Thursday, 26 March 2015

Increase seen in law suits for failing to protect personal data

Thu, Mar 26, 2015

Increase seen in law suits for failing to protect personal data


Data Protection Commissioner Helen Dixon said there had been an increase in the number of civil cases taken against organisations for failing to protect personal data.

Conference hears case against government department settled before court hearing

 There has been in increase in the number of civil law actions taken against organisations and even government departments for failing to protect people’s personal information, a conference has heard.

Such an action against one government department for allegedly breaching a person’s data protection rights settled ahead of a listed court hearing this week.

The action, understood to have been against the Department of Social Protection, is one of an increasing number of such cases being taken against companies or public bodies that allegedly fail in their duty of care to protect people’s personal information.

The issue was raised at a Public Affairs Ireland (PAI) data protection conference in Dublin on Wednesday.

Several such cases under the Data Protection Acts have been listed for hearing in the past year or so, but they have generally been settled on the steps of the court.

They included the case of a woman who sued a pharmacist for allowing her husband view CCTV footage which showed her buying a pregnancy test. Another such case involved a GP who handed over excessive personal information about a patient to an insurance company.

The actions are taken under section 7 of the Data Protection Acts, which provide that a data controller owes a duty of care to individuals in respect of the personal information it collects or processes.

Data Protection Commissioner Helen Dixon told the PAI conference there had really been “no activity” in relation to such civil lawsuits until “very recently” but that there were now “quite a number of cases” where people were taking actions under section 7 of the Acts.

The commissioner cannot impose direct fines on organisations that fail to respect data protection rights. This will change under proposals in a new European data protection regulation currently being negotiated.

Ms Dixon also noted a recent case involving a GP who had handed over excessive personal data about a patient to an insurance company. Her office had been called as a witness. The case was settled after a day in court.

“In that particular case, the witness from the [Data Protection Commissioner] said that it really had huge impact on them to hear the data subject in that case set out for the court the damage that was suffered as a result of that unfair disclosure of their data – the excessive data disclosure – to the insurance company.”

The person had gone on to suffer enormous health problems as a result of the data breach.

Ms Dixon said she was aware of another case listed that had directly involved a government department, but it had been settled out of court.

While she did not identify the government department concerned, the commissioner said she imagined the person in question had been paid damages.

Rob Corbet, a partner and Head of Technology and Innovation at Arthur Cox, also confirmed in his speech to the event that there had been an increase in the number of people suing for breaches of their data protection rights.

The commissioner reminded those in the public sector of their responsibilities in relation to handling personal data, noting her office had successfully prosecuted private investigators last year for offences involving the ‘blagging’ of people’s personal details from a government department.

Ms Dixon said that over 100 data breaches involving public sector bodies were reported to her office every year.

“Fortunately, in most instances in recent years these have concerned breaches that are really non-systemic and haven’t affected a great volume of data subjects.”

Minister for Data Protection Dara Murphy, who also addressed the event, spoke about the Government’s key priorities for the year.

He said he had established an inter-departmental committee on data issues, bringing together the key individuals dealing with data protection in each government department.

Mr Murphy said the committee would assist in the delivery of “more effective public policy through the improved use of data”.

He said exciting advances in technology created huge potential for society and for the economy.

Departments and State agencies needed to show leadership and commitment to data protection rules as they evolved over the next year, during which a conclusion to negotiations on the new European General Data Protection Regulation is expected, he said.

The minister said the committee’s engagement would be formalised in the coming weeks with the establishment of a “data issues forum”, with input from business, civil society and other key stakeholders.

Dr Eoin O’Dell, Associate Professor of Law at Trinity College Dublin, addressed the conference on the challenges posed for privacy by new technologies and the Internet of Things.

He said that increasingly, the kind of personal and public data becoming available, as well as the sharing of public sector information and datasets online, would have an impact on decision-making processes.

“All of this is heading towards a nice, bright Utopian future. But, I think that this rhetoric needs to be accompanied by an attention to privacy, both on our own part in the creation of the data, and in our professional lives in the use of the data.”

