Showing posts with label GDPR. Show all posts
Showing posts with label GDPR. Show all posts

Monday, 2 December 2019

Anonymity in social networks: the case of anonymous social media

an article by Vasileios Chatzistefanou and Konstantinos Limniotis (Open University of Cyprus, Nicosia) published in International Journal of Electronic Governance Volume 11 Number 3/4 (2019)

Abstract

The anonymity provided by the so-called anonymous social networks is studied in this paper. More precisely, emphasis is given on investigating whether the underlying personal data processing in such networks may suffice to result in tracking or identification of the users.

To this end, five popular anonymous smart applications are being analysed through monitoring the outgoing traffic of Android devices in real-time when using these applications, to examine which personal data – including device data – are being processed by either the anonymous networks or third parties such as library providers.

The corresponding privacy policies of these applications are also examined, towards evaluating whether the information provided to the users is sufficient.

Our analysis concludes that there is personal data processing in place even in such (so-called anonymous) applications which in turn implies that users anonymity cannot be ensured, whilst the corresponding privacy policies may leave room for further improvement.


Wednesday, 24 April 2019

Bridle-ing at a SAR?

a post by Christopher Wright for the Panopticon blog (a blog about information law written by specialist barristers from 11KBW)

Sometimes the Easter Bunny comes bearing mysteriously non-egg shaped gifts to the data protection practitioner. The judgment of the always-worth-reading Warby J in Rudd v Bridle & J&S Bridle Ltd [2019] EWHC 893 (QB) is just such a delivery, albeit that this one appears to contain a high content of asbestos.

The factual background to the case is set out in the judgment in some detail, and it is, frankly, too long, boring and depressing to warrant repetition here. In essence, Dr Rudd is a medical expert on exposure to asbestos. Mr Bridle is a long-standing campaigner on asbestos issues, who takes a heavily divergent view from Dr Rudd and is mostly sceptical of claims about the effects of asbestos exposure. Mr Bridle has been running an almost equally long-standing campaign against Dr Rudd, which including reporting him to the GMC on the grounds of having made false reports in his expert evidence in various legal proceedings. It is clear from the evidence set out in the judgment that Mr Bridle considers that Dr Rudd is part of conspiracy to assist asbestos claimants to recover damages on (in his view) a false basis.

Entirely unsurprisingly, Dr Rudd is unkeen on Mr Bridle’s allegations against him and wished to learn more about what Mr Bridle was doing. He made a subject access request under section 7 DPA, and indeed issued a notice under section 10 DPA 1998. This, on any view, somewhat spiralled. On being told by Mr Bridle that he was not the data controller at all, but rather his company was, a second SAR and notice were issued against the company. The view of the Defendants in response to the issued subsequent claim was that almost all of the data requested was exempt on grounds of legal professional privilege (para 10 of Sch 7), the journalism exemption (section 32) or the regulatory proceedings exemption (section 31). By the time of trial, the data withheld on the basis of the latter two exemptions had been disclosed, but on the basis that it had been properly within the exemptions.

Continue reading

Hazel’s comment:
I do not as a normal rule bring you items on data protection or, indeed, on other aspects of information law but this case fascinated me not so much for the legal aspects but the personal animosity shown between the two parties.


Saturday, 26 August 2017

What small businesses need to know about the General Data Protection Regulation

via Bytestart by Stuart Crook a data protection expert and Associate at the national law firm, Stephensons.

General Data Protection Regulation

Despite Brexit, the UK government has confirmed it will abide by the new General Data Protection Regulation (GDPR), which is due to come into effect on 28 May 2018.

The aim of General Data Protection Regulation is to encourage companies across the European Union to think seriously about data protection. In practice, the new GDPR lays down some fairly stringent legislation, for both large and small businesses, governing the standards by which personal data is collected and stored.

To help UK businesses understand the new laws, and avoid the heavy punishments failure to abide by them bring, here’s a guide to the GDPR legislation.

Continue reading


Thursday, 13 July 2017

Cyber Security Breaches Survey 2017

I’ve just been reading Privacy & Data Protection (Volume 17 Issue 5 (April/May 2017). An analysis of the above report published by the DCMS forms the subject of Expert Comment by Bridget Treacy, a partner at global law firm Hunton & Williams.

Ms Treacy tells us that it unsurprising that 61% of businesses view cyber security as an important issue.

What is surprising, both to Ms Treacy and to me, is that viewing security seriously and doing something about risk are two very different things. Specifically, the report notes that:
  • only 37% have segregated wireless networks, or any rules around the encryption of personal data;
  • 33% have a formal policy that covers cyber security risks, and only 32% document these risks in business continuity plans, internal audits or risk registers;
  • 29% have made specific board members responsible for cyber security;
  • a mere 20% have required staff to attend cyber security training in the last twelve months, with non-specialist staff being particularly unlikely to have attended;
  • although 19% of businesses are worried about their suppliers’ cyber security, only 13% require suppliers to adhere to specific cuber security standards or good practice; and
  • only 11% have a cyber security incident management plan in place.
You can access the full report here (PDF 66pp)

Ms Treacy, writing in a personal capacity, ends her article by commenting that “These are worrying conclusions for all of us who regularly entrust our personal data to UK companies for processing.”