who don’t have a paid TV subscription then don’t have a TV license? It is not outside the bounds of possibility that the ENTIRETY of the 16% that the Minister seeks to pursue are contained in the 27% that Sky and UPC would also love to separate from their subscriptions. Perhaps these people don’t have a television at all?

Even assuming that the two groups are unrelated, the question of whether allowing An Post access to the subscriber lists of UPC and Sky is a proportionate response. It’s not. If it is not a proportionate response for serious offences under the now defunct Data Retention Directive to allow law enforcement blanket access to telecommunications call history and internet usage data, it is probably not proportionate for a private company to have access to the subscriber lists of potential competitors (who knows what An Post might want to pivot into, given they are in the telecommunications business ) for the purposes of detecting where people don’t have a TV license.

[Update] Based on a report on TheJournal.ie, it appears that what is proposed is an en masse cross checking of data between An Post’s TV License database and the databases of Sky and UPC.  This is borders, in effect, on a form of mass surveillance. It is, in my opinion, that this would be seen as a proportionate response to the problem. This is particularly the case where alternatives to the bulk access to data can achieve the same overall objective without the need for the data to be processed in this way. [/update]

What would be proportionate would be for An Post to be able to make a request, on a case by case basis, for confirmation if a property which does not have a TV license is in receipt of a subscription TV service, once there was a detection that there was someone resident at the address or a business operating at the address which had a receiving device (i.e. a TV). Sky or UPC would simply need to respond with a “Yes they have service” or “No they do not” with no other data being accessed.

A wrinkle though…

One wrinkle is that Sky and UPC are not just TV service companies. They are telecommunications service providers as well. They provide home phone and broadband services. So the scope of the potential legislation is to allow a telecommunications company (An Post) access to the subscriber data of other telecommunications companies. This raises significant issues from a Data Protection perspective under SI336 ,where telecommunications providers have very serious security obligations to their subscribers around notifying of potential security issues on their network and also notifying subscribers and the Data Protection Commissioner where there has been a breach of data security.

It also raises the spectre of other telecommunications companies being required to provide the same data, depending on how the legislation is drafted.

Almost inevitably, the telecommunications providers would be asked to provide data to An Post about users who were accessing particular types of services or IP addresses (e.g. RTE online services or TV3 Player, or Netflix, or similar). This is EXACTLY the type of data that the ECJ has ruled on in the Digital Rights Ireland case. Proportionality raises its head again, along with the need to avoid information security breaches on the part of the telecommunications companies being asked to provide access to their data.

The Upshot

At this remove I can identify a few mechanisms that would be a proportionate interference in personal data privacy rights, and would minimise the risks of unauthorised access to or disclosure of subscriber data by a telecommunications service provider.

  1. An Post would need to make their requests as part of an investigation of a specific instance of an offence with a view to prosecution. Each request would need to relate to the investigation of a specific offence (“Mr X, at address Y, has no TV license but has a receiving apparatus he claims is not connected to any service, please verify he is not a subscriber”). The subscription TV service providers or Telecommunications service providers would simply respond back with a “Yes” or “No” to the specific question. But that answer may not confirm if they use their broadband to access streamed broadcast services. It is very easy to mask internet usage by using VPN tunnelling services, so the net may not catch all the fishes the Minister is trawling for.
  2. Another option would be to simply add the cost of the TV license to the subscription fee for Sky or UPC television services and, potentially, to the cost of broadband services in the State.  This would require zero sharing of data and a single annual transaction between the service providers and the State. It would also avoid entirely the risk of unauthorised access to or disclosure of subscriber data as a result of An Post (or any other entity) having access to subscriber data.

(Of course, just because you have a broadband connection doesn’t mean you are watching TV programmes on your device. I have a good friend who has a very large computer monitor and watches DVDs streamed from a laptop. They have broadband. For email, internet access, and work stuff. Their TV and movie viewing is entirely DVD boxed set driven.  A mechanism would be required for people in that category to opt-out, unless this is a flat-rate tax on telecommunications services flying under a false flag. That is a matter for a different blog post.)