Fintan Lawlor is a dedicated data protection consultant and solicitor at Lawlor Partners. For more information see our website : www.lawlorpartners.ie

Wednesday, 21 January 2015

Alan Shatter loses appeal against Mick Wallace data ruling

Irish Times, 21st January 2015

Former minister for justice Alan Shatter has lost his appeal against a decision by the Data Protection Commissioner that he breached data protection laws by disclosing information about Independent TD Mick Wallace on RTE’s Prime Time.

The commissioner found that Mr Shatter had failed to uphold his statutory duties under the Data Protection Act by disclosing during a televised interview in 2013 that Mr Wallace had been cautioned by gardaí for using a mobile phone while driving. Mr Shatter had appealed that decision to the Circuit Civil Court, arguing that the commissioner had pre-determined the matter before he made his finding.

Dismissing Mr Shatter’s appeal on Wednesday, Judge Jacqueline Linnane said that in her view the commissioner had considered the matter fully. She said the commissioner had taken into account the arguments put forward by Mr Shatter, that fair procedures were followed and that reasons were given for the final decision.

“I do not consider that it has been shown that the decision made was vitiated by any serious or significant error or series of such errors,” Judge Linnane said.

She also said the argument that Mr Shatter did not have standing to take the appeal was “well founded”, as his actions at the time had been carried out in his capacity as minister for justice.

Commenting on the judgment, Mr Wallace said it was a “good decision” and that Mr Shatter had pulled a political stroke by divulging details of his caution.

“I was very surprised that the minister did what he did. It seemed a bit out of character at the time. I think the data commissioner though was very, very thorough in how he analysed the whole thing,” the Wexford TD said.

In his appeal, Mr Shatter had claimed the commissioner pre-judged his inquiry into his actions on Prime Time and made “serious errors” in deciding that he breached data protection laws.

Eileen Barrington SC, for Mr Shatter, had told the court last November that the decision had consequences for the former minister “personally, politically and professionally” and was “a factor” in his resignation last May.

Ms Barrington said there was a “clear absence” of fair procedures in the commissioner’s decision-making process. She told the court on the same day that Mr Wallace lodged a complaint against Mr Shatter, the commissioner made a statement to RTÉ News to the effect that personal data had been disclosed during the Prime Time debate. This showed a “predetermination of matters” and was “quite inappropriate”.

She said that in a letter to Mr Shatter the following day, the commissioner said he was satisfied that personal data about Mr Wallace had been processed by the then minister. “The DPC wrongly started the process with the expression of a conclusion,” she said, adding that there appeared to be a “rush to judgment”.

Ms Barrington said the Data Protection Commissioner’s decision was “flawed” and wrongly applied definitions in the data protection laws. Mr Shatter could not be a “joint controller” of personal data, as the Data Protection Commissioner stated, because he “clearly” did not control its content and use. The information about Mr Wallace was passed to him orally by the Garda Commissioner and he never saw any relevant written records.

Barrister Paul Anthony McDermott, for the commissioner, had told the court that Mr Shatter had no right to take the appeal. He said that at all stages the complaint to the commissioner was made against the minister for justice, “who happened to be Mr Shatter at the time.”

Mr Shatter’s correspondence with the commissioner, on ministerial headed notepaper, made clear that he had acted at all times in his capacity as minister, Mr McDermott said, and the only person who could take such an appeal was Frances Fitzgerald, the current minister for justice.

“Mr Alan Shatter the private citizen wouldn’t have been given the information by the (Garda) commissioner, wouldn’t have been invited on Prime Time and wouldn’t have deployed the information in defence of the gardaí,” Mr McDermott said.

“This appeal failed from the outset because it is brought by someone who doesn’t have a right to take an appeal.”

Fintan Lawlor is a dedicated data protection consultant and solicitor at Lawlor Partners. For more information see our website : www.lawlorpartners.ie

Wednesday, 17 December 2014

Welfare staff opposed giving PPS numbers to Irish Water

Irish Times 13th December 2014
Photograph: Cyril Byrne/The Irish Times

Staff at the Department of Social Protection vigorously opposed the handing over of PPS numbers – particularly of children – to Irish Water, it has emerged.

