<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The DOBlog &#187; Read/Write Collaboration</title>
	<atom:link href="http://obriend.info/category/business/web-20/readwrite-collaboration/feed/" rel="self" type="application/rss+xml" />
	<link>http://obriend.info</link>
	<description>Daragh O Brien on Information Quality Management &#38; other issues</description>
	<lastBuildDate>Mon, 06 Feb 2012 15:14:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Setting tone from the Top</title>
		<link>http://obriend.info/2011/01/05/setting-tone-from-the-top/</link>
		<comments>http://obriend.info/2011/01/05/setting-tone-from-the-top/#comments</comments>
		<pubDate>Wed, 05 Jan 2011 16:34:19 +0000</pubDate>
		<dc:creator>Daragh</dc:creator>
				<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Read/Write Collaboration]]></category>
		<category><![CDATA[Web 2.0]]></category>
		<category><![CDATA[fine gael]]></category>
		<category><![CDATA[privacy by design]]></category>

		<guid isPermaLink="false">http://obriend.info/2011/01/05/setting-tone-from-the-top/</guid>
		<description><![CDATA[In the rush to adopt new technologies and new ways of working, particularly When an organisation embarks on a change to systems and processes it is often very easy to get caught up in the whirlwind of enthusiasm for the new technology and the promised benefits of new ways of working. Nearly 2 years ago [...]]]></description>
			<content:encoded><![CDATA[<p>In the rush to adopt new technologies and new ways of working, particularly When an organisation embarks on a change to systems and processes it is often very easy to get caught up in the whirlwind of enthusiasm for the new technology and the promised benefits of new ways of working.</p>
<p>Nearly 2 years ago <a href="http://obriend.info/2009/03/24/politics-20-and-information-quality/">I wrote a post on this blog</a> about the adoption of US style internet campaigning and the use of Web2.0 in Irish politics from an information quality perspective. The scorecard wasn&#8217;t good from a data quality perspective. The strategy seemed to be &#8220;If Obama can get elected using this Internet thingy, then we need to copy what he did&#8221;. No attention seemed to have been paid to the simple fact that a &#8220;cut and paste&#8221; adoption of a pre-canned solution from elsewhere would not necessarily work.</p>
<p>2 years on I would have thought that some lessons might have been learned. So when Fine Gael announced they&#8217;d &#8220;stood down&#8221; their finegael.ie website in favour of a more <a href="http://finegael2011.com/">interactive presence</a> in the run up to the election I thought I&#8217;d take a quick look. While the Information Quality issues with the form were not <em>too</em> bad, the structure and operation of the site raise a number of concerns from a Data Protection perspective.</p>
<p>Bluntly – when a US election solution provider rolls up in Europe they will find that they literally ain&#8217;t in Kansas anymore, particularly with regards to what you must and must not do with regards to the capture and processing of personal data. Political parties buying these services need to be aware that they are Data Controllers and that the solution providers are Data Processors in the context of the Data Protection Acts 1988 and 2003.</p>
<p>Failure to set the &#8220;tone at the top&#8221; and cascade it through the organisation means that often the important questions are not asked (or the answers are ignored).</p>
<p>Ultimately, in a Data Protection context, you are dealing with issues that can impact on your brand. If you are positioning yourself as being a political party that will &#8220;get tough&#8221; with vested interests through more effective regulation and enforcement you can&#8217;t really start the ball rolling by flouting basic principles of Data Protection law.</p>
<p>Indeed, back as far as 2004 the Data Protection Commissioner wrote:</p>
<blockquote><p><span style="font-family: Verdana; font-size: 9pt;">It is important that public representatives and candidates for elective office realise the importance of their obligations under the Acts and that, in so far as responding to legitimate investigations from statutory office holders is concerned, in no sense should they consider themselves above the Law<br />
</span></p></blockquote>
<p>In <a href="http://www.dataprotection.ie/documents/annualreports/AR2010.pdf">2009&#8242;s annual report</a> the Commissioner also wrote that:</p>
<blockquote><p>Rapidly changing technology can be both a threat to this right and the means of protecting it. Building data protection safeguards into new technologies and applications of these technologies remains the best approach. This is as much true of data processing in the &#8220;cloud&#8221; as it is of a routine development of an IT application in an organisation.</p></blockquote>