What ever approach is ultimately taken it will need to constitute an invasion of data privacy that is proportionate to the problem that presents itself. THAT is the Data Protection requirement that must be met. It is not a guideline. It is the law, and it is a matter of fundamental rights.

For the Minister to view Data Protection as a “guideline” further evidences the horridly discordant tone at the top in the Irish State about Data Protection (which I’ve written about here and here and here and here).

Jul 1 14

Serendipity

by Daragh

So, within hours of me blogging about data protection consent issues in the Facebook mood manipulation study, the Register has the EXCLUSIVE that Facebook is being investigated by the irish DPC with specific questions around the consent relied upon. http://www.theregister.co.uk/2014/07/01/uk_and_irish_data_watchdogs_wade_in_on_facebook_messin_with_your_head_scandal/

I’m not saying anyone in an office above a Centra in Portarlington reads this blog but it is a serendipitous co-incidence.

And it may turn out that manipulating user timelines to provoke emotional responses could make Facebook management very sad.

Jul 1 14

Facebook, Manipulation, and Data Protection – part 2

by Daragh

Right. Having gotten some day job work out of the way I return to this topic to tease out the issues further.

One aspect that I didn’t touch on in the last post was whether or not Data Protection exemptions exist for research and if those exemptions apply in this case. This discussion starts from the premise that EU Data Protection law applies to this Facebook research and that Irish Data Protection law is the relevant legislation.

The Exemption

Section 2(5) of the Data Protection Acts 1988 and 2003 provides an exemption for processing for research purposes:

(a) “do not apply to personal data kept for statistical or research or other scientific purposes, and the keeping of which complies with such requirements (if any) as may be prescribed for the purpose of safeguarding the fundamental rights and freedoms of data subjects.

And

(b) “the data or, as the case may be, the information constituting such data shall not be regarded for the purposes of paragraph (a) of the said subsection as having been obtained unfairly by reason only that its use for any such purpose was not disclosed when it was obtained, if the data are not used in such a way that damage or distress is, or is likely to be, caused to any data subject

The key elements of the test therefore are:

  1. The data is being processed for statistical or scientific purposes
  2. And the processing of the data complies with requirements that might be prescribed for safeguarding fundamental rights and freedoms

This means that for research which is being undertaken for scientific purposes with an appropriate ethics review that has identified appropriate controls to safeguard fundamental rights of Data Subjects, which since the enactment of the Charter of Fundamental Rights in the EU includes a distinct right to personal data privacy. This was reaffirmed by the Digital Rights Ireland case earlier this year.

The question arises: was the Facebook study as scientific purpose? It would appear to be so, and in that context we need to examine if there was any processing requirements set out to safeguard fundamental rights and freedoms of Data Subjects. That is a function of the IRB or Ethics committee overseeing the research. Cornell University are clear that the issues of personal data processing were not considered in this case as their scientists were engaged in a review and analysis of processed data and they did not believe that there was human research being undertaken.

Whether or not you consider that line of argument to be Jesuitical bullshit or not is secondary to the simple fact that no specific requirements were set out from any entity regarding the controls that needed to be put in place to protect the fundamental rights and freedoms (such as freedom of expression) that the Data Subject should enjoy.

Legally this means that the two stage test is passed.  Data is being processed for a scientific purpose and there has been no breach of any provision set down for the processing of the data to safeguard fundamental rights, so consent etc. is not required to justify the processing and the standard around fair obtaining is looser.

Apparently if your review doesn’t consider your research to be human research then you are in the clear.

Ethically that should be problematic as it suggests that careful parsing of the roles of different participants in research activity can bypass the need to check if you have safeguarded the fundamental rights of your research subjects. That is why ethics reviews are important, and especially so when it comes to the ethics of “Big Data” research. Rather than assessing if a particular research project is human research we should be asking how it isn’t, particularly when the source of the data is identifiable social media profiles.

A Key Third test…

The third part of the test is whether or not the data is being used in a way that would cause damage or distress to the data subject. This is a key test in the context of the Facebook project and the design of the study. Consent and fair obtaining requirements can be waived where there is no likelihood of damage or distress being caused to the research subject.

