Thursday, 2 January 2014

European Court ruling condemns mass surveillance


From Digital Rights Ireland
12th December 2013
The Advocate General of the European Court of Justice today gave an important opinion in our favour in a case brought by Digital Rights Ireland to challenge European mass surveillance law.
The challenge – which we started in 2006 – is to the Data Retention Directive. This is a law which requires ISPs and telecoms companies to record details of all your internet and telephone use – logging details of who you ring or text, where you travel and who you email – and to record that information for up to two years. We argue that this constitutes an unjustified invasion of the right to privacy and in an interim ruling the Advocate General has agreed, holding that the law is a “particularly serious” interference with individual privacy which creates a:

faithful and exhaustive map of a large portion of a person’s conduct strictly forming part of his private life, or even a complete and accurate picture of his private identity.
The Advocate General accepted our argument that storing this information on all citizens created an “increased risk” that it could be used for unlawful, fraudulent and malicious purposes against them – something we have already seen in Ireland where a Garda sergeant has abused the system to spy on a former lover and where it has been used to spy on journalists.

The Advocate General also held that this type of surveillance would have a “chilling effect” on freedom of expression, and went on to say that the Directive failed to provide even “minimum guarantees” regarding access to or use of the information collected on all citizens. According to the Advocate General the Directive therefore “is as a whole incompatible with Article 52(1) of the Charter of Fundamental Rights of the European Union”.

According to the Advocate General:
the collection and, above all, the retention, in huge databases, of the large quantities of data generated or processed in connection with most of the everyday electronic communications of citizens of the Union constitute a serious interference with the privacy of those individuals, even if they only establish the conditions allowing retrospective scrutiny of their personal and professional activities. The collection of such data establishes the conditions for surveillance which, although carried out only retrospectively when the data are used, none the less constitutes a permanent threat throughout the data retention period to the right of citizens of the Union to confidentiality in their private lives. The vague feeling of surveillance created raises very acutely the question of the data retention period…

the effects of that interference are multiplied by the importance acquired in modern societies by electronic means of communication, whether digital mobile networks or the Internet, and their massive and intensive use by a very significant proportion of European citizens in all areas of their private or professional activities. [emphasis added]
A final judgment on our case will be delivered next year. In approximately 80% of cases the European Court of Justice follows the opinion of the Advocate General. Even pending the full judgment, however, this is already a significant step forward in the very first case of this nature to be brought to the ECJ and confirms the importance of our case.

Users of public wi-fi may have had personal details stolen


The Journal
11th December 2013

PEOPLE WHO USED wi-fi in public areas such as hotels may have had their details stolen due to security flaws, an Irish firm has warned.

Cork-based IT firm Smarttech.ie said that they had discovered “serious flaws” in cyber security measures after visiting 10 hotels in October and November.

They say that finding the flaws took “minimal” effort.

Smarttech say that they “wanted to demonstrate just how dangerous using unencrypted logins and passwords across a public network can be”.

Over the course of these security tests however, Smarttech.ie soon realised that the level of security being provided was a serious problem. In addition, they say that users seemed “completely oblivious to the dangers of using public wi-fi”.

The company carried out tests on public wi-fi systems and spotted flaws within 20 minutes.

They were then able to access users’ information, including email logins, credit card details, social media passwords and banking information.

In some cases, networks were accessed from outside the hotels.

Smart-tech says that they informed all of the hotels and made recommendations on how to close the gaps.

They added that anyone who operates a network should be aware of the security on their network. Under EU law, it is the duty of the premises supplying the network to ensure that the network is secure.

According to Ronan Murphy, CEO of Smarttech.ie, “Consumers need to be aware that if you are accessing public wi-fi there are serious security challenges. The tests we carried out prove that these risks affect anyone using public Wi-Fi. However there are steps that hotels and restaurants can take to secure their Wi-Fi service and therefore protect their customers”.

Tuesday, 3 December 2013

Data Breach at Loyaltybuild: Update 22 November 2013

Following the data breach which occurred at Loyaltybuild in October resulting in the breach of personal data of some 1.5 million individuals (including 376,000 individuals whose full credit card data was compromised), the investigation of the ODPC has been continuing.

The ODPC received a full client company list from Loyaltybuild in respect of those client companies whose customer data was exposed during the data breach. The ODPC immediately instructed Loyaltybuild to notify these client companies of the breach of their customer’s data and received confirmation from Loyaltybuild that this has taken place.

