Showing posts with label GDPR. Show all posts
Showing posts with label GDPR. Show all posts

2025-11-15

Personal use call recordings

This has me a tad unsure, and curious on views...

Someone on the internet said ...

... that it is better to not use a call recording when making a complaint or dispute. Why? Because you can "legally only make the call recording for personal use".

Well, yes, first off, GDPR related, "personal use" is a thing that takes stuff out of  GDPR. But it is also possible to make a call recording as someone registered with the ICO under GDPR and comply with the rules and use for something else. After all, the call centre you are calling does that. But I fully agree, that would be unusual for someone personally making some sort of complaint. So yes, it would be for "personal use".

But then, surely, "personal use" must cover "having a record of what I said and what was said to me", and "personally using that in a court or with an ombudsman" - is that "personal use"? Maybe, maybe not, I really do not know.

But then... I could definitely make "personal use" of a recording to "aid my memory" in making a transcript of the call - nobody else hears the recording, only me. And making a transcript of a call is something I can legitimately do with, or without, a call recording, yes? The fact that "I made this transcript using a call recording to aid my memory so as to ensure it is 100% accurate" has to carry a lot of weight with a court or ombudsman. Indeed, if the other party claimed my transcript is wrong, it starts to be accusations of fraud, and I am sure in such cases a recording could then be used to validate the transcript, surely?

I also seriously doubt a court or ombudsman would ever exclude a call recording anyway. The other party raising legal objections that the recording should not have been made would rather hurt their argument as it is "we only said wrong things because we thought you would not have proof of it". Of course if a court or ombudsman said they won't accept a call recording, you just say "fine, here is the transcript I made, using the call recording to aid my memory" (perhaps even with an oath of its accuracy) - they are going to accept that - so the call recording has been useful.

I also find that simply saying "I'll check the call recording" is a hugely powerful phrase, and you don't even need the recording most of the time!

However, this then got me thinking of the alternatives suggested.

Email - keeping a record of the emails sent and received. I 100% agree this better, but not based on "not being able to use a call recording". I can take my time composing an email (I fail to do that some times, sadly). I can avoid losing my cool, etc. But then so can the other party (and they may have more training and practice).

My thought here is: how exactly is a record of an email exchange any different, legally, from a record of a spoken exchange. Why would one be "legal" and one not? Surely they hold the same "personal information" (if any). Does GDPR differentiate between them? Or is this not GDPR but something else? Surely the record of emails is just as much only allowed for "personal use"?

And how is that different than taking a screenshot of an "on-line chat" (another suggested idea). This even has the fact that the other party cannot simply assume that of course you have a copy (like email), as you had to actively make a copy, without asking.

And really, how is this different from old school written letters?

I am curious to know - where is the line drawn, why, and by what law?

2024-02-27

CCTV

Warehouse 22?
Picking a CCTV management system

CCTV has moved on a lot these days, and there are a lot of cameras now. Some use proprietary systems, and some have clever custom detection and face recognition and ANPR and hardware inputs and outputs. Some have low light colour. Some have infrared. The options are endless.

But ultimately, whatever they are, you want a management system to record and allow local and remote viewing, alerts and events, basically providing a way to see what is going on and what happened later.

At home

At home, a CCTV system is largely engineered to be a deterrent for theft. A house with a load of cameras should be less likely to be burgled than the next house with none.

But it has a load of other uses, and ironically the main one is deliveries.

  • Seeing a delivery in real time remotely, even "talking through the camera" to the delivery person when not there.
  • Proving they did not delivery when they said they did, or that they "chucked it over the fence and that is why it broke".

But also, police, and neighbours, may ask if your camera caught something. Yes, this surprising (police asking) as it is an issue with ICO guidance, which is very confusing. They work on the basis of a case law that somehow, even though the collection and processing of potentially personal information is for personal domestic use (so outside scope of GDPR), that somehow it matters what you are seeing with the camera - i.e. seeing a road or path that is off your land. The GDPR does not have that as a criteria, and the second you try to apply that logic it to dash cams and cycle helmet cams and the like it all falls apart. I.e. my cycle helmet cam is "OK" somehow (personal use) but park my bike by the wall of may house and put the helmet on it, viewing the road, is that OK? Then run a power lead to the helmet cam so it runs 24/7, is that OK? As what point does it become not OK as it is a CCTV on my house viewing the road, not a camera on my cycle helmet viewing the road. No logic to it at all.

Of course, even if camera covers public spaces, you can "mask" them on many cameras now, to meet ICO rules.

I also wonder about CCTV, especially the CC part. What if I made cameras open to the world on the internet, it is then OCTV not CCTV, so do any of the ICO rules on CCTV now apply?

At work

At work is different, not personal/domestic use, so needs proper ICO registration, privacy policies, and notices, but once sorted you can run CCTV. There are a lot of legitimate interests for any business running CCTV, for crime detection prevention, both external (break in) and staff fraud (eeeew, don't trust your staff?). As long as you are totally clear about the CCTV, and how and what is processed for what purpose you are probably OK, but don't take my word for it - get legal advice.

Back to the point - recording and management

Whatever cameras you use, and as I say - there are a lot, you need a way to view live, and record, and view and save recordings.

There are many systems, and I have used several. However, the latest I am using has impressed me, so much I feel I should share my fortune and tell you all about it.

The system is "NX Witness", and Simon (of Dedicated Programmes) is an expert at settings these up (and supplying a range of cameras). I am lucky to have got a system from him as a birthday present, thank you.

  • It is easy to use
  • It is slick
  • It is fast
  • It is so very responsive

I have used Synology previously, and once wanted to check a delivery (that did throw a parcel over the fence) remotely from mobile, and it took me like half an hour. It was so slow and unresponsive and hard to use.

NX Witness, just works. An app on my phone and on my Mac, but I understand Android and Windows are just as easy.

I had to ask Simon how I save a video clip, as on Synology it was a nightmare, and he was "Duh! draw on timeline, right lick, export video", and it was, and it worked, and that was it!

When I click a time in the past the videos all show it, instantly, no delay. When I click a motion event, the same.

And I have custom icons on my videos now that allow me to turn on lights, open gate, and so on, simply, from my phone.