However, this study specifically set out to create test conditions that would cause distress to data subjects.

It may be argued that the test is actually whether or not the distress would be measured as an additional level of distress that would be caused over and above the normal level of distress that the subject might suffer. But given that the Facebook study was creating specific instances of distress to measure a causation/correlation relationship between status updates and emotional responses, it’s hard to see how this element of the exemption would actually apply.

Had Facebook adopted a passive approach to monitoring and classifying the data rather than a directed approach then their processing would not have caused distress (it would have just monitored and reported on it).

The Upshot?

It looks like Facebook/Cornell might get off on a technicality under the first two stages of the test. They were conducting scientific research and there was no prerequisite from any Ethics committee to have any controls to protect fundamental rights. However that is simply a technicality and it could be argued that, in the absence of a positive decision that no controls were needed, it may not be sufficient to rely on that to avail of the Section 2(5) exemption.

However, it may be that the direct nature of the manipulation and the fact that it was intended to cause distress to members of the sample population might negate the ability to rely on this exemption in the first place, which means that consent and all the other requirements of the Data Protection Acts should apply and be considered in the conduct of the research.

The only saving grace might be that the level of distress detected was not found to be statistically large. But to find that they had to conduct the questionable research in the first place.

And that brings us back to the “wibbly-wobbly, timey-wimey” issues with the consent relied upon in the published paper.

Ultimately it highlights the needs for a proactive approach to ethics and data privacy rights in Big Data research activities. Rather than assuming that the data is not human data or identifiable data, Ethics committees should be invoked and required to assess whether the data is and ensure that appropriate controls are defined to protect fundamental rights. Finally, the question of whether distress will be caused to data subjects in the course of data gathering needs to be a key ethical question as it can trigger Data Protection liability in otherwise valuable research activities.

Jul 1 14

Facebook Research, Timeline Manipulation, & EU Data Protection Law

by Daragh

This is an initial post based on the information I have to hand today (1st July 2014). I’ve written it because I’ve had a number of queries this morning about the Data Protection implications of Facebook’s research activity. I’m writing it here and not on my company’s website because it is a work in progress and is my personal view. I may be wrong on some or all of these questions.

Question 1: Can (or should) the Data Protection Commissioner in Ireland get involved?

Facebook operates worldwide. However, for Facebook users outside the US and Canada, the Data Controller is Facebook Ireland, based in Dublin. Therefore EU Data Protection laws, in the form of the Irish Data Protection Acts 1988 and 2003 applies to the processing of personal data by Facebook. As a result, the Irish Data Protection Commissioner is the relevant regulator for all Facebook users outside the US and Canada. The key question then is whether or not Facebook constrained their research population to data subjects (users) within the US and Canada.

  • If yes, then this is not a matter for investigation by EU data protection authorities (i.e. the Data Protection Commissioner).
  • If no, then the Irish Data Protection Commissioner and EU Data Protection laws come into play.

If Facebook didn’t constrain their population set, it is therefore possible for Facebook users outside of the US and Canada to make a complaint to the DPC about the processing and to have it investigated. However, the DPC does not have to wait for a complaint. Section 10 of the Data Protection Acts empowers the Commissioner to undertake “such investigations as he or she considers appropriate” to ensure compliance with legislation and to “identify any contravention” of the Data Protection Acts 1988 and 2003.

[update] So, it is clear that the data was obtained from a random sample of facebook users. Which raises the question of the sampling method used – was it stratified random sampling (randomised within a sub-set of the total user base) or random sampling across the entire user base? If the former then the data might have been constrained. If the latter, the data inevitably will contain data subjects from outside the US/Canada region. [/update]

Answer: If Facebook hasn’t constrained their population to just North America (US/Canada) then… Yes.

Question 2: If Irish/EU Data Protection Law applies, has Facebook done anything wrong?

