{"id":2539,"date":"2020-05-24T09:50:10","date_gmt":"2020-05-24T09:50:10","guid":{"rendered":"http:\/\/www.bizlegal.eu\/?page_id=2539"},"modified":"2020-05-24T09:50:11","modified_gmt":"2020-05-24T09:50:11","slug":"newsletter-june-2019","status":"publish","type":"page","link":"https:\/\/www.bizlegal.eu\/?page_id=2539","title":{"rendered":"Newsletter June 2019"},"content":{"rendered":"\n<figure class=\"wp-block-table\"><table><tbody><tr><td><\/td><\/tr><tr><td><\/td><td><img loading=\"lazy\" src=\"\" width=\"300\" height=\"104\"><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>Welcome to June\u2019s newsletter&nbsp;<\/strong><\/p>\n\n\n\n<p>This month sees GDPR\u2019s first aniversary, and as the Data Protection Commission reflects on the past 12&nbsp; months, the headline statistics were as follows;&nbsp;<\/p>\n\n\n\n<p>&#8211; 6,624 complaints were received&nbsp;<\/p>\n\n\n\n<p>&#8211; 5,818 valid data security breaches were notified&nbsp;<\/p>\n\n\n\n<p>&#8211; Over 48,000 contacts were received through the DPC\u2019s Information and Assessment Unit&nbsp;<\/p>\n\n\n\n<p>&#8211; 54 investigations were opened \u2013 35 of these are non cross-border investigations and 19 are cross-border&nbsp;<\/p>\n\n\n\n<p>investigations into multinational technology companies and their compliance with the GDPR.&nbsp;<br>&#8211; 1,206 Data Protection Officer notifications were received.&nbsp;<\/p>\n\n\n\n<p>&#8211; Staffing numbers increased from 85 at the end of 2017 to 137 in May 2019.&nbsp;<\/p>\n\n\n\n<p>For our thoughts on GDPR, see section 2 Thought leadership&nbsp;<\/p>\n\n\n\n<p><strong>1. Technical News&nbsp;<\/strong><\/p>\n\n\n\n<p><img loading=\"lazy\" src=\"\" width=\"265\" height=\"247\"><strong>Biometric Data and explicit consent:&nbsp;<\/strong><\/p>\n\n\n\n<p>As technology takes ever greater strides, so organisations and&nbsp;<br>businesses are harnessing its capabilities to help manage their contact&nbsp;<br>with customers, including using it for means of identification and&nbsp;<br>authentication.&nbsp;<\/p>\n\n\n\n<p>While there are undoubtedly significant benefits in using new&nbsp;<br>technologies, organisations need to be aware of the potential&nbsp;<br>challenges when choosing and using any systems involving biometric&nbsp;<\/p>\n\n\n\n<p>data.&nbsp;<\/p>\n\n\n\n<p>A deputy commissioner of the Information Commissioner\u2019s Office (ICO)&nbsp;<br>has warned that organisations need to obtain explicit consent for the&nbsp;<br>use of biometric data.&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/www.ukauthority.com\/articles\/ico-deputy-highlights-consent-issue-for-biometrics\/?utm_content=buffer39f92&amp;amp;utm_medium=social&amp;amp;utm_source=linkedin.com&amp;amp;utm_campaign=HOBbuffer\">https:\/\/www.ukauthority.com\/articles\/ico-deputy-highlights-consent-issue-for-<\/a><br><a href=\"https:\/\/www.ukauthority.com\/articles\/ico-deputy-highlights-consent-issue-for-biometrics\/?utm_content=buffer39f92&amp;amp;utm_medium=social&amp;amp;utm_source=linkedin.com&amp;amp;utm_campaign=HOBbuffer\">biometrics\/?utm_content=buffer39f92&amp;utm_medium=social&amp;utm_source=linkedin.com&amp;utm_campaign=<\/a> <a href=\"https:\/\/www.ukauthority.com\/articles\/ico-deputy-highlights-consent-issue-for-biometrics\/?utm_content=buffer39f92&amp;amp;utm_medium=social&amp;amp;utm_source=linkedin.com&amp;amp;utm_campaign=HOBbuffer\">HOBbuffer&nbsp;<\/a><\/p>\n\n\n\n<p>A complaint from Big Brother Watch to the ICO revealed that callers were not given further information or&nbsp; advised that they did not have to sign up to the service. There was no clear option for callers who did not&nbsp; wish to register. In short, HMRC did not have adequate consent from its customers and we have issued&nbsp;<\/p>\n\n\n\n<p>an Enforcement notice to have the Data deleted that it continues to hold without consent.&nbsp;<\/p>\n\n\n\n<p>In the notice, the Information Commissioner says that HMRC appears to have given `little or no&nbsp;<br>consideration to the data protection principles when rolling out the Voice ID service\u2019.&nbsp;<br><\/p>\n\n\n\n<p>ICO highlights the scale of the data collection \u2013 seven million voice records \u2013 and that HMRC collected it in&nbsp; circumstances where there was a significant imbalance of power between the organisation and its&nbsp;<br>customers. It did not explain to customers how they could decline to participate in the Voice ID system. It&nbsp; also did not explain that customers would not suffer a detrimental impact if they declined to participate.