I really an impressed, simple as that!

Record all

You could record only on motion or events, but hard disks are cheap enough, and recording all has advantages.

The NX Witness makes it easy to see the motion events, and the like.

But recording all allows you to also see when something didn't happen! When a delivery claimed to happen and you can send video covering 10 minutes either side of the time with no delivery happening.

So that is what I do, only for maybe a month's worth, but that allows me to find something if I need.

One edge case was damage to some rendering on a wall, on Synology it was hard to track down, and I imagine on NX witness it would be so much quicker. It was focusing on events for a small part of the image, and the NX witness lets me highlight an area and pick only motion events covering that area.

Don't use WiFi

This should not need saying, but so many cameras these days are WiFi, and even "only 2.4GHz". Just say no. Sorry. Apart from the ease of jamming the WiFi if you want to not be seen, WiFi is very much a shared medium, and a couple of cameras constantly streaming over WiFi can make it shit very quickly.

You need wires anyway for power to the camera, so use PoE, one wire, not that hard even if it means a few holes and cable clips.

Public space

A small follow up because of a comment.

The issue with GDPR is that it covers the purpose of the processing, being domestic/personal, not what you are processing, which is why the case law on CCTV covering a public space makes no sense. And so why trying to draw a line makes no sense. The fact that helmet cams and dash cams are OK, even recording public space, but not fixed CCTV, is a totally mental and wrong interpretation of the law.

I have a couple of good examples. One relative has a doorbell camera, but the house is directly on the public pavement. So to record anything they are recording public space, even when it is a delivery person ringing their door bell. That clearly should be allowed as personal/domestic purpose. (I am lucky to have a small (maybe 1m) space from public pavement).

On the other hand I have a corner that is tarmac'd along with the pavement. I was careful to ensure the tarmac has a clear line for the border of my properly, but lots of people, almost everyone, cuts the corner, walking over my properly when simply walking along the public road. So, in my case, I can record them, under ICO rules, as they are on my property. I have no real reason to, other than I am allowed to as they have not jumped over my gate, etc.

2023-03-09

Bed sensor

Some time ago I got a Withings sleep sensor. Not cheap. I am not really sure it helps me understand my sleep well. It does a lot - tracks sleep, types of sleep, snoring, sleep apnea, heart rate. Clever bugger.

However, it does not allow you to use it without consenting to your data being used for other things, which, seems to me, to be a clear breach of GDPR. Obviously I reported it, and ICO were obviously inept, though they got as far as referring to EU, and then Brexit happened, so no idea where the case is now. I think it has fallen down the cracks and Withings just ignore GDPR, it seems.

Apart from some interest in what it says about my sleeping, my main use for this is reporting to my home automation when I go to bed and when I get up. I then link this to various things from simple lights, to air-con, directing the vents for lossnay (fresh air), illumination settings on environmental sensors, and so on. I rather like that lying down turns off the lights, and that getting up in the night turns on one light on a mirror in the en-suite bathroom. If I get up in the morning for 5 minutes it turns on the rest of the lights, and my office air-con, and so on. The possibilities are endless and there are people that are way more in to this than I am.

The problem is that the way this works is convoluted!

  • Sensor detects in/out of bed.
  • Sends to Withings which is in France I think
  • That is linked IFTTT - no idea where that is
  • IFTTT does a get on my server in my loft
  • My server pokes MQTT for various things to happen

It can take a few seconds to a few minutes, or not at all if any servers or internet access is not working.

The solution

Recently I realised that a simple bed sensor mat is something one can buy cheaply. I mean I realise now that obviously such things must exist, but it had not occurred to me before.

I got one of them - a larger one for a bed (amazon, or cheaper direct). They also sell smaller ones. They could be used on a bed, a wheel chair, even under a door mat. They are sold for healthcare to track someone getting out of bed, or falling out of wheelchair, etc.

I was surprised to find it copes with my thick memory foam mattress, and slats. The Withings one has a pump to pump it up with air to adjust for weight of things like a mattress, but it is doing more than just detecting I am on the bed (e.g. heart rate, etc).

Withings (top, grey) and new sensor (bottom, white)

The trick is what they connect to - alarm devices are sold to work with them. I decided to give it a try, and found it was actually easy to make this work with my home automation. The trick was to use a Shelly Plus i4 DC (here). The reason for the DC model is that I don't want mains under my bed really, and the switch inputs on most Shelly are mains. They do an isolator which has digital and analogue inputs which would allow a Shelly Plus 1 to be used, but the DC i4 is easier. The other feature is it can work from 5V to 24V, and so can be powered from a USB socket. I got a USB lead (amazon).

Too many USB devices already!

The wiring was simple - the sensor appears to be a simple passive sensor. The 4 wires are actually two wires connected and two wires connected, so only effectively two wires, between which is open circuit when no pressure. When pressure applied they go to around 2kΩ, but I suspect it changes with the level of pressure. Thankfully it is low enough to trigger the input on the Shelly Plus i4 DC.

The sensor operates like a switch input, and so can be linked in to any home automation that can work with a Shelly. There is HomeKit stuff for that, but I re-flash with tasmota personally. Obviously this could work up to 4 such sensors, ideal for his/her side of bed, or floor mats as well, etc.

The nice thing is that it is instant in reacting, though obviously I can add a delay if I want. The important thing is it is not a random 10 seconds or several minutes delay as before.

2022-12-02

Dave

So it seems, from what I can tell, under UK GDPR...

✓ Banning someone from your service called "Dave"

Yep, it seems GDPR does not have any issue with your refusing someone "joining a service" based on some aspect of their personal information as long as it it not some discrimination related protected characteristic. So if you designed your system to not allow anyone called "Dave" you can do that.

✓ Banning someone changing their name to "Dave"

Surprisingly, despite the UK GDPR "right to rectification", a company, it seems, according to the ICO and even the parliamentary ombudsman, a company can refuse your changing personal information in any way they like as long as it is a "technical issue". I.e. if you designed a system that cannot handle some specific personal information for some arbitrary reason (such as a short email address, or a name of "Dave") then that is a valid excuse, even though nothing in UK GDPR seems to say it is a valid excuse, and you can refuse to allow the change.