Tricky question, and I wouldn’t want to prejudge any possible investigation by the Data Protection Commissioner (assuming the answer to Question 1 would get them involved).  However, based on the information that is available a number of potential issues arise, most of them centred on the question of consent. Consent is a tricky issue in academic research, market research, or clinical research. The study which was conducted related to the psychological state of data subjects. That is categorised as “Sensitive Personal Data” under the Data Protection Acts. As such, the processing of that data requires explicit consent under Section 2B of the Acts. Beyond the scope of the Data Protection Acts, clinical research is governed by ethical standards such as the Nuremburg Code which also requires a focus on voluntary and informed consent:

The voluntary consent of the human subject is absolutely essential… and should have sufficient knowledge and comprehension of the elements of the subject matter involved as to enable him to make an understanding and enlightened decision. This latter element requires that before the acceptance of an affirmative decision by the experimental subject there should be made known to him the nature, duration, and purpose of the experiment

Question 2A: Was Consent Required? Consent is required for processing of sensitive personal data. For that data to be sensitive personal data it needs to be data that is identifiable to an individual and is sensitive in nature. However, if the data being processed was anonymised or pseudonymised then it falls outside the scope of personal data, assuming appropriate controls are in place to prevent re-identification. The Irish Data Protection Commissioner has published guidance in 2007 on Clinical Research in the Healthcare sector which provides some guidance on the question of consent, albeit from the perspective of a pure clinical healthcare perspective. A key point in the guidance is that while anonymising data may remove the Data Protection question around consent, it doesn’t preclude the ethical questions around conducting research using patient data. These kind of questions are the domain of Ethics Committees in Universities or commercial research organisations. Research of this kind are governed by Institutional Review Boards (IRB) (aka Ethics Committees).

Apparently Cornell University took the view that, as their researchers were not actually looking at the original raw data and were basing their analysis of results produced by the Facebook Data Science team they were not conducting human research and as such the question of whether consent was required for the research wasn’t considered. The specifics of the US rules and regulations on research ethics are too detailed for me to go into here. There is a great post on the topic here which concludes that, in a given set of circumstances, it is possible that an IRB might have been able to approve the research as it was conducted given that Facebook manipulates timelines and algorithms all the time. However, the article concludes that some level of information about the research, over and above the blanket “research” term contained in Facebook’s Data Use policy would likely have been required (but not to the level of biasing the study by putting all cards on the table), and it would have been preferable if the subjects had received a debrief from Facebook rather than the entire user population wondering if it was them who had been manipulated. Interestingly, the authors of the paper point to Facebook’s Data Use Policy as the basis of their “informed consent” for this study:

As such, it was consistent with Facebook’s Data Use Policy, to which all users agree prior to creating an account on Facebook, constituting informed consent for this research.

Answer: This is a tricky one. For the analysis of aggregate data no consent is required under DP laws and, it appears, it raises no ethical issues. However, the fact that the researchers felt they needed to clarify that they had consent under Facebook’s Data Use policy to conduct the data gathering experiments suggests that they felt they needed to have consent for the specific experimentation they were undertaking, notwithstanding that they might have been able to clear ethical hurdles over the use of the data once it had been obtained legally.

Question 2b: If consent exists, is it valid? The only problem with the assertion by the researchers that the research was governed by Facebook’s Data Use policy is that, at the time of the study (January 2012) there was no such specified purpose in Facebook’s Data use policy. This has been highlighted by Forbes writer Kashmir Hill.

The text covering research purposes was added in May 2012. It may well have been a proposed change that was working its way through internal reviews within Facebook, but it is impossible for someone to give informed consent for a purpose about which they have not been informed. Therefore, if Facebook are relying on a term in their Data Use Policy which hadn’t been introduced at the time of the study, then there is no valid consent in place, even if we can assume that implied consent would be sufficient for the purposes of conducting psychological research. If we enter into a degree of speculation and assume that, through some wibbly-wobbly timey-wimey construct (or Kashmir Hill having made an unlikely error in her analysis), there was a single word in the Data Use Policy for Facebook that permitted “research”, is that sufficient?