&nbsp;<\/p>\n\n\n\n<p>The case raises significant data governance and accountability issues that require monitoring.&nbsp;<\/p>\n\n\n\n<p>Any organisations planning on using new and innovative technologies that involve personal data, including&nbsp; biometric data, need to think about these key points:&nbsp;<\/p>\n\n\n\n<p>1) Under the GDPR, controllers are required to complete a DPIA where their processing is \u2018likely to result in&nbsp; a high risk to the rights and freedoms of natural persons\u2019 such as the (large scale) use of biometric data. A&nbsp; DPIA is a process which should also ensure that responsible controllers to incorporate \u2018data protection by&nbsp; design and by default\u2019 principles into their projects. Data protection by design and default is a key concept&nbsp; at the heart of GDPR compliance.&nbsp;<\/p>\n\n\n\n<p>2) When you\u2019ve done your DPIA, make sure you act upon the risks identified and demonstrate you have&nbsp;<br>taken it into account. Use it to inform your work.&nbsp;<\/p>\n\n\n\n<p>3) Accountability is one of the data protection principles of the GDPR &#8211; it makes you responsible for&nbsp;<br>complying with the GDPR and says that you must be able to demonstrate your compliance by putting&nbsp;<br>appropriate technical and organisational measures in place.&nbsp;<\/p>\n\n\n\n<p>4) If you are planning to rely on consent as a legal basis, then remember that biometric data is classed as&nbsp;<br>special category data under GDPR and any consent obtained must be explicit. The benefits from the&nbsp;<br>technology cannot override the need to meet this legal obligation.&nbsp;<\/p>\n\n\n\n<p>Encryption&nbsp;<\/p>\n\n\n\n<p>The GDPR\u2019s security principle requires to you put in place appropriate technical and organisational&nbsp;<br>measures to ensure you process personal data securely.&nbsp;<\/p>\n\n\n\n<p>Article 32 of the GDPR provides further considerations for the security of your processing. This includes&nbsp;<br>specifying encryption as an example of an appropriate technical measure, depending on the risks involved&nbsp; and the specific circumstances of your processing. The ICO has seen numerous incidents of personal data&nbsp;<br>being subject to unauthorised or unlawful processing, loss, damage or destruction. In many cases, the&nbsp;<br>damage and distress caused by these incidents may have been reduced or even avoided had the personal&nbsp; data been encrypted.&nbsp;<\/p>\n\n\n\n<p>It is also the case that encryption solutions are widely available and can be deployed at relatively low cost.&nbsp; It is possible that, where data is lost or destroyed and it was not encrypted, regulatory action may be&nbsp;<br>pursued (depending on the context of each incident).&nbsp;<br><\/p>\n\n\n\n<p><strong>2. International news&nbsp;<\/strong><\/p>\n\n\n\n<p><img loading=\"lazy\" src=\"\" width=\"275\" height=\"163\"><strong>Ireland: Facebook and Whats App \u2013 Investigations into passwords being stored as plain text&nbsp; <\/strong>The DPC Ireland has notified us of an investigation into Facebook\u2019s&nbsp;<\/p>\n\n\n\n<p>storing of passwords in plain text has been initiated which concerns&nbsp;<\/p>\n\n\n\n<p>fundamental issues in GDPR.&nbsp;<\/p>\n\n\n\n<p>It also issued the following Statement about Whats App: \u201cThe Data&nbsp;<br>Protection Commission (DPC) has been informed (Monday evening&nbsp;<br>13 May 2019) by WhatsApp Ireland of a serious security&nbsp;<\/p>\n\n\n\n<p>vulnerability on the WhatsApp platform. The DPC understands that&nbsp;<br>the vulnerability may have enabled a malicious actor to install&nbsp;<br>unauthorised software and gain access to personal data on devices&nbsp;<br>which have WhatsApp installed\u201d.&nbsp;<\/p>\n\n\n\n<p><strong>Denmark:&nbsp; 160 000\u20ac Fine for not deleting personal data in time&nbsp;&nbsp;<\/strong><\/p>\n\n\n\n<p>Following an inspection by the Danish Data Protection Agency in October 2018, the taxi company, Taxa&nbsp;<br>4\u00d735, have been reported by the Danish Data Protection Agency to the police and the Agency has&nbsp;<br>recommend a fine of 160 000\u20ac for violation of the GDPR.&nbsp;&nbsp;<\/p>\n\n\n\n<p>In most jurisdictions, the Data Protection Authority can issue fines by their own but in Denmark a police&nbsp;<br>report must be issued, and the fine will be determined by the courts of Denmark.