Legal complaint lodged with UK data watchdog over claims coronavirus Test and Trace programme flouts GDPR
- Reference: 1591279922
- News link: https://www.theregister.co.uk/2020/06/04/test_and_trace_ico_gdpr_complaint/
- Source link:
In addition to the Information Commissioner's Office (ICO), the digital rights body's lawyers have also written to the country's health secretary Matt Hancock, the CEO of NHS digital agency NHSX, and the chief exec of Public Health England, asking for clarity around the system.
The complaint to the ICO relates to the failure by the NHS and Public Health England (PHE), which runs the Test and Trace programme, to conduct a Data Protection Impact Assessment (DPIA), which is required under the GDPR before processing of data in high-risk situations.
The Open Rights Group argues that because Test and Trace is experimental, and processes data of a sensitive nature on a large scale, a DPIA was required before data processing started. PHE and the NHS confirmed that a DPIA has not been conducted, in breach of those GDPR requirements.
Jim Killock, executive director of Open Rights Group, said: "The ICO must act to enforce the law. The government is moving too fast, and breaking things as a result. If they carry on in this manner, public confidence will be undermined, and people will refuse to engage with the Test and Trace programme."
The Open Rights Group has instructed Ravi Naik, legal director of the data rights agency AWO, who said: "Rushing out Test and Trace without following basic legal requirements is troubling. These legal obligations are designed to ensure that risks are identified and mitigated. Not conducting these assessments has caused our clients concern that those risks have not been properly thought through.
"Added to this is the lack of transparency around data sharing and relationships with third parties. We trust that the ICO will act accordingly to enforce the law and bring some transparency to the Test and Trace process."
PHE said earlier this week that it was currently working to complete the DPIA for NHS Test and Trace. It committed to provide this document to the ICO next week, saying: "Public Health England has taken careful steps to ensure that the NHS Test and Trace complies with its legal obligations and will publish the Impact Assessment on the NHS Test and Trace website, alongside the existing privacy notice, as soon as possible after consulting with the ICO."
Neil Brown, tech lawyer behind firm decoded.legal, said the ICO did not have a legal obligation to respond to every complaint, but that the letter may carry some weight. "If they've had a complaint from a pretty well-regarded data protection expert lawyer, the ICO may well be minded to respond," he said.
If the Open Rights Group is not satisfied with the response, it still had the option of instigating litigation or issuing an injunction, he said.
There are also questions over the ICO's ability to respond to a complaint, [1]given its struggle to handle its current caseload during the COVID-19 lockdown .
Meanwhile, head of the Test and Trace programme, Baroness Dido Harding, formerly CEO of TalkTalk, answered questions before the UK Parliament's Health Select Committee yesterday. Or rather, did not.
Pressed by committee chairman and former health secretary Jeremy Hunt on the proportion of new COVID-19 cases being contacted by the programme within 24 hours of a positive test result, she said she couldn't share data until it had been validated by the UK Statistical Authority.
"We need to make sure that any data that we share is accurate and validated, as you will see an exchange of letters between [2]Sir David Norgrove , chair of the UK Statistical Authority, and the [health secretary] in the last couple of days. I spoke with him yesterday and all our teams are working together now to agree on a weekly dashboard update for the overall intelligence on the testing programme."
Hunt said he was disappointed in the response and said Harding, who earned the moniker [3]Dido, queen of carnage for her role in the 2017 TalkTalk data breach, should provide the information to the committee by the end of next week. ®
[1] https://www.theregister.com/2020/04/08/ico_tribunal_cases_halted_bundle_bewilderment/
[2] https://www.statisticsauthority.gov.uk/correspondence/sir-david-norgrove-response-to-matt-hancock-regarding-the-governments-covid-19-testing-data/
[3] https://www.theregister.com/2017/02/01/dido_of_carnage_steps_down_from_talktalk/
Re: Conspiracy time?
No. They can blame it on a number of things, including
1. The government deciding to "go it alone" instead of with Apple and Google.
2. A centralised model instead of a more secure decentralised one.
3. Letting politicians decide on software instead of people who actually knew about it.
4. Ignoring the law instead of doing it properly.
Those overlap but it is the fault of the people in charge - not the developers themselves or the people trying to stop some of their mistakes.