Emails released under Freedom of Information legislation show Irish Water (IW) was seeking a “data dump” from the department, including information on all children for whom child benefit was paid.

Documents also show the utility failed to engage with the department on the question of accessing the data until weeks after Irish Water started posting application forms to households in September.

These forms sought PPS numbers of householders and any children who were eligible for child benefit.

It said these were necessary in order for it to apply Government allowances for water charges and it expected the department would verify them once customers had handed them over.

Implications questioned However, staff in the department questioned the data protection implications of handing over the PPS numbers and their obligations under official secrets legislation.

Secretary general of the department, Niamh O’Donoghue, told staff the utility was to “get nothing” until it wrote to her formally, which it did not do until September 18th – several weeks after it started media advertising and sending out packs to householders.

As late as October, an internal department email following a meeting with Irish Water said the utility had given the issue “little thought, so this discussion will go on for a wee while”.

It added: “We are making progress as you will see, but DSP objective is to protect its data, its reputation and minimise its commitment while being supportive to IW as directed in the Government decision (on water charges).” Email exchanges There are concerns throughout six months’ worth of email exchanges about “very limited” contact from Irish Water, with one document expressing concern the department “may be blamed for shortfalls in IW performance”.

The department documents indicate it was “pushing back strongly” on Irish Water’s request that it verify a customer was a recipient of child benefit.

Department officials ultimately conceded it seemed “likely” the utility was entitled to get the information it was seeking, but certain information could not be provided unless it was to allow some “fishing”.

The Social Welfare & Pensions Act, signed into law in July, amended the law to add Irish Water to the list of ‘specified’ bodies allowed to ask for PPS numbers.

But the requirement for customers to hand over this information to the utility was eventually dropped when Minister for the Environment Alan Kelly announced a revised package of measures on water charges in November.

Reaction expected Department official Tony Kieran of the child benefit (CB) section in Letterkenny told colleagues in emails he expected a major public reaction and had made it clear to Irish Water in a meeting in June his section would “not be dealing with phone or other queries on this”.

 “I have serious reservations about providing a wide-ranging data dump as I believe we (DSP and CB) will be dealing with a lot of fallout and get into arguments that have nothing to do with our schemes. This is without even considering the data protection implications of such an approach.”

By July, Mr Kieran was expressing concern that he was hearing radio ads from Irish Water stating correspondence would issue to the public shortly and that, as yet, it had not been back in touch with the department or drafted up any rules to apply to crediting water allowances.

Fintan Lawlor is a dedicated data protection consultant and solicitor at Lawlor Partners. For more information see our website : www.lawlorpartners.ie

Monday, 24 November 2014

Private investigator fined €5,000 for accessing Garda data


Irish Times 24th November 2014

A private investigator have been convicted on two charges of illegally obtaining information from the Garda Pulse system.

Michael J Gaynor, trading as MJG Investigations, Beatty Grove, Celbridge, Co Kildare, was before Dublin District Court facing a prosecution by the Data Protection Commissioner.

Mr Gaynor (62) faced three charges of illegally accessing personal information held by An Garda Síochána and of disclosing it without authority, under the provisions of section 22 (1) of the Data Protection Acts 1988 and 2003.

He was convicted on two of those charges and fined €2,500 for each offence.

Judge John O’Neill said that in his view Mr Gaynor had not given convincing evidence of why he was contacting a serving garda.

Mr Gaynor pleaded guilty to 69 other charges but pleads not guilty on the three related to accessing the Garda information.

Remy Farrell SC for the Data Protection Commissioner told the court Mr Gaynor had allegedly provided tracing reports to three credit unions - in Balbriggan, Lucan and Citybus Credit Union - on individuals they hoped to take action against for non-payment of debts.

He had allegedly obtained the information from Detective Garda Paul Cullen, a member of the Garda National Immigration Bureau, who had “little cause to be accessing information” on the three individuals concerned.

Assistant data protection commissioner Tony Delaney told the court that in an interview with Det Garda Cullen at the GNIB headquarters on March 18th 2014, the garda had admitted accessing all the records on the individuals concerned.