&nbsp;<\/p>\n\n\n\n<p>The conclusions are interesting, as they expose several interesting mistakes conducted by Taxa&nbsp;&nbsp;<\/p>\n\n\n\n<p>Article 5 of the EU General Data Protection Regulation outlines the processing requirements for personal&nbsp;<br>data. A recent fine imposed by the Danish DPA gives some guidance on how these Article 5 principles could&nbsp; be enforced going forward. In its ruling, the Danish DPA found that Taxa had violated Article 5 of the GDPR&nbsp; in three ways: purpose limitation, data minimization and storage limitation(retention)&nbsp;<\/p>\n\n\n\n<p>Article 5(1)(b) requires that data be collected for a legitimate purpose and not be further processed in a&nbsp;<br>matter that is incompatible with that purpose. Taxa violated this principle when it transformed the phone&nbsp; numbers of customers into \u201canonymous\u201d account numbers. Taxa admitted that the phone number was not&nbsp; necessary; only an account number to be associated with taxi ride data was needed. Taxa did not treat the&nbsp; phone number as personal data and apparently had no intention of using the phone number to contact or&nbsp; personally identify the individual customer. Instead, it intended it to be an anonymous way to track data to&nbsp; meet a business purpose. The Danish DPA clearly found that personal data must be processed in&nbsp;<\/p>\n\n\n\n<p>compliance with the GDPR, regardless of how the company intends to treat the data.&nbsp;<\/p>\n\n\n\n<p>Article 5(1)(c) requires personal data be adequate, relevant and limited to what is necessary in relation to&nbsp;<br>the purposes for which it is processed. Taxa argued that it had met minimization requirements by removing&nbsp; the names associated with the phone numbers and that its systems were not capable of transferring the&nbsp;<br>anonymous data about the taxi ride from a phone number to a unique ID. The Danish DPA did not care that&nbsp; the computer systems made it difficult to create new account numbers and stated, in no uncertain terms,&nbsp;<br>that costs associated with migrating personal data to a new anonymous data structure do not justify&nbsp;<br>continued use of the phone number beyond the retention policy.&nbsp;<\/p>\n\n\n\n<p>Article 5(1)(e) requires that personal data is kept in a form that permits the identification of a data subject&nbsp; for no longer than is necessary for the purposes for which the personal data is processed. Taxa had a&nbsp;<br><\/p>\n\n\n\n<p>retention policy in place that stated data collected during a taxi ride is only necessary for two years.&nbsp;<br>However, at the end of the two years, Taxa only deleted the name associated with the ride but kept all the&nbsp; taxi-ride data relating to the ride (date, GPS coordinates of starting and ending location, distance, payment)&nbsp; and associated with the customer\u2019s phone number for an additional three years.&nbsp;<\/p>\n\n\n\n<p>Retention schedules are only as good as long as they are followed. Privacy professionals need to ensure&nbsp;<br>that the timetable of retention is no longer than is necessary and that once time has expired that all&nbsp;<br>personal data is removed.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-embed-wordpress wp-block-embed is-type-wp-embed is-provider-hanterar-personuppgifter-i-ostrukturerad-data-under-gdpr-med-ai\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"wp-embedded-content\" data-secret=\"tCATq0QRyi\"><a href=\"https:\/\/aigine.se\/en\/not-deleting-personal-data-in-time-price-160-000e\/english\/\">Not deleting personal data in time. Price: 160 000\u20ac<\/a><\/blockquote><iframe title=\"&#8220;Not deleting personal data in time. Price: 160 000\u20ac&#8221; &#8212; Hanterar personuppgifter i ostrukturerad data under GDPR med AI\" class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" src=\"https:\/\/aigine.se\/en\/not-deleting-personal-data-in-time-price-160-000e\/english\/embed\/#?secret=tCATq0QRyi\" data-secret=\"tCATq0QRyi\" width=\"500\" height=\"282\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe>\n<\/div><\/figure>\n\n\n\n<p><strong>Norway: \u20ac170,000 fine for having one file saved in the wrong location. Or actually, for not knowing&nbsp;<\/strong><br><strong>where the personal data they are processing are stored at all.