<p>So… the issues?<span id="more-576"></span></p>
<h3>Obscured by Clouds (Personal Data and Cross Border Transfer)</h3>
<p>This site appears to be a reskinning of a solution provided by <a href="http://electionmall.com">Electionmall.com</a>, a US-based provider of &#8220;on demand&#8221; web-based campaign tools. So, FG have embraced the Cloud. However, as I&#8217;ve repeatedly said through 2010, and as the Irish Data Protection Commissioner also clarified at a number of events in 2010, there are certain due diligence steps that Data Controllers (and FG is a Data Controller) need to perform before embracing cloud.</p>
<ol>
<li><strong>Where is the data going?</strong> It would seem that the Data Processor in this case (ElectionMall Technologies) is a US based company. Transfer of Personal Data to the US from the EU is permitted where the Data Processor is registered with the <a href="http://www.export.gov/safeharbor/eg_main_018236.asp">Safe Harbor</a> scheme. EMT does not appear to be listed on the <a href="https://safeharbor.export.gov/list.aspx">Safe Harbor list</a> (feel free to search for yourself – I couldn&#8217;t find them). EMT state (in their <a href="http://www.electionmall.biz/_privacy_policy.asp">privacy policy</a>) that the data is processed on their servers in the US, but the way this privacy statement is drafted it seems to be directed at the processing of personal data of <strong>their customers</strong> (who are the politicians) not necessarily the actual individuals who may submit data. The Data Protection Commissioner has <a href="http://www.dataprotection.ie/ViewDoc.asp?fn=/documents/responsibilities/3ma.htm&amp;CatID=56&amp;m=y">some good advice for organisations considering transferring personal data abroad</a>.</li>
<li><strong>Is there a contract?</strong> The Data Protection Acts require any processing being undertaken by a Data Processor to be done so on foot of a written contract. Given that Enda Kenny famously took out a contract for Ireland in the 2007 General Election, one must assume that there is a clear contract that gives FG assurances re: technical and organisational measures re: security and Data Protection compliance in EMT. This is an issue for any organisation that is outsourcing the processing of personal data to a &#8220;Cloud&#8221; provider. Where the Data Processor in turn has hosting services provided by another 3<sup>rd</sup> party, that &#8220;chain of contracts&#8221; can become important if there is a loss of personal data or an unauthorised disclosure.</li>
</ol>
<p>Over on my company site I have a tutorial on Data Protection in Cloud Computing.</p>
<h3>Fair Use/Fair Obtaining</h3>
<p>S2 of the Data Protection Acts deals with the whole area of fair obtaining and fair use of personal data, including Sensitive Personal Data. There is a requirement for websites which are capturing personal data (and which fall within the remit of the Acts) to have a Privacy Statement. The <a href="http://www.dataprotection.ie/docs/PrivStatements/290.htm">Commissioner is quite clear about this</a>. If data has not been obtained fairly it cannot be processed. I&#8217;ve looked all over <a href="http://finegael2011.com/">finegael2011.com</a> and cannot find a link to any Privacy Statement. (Unfortunately this is all too true for a number of other commercial and political websites from Ireland that I&#8217;ve looked at recently). The Commissioner provides some basic guidelines as to what should be in a Privacy Statement, including the need to take cross border data transfers into account when including information in the Privacy Statement and the importance of having contracts with Data Processors.</p>
<p>Examples of Political Party privacy statements include: <a href="http://www.fiannafail.ie/content/pages/privacy-policy/">Fianna Fail</a>, the <a href="http://www2.labour.org.uk/privacy">UK Labour Party</a> , <a href="http://www.conservatives.com/Information/Privacy.aspx">UK Conservatives</a>.</p>
<p>Ultimately, the test of a Privacy Statement is whether something happens with personal data provided which a reasonable person reading the statement wouldn&#8217;t have expected to happen. For example, if you have to provide an email address to make a comment on a site but you find you&#8217;ve been added to a mailing list as a result then that would need to have been made clear in the Privacy Statement.</p>
<p>Likewise, if your personal data is being transferred outside of the EU to a Data Processor then that too would have to be made clear in the Privacy Statement, along with the grounds on which that transfer was legitimate (e.g. the Data Processor is Safe Harbor registered).<strong><br />