After questioning Det Garda Cullen for several minutes in the witness box, Mr Farrell made an application to have him treated as a hostile witness.

The detective contended Mr Gaynor, with whom had served as a garda for about 20 years, was in fact an “informal informant” who would telephone him from time to time with information about individuals who may be “of interest” to An Garda Síochána.

He said he may have “inadvertently” disclosed information to Mr Gaynor after the private detective contacted him in this context, but that he never provided information directly from the screen in front of him when logged into either the Pulse or GNIB databases.

Mr Cullen said that when Mr Gaynor had given him a name, an address or a car number, he would immediately check them on one of the systems available to him.

“He was offering me information,” the garda said.

He said he did not confirm any information to the private detective other than to tell him it was “not of interest to the gardaí”.

Mr Farrell asked at one stage why Mr Gaynor would be passing information on individuals to Mr Cullen and whether they were perhaps members of “al-Qaeda”.

Judge John O’Neill said he had “no difficulty” in having Mr Cullen treated as a hostile witness and said he agreed with prosecuting counsel that the detective was “playing with words”.

Friday, 14 November 2014

Pharmacy allowed husband watch footage of wife buying pregnancy test, court hears

Irish Times, 14th November 2014

A Co Wicklow mother, who claimed a pharmacy allowed her husband to watch CCTV footage of her buying a pregnancy test kit, has settled a €38,000 damages claim against the pharmacy for an undisclosed sum.

The woman, who cannot be named by order of the judge in the Circuit Civil Court, said her marriage had been highly dysfunctional and difficult for a number of years before the October 2010 incident. The incident, she said, worsened her relationship with her now deceased husband.

She told her barrister Martina O’Neill that she had bought the pregnancy test for a friend, but her husband found the receipt in their home and went to the pharmacy with it.

The court heard the husband was very possessive and had displayed abusive and violent behaviour towards his wife. When he arrived at the pharmacy he pretended to be very distressed and “tricked” one of the employees into showing him CCTV coverage of the actual purchase.

The husband told the pharmacy employee he had found the receipt in his teenage daughter’s bedroom and was concerned that she was sexually active. This had been why he had asked to be shown CCTV footage.

When asked by counsel for the pharmacy if her husband could have played “a low trick” on the employee, the woman said she could see him playing such a role as he would have been very good at it.

Mr English told the court the pharmacy assistant was very concerned for the wellbeing of the man’s teenage daughter and, due to his agitated state, showed him CCTV footage of a woman purchasing the test.

Circuit Court president Mr Justice Raymond Groarke was told that the father, who had identified the woman as being his daughter’s aunt, had secretly taken pictures of the CCTV footage with his mobile phone. The court heard the woman in the video was, in fact, the girl’s mother and plaintiff in the court proceedings.

The mother told the court she and her husband were not having an intimate relationship at the time and this had led to a row with her husband as he thought she had bought the test for herself.

She said her husband sent her, on her own mobile phone, a picture of her purchasing the pregnancy test. She had been scared about going home as she knew he would use it to start a row.

The woman told the judge that her husband and she had separated on and off. He had been physically and mentally abusive towards her. Gardaí­ had intervened several times after being called by the couple’s children.

The court heard the incident had not made their “traumatic marriage” any better as the husband had used the pregnancy test purchase as “a stick to beat her with” and made her life a misery.

“Every day after that he would talk about it any chance he could get. He became abusive on a daily basis,” she told the court.

She suffered acute stress and depression and had needed to obtain counselling and medication.

The woman said she had complained to the then Data Protection Commissioner, Billy Hawkes, who had found there had been a breach of the Data Protection laws.

The mother had afterwards issued the court proceedings in which she sued the pharmacy under the Data Protection Act for negligence and breach of duty in allowing the footage to be shown to the father.

Mr English told Judge Groarke that if the father had taken photographs of a computer screen, he had done so without the pharmacy’s consent and the pharmacy fully contested the mother’s claim.

Counsel said the act allowed for personal data to be given to a third party if it was required urgently to protect someone’s health. He said the father had been highly agitated and distressed.