Re: Conspiracy time?
All reasonable points.
Now imagine you are Cummings writing a press notice for the Daily Mail
Re: Conspiracy time?
Now imagine you are Cummings updating your blog.
FTFY
Re: Conspiracy time?
@Spanners
You can add to your list;
The old boys/girls network appointing the wrong people and companies to roll this out.
Re: Conspiracy time?
You missed:
5. Contracting the work out to a private company with no open tender process. A company which just happens to be linked with Cummings and his mates*.
6. Retaining data on people's movements for ten years with no clear rationale.
*The link between DC and the owner of this company, who is the brother of DC's other non-scientist mate who sits with him on the SAGE committee is publicly available information - I'm going on memory for the details here, so I'd encourage readers to look it up themselves.
Re: Conspiracy time?
The app has largely been abandoned, so the issue of Apple/Google etc is now moot.
Trace & isolate is now essentially a CRM system operated by home-based customer service reps - they get assigned a few people to follow up who've tested positive and attempt to get a list of contacts and their details. You can even enter your own information [1]yourself .
There are a number of concerns about the data collection. One is that the data is shared with a significant number of organisations and stored for up to 20 years (the [2]privacy statement seems to have been amended since I last read it which is a worry if it's dynamic). Another, possibly larger concern, is that local public health officials are not currently able to make use of the data for local outbreak control. By the end of the month, they expect to have access to the total number of cases/contacts in their local authority, but not the postcode-level information that would allow them to implement targeted lockdowns.
So although this information is being stored, it may, in fact, be of no use for the purpose for which it is being gathered. In other words, another knee-jerk reaction to accusations of poor preparedness with no real thought as to the practical implementation. We know Boris doesn't do detail - or indeed anything, but it seems none of the rest of them does either.
[1] https://contact-tracing.phe.gov.uk/
[2] https://contact-tracing.phe.gov.uk/help/privacy-notice
Re: Conspiracy time?
"... the UK govt can blame it's total failure of test/trace on a bunch of Guardian reader social justice types using European GDPR legislation to block vital tracing app."
Hardly. UK data protection legislation predates EU legislation in this field. As far as I'm aware the GDPR only resulted in relatively minor changes to the UK Data Protection Act. (Though that didn't stop a lot of folk claiming that the changes were massive and that you had to buy their expensive consultancy services to cope with them.)
---------------
Incidentally, may I quote from one of my earlier posts:
[GDPR runs to] 78 pages, with wide margins, so about 50 standard pages.
The UK ICO's GDPR guidelines are about three times longer. And the Data Protection Act, which transposes the GDPR to UK legislation runs to 354 pages: http://www.legislation.gov.uk/ukpga/2018/12/pdfs/ukpga_20180012_en.pdf.
--------------
Even more incidentally, "it's total failure" should be "its total failure".
--------------
Oh, and the countries you refer to also have data protection legislation, e.g.:
https://www.dlapiperdataprotection.com/index.html?t=law&c=AU
https://www.dlapiperdataprotection.com/index.html?t=law&c=NZ (about to be updated)
By the way, although I do read the Guardian occasionally I'm more of an FT reader (and pay for that).
That's simply not true
Singapore is not coming out of it quickly, its the failed man of Asia. They blew it with the migrant camps.
You know those apps aren't used worldwide even in successful countries right?
Thailand, no internal case, the Thai MorChana tracing app:
https://play.google.com/store/apps/details?id=com.thaialert.app
"100,000+ installs"
These things, they don't have a lot to do with fighting Corona Virus.
Wear the mask, avoid touching shared surfaces and when you do, clean your hands. This fixes the virus.
Telling people they may have the virus, that doesn't fix the virus. Why waste time on a distraction that simply distracts from the core Corona Virus fixes?
So what's the problem?
Facebook and Google track and trace people all the time - this program would win approval if advertisements were being delivered instead of vaccines. Cambridge Analytica sailed away for all their tracking issues but now we're concerned? I guess the problem is that you can't deliver a vaccine via peoples phones.
Re: So what's the problem?