</strong></p>
<p>While political parties, politicians, and candidates for elected office enjoy certain exemptions under the Data Protection Acts they do not have immunity from the Acts. <a href="http://www.dataprotection.ie/viewdoc.asp?Docid=264">This case study</a> from the Data Protection Commissioner&#8217;s website outlines the nature of those exemptions quite well. The exemptions extend to the processing of and disclosure of data, in particular Sensitive personal data (which includes statements of political opinion or belief). A key element of these exemptions in the context of an Election campaign would be S2B(1)(ix) which allows sensitive personal data to be processed by political parties without consent &#8220;in the course of electoral activities for the purpose of compiling data on people&#8217;s political opinions&#8221;.</p>
<p>They do not absolve politicians and political parties from the need to comply with the rest of their duties as Data Controllers under the Acts.</p>
<h2>Wrap up</h2>
<p>&#8220;Privacy by Design&#8221; is becoming the mantra of Data Protection enforcement world wide. Simply cutting and pasting a solution from another jurisdiction into an Irish or EU context invites breaches of legislation and failures of the required governance and controls. This is not just a technology issue.</p>
<p>Given that politicians are asking us to trust them, they should ensure that they take the necessary steps to earn that trust. Just like any other organisation embracing new technologies, they must ensure that the necessary due diligence and governance structures are in place to ensure that they are acting in compliance with long established legislation. If they are promoting a &#8220;tough on regulation&#8221; policy platform, then they must lead with a clear &#8220;tone from the top&#8221; of Compliance and good Governance.</p>
<p>In short they must <strong>Lead</strong>.</p>
]]></content:encoded>
			<wfw:commentRss>http://obriend.info/2011/01/05/setting-tone-from-the-top/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>Imitation the sincerest form of flattery</title>
		<link>http://obriend.info/2008/10/23/imitation-the-sincerest-form-of-flattery/</link>
		<comments>http://obriend.info/2008/10/23/imitation-the-sincerest-form-of-flattery/#comments</comments>
		<pubDate>Thu, 23 Oct 2008 12:10:28 +0000</pubDate>
		<dc:creator>Daragh</dc:creator>
				<category><![CDATA[Information Quality]]></category>
		<category><![CDATA[Read/Write Collaboration]]></category>
		<category><![CDATA[The Business of IQ]]></category>
		<category><![CDATA[Web 2.0]]></category>

		<guid isPermaLink="false">http://obriend.info/?p=259</guid>
		<description><![CDATA[I noticed that Informatica have launched a new website called www.doyoutrustyourdata.com, to highlight issues with poor quality information from the media. My personal opinion on the site is that it isn&#8217;t very nice looking (but then I&#8217;m not a big fan of black on green). However, I&#8217;m biased as I moderate the IQTrainwrecks.com blog for [...]]]></description>
			<content:encoded><![CDATA[<p>I noticed that Informatica have launched a new website called <a href="http://www.doyoutrustyourdata.com">www.doyoutrustyourdata.com</a>, to highlight issues with poor quality information from the media.</p>
<p>My personal opinion on the site is that it isn&#8217;t very nice looking (but then I&#8217;m not a big fan of black on green). However, I&#8217;m biased as I moderate the <a href="http://www.iqtrainwrecks.com">IQTrainwrecks.com </a>blog for the IAIDQ which has been doing this for over 2 years now in an occasionally tongue in cheek manner. IQTrainwrecks.com gets reasonably good search returns on google (and we&#8217;re looking at ways to improve that further). </p>
<p>I&#8217;m flattered that Informatica have stumbled upon the same idea that the IAIDQ had back in 2006. I hope that we can figure out a way to have both sites working together for the benefit of information consumers everywhere. For example, the IAIDQ would love to reward members for submitting stories to IQTrainwrecks.com but our resources aren&#8217;t extensive enough to fund that (yet).</p>
<p>[Update] As Vincent McBurney correctly points out, the <a href="http://iaidq.org">IAIDQ</a> wasn&#8217;t the first to try to create a resource like this. <a href="http://iqtrainwrecks.com">IQTrainwrecks</a> is a spiritual descendant of <a href="http://dataquality.com">www.dataquality.com</a> and also the listing of issues that Tom Redman has been tracking over on <a href="http://navesink.com">www.navesink.com</a>). [/update]</p>
]]></content:encoded>
			<wfw:commentRss>http://obriend.info/2008/10/23/imitation-the-sincerest-form-of-flattery/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