Yep, it is all messed up. What a surprise!

P.S. changing your name to Dåve would probably be something you can insist on, due to case law: https://gdprhub.eu/index.php?title=Court_of_Appeal_of_Brussels_-_2019/AR/1006

2022-08-31

Is GDPR even more flawed than I thought?

NHS Digital have refused to update my personal information, even though I have a right to rectification under GDPR.

As I have previously posted, I think GDPR has a flaw, in that it seems an organisation can say they will not "accept" you as a customer/client/whatever if they don't like some aspect of your personal information (in this case, the length of my email address). This seems broken, given that once they have accepted you, then you have a right to have personal data corrected. I have asked my MP if they can try and poke someone to fix this flaw in GDPR. My personal information is what it is, including the many bits I get to choose (like name, religion, email address, etc).

But it sounds like it is even more flawed than I thought! It seems that an organisation can simply refuse to update the personal information, instead just terminating access.

Apparently I am welcome to re-register with NHS Digital, providing I comply with their rules on my personal information.

Now, this is, in my case "just" my email address, but it sounds like the same logic could apply to someone's choice of name, or religion, or gender and job title combination, well, anything. Just make up arbitrary rules and refuse anyone that does not fit, cancelling their service if they ask for it to be corrected.

It makes a total mockery of the "right to rectification" even being in GDPR.

How can I have a "right" which can be so simply side-stepped. Does this create a situation where people will be afraid to ask for data to be corrected for fear they lose some service?

I wonder what taking them to court would actually cost?

(The ICO seem complicit, refusing to even understand that NHS Digital has a wrong email address for me)

2022-07-02

A flaw in GDPR

One of the aspects of the General Data Protection Regulation (GDPR, and UK GDPR) is that you can expect that the personal data an organisation holds on you to be accurate.

Specifically, that if it is inaccurate, you have a right to rectification, and you can require them to correct it and make it accurate (even if the ICO don't quite understand that, it is the law).

This is important if the information is mistakenly wrong, but also if it changes over time...

  • If you move house and your postal address changes
  • If you change your name
  • If you change your gender
  • If you change your title
  • If you change your phone number
  • If you change your email address
  • Etc...
(obviously if someone has a record of "the postal address you had when you signed up", then that does not need to change just because you move, unless it is a mistake, but a record of "current address" needs to change when you move).

The organisation has to, legally, rectify the inaccurate personal information they hold on you when you ask them to. That is the law.

But, in my opinion, there is a flaw in GDPR. When "signing up", "registering", etc, when first becoming a data subject with an organisation, it is apparently legal for that organisation to impose rules on what they consider acceptable personal information.

A perfect example is, apparently, British Airways, this week, refused to accept someone that was female and a Doctor, as the gender and title did not match!

But organisations will decide someone cannot have a first name that is one letter, of that you have to have a first and last name, or that your email address cannot have a dot before the @, etc.

Of course, the person could have recorded themselves as male and a doctor, and having been accepted they could require the incorrect personal information be corrected, under GDPR. The same is true for email addresses that an organisation decides is not valid, or a phone number, or postal address or name, etc. Ultimately, legally, they have to accept the accurate personal information in the long run if you required them to rectify the inaccurate personal information they hold and collected at "sign up".

But it seems nothing in GDPR requires that organisations accept the "accurate" personal information from data subjects "in the first place". They can make any arbitrary rules they wish. So we see shit like this, even for perfectly valid email addresses.

To be fair, companies can, and should, validate that something like an email address is valid and is the subject's email address. That is part of GDPR when it comes to rectifying personal data as well. But if it is valid, they should accept it, in my view. Making random rules on names, genders+titles, email addresses, phone numbers, etc, are all stupid and should be fixed by an update to the law.

I feel GDPR (or UK GDPR) needs updating so that no data controller can discriminate (i.e. refused to accept a new data subject) based solely on the format or syntax or rules they have created relating to any valid and accurate personal information at the point of becoming a data controller, any more than they could at the point of being required to rectify inaccurate personal data later.

The fact this is not part of the GDPR, is, in my view, a flaw, that needs fixing.

I have written to my MP asking for this, maybe you could too?

2019-08-08

Body cams are weird #GDPR

Body cams are weird - you walk in to a shop with one on, especially with a big WARNING: VIDEO/AUDIO RECORDING sign on it, and you get strange looks. But at the same time, half a dozen CCTV pointing at you, is "normal".

I have yet to be challenged on this, and I am not sure I really want the altercation, but I imagine if asked to "turn that off" it would be valid to say "I will, if you turn that off [point to CCTV]".

Let me stress, I am not a lawyer or GDPR expert, but I'll try and make sure this post is technically accurate and update any errors pointed out to me. And thank you Neil for the links, case references, and definitions and correction of my many typos.

Domestic purposes

One of the things that is outside the scope of GDPR is processing of personal data by a natural person in the course of a “purely personal or household activity”, which is commonly called processing “for purely domestic purposes" This is a tad complicated in interpretation though, and there is some confusion on this.

There has been a judgement on fixed position CCTV cameras recording in a continuous loop in people's homes (domiciles!) that says that it is only domestic purposes if there is no view of any area outside the property boundary. i.e. if the CTTV covers the road, or neighbour's property, it is not domestic purposes and hence you need a lawful basis, a privacy notice, to comply with data subject rights, and everything else that goes with GDPR compliance.

Personally (and I think I am not alone on this), I think this ruling is wrong: The cost seems to have confused the setting of the processing with the purpose of the processing. The classic example of domestic purposes, an "address book", will have names and addresses and phone numbers of people not within the boundary of my property. So clearly it is not the data subjects that define "domestic purposes" but the "purpose" of the processing (the clue is in the words used!). But as we have a ruling, that becomes risky to try and argue that CCTV covering the road is domestic purposes.

Indeed, for security of my home (domestic purposes) I want recordings of people "casing the place" (on the road or opposite my home) as that may have much better, daylight, views of faces to use when later the same vehicle is caught on camera relating to the place being burgled.

Dash cams, and helmet cams, were at that point considered "OK" though (or, at least, there has been no case law yet involving them), which leads to a whole series of scenarios where one cycles home and puts the helmet cam on the wall of the house, and then connects to power, and so on - at what point does it change from "OK" as a helmet cam covering the road, to not "OK" as a CCTV covering the road?

So, to be clear, if you have seen my body cam and found this post because the URL on the label, my purpose in recording is domestic purposes - I record my cycle rides mainly. Just like a dash cam in a car.

Continuous recording

There is some draft guidance on the matter of dash cams which actually suggests that dash cams must not  be continuously recording!

Yes, you read that right - it seems to suggest that you have to start recording just before the "accident" you want to record. I know, that is utter madness.

Of course there are plenty of people who will jump in and point out the technical solution is a pre-recording buffer. That is only saved if you "press the button" (after the accident), or the camera detects a collision, even, which some can!

But that *IS* processing personal information, even if it just goes in to RAM and is replaced after 5 minutes. An example of why that is processing is simple - imagine a dash cam where the camera owner is the cause of an accident. They have a choice about processing of that personal data in the RAM of their camera - they can choose to "press the button" and save the (incriminating) evidence, or not. The data subject can, if they are quick, ask for a copy of that data, at which point they have to "press the button" as otherwise they are deleting personal data after being given (what used to be called) a subject access request. Clearly the data in the pre-record buffer is personal data, and there are data processing decisions to be made in relation to that data.

We can only hope that such a nonsense paragraph is removed from this draft guidance (or, even better, replaced with something more akin to common sense, that someone trying to protect themselves from an accident, or put themselves in a good position if they do suffer an accident, is “domestic purposes”, even if it films someone else in a public setting).

Transition from domestic purposes to commercial

There is then one area about which I am really unsure. If I have personal data, recorded purely for domestic purposes, e.g. my address book, but I then tweet that!

In another recent case, the Court of Justice of the European Union has held that "since [someone] published the video in question on a video website on which users can send, watch and share videos, without restricting access to that video, thereby permitting access to personal data to an indefinite number of people, the processing of personal data at issue in the main proceedings does not come within the context of purely personal or household activities”.

Applying this to a dashcam or helmet cam, even if my filming would be considered to be “domestic purposes”, posting the resulting video on Twitter or Facebook (e.g. to highlight bad driving, or just as part of a journal of my day), unless I lock down access to the video, it looks like I would be outside the scope of domestic purposes.

Given how many people live out their lives online, engaging in the type of chat that one might previously have had in a pub or coffee shop, this feels like it could entail the imposition of GDPR — which, let’s face it, is not something normal people should have to understand — on the general public, for very common activities. It seems to me like rather too much of an interference with people's private lives.

Somewhere in between

Sharing a family video (e.g. my grandson riding a bike for the first time) with family is clearly domestic purpose.

I assume doing so over iMessage is still so, as I do not hand the video to Apple (end to end encryption).

What of posting to a small (family) group on Facebook? My "purpose" is clearly domestic, but Facebook have the image and they do things with images that are not domestic purposes.

What does that mean for GDPR I wonder? I assume that this means that Facebook needs to comply with GDPR, but I do not (since I am not sharing with an indefinite number of people).

2019-05-24

Tipping the scales

I am getting really good at upgrading the scales to do WiFi now, and read cards. The card of choice is a Monzo card which works perfectly well as an ID for weighing yourself. Notably Amex have an ID of 00000000 which is useless.

Really neat PCB, locking molex connectors, cables, the lot. It is working well. Marsden kindly sent the service manual so I can set to "kg" and "st/lb" modes for those that like old-school weights.

The system has a QR code on the scales, which allows you to register any card against your email address. You then weigh yourself and tap the card on the scales to record the weight.

When you tap the card it beeps to confirm it is working, and keep beeping until a stable weight is recorded over WiFi to the server. Simple UI if ever I made one!

Sadly, I have fried a couple of boards whilst doing these upgrades, but Marsden do spare parts (not cheap) and whilst I have a few clues what I may have done, I am not 100% sure of how I killed them. I think, with care, and anti-static, and being neat (avoiding any shorts, or diodes backwards) I can do this reliably now. Obviously very unofficial so I cannot expect any help from Marsden. They do make very nice scales though.

The next challenge is to make the web site that holds the data have graphs and sharing options and so on. At present it is just a list of weights. But even that is working for relatives using this solution.

This is turning in to the new fat-shamers club or something, not sure.

But what was the first thing on the web site? after registering the domain? well, it was getting an excellent lawyer to put together the privacy policy for us and ensuring we are GDPR compliant.

You have to love any lawyer that covers standing on scales with your pet cat as part of the privacy policy. Thank you Neil.


2019-02-01

Personal (medical?) data

I am having a bit of an issue with a company called Withings!

I purchased a sleep monitoring gizmo, it goes under the mattress. It is actually pretty cool as it tracks sleep, and heart rate, and snoring. Working out what to do with the data is another matter, but is interesting, and could be quite helpful.


Obviously this device needs a way to present the data to me, and that is via an app on my phone. The ideal way would be to, say, bluetooth it to the app. Simple, and it has bluetooth.

But no, it seems to be set up so it uses my wifi to send data to Withings over the internet, and then the app on my phone gets it from them and displays it. This is not ideal, and it annoys me a little that people make devices work like that, but, in theory, GDPR comes to the rescue.

My sleep is not always good
Once upon a time companies could probably do what they like as part of T&Cs of some service they offered (though, bear in mind, I have not bought a "service", I bought a "device"). However, these days, they cannot simply use my data, they need to have a legal basis, and perhaps even consent.

Also, arguably, this is sensitive personal data (medical data), so subject to even tighter controls.

So, in theory, I should be able to use the device with the data being conveyed to them and back too my phone, and no more. Data being deleted when no longer needed, and not used for any other purpose. Or so you would hope.

The first clue of a problem was that the installation not only required me to agree their T&Cs (annoying) but "consent" to their privacy policy (here). This immediately rang alarm bells as "consent" is meant to be "freely given" under GDPR. Insisting I consent as part of installation is wrong.