&nbsp;&nbsp;<\/strong><\/p>\n\n\n\n<p>The Municipality of Bergen has been fined 170 000\u20ac by the Norwegian DPA, Datatilsynet.<strong> <\/strong>&nbsp;&nbsp;<\/p>\n\n\n\n<p><img loading=\"lazy\" src=\"\" width=\"241\" height=\"258\">The breach came to the DPAs attention by the report of one of the students of the public school,&nbsp;<br>administrated by the Municipality of Bergen, who found a file with login&nbsp;<\/p>\n\n\n\n<p>credentials for 35 000 students and employees, in a public storage area.&nbsp;<\/p>\n\n\n\n<p>The fine is for having one file saved in the wrong location. Or actually, for&nbsp;<br>not knowing where the personal data they are processing are stored at all.&nbsp;<\/p>\n\n\n\n<p>Not knowing this means they cannot apply appropriate measures to&nbsp;<br>protect it, and they are therefor in breach of both art. 5(1)f and art. 32&nbsp;<br>GDPR.&nbsp; &nbsp;&nbsp;<\/p>\n\n\n\n<p>Do you know where the personal data you are processing is stored?&nbsp;<br>Datatilsynet found that the municipality\u2019s lack of appropriate measures to&nbsp;<br>protect the personal data in the computer file systems constituted&nbsp;<br>violations of both art. 5(1)f and art. 32 GDPR.&nbsp;<\/p>\n\n\n\n<p>The fact that the security breach encompasses personal data to over 35 000 individuals, and that the&nbsp;<br>majority of these are children, were considered to be aggravating factors.&nbsp;<\/p>\n\n\n\n<p>The Norwegian decision points the finger on the need to perform a privacy data inventory. The Municipality&nbsp; of Bergen has conducted a number of projects relating to information security and access management.&nbsp;<br>However. There is no point in investing in security measures and access management, until one has full&nbsp;<br>control of where personal data resides within the data sources.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-embed\"><div class=\"wp-block-embed__wrapper\">\nhttps:\/\/www.datatilsynet.no\/en\/about-privacy\/reports-on-specific-subjects\/administrative-fine-of-170.000\u2013imposed-on-bergen-municipality\/\n<\/div><\/figure>\n\n\n\n<p>Business Legal&nbsp;<\/p>\n\n\n\n<p>26 Pembroke Street Upper&nbsp; Dublin 2&nbsp;<\/p>\n\n\n\n<p>+353 1 636 3165&nbsp;<\/p>\n\n\n\n<p>+353 1 640 1899&nbsp;&nbsp;<br><a href=\"http:\/\/www.bizlegal.eu\/\">www.bizlegal.eu&nbsp;<\/a><br><a href=\"mailto:info@bizlegal.eu\">info@bizlegal.eu<\/a>&nbsp;<\/p>\n\n\n\n<p>Business Legal&nbsp;<\/p>\n\n\n\n<p>3003 Euro Business Park&nbsp; Little Island&nbsp;<\/p>\n\n\n\n<p>Cork&nbsp;<\/p>\n\n\n\n<p>+353 21 452 4862&nbsp;&nbsp;<br><a href=\"http:\/\/www.bizlegal.eu\/\">www.bizlegal.eu&nbsp;<\/a><br><a href=\"mailto:info@bizlegal.eu\">info@bizlegal.eu<\/a>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Welcome to June\u2019s newsletter&nbsp; This month sees GDPR\u2019s first aniversary, and as the Data Protection Commission reflects on the past 12&nbsp; months, the headline statistics were as follows;&nbsp; &#8211; 6,624 complaints were received&nbsp; &#8211; 5,818 valid data security breaches were notified&nbsp; &#8211; Over 48,000 contacts were received through the DPC\u2019s Information and Assessment Unit&nbsp; &#8211; &hellip;<\/p>\n<p class=\"read-more\"> <a class=\"\" href=\"https:\/\/www.bizlegal.eu\/?page_id=2539\"> <span class=\"screen-reader-text\">Newsletter June 2019<\/span> Read More &raquo;<\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"advgb_blocks_editor_width":"","advgb_blocks_columns_visual_guide":""},"coauthors":[],"author_meta":{"author_link":"https:\/\/www.bizlegal.eu\/?author=3","display_name":"Sharon McGauley"},"relative_dates":{"created":"Posted 6 years ago","modified":"Updated 6 years ago"},"absolute_dates":{"created":"Posted on 24\/05\/2020","modified":"Updated on 24\/05\/2020"},"absolute_dates_time":{"created":"Posted on 24\/05\/2020 9:50 am","modified":"Updated on 24\/05\/2020 9:50 am"},"featured_img_caption":"","featured_img":false,"series_order":"","_links":{"self":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages\/2539"}],"collection":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2539"}],"version-history":[{"count":2,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages\/2539\/revisions"}],"predecessor-version":[{"id":2542,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages\/2539\/revisions\/2542"}],"wp:attachment":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2539"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}