The ODPC also made contact with the client companies of Loyaltybuild based in this jurisdiction and instructed them to inform their customers of the breach of their data in accordance with our data security breach code of practice. The focus of our investigation to date has been uncovering the extent and nature of the personal data involved in the breach and ensuring that affected individuals have been duly notified. It is our understanding that this notification process is nearing completion.

Given the transborder nature of this data breach, the ODPC has taken the important measure of notifying relevant European colleague data protection authorities providing them with relevant information for any follow up action they may need to take.

The ODPC investigation is continuing with the focus now on security practices and procedures employed by the company. Part of this phase of the investigation will also involve the carrying out of a follow up inspection. The company has ceased its processing of personal data until such time as it can satisfy this Office that adequate security measures are in place.

Tuesday, 12 November 2013

Criminal Involvement in Super Valu Customer Breaches


A criminal attack is behind the data breach affecting customers of SuperValu and Axa Insurance, the data protection commissioner said today

Billy Hawkes also said warned that the criminals involved have the information needed to use the credit cards of people affected by the data breach.

“We were told about the original issue last week, last Monday, but we were updated and told the situation was more serious because we now know the criminals involved have all the information needed to use the credit cards of the people concerned to make purchases,” he told RTE’s Morning Ireland.

As a result, the Consumers Association of Ireland (CAI) is advising affected customers to cancel their credit cards.

"We’re suggesting that customers certainly get in contact with their credit card providers immediately," said Dermott Jewell, Policy and Council Advisor at the CAI.

"In light of what the Data Commissioner has announced this morning - that criminals have full access to confidential bank details – we would advise those affected to contact their credit providers and get advice on how to proceed."

Mr Hawkes said today a team of investigators is to enter Loyaltybuild in Clare- the company operating the loyalty holiday scheme on behalf of the companies.

The company operates loyalty schemes for a number of European companies, he told RTE radio’s Morning Ireland.

“That is why we need to send in our inspection team,” Mr Hawkes said.

“We need to find out for ourselves if more action is needed to be taken.”

Earlier it emerged that the breach was worse than expected - over 60,000 SuperValu customers may have had their financial data stolen after the retailer announced a data breach is more extensive than first thought.

Axa Insurance said about 8,000 customers had been affected.

Last week, Super Valu warned customers of its loyalty holiday scheme that their banking information may have been accessed by a third party.

The programme has since been suspended and the data protection commissioner was informed of the leak - but at the time SuperValu said it was not aware of any breaches of financial information

But tonight a statement by SuperValu warns customers that Loyaltybuild had advised the Data Protection Commissioner that the security breach of its system “is more extensive than it first anticipated”.

“Based on this latest information from Loyalty Build, SuperValu are tonight contacting Getaway Breaks customers that there is a high risk that an unauthorised third party accessed the details of payment cards used to pay for Getaway Breaks between January 2011 and February 2012,” the statement read.

It said that 62,500 customers who made bookings during this period have been told to contact their bank or financial institution as soon as possible.

They have also been advised to immediately check the transactions on their payment cards for any suspicious activity.

Customers of the scheme have also been advised to treat any unsolicited communication they receive claiming to represent SuperValu Getaway Breaks or Loyalty Build with extreme caution.

Super Valu and Loyaltybuild are continuing to investigate the matter which is affecting customers of the holiday scheme only.
Irish Indepenent 12th November 2013

Thursday, 7 November 2013

Super Valu breach customers' data protection rights


Irish Times

Supervalu has been forced to contact thousands of customers who have bought its “getaway breaks” after a security breach at the company that oversees the scheme left sensitive financial data potentially compromised.

The “getaway breaks” vouchers are a key loyalty reward programme run by the US-owned company Loyaltybuild, which is based in Co Clare. It is reviewing the security of the personal and payment card information held on its booking system.

“This review is necessary as Loyaltybuild has advised its client base in Ireland that its system may have been compromised by a third party,” said Supervalu in a statement.

‘Precautionary measure’
He said that there was no information to suggest that any sensitive customer data had been obtained “as yet”, and said that “as a precautionary measure” it was urging customers who had booked a getaway break recently to review their accounts and report any unusual activity or unsolicited communication connected with the deal to their bank.