So, I consented on the basis I want to use the device, and immediately emailed withdrawing my consent, as is my right. To be clear, I explained I accepted that there would be some data processing to provide the core functionality of monitoring my sleep and displaying that on the phone app, but I withdrew consent for any other purposes - specifically (as per their privacy policy): Developing and managing Products and Services, Conducting data studies, and Marketing, advertising and making recommendations. The last one being my main concern.

It is worth noting, had they had a number of entirely optional consent settings such as "share data with our developers to help improve the product" and so on, I may well have clicked on some. Making it mandatory to consent to usage as per their privacy policy was what kicked this all off!

They basically have no clue, seriously. Many emails back and forth. They kept telling me where their privacy policy was and asking if there was anything else they could help with. They totally failed to understand their obligations or what I was asking. Finally I have an email saying if I don't consent then that is not compatible with use of the product and they offer a refund. Well, no, I want to use the product, but my data only be used for that usage and nothing more. That is my right!

We'll see what happens next - I have written to them now as well.

However, there is a big gotcha here, and this is the same with T&Cs for installing a smart TV and a lot of other internet of shit stuff.

EVEN IF I CONSENT, what of other people?

This is not entirely hypothetical now. I was away for the weekend, and my sleep tracker says I slept one of those nights I (someone that does not snore!). Now, I happen to know who did sleep in my bed, he is 5, and not only did he not consent to Withings having his data, but he legally is too young to have done so.

(I believe my having his data probably comes under personal/domestic use in much the same way as if I marked his high on a door post).

But Withings will presumably want to use the data for Developing and managing Products and Services, Conducting data studies, and Marketing, advertising and making recommendations.

If the basis of this use is "consent", which they seem to suggest, then when and how did they get his consent exactly? I have asked them this. We will see what they say.

Basically, they cannot assume they have consent for any sleep data they collect to be used in such a way, at all, ever, as even if the installer or owner of the device consents, they do not know the person sleeping in the bed has consented.

As I say, this is much the same as smart TVs that could be recording you viewing patterns. Even if the installer has agreed terms and consented to such data processing, the people viewing the TV may not have.

This is a legal issue that needs sorting. I wonder if the sensitive nature of medical data in the case of the Withings sleep monitoring device will help get this to a test case? ICO have been told.

P.S. I checked, and it is at least talking over https.

2018-09-23

When is a final bill not a final bill? British Gas

British Gas

I changed energy supplier from British Gas to Bulb. Given that my son now has an electric car, this seemed a responsible thing to do so as to be buying 100% renewable energy, and actually Bulb were a tad cheaper.

I got the final bill from British Gas, paid it, and then started paying Bulb. All pretty seamless (apart from the smart meter now being dumb). I did not expect to hear any more from British Gas, obviously.

In fact, the final bill had actual smart meter readings for the date I left them, so not doubt whatsoever that I had paid correctly up to the reading on that day, no estimates.

To my surprise, nearly 5 months later, I get another "final" bill from British Gas!

Yes, it covers a different, longer, overlapping period.

But strangely the bill is now for an estimated final reading?

There is nothing on this bill saying it is a replacement of the previous bill (or bills), and no formal VAT credit note received. Indeed it lists charges for gas and electricity totalling £384.36, but showing balance and previous payments making only £19.49 due.

Unsurprisingly, even I was confused, especially at the electricity charge being based on an estimated final reading not an actual one. I thought smart meters meant an end to estimated readings, and indeed the previous "final bill" made that clear.

What ensued was a long, and very frustrating, conversation with British Gas, I can't be arsed to publish the recording as it is very repetitive to be honest. This blog is mind numbing enough without it.

Sadly I had someone that refused to actually answer questions most of the time, or even acknowledge the point I was making, constantly saying things like "you have mentioned that before" rather than agreeing, or even disagreeing, with what I was saying.

He "explained" that I have a new bill because my new energy supplier contacted them to "correct" the final electricity meter reading from 51361 to 51485, and that is why the £19.49 was due. He explained this was a replacement of my last bill and that the gas reading had not changed, which makes the bill even more confusing, but OK. I have no idea why Bulb would have contacted British Gas to make such a change.

I explained that British Gas have smart meters. That the previous final bill had a smart meter reading of 51361. He confirmed smart meters are meant to be "100% accurate", and after much going round in circles he agreed that the new supplier "must have sent incorrect information".

Well, from my point of view that is the end of the matter: I have paid British Gas fully up to the "100% accurate" smart meter reading for the day I left them, done. This new "final" bill is based on incorrect information - information British Gas know for a fact (based on their "100% accurate" smart meter reading) is incorrect. So I don't need to pay it, do I?

He really got annoying with the "you mentioned that before" replies - so much so that at one point I said "Yes, I have, but is what I am saying incorrect?" which he refused to answer.

He also got annoying with the repeated "I just need to explain why you have this bill" and I kept saying "You explained, it was new supplier sending you incorrect information, but as you know it is incorrect I don't have to pay it". He eventually said I could not just ignore the bill and that I would have to contact the new supplier - why?!?! How is that my job?

No matter how many times I explained that the final meter reading is a matter of fact, one that they have absolute proof to confirm (smart meter reading), and that I have paid all usage up to that 100% accurate" final smart meter reading on the day I left so could not possibly owe any more, he would have none of it. He just kept trying to "explain" why I have this new "final" bill!

We did have one slight digression which really made no sense: He said that even though the first final bill said "smart meter reading" the 51361 shown was actually what Bulb had told them. Obviously saying it is a "smart meter reading" is a tad misleading if it is not so (fraudulent maybe?). I asked him what the actual smart meter reading was and he (eventually) confirmed it was in fact 51361. So basically Bulb had confirmed the same meter reading that British Gas had actually taken - even more proof that this matter of fact was correctly recorded the first time (by both energy suppliers).

First "final" bill


New "final" bill


We were going round in circles so I finally resorted to stating that as they knew the factually correct meter reading, they know that what they have on record now is wrong. It is wrong personal information and so I formally requested that they correct the incorrect personal information they hold on me as required by GDPR and the Data Protection Act. I had to insist on this many times. I had to ask if he would be correcting the data many times, and insist on a "yes" or "no" answer before finally getting a "no"!