For consent to be valid it must be specific, informed, unambiguous, and freely given. I would argue that “research” is too broad a term and could be interpreted as meaning just internal research about service functionality and operations, particularly in the context in which it appears in the Facebook Data Use Policy where it is lumped in as part of “internal operations”. Is publishing psychological and sociological research part of Facebook’s “internal operations”? Is it part of Facebook’s “internal operations” to try to make their users sad? Interestingly, a review of the Irish Data Protection Commissioner’s Audit of Facebook in 2012 reveals no mention of “Research” as a stated purpose for Facebook to be processing personal data. There is a lot of information about how the Facebook Ireland User Operations team process data such as help-desk queries etc. But there is nothing about conducting psychometric analysis of users through manipulation of their timelines. Perhaps the question was not asked by the DPC?

So, it could be argued by a Data Protection regulator (or an aggrieved research subject) that the consent was insufficiently specific or unambiguous to be valid. And, lest we forget it, processing of data relating to Sensitive personal data such as psychological health, philosophical opinions etc. requires explicit consent under EU law. The direct manipulation of a data subject’s news feed to test if it made them happier or sadder or had no effect might therefore require a higher level of disclosure and a more positive and direct confirmation/affirmation of consent other than “they read the document and used the service”. There are other reasons people would use Facebook other than to be residents of a petri dish.

Does this type of research differ from A/B testing in user interface design or copywriting? Arguably no, as it is a tweak to a thing to see if people respond differently. However A/B testing isn’t looking for a profound correlation over a long term between changes to content and how a person feels. A/B testing is simply asking, at a point in time, whether someone liked presentation A of content versus presentation B. It is more functionally driven market research than psychological or sociological analysis.

Answer: I’d have to come down on the negative here. If consent to the processing of personal data in the manner described was required, it is difficult for me to see how it could be validly given, particularly as the requirement is for EXPLICIT consent. On one hand it appears that the magic words being relied up on by the researchers didn’t exist at the time of the research being conducted. Therefore there can be no consent. Assuming some form of fudged retroactivity of consents given to cover processing in the past, it is still difficult to see how “research” for “internal operations” purposes meets the requirement  of explicit consent necessary for psychological research of this kind. It differs to user experience testing which is more “market research” than psychological and therefore is arguably subject to a higher standard.

Question 3: Could it have been done differently to avoid Data Protection Risks

Short answer: yes. A number of things could have been done differently.

  1. Notification of inclusion in a research study to assess user behaviours, with an option to opt-out, would have provided clarity on consent.
  2. Analysis of anonymised data sets without directed manipulation of specific users timelines would not have raised any DP issues.
  3. Ensure validity of consent. Make sure the text includes references to academic research activities and the potential psychological analysis of user responses to changes in Facebook environment. Such text should be clearly highlighted and, ideally, the consent to that element should be by a positive act to either opt-in (preferred) or to opt-out
  4. Anonymise data sets during study.
  5. Restrict population for study to US/Canada only – removes EU Data Protection issues entirely (but is potentially a cynical move).

Long Answer: It will depend on whether there is any specific finding by a Data Protection Authority against Facebook on this. It does, however, highlight the importance of considering Data Protection compliance concerns as well as ethical issues when designing studies, particularly in the context of Big Data. There have been comparisons between this kind of study and other sociological research such as researchers walking up to random test subjects and asking them to make a decision subject to a particular test condition. Such comparisons have merit, but only if we break them down to assess what is happening. With those studies there is a test subject who is anonymous, about whom data is recorded for research purposes, often in response to a manipulated stimulus to create a test condition. The volume of test subjects will be low. The potential impact will be low. And the opportunity to decline to participate exists (the test subject can walk on by… as I often did when faced with undergrad psychology students in University) With “Big Data” research, the subject is not anonymous, even if they can be anonymised. The volume of test subjects is high. Significantly (particularly in this case) there is no opportunity to decline to participate. By being a participant in the petri-dish system you are part of the experiment without your knowledge. I could choose to go to the University coffee shop without choosing to be surveyed and prodded by trainee brain monkeys. I appear to have no such choice with Data Scientists. The longer answer is that a proper consideration of the ethics and legal positioning of this kind of research is important.

%d bloggers like this: