Wide-ranging UK DATA SHARING moves one step closer

Report shelved as government looks for quick fix


Privacy safeguards?

The 28 July documentation claims that the privacy safeguards against excessive data sharing include: "The Data Protection Act 1998; Law of Confidentiality; Article 8 of the European Convention on Human Rights and EU legislation on data sharing". I will now show when these legal safeguards are unlikely to apply.

For instance, with respect to the common law of confidence, it is well known that one can always set aside a confidentiality obligation if there is a statutory requirement to disclose such confidential personal data. So as soon as ministers exercise their data sharing powers to demand disclosure, so it's “goodbye” common law of confidence.

It is also well known that the Human Rights Act is under threat of abolition by the Conservative ministers in the coalition, who are currently driving the data sharing agenda. So if a Conservative government is returned after the next Election, we don’t know the nature of the Article 8 replacement. As for Europe – we might leave following an in-out referendum! In both cases, the safeguards on offer are uncertain.

With respect to the Data Protection Act (DPA), I have often argued that once statutory powers are applied to a disclosure, then the disclosure is almost invariably “lawful” and the disclosure itself can be subject to the exemption from the non-disclosure provisions (S.35(1)). This exemption can exclude several data protection principles (Fairness, Second to Fifth Principles) and the rights that could block disclosure.

The Third Principle can be neutered if broad purposes are defined in data sharing legislation. For example, if a controller says "personal data item X is relevant to a housing benefit purpose", the claim can objectively be tested: essentially, we can ask “is the data item relevant or not relevant to the housing benefit purpose?”.

However, this test is substantially diminished if the purpose is broadly defined as in "the purpose of the efficient delivery of public services"; many items of personal data could satisfy this requirement.

In summary, when a purpose is narrowly defined, the more precise the relevance test of the Third Principle becomes, and the more protection there is from the DPA. The converse is also true; the broader the purpose description, the less precise is the relevance test and the poorer the protection afforded by the DPA. The same argument applies to the retention criteria of the Fifth Principle as it, like the Third, the level of protection is linked to "the purpose" of the processing.

In summary, there will be not much data protection on offer when statutory data sharing powers are exercised.

What's missing....

Some of these are listed below; they are very easy to identify if, unlike the document, one asks the simple question “what could go wrong?”.

Whenever data subject consent is impracticable, then there has to be a right for any data subject to object to any further data sharing, at any time, without providing a reason. In fact, transparency arrangements should offer an “opt-out”. Exceptions to this right to object can be catered for and easily be identified (e.g. to permit data sharing in relation to fraud).

At the moment, there is no right to object that would apply to non-consensual data sharing, and it is important to understand that the current right to object to the processing under the DPA (S.10) won’t apply.

As soon as statutory powers for data sharing are exercised any data sharing required by law would be legitimate in terms of Paragraph 3 of Schedule 2, whereas the current right to object in the DPA only applies when paragraph 5 and 6 applies to the data sharing. In addition, the data subject has to show that data sharing would cause or likely to cause “unwarranted” and “substantial” damage or distress; this is a high barrier to the exercise of this right.

The second safeguard, I suspect, is needed when personal data are used for data matching and/or profiling; the Information Commissioner should be tasked to produce a statutory code of practice if data sharing involves these two.

Thirdly, there needs to be a counter-balance to the exercise of ministerial powers by Statutory Instrument (SI) as the UK parliament hardly ever rejects the use of powers granted to ministers (even when the SI is subject to debate in a Select Committee). The Information Commissioner should be given the explicit right to apply to court on the grounds that the processing of personal data is disproportionate in terms of Article 8 of the Human Rights Act. This raises the prospect of the power being declared unlawful and the SI being struck out.

Broader topics


Other stories you might like

  • China reveals its top five sources of online fraud
    'Brushing' tops the list, as quantity of forbidden content continue to rise

    China’s Ministry of Public Security has revealed the five most prevalent types of fraud perpetrated online or by phone.

    The e-commerce scam known as “brushing” topped the list and accounted for around a third of all internet fraud activity in China. Brushing sees victims lured into making payment for goods that may not be delivered, or are only delivered after buyers are asked to perform several other online tasks that may include downloading dodgy apps and/or establishing e-commerce profiles. Victims can find themselves being asked to pay more than the original price for goods, or denied promised rebates.

    Brushing has also seen e-commerce providers send victims small items they never ordered, using profiles victims did not create or control. Dodgy vendors use that tactic to then write themselves glowing product reviews that increase their visibility on marketplace platforms.

    Continue reading
  • Oracle really does owe HPE $3b after Supreme Court snub
    Appeal petition as doomed as the Itanic chips at the heart of decade-long drama

    The US Supreme Court on Monday declined to hear Oracle's appeal to overturn a ruling ordering the IT giant to pay $3 billion in damages for violating a decades-old contract agreement.

    In June 2011, back when HPE had not yet split from HP, the biz sued Oracle for refusing to add Itanium support to its database software. HP alleged Big Red had violated a contract agreement by not doing so, though Oracle claimed it explicitly refused requests to support Intel's Itanium processors at the time.

    A lengthy legal battle ensued. Oracle was ordered to cough up $3 billion in damages in a jury trial, and appealed the decision all the way to the highest judges in America. Now, the Supreme Court has declined its petition.

    Continue reading
  • Infusion of $3.5bn not enough to revive Terra's 'stablecoin'
    Estimated $42bn vanished with collapse of UST, Luna – we explain what all this means

    TerraUSD, a so-called "stablecoin," has seen its value drop from $1 apiece a week ago to about $0.09 on Monday, demonstrating not all that much stability.

    The cryptocurrency token, abbreviated UST, is supposed to be pegged to the price of the US dollar. Hence the "stable" terminology.

    But UST is not a "centralized stablecoin" that's exchangeable for a fiat currency; UST for USD (US dollars). Rather, it's a "decentralized stablecoin," meaning it can be exchanged for Luna (LUNA) tokens, another cryptocurrency tied to the Terra blockchain.

    Continue reading
  • DigitalOcean tries to take sting out of price hike with $4 VM
    Cloud biz says it is reacting to customer mix largely shifting from lone devs to SMBs

    DigitalOcean attempted to lessen the sting of higher prices this week by announcing a cut-rate instance aimed at developers and hobbyists.

    The $4-a-month droplet — what the infrastructure-as-a-service outfit calls its virtual machines — pairs a single virtual CPU with 512 MB of memory, 10 GB of SSD storage, and 500 GB a month in network bandwidth.

    The launch comes as DigitalOcean plans a sweeping price hike across much of its product portfolio, effective July 1. On the low-end, most instances will see pricing increase between $1 and $16 a month, but on the high-end, some products will see increases of as much as $120 in the case of DigitalOceans’ top-tier storage-optimized virtual machines.

    Continue reading
  • GPL legal battle: Vizio told by judge it will have to answer breach-of-contract claims
    Fine-print crucially deemed contractual agreement as well as copyright license in smartTV source-code case

    The Software Freedom Conservancy (SFC) has won a significant legal victory in its ongoing effort to force Vizio to publish the source code of its SmartCast TV software, which is said to contain GPLv2 and LGPLv2.1 copyleft-licensed components.

    SFC sued Vizio, claiming it was in breach of contract by failing to obey the terms of the GPLv2 and LGPLv2.1 licenses that require source code to be made public when certain conditions are met, and sought declaratory relief on behalf of Vizio TV owners. SFC wanted its breach-of-contract arguments to be heard by the Orange County Superior Court in California, though Vizio kicked the matter up to the district court level in central California where it hoped to avoid the contract issue and defend its corner using just federal copyright law.

    On Friday, Federal District Judge Josephine Staton sided with SFC and granted its motion to send its lawsuit back to superior court. To do so, Judge Staton had to decide whether or not the federal Copyright Act preempted the SFC's breach-of-contract allegations; in the end, she decided it didn't.

    Continue reading

Biting the hand that feeds IT © 1998–2022