Supervalu apologised to its customers for any unnecessary concern that details of the breach may have caused and said the “Getaway Breaks” booking system will remain temporarily suspended until the Loyaltybuild system has been given the all clear.

Encrypted
The company managing the rewards programme has informed the Data Protection Commissioner of the potential breach, which was uncovered on October 25th, and it stressed that all payment card information it holds is encrypted.

“We immediately engaged the services of a firm of leading, international, online security experts,” a spokeswoman said. “They are conducting a forensic investigation to help us identify whether any of our stored data was compromised, and, if so, to what extent.”

She said that as of 5pm yesterday, the forensics team reported there had been no signs of personal or financial details data being extracted or compromised but added that the examination is ongoing.

She said that the company was “working around the clock with our security experts to get to the bottom of this and to further enhance our security”.

Wednesday, 16 October 2013

Company convicted of sending spam email to former swimmer Michelle Smith de Bruin


Two companies have been convicted of sending spam email or text messages, including one sent to barrister and former Olympic swimmer Michelle Smith de Bruin.

Lex Software Ltd, trading as Legal and General Software, pleaded guilty before the Dublin District Court to two charges of sending unsolicited email messages – one to Ms Smith de Bruin and another to Patrick Wilkinson.

In evidence, assistant data protection commissioner Tony Delaney told the court the defendant company had admitted sending the spam email after a formal warning had previously been issued by the Data Protection Commissioner following an earlier complaint by Ms Smith de Bruin.

He said it had also confirmed having sent a spam email to Mr Wilkinson without providing a means of allowing him opt out of receiving further marketing emails. The company pleaded guilty to both charges.

Operations director of Lex Software, John Gilmartin, submitted that Ms Smith de Bruin’s details had been removed from the company’s list at her request but when a new list of contacts had been created using the updated legal directory, her details had been included in error.

The company had engaged an external provider to ensure all future marketing emails would contain a means of opting out.

Judge William Hamill imposed convictions on both charges and fined the company €200 in respect of each one.

Separately, Judge Hamill convicted Hanford Commercial Ltd, trading as the Maldron Hotel, Wexford, on a charge of sending an unsolicited marketing message by text, where a complainant had previously opted out of receiving such messages. The company pleaded guilty to the charge. Judge Hamill imposed a fine of €200.

Mr Delaney told the court the complainant, Robert Gogan, had previously sought the assistance of the Data Protection Commissioner to ensure his details were removed from the company’s database and that a formal warning had been issued to it in February of last year.

Sean McKeon, of the hotel group, told the court steps had been taken to ensure compliance with the regulations on sending such material.

Tuesday, 10 September 2013

Garda Síochána Ombudsman Commission seeks unlimited access to criminal records

The Irish Times - 10th of April 2013 

The Garda Síochána Ombudsman Commission has urged Minister for Justice Alan Shatter to give it unfettered access to the Garda’s Pulse computer database, which includes intelligence on criminals.

The Data Protection Acts 1998 to 2003 confer rights on you to access certain information (on computer, in manual or paper files) about you which is held by the Gardaí. An example of this information would be any entry by the Gardaí on the Garda PULSE system (the Garda computer system), or in Garda investigation files.  

Can I access any data being held on me by the Gardaí? 

• A copy of the data being kept about you

• A copy of any data held about you which is an opinion (except where such opinions were given in confidence)

• Know the purpose for which the data is being kept

• Know the identity of anyone to whom the Gardaí disclose that data

• Know the source of the data (i.e. where the data came from) unless it is contrary to public interest.

• Supply the information to you within 40 days of receiving your request • Provide the information in a manner or form which will be clear to you.

• If the access application or request for data would identify someone else. This also applies in relation to the obligation on the Gardaí to provide details of the source of the information held. If the source or origin of the information identifies a third party, then it can be withheld.

• If the personal data being kept is for the purpose of preventing, detecting or investigating crime, or for arresting or prosecuting offenders.

• The child does not have the intellectual ability to understand the nature of the request • The parent or guardian is acting in the best interest of the child.

• If in the opinion of a member of the Gardaí (not below the rank of Chief Superintendent), the personal data is required for the purpose of safeguarding the security of the State

• If the personal data is required for the purpose of preventing, detecting or investigating crime or for arresting or prosecuting offenders

• Your full name

• Your correct date of birth

• Any other names used by you

• Your current address and previous addresses in Ireland

• A copy of your passport, driving licence or birth certificate

• A fee of €6.35.