There's a reason any sane person disables as many ad-trackers and cookies as possible, and that reason is to provide as little personal data as possible to the likes of Google and Facebook. Compared to governments, ad-spewers are relatively benign as they are only interested in profit. Governments have the power to legislate against their own people, and the thought of being tracked by the sort of people linked to Johnson, Cummings, Cambridge Analytica et al sends a shiver up my spine. Their interests almost certainly do not align with mine, in the same way that those of a reef shark do not.
Re: So what's the problem?
I completely agree, I feel the same way but I'm not going to fool myself into believing that these companies can't track me just because I said "no tracking". Sure, we can object to this but they all find their way around our objections ... Facebook tracks people who have "visited" Facebook friendly sites but never signed up for Facebook - it's just data collection in their eyes.
You can say no tracking, you can live on a VPN, delete cookies when you close the browser, and they can still track you - these companies are not dumb, this is how they make their money by selling our data so they are not going to stop no matter what you think.
Re: So what's the problem?
"So what's the problem?"
The problem is that this is a Public Health data, something which my be very personal.
Historically data about your health matters are personal and not shared outside of the medical practitioners who need access for your treatment.
The Government has refused to put any legislation around the Track & Trace activity to limit the reach of what the data may be used for or who can legitimately (for health reasons) access it.They intend to retain the data for 20 years! Why?
The data will be passing across the sight of at least three private organisations and will be viewed by employees of those organisation. Those employees will be using their own personal computers with, apparently, no audit of security. In other words the whole activity may have more holes than my kitchen sieve.
Then consider that, without legislation prohibiting it, the data will be available to any Tom Dick or Harry who has been granted access to data under the RIPA laws.
At least Australia rushed through very simple legislation to prevent abuse of the data or access for any other purpose than fighting Corona. I would urge those of you interested to read though the page and a half to see what abuses the Australian Government felt may occur if the tracking data was not protected
https://www.legislation.gov.au/Details/F2020L00480
legislation to prevent abuse of the data or access for any other purpose
Legislation prevents nothing. It's a vehicle to punish transgression, at most.
Re: So what's the problem?
They intend to retain the data for 20 years! Why?
Going by form, reaching back beyond WWI's DORA, the British government's mode engaging with data --- Official Secrets Act ! The 100 Year Rule ! --- is to hug it close and never let it go.
.
In practice though, they will need to hold on for the initial 20 yrs to safeguard us all from future viruses, then reset for another 20 yrs whenever each 20 year span is up.
"Jim Killock, executive director of Open Rights Group, said: "The ICO must act to enforce the law. The government is moving too fast, and breaking things as a result. "
From the way this government has reacted to COVID19 I definitely would not ever say they were moving too fast with their test and trace, as they should have had this up and running back in the beginning of March and then perhaps we wouldn’t be approaching 40,000 deaths from the virus in the UK.
We still don't have this app ready yet and yet millions have been encouraged to go back to work and all shops will be able to open in another 10 days.
GDPR?
I thought Brexit had happened?
Re: GDPR?
Not yet it hasn't... We may have technically left but we are in the 'transition period' where everything really stays the same while they argue what they should have sorted out before we even had a referendum.
That aside, GDPR is enshrined in UK law, just as all of the EU laws are. We will need to rewrite our laws to repeal the EU bits before we can say we are 100% EU free - but, as most of it is required to do any form of trade with the EU that isn't going to happen any time soon. Something else that has never been made clear unless you follow it.
Oh heck, I replied to a Brexit post - cue the downvotes... It is bound to upset someone!
Re: GDPR?
Also, the UK government had committed to retaining GDPR or something functionally identical to it despite Brexit
Re: GDPR?
We will need to rewrite our laws to repeal the EU bits
It's been done, that was part of the Brexit preparation. Data protection equivalent to, or stronger than, GDPR was specifically included to ensure that trade with the EU could continue.
Is it just me, or should we all be a little worried when Dido Harding talks about 'sharing data' ? - just saying.
As soon as I saw that Dido Harding was going to be in cahrge, I knew my data was going to be in safe hands.
Unfortunately not hers.
Last month's solution?
Do epidemiologists even recommend Track and Trace apps any more? It feels