Following a brief adjournment to allow talks between the parties, Ms O’Neill said the matter had resolved. The judge, who had earlier refused an application by Ms O’Neill for the case to be heard in camera but had made an order restraining identity of any of the parties, struck out the case

 

Thursday, 25 September 2014

20% of ‘right to be forgotten’ requests concern an image

French start-up Forget.me, which helps consumers remove information about themselves from Google, has said almost 20 per cent of Irish requests under the “right to be forgotten ruling” concern an image.
The European Court of Justice ruled in May that individuals have the right, in certain circumstances, to ask search engines to remove links with personal information about them.
Established by online reputation agency Reputation VIP, Forget.me helps users through the process of asking Google to remove information.
Since setting up in June, the start-up has received applications requesting the removal of almost 300 links from Irish people.
Three-quarters of applications were refused by Google, as they were “deliberately placed in public”, concerned another person, or were still relevant.
Some 8.5 per cent of requests were refused as the person seeking removal of information was the author of that information and could change it themselves on social media.
Forget.me said 18 per cent of Irish requests concerned an image, and Ireland is the ninth country in the number of requests, with 294 URL removals. In comparison, the UK ranked first with 3,700 requests for URL removals.

Requests declined
Overall, Google decli- ned 59 per cent of requests submitted by Forget.me seeking the removal of information on behalf of people throughout Europe.
This is based on more than 15,000 URLs sent to Google via Forget.me, from 30 countries.
Within one week of launching on June 24th, 13,000 people had registered on Forget.me and submitted 1,106 “right to be forgotten” applications requesting the removal of a total of 5,218 links.
Invasions of privacy, defamation and insult represented just over 50 per cent of all Google content removal requests.

Helen Dixon appointed as Data Protection Commissioner

Former companies registrar and Department of Jobs official succeeds Billy Hawkes
Irish Times, 10th September 2014
The Government has announced the appointment of Helen Dixon as the new Data Protection Commissioner.
Ms Dixon, who has previously held senior management positions in the Department of Jobs, Enterprise and Innovation, succeeds Billy Hawkes, who retired last month.
He had been in the role since 2005, serving two separate terms.
In a statement, a Government spokesman said Ms Dixon brings “a wealth of experience and expertise to her new role, both in the public and private sectors”.
She was appointed registrar with the Companies Registration Office in December 2009 having previously held senior management positions in the Department of Jobs.
She served an 11-year career in two US IT multinationals with their EMEA bases in Ireland.
The new commissioner holds an honours undergraduate degree in Applied Languages (French and German), a Masters in European Economic and Public Affairs, a postgraduate diploma in Computer Science and a Masters in Governance from Queen’s University Belfast.
She was appointed an honorary fellow of the Institute of Chartered Secretaries and Administrators in 2014.
Ms Dixon is the first woman in the role. She will take up her appointment over the coming weeks.
Minister for Data Protection Dara Murphy, who was just recently appointed to the newly created Government position, welcomed the appointment.
“The role of the office of the Data Protection Commissioner as an independent body which has responsibility for safeguarding data in Ireland is of critical importance.
“As we move at an increasingly faster pace into the digital age, it is fundamental that we ensure that our data, which is becoming an increasingly valuable asset, is afforded the optimum level of protection,” he said.
“This is a function which the Data Protection Commissioner has performed since the role was established in 1988 and will become even more significant in the years ahead.”
Mr Murphy congratulated Ms Dixon on her appointment andwished her success in her “important new role”.
The appointment comes at a challenging time for the protection of individual privacy and at a major juncture in the development of European data protection law.
Ms Dixon will be responsible for the protection of the personal data of hundreds of millions of European citizens due to the fact that several US multinationals, including Facebook, Linkedin and Apple have based their EU headquarters in Ireland.
A case in which her predecessor, Billy Hawkes, refused to investigate claims of a mass transfer of personal data to US intelligence services via Facebook has been referred by the High Court to the Court of Justice of the European Union.
A decision is not expected in the case - which has implications for an agreement between the EU and the European Union on how such transfers of personal data may legally take place - before next year.