I then tried to get him to answer as to whether he understood that correcting incorrect personal information was a legal requirement. He refused to give a "yes" or "no" answer and finally went to talk to someone and came back saying he would credit the bill and nothing is owed.

No acceptance that they had the correct final meter readings as a matter of fact.
No acceptance they have any obligation to correct incorrect personal information.
Nothing.

Oh, well, at least it is sorted, but just really annoying conversation to have.

Anyway I ends by saying I was making a Subject Access Request and required all data including all smart meter readings ever. Apparently I'll had that in 7 days, nice! It should be interesting.

Bulb

Anyway, having sorted all of this I checked my Bulb bills. I pay them a fixed monthly amount by Direct Debit, so had not actually checked the detailed bills. But this seemed like a good time to do it.

My first 3 Bulb statements charged £0.00 for electricity usage, estimated meter readings 46791 to 46791, and then a bill for £1,496.61 for 46791 to 59129 (my reading).

Well, apart from a very strange way of doing estimates, that initial meter reading of 46791 is rather at odds with the final meter reading of 51361 up to which I had paid British Gas, and it does not even match the 51485 that British Gas claimed Bulb has sent them as a "correction".

We'll see how well Bulb sort that one out tomorrow when they are open.

Prediction: Bulb tell British Gas 46791 and I get a large credit from British Gas, but they won't know how to actually pay me money...


Seriously, how is something so stunningly simple handled so badly by two different energy suppliers. Crazy!

P.S. Sorry, before someone says this - yes, he could have said something like "There needs to be an agreed handover reading which may not be the same as the smart meter reading because of time of day or it being taken a day before or after, etc, but the bill is based on the agreed handover reading which both energy suppliers used as the reference to stop and start billing". He did not say that. Had he said that it would have made more sense except for Bulb working on such a completely different starting reading. Also, assuming that is the case, it would be better for the bill to say "agreed handover reading" rather than either "smart meter reading" or "estimated reading". They also need to not simply "replace" two previous bills with no explanation whatsoever.

2018-08-06

GDPR: Secret black lists

I think I have this right, but it seems rather concerning to me with the way GDPR has tightened things up so much there looks to be a concerning loophole.

I say loophole, it is there for good reason, but even so.

The GDPR is an EU-level document — a regulation — and regulations apply automatically in Member States, without the need for national implementation. The GDPR is a bit of an odd regulation though, as it contains a reasonably large number of areas where Member States are permitted to implement national derogations.

The UK’s new data protection act — the Data Protection Act 2018 — came in with the GDPR, repealing the previous Data Protection Act 1998. The Data Protection Act 2018 does various things, and one of them is to set out certain exemptions to some of the provisions of the GDPR.

For example, the Act exempts a data controller from complying with some aspects of the GDPR where they are processing personal data for "prevention and detection of crime", and where applying the GDPR’s provisions would be likely to prejudice that. This includes provisions dealing with subject access, as well as the right of rectification. This is, in principle a good idea, but I think I can see a problem - "black lists".

I know someone that recently tried to buy an item on-line and the order was cancelled as their email/number is, according to the retailer, on a "fraud list". The obvious answer (on basis that they have not committed any fraud) is Subject Access Request and a demand to have the data corrected.

However Data Protection Act 2018 SCHEDULE 2 part 2 says otherwise. Most of the rights you have, like Subject Access Request and rights to correction of the data simply do not apply where the data is for the purpose of preventing and detecting crime - which could be argued here.

There is a caveat "to the extent that the application of those provisions would be likely to prejudice any of the matters" but I am not sure that helps.

Even arguing it is wrong to be on the list is not clear, what if the list was "the following email address or phone numbers have demonstrated behaviour which is consistent with the behaviour demonstrated by fraudsters" - it could be correct to be on the list. i.e. being on the list may not mean you have committed fraud or are being investigated for doing so, simply that it could be a list useful for preventing and detecting crime.

But as you may not even know of the list (though in this case the retailer said so), let alone its purpose, or what of your data is on it, why and how, then there is no way you can know or do anything about it!

So it looks a lot like secret blacklists of people are completely allowed by GDPR. Am I wrong? Is this morally wrong?

[Some paras courtesy of Neil, thanks for the explanation of how GDPR applies to UK]

2018-07-03

Blogspot did it again

A while ago (GDPR day) I stopped getting moderation emails for comments.

Eventually after changing the setting to a totally different email address, and getting a confirmation email with a link, I started getting them again, yay.

However, it seems to have broken again, and I am not longer getting them - so loads of comments have only just been posted.

I'll try changing email again - thanks GDPR - this is the sort of hassle we wanted, and I still get loads of spam about which I can do bugger all.

2018-06-05

Did GDPR kill my blog?

No comments since 23rd? I almost had not noticed, I was sort of beginning to think I was boring all of a sudden. I have also been a tad busy.

Then I checked the "awaiting moderation" and loads of comments! I have approved all that look non spammy as always, sorry for the delay. Yay! I am not boring, well, that much, yet...

So I checked settings and the moderation email is marked "The email address added in this field will be invited by email, and will have 14 days to accept the invitation in order to receive notifications."

So I am wondering if I missed an email pre-GDPR and so stopped getting the moderation emails. Makes some sense...

Though, having changed the moderation email, I have not had any "invitation", so maybe it is just broken at blogger?

Sorry for the delay, and thanks for posting comments. And thanks to geekypenguin for asking on irc.

How could I think I was just boring :-)

2018-05-16

GDPR

I am not planning to say a lot here at this stage, but I suspect people would be rather surprised if I did not comment a little on GDPR. I remind you all I am not a lawyer. I'll try to cover the basics...

Is this a big change?

You would be forgiven for thinking it is. To be honest, I think for the most part the basic principles have not changes a lot, and if you were "doing it right" before, you are probably "doing it right" now. There are changes, yes, but it seems to me that the biggest change is around "accountability". Under GDPR you are expected to have a lot more processes in place, and be able to show that. Before, if you did things right you may have more easily got away without all of the paperwork to prove that was the case, but GDPR puts a lot of onus on the paperwork and accountability... GDPR also has big fines which is what is actually making people jump!

"Consent" has changed...

As a basis for processing personal data the use of "consent" has changed, in rather odd ways. For a start it has to be "freely given" so cannot be in exchange for some service, which is interesting. But also it has to be revokable. Some of the rules on proving you got consent (i.e. not default pre-ticked boxes) have changed a bit too. And of course the accountability to show you actually got consent is clearer now.

The upshot of this, and paraphrasing the advice from our lawyer, is that anyone relying on "consent" as the basis for processing, is crazy.

I know I am seen as speaking for A&A here on my blog in spite of my caveats on the matter, so to be clear, A&A do not use "consent" as the basis for processing. It is far too difficult, and fragile a basis for doing anything really. Why would we - you can withdraw it at any time...

Extra rights

Not that many to be honest, you had loads of rights before, but maybe a few more now. One thing is that subject access requests are to be free. This is likely to be a pain for many companies.

Once again, with an A&A hat on, pretty much everything we have on you is available on the web pages now (accounts or control pages), and indeed, I expect some level of "full SAR" to be in there soon anyway, depending on if anyone starts asking for lots of data. I'd rather people do not go mad on 25th asking for data, to be honest, as basically we are not the bad guys here hoarding loads of personal data on people, and never have been. A lot of replies will be referencing the data you can access anyway. That is not to say we won't welcome suggestions and feedback on this all.

Privacy at the core of the business

This is where A&A are a bit different, and I had a long chat with out company lawyer on this the other day. Obviously we have been working on this for months, but he was impressed how we do take privacy seriously at every level as a matter of course really. It has made his job a bit easier as basically we are not changing what we do, but doing the paperwork to document what we do and so on. Not only is the company simply not in the "business" of selling / processing personal data in the first place, but we have myself and key staff on the case every day challenging everything we do, or consider doing, from a privacy standpoint.

Some changes at A&A

To be honest, the whole process has meant we are looking more closely at some aspects of what we do, and so some things like the way we identify customers that call/irc/email/etc may be tightened up a bit. We need the right compromises of helpful and secure. We did a lot of this last year with controls over levels of security on accounts and two factor authentication so as to give our customers a choice of the level of security (or paranoia) they felt was needed for their data. That was all done before we even really considered GDPR, just how we work and how we can be better at privacy!

But obviously we welcome feedback, if you feel we are too strict or not strict enough on verifying you as a customer, please do tell us. The whole process here is a lot about learning the right balance to ensure people have the right level or privacy and convenience.

OK, the real reason to read this - those annoying emails to re-conform consent!

We have all had them, heck they are filling the inbox for us all - asking to reconfirm "consent" before 25th May.

I don't know what to say to be honest. I do not think a single one of these emails is from someone that I actually gave consent to in the first place!!!

We've had them sent to mailerdaemon@somedomain at the office, clearly not an email address anyone used or consented to marketing (or any other) emails to.

The only light at the end of the tunnel is that, if we are lucky, all of these muppets delete us from their mailing lists for fear of fines related to GDPR.

But, really, none of them should have us on the mailing list anyway under existing privacy and data protection laws, FFS! If only the ICO had enforced the laws we had, this would have not been an issue, IMHO.

If you have a lawful basis to have someone's details and send them email, GDPR does not really take that away, and so you do not need these stupid emails asking to re-consent.

Anyone considering sending such emails over the next week or so - talk to someone that understands GDPR properly, i.e. @neil_neilzone

2018-05-14

(mis) targeted adverts

OK I get that there is a lot of tracking.

I get that if I search on the Internet for green jelly babies, I'll start seeing adverts for people selling green jelly babies.

What I do not get is how people actually pay advertisers to bombard me with adverts for the very thing I have just purchased by the very company from which I have just purchased it.

That has to be the daftest thing possible?

Arrrrg!

Will GDPR help, like fuck it will...

P.S. I am assuming that posting this (with names) on my blog (for all the world to see) is morally no different to clicking "like" on it (for all the world to see)? Is it? Is it legally wrong?

2018-03-08

LG and privacy (again)

Just to explain, as some people did not get it, sorry.

This issue here is that LG can do stuff - they can log what programmes and channels I (or anyone else here) watch, and log when I use the voice activated thing.

1. The voice thing being "cloud processed" I can understand, necessary part of the service. I'd like to know it is encrypted to them. I'd like to know it is not retained and sold later. But the basic "process the voice to understand the command, and then forget it all" I would be reasonably happy with if encrypted to them.

2. The tracking what I watch, and worse - selling that to other people? Well no thanks... Why track what I watch?

At the end of the day, they either need consent in order to process this personal data (and they have a postcode anyway and an IP address, so very possible to make "personal" data here), or they do not need consent...

If they need consent they are screwed as people can come and go, enter the room, watch TV, without ever having engaged with LG nor given any consent to any processing of such personal data. They have to stop processing such data now. Needing consent and not having it is a problem!

If they do not need consent then why the hell do we have to jump through hoops in the set up to agree terms and consent to shit in the first place. I can understand the simple processing of encrypted voice to make a command, and not recording/logging/selling that information may be something that is "necessary" and not need consent - not worried if that is the case.

But which is it?

I hope that makes some sense - as to what I choose to publish on my blog, well that is up to me...

2018-03-07

LG and privacy

I tweeted LG, and no reply.


But I also sent a support email request like this:-

I noted during installation of my new OLED65W7V that there is a point you are expected to agree to terms and conditions, and consent to processing various personal data.

In this instance, as he was helping me install it, my son clicked "agree", so I have no contract with LG, have not agreed any terms and are not bound by any terms and have not consented to any processing of personal information.

1. Given that GDPR will be law soon, how will you be changing the terms and these pages so that any consent is "freely given", i.e. not "in exchange for using some smart TV features" exactly?

2. Given that I have not agreed terms or consented to processing information, how exactly does the TV know not to process voice recordings of me, or my TV viewing data? I.e. how does it tell who has consented and who has not, before processing any data?

3. If it cannot tell, does that mean you have been processing voice recordings and other personal data without my consent?

4. If so, will you be reporting this breach to the Information Commissioner's Office your self, or would you like me to do it for you?

I hope you can help answer these important questions.

To my surprise they replied!

Good morning Adrian,

Thank you for your query regarding your LG TV; I would be more than happy to assist you with this query today.

I can confirm that the TV does not record your voice or use voice controls unless you hold the button on the magic remote to do so.

It is not possible for the TV to function to its fullest without accepting the terms and conditions as it needs to know things like your country for region locked apps like Netflix as well as tracking what you have watched to make recommendations and keep track of where in a series or movie you are. We could revert back to how it used to be and how most manufacturers work and not ask and just do it without your permission.

As previously mentioned the TV does not record or listen to your voice unless you select the option to do so. You can disable this functionality in the terms and conditions by following the steps below;

Home → Settings → All Settings → General → About this TV → User Agreements

There has been no breach of any sort here. While you did not personally agree to the terms and conditions the person you allowed to set up the TV (Your Son) did. At any point you could have prevented this decision or reverted it by following the mentioned steps above.

If you do wish to discuss this further please do not hesitate to contact us on 0344 847 5454 or alternatively you can also reply to this email.

Thank you in advance.

Kind regards 
Carlin
LG Electronics UK Help desk 
---------------------------------- 
LG Customer Services

Wow... Just wow.

2018-02-10

2D bar codes

I have done a lot on barcodes on my blog, and I am sure I have mentioned the URL shortener I made that is www.4.gg in the past.

It allows you to provide a URL and gives you a barcode for that in a variety of formats. Some time ago I changed from IEC16022 (DataMatrix) codes to IEC18004 (QR) codes simply because this is a tad like betamax vs VHS, and clearly QR codes have won. Shame, in my view, but they work. It's is even possible to script it to get codes for URLs from automated systems.

I was looking today at some of the stats on the site. It collects very few pieces of data - obviously it has a log of the mapping from an assigned code to a URL, it has to have that, and it records the date/time it was made, and the IP from which it was made and a hit count and latest time of use, and well, that is it.

It was never any attempt to collect data, personal or otherwise. I intended it to be useful, and well, we (A&A) use it for things like barcodes on invoices.

What makes it special is that the barcode is designed to fit the minimal QR code format, so is compact and/or easy to read. For example :-

That is the size of all of the barcodes it makes, the smallest allowed in normal IEC 18004 QR codes. But the URL shortener aspect means that can be any URL you like.

I checked, and was amazed that there are literally millions of hits on these codes now. It has been working for like 9 years now. We actually have over a 1000 new codes created a day now, which shocked me! When I started some camera phones had QR or data matrix readers, and even the Nokia phone had a bug that did not like a "z" in the code. These days phones have QR code readers in the camera apps, and iPhones just "see" QR codes when taking a picture...

So then comes GDPR, and I am concerned - we collect IP address when codes created and hit counts. Importantly we could collect way more if we wanted to. Some may count as "personal data" though that is questionable. So do I have to worry.

Well, best plan is make this an official free service by A&A and include in GDPR privacy statements. Annoying we have to do this crap in many ways, but let's do the right thing shall we.

BTW, the most popular code is some site that is now a parked domain, over 500k hits and even one today, so someone has put that barcode somewhere massively popular and I know nothing about it. Amazing how a free service I have not even advertised has taken off.

What is especially amusing is Facebook hampering my freedom of speech talking about it!


First time I have ever been accused of spamming... What is amusing is that I could post that screen shot on Facebook and a QR code of my post and the various comments and replies in QR code with no problem. Shows how effective Facebooks policies are in practice. LOL.

2017-09-14

Data Protection

So there is the new Data Protection Bill to put in place the rules under the General Data Protection Regulation, under EU law.

Well, there is a lot to this, so this is just a placeholder post really - to say there is a lot of shit going down, and with any luck I can post more about this in due course.

This, and the NIS directive, almost feel like exactly the sort of thing those Brexit voters were wanting to kill off!

2017-08-11

Public Interest

At present the Data Protection Act contains an exception for journalistic / public interest processing and disclosures of personal information - this is why the press can name people in stories, especially public figures.

I don't know if the new GDPR (General Data protection Regulation) stuff has the same exception - if not then the newspapers are going to be very strange, with no pictures of anyone, and even saying "The Home Secretary" will be identifying an individual, so not allowed. The exception must exist, surely?

Now, I wonder if it is public interest to state the full name of the person that works for British Telecommunications plc that has stated that BT is not a communications provider? I mean it seems such a stupid lie that he deserves "naming and shaming" surely?

P.S..

I was not trying to make this yet another unhinged rant, honest, it was a genuine DPA/GDPR issue. Can I name the person?

Now, I was thinking, I could give his first name, which is Andrew, as we know many Andrews, even in BT, and so could not, as data controller, identify the person from his first name alone.

However, it got me thinking, The rule is, as far as I know, that anything which allows the data controller to identify the person, including access to other data the data controller has, or could get access to from third parties even, counts as personally identifiable data - even if the rest of the world could not use that data to identify the person.

So if I said "customer number 1209", to me, that is an identifiable individual, so that data, just "customer number 1209" is personally identifiable data, and I could not post it, even if nobody reading this knows who that is? Is that the case, really? Thankfully customer 1209 has agreed to that much data about him (or her) being posted in this blog post.

However, this BT person - I (as the data controller) can identify him from the "story". Just saying "The BT person that said BT is not a communications provider" is enough for the data controller to identify that person.

Basically, I cannot post *ANYTHING* about the story in any way without releasing personal identifying information - i.e. information the data controller can use to identify that person (given other data the controller has, or has access to).

Surely that makes no sense? Or is giving his identifiable information in public interest? If not, I cannot post the store at all. If so, then giving his full name is no more help to the data controller in identifying the person than the content of the story is.

So what is the question? Is the question "Is revealing personal identifiable data in public interest? yes/no". Or is the question "Is revealing this persons full name in public interest? yes/no?"

As I say, not an unhinged rant, a real question...

Time for something new...

Latest project is a time server. So why? Well, they exist - you can buy a really nice LeoNTP server, with impressive specs. We see response ...