You have a number of other rights under the Data Protection Acts, in addition to the right of access described above These additional rights include the right to have any inaccurate personal information about you corrected or erased and the right to complain to the Data Protection Commissioner. 


Why can the Gardaí refuse my request? 


Can somebody apply to the Gardaí for my personal data on my behalf? 


Can the Gardaí access personal data held on me by other people? 

How to apply.
What can I do if the Gardaí refuse my request?
The move is likely to be strongly resisted by Garda Headquarters as it would represent the first time in the history of the force that the Garda did not have full control, and the ability to disseminate as it sees fit, the intelligence at its disposal. The Commission has expressed concern that under current procedures it is reliant on assurances from the Garda that information passed to it represents the “totality of such information held” on whatever matter it may be investigating.

“The absence of any independent access to (the Pulse) systems raises issues around the effectiveness of the Ombudsman Commission’s oversight investigative function,” it said in a report to Mr Shatter.

The report contains a series of recommendations arising from the Commission’s  recently concluded major investigation into how gardaí handled drug dealer and informer Kieran Boylan. It had encountered “delays in access to documentation and intelligence” held by the Garda as a “constant feature” of the four-year investigation, citing those delays as the reason for the excessive time taken to complete the inquiry.

Aside from what it believes were serious delays in providing information to it, Gsoc has also expressed serious concern that measures around the registering of Garda informers and recording the extent and nature of contact with them are possibly not being followed. It outlined its concerns in a brief report published yesterday at the conclusion of its investigation into the Boylan affair. Mr Shatter later released a fuller version of that report sent to him by Gsoc last week in which it made a number of recommendations.Mr Shatter is reviewing the report and awaiting observation on it from Garda Commissioner Martin Callinan.

However, Mr Shatter last night released a two-page report from a retired High Court judge TC Smyth SC, who has examined the use of informers. In a report on it dated October 2012 the judge informed Mr Shatter there appeared to be “substantial compliance” with the rules set down for handling informants under it.

Section 4 of the Data Protection Act allows you to make a request to the Gardaí for a copy of any of your personal data being kept by them. On making an access request to the Gardaí, you are entitled to: Once the Gardaí receive a correct request from you, they must reply to you within 40 days. This is the case even if they do not hold any of your personal data or they are refusing the request.

If the Gardaí decide that the information is to be provided to you, they must: Under the Data Protection Acts, the Gardaí can refuse any request for personal data and can withhold that information on the following grounds: Yes. The Gardaí may receive an access request by a representative on your behalf. They will however will need to satisfy themselves as to the identity of that person and will have to be provided with enough information about you to assist in establishing identity and locating the data sought or requested.

The Gardaí will require written confirmation from you, authorising your representative to make the request. An example of this could be where your solicitor would be authorised by you to request the information. Where the request is in relation to a child, then a parent or guardian can exercise the right to apply for and receive the information on behalf of the child if:

Yes. In certain circumstances, the Gardaí are entitled to access your personal data. In such circumstances the person holding such personal data on you will not be in breach of the rules against disclosing personal data to third parties. The following are the occasions where the Gardaí are allowed to access such personal data:

How do I apply to the Gardaí for my personal data?

Requests for personal data must be made in writing to the Garda Criminal Records Office. While it is not a requirement to mention the Data Information Acts, it is recommended that you do. You can download the Gardaí's access request form (pdf).

You must provide enough information to establish your identity and to allow the Vetting Unit to locate the information you request. It is important (from the Gardaí’s point of view) that they establish your identity to ensure the information is given to the right person.

In order to obtain your own personal data, you are required to provide the following: 

If you are of the opinion that the Gardaí are in breach of the law by not giving you the personal data you requested, you can make a complaint to the Data Protection Commissioner. The Commissioner will investigate your complaint unless they are of the opinion that the complaint is frivolous or vexatious. (That is, your complaint is without any foundation). As soon as the Data Protection Commissioner has investigated your complaint, you will be notified in writing of the decision.

 If the Data Protection Commissioner is of the opinion that the Gardaí are in breach of the Act, the Commissioner may serve what is called an enforcement notice on the Garda Commissioner and make the Gardaí hand over to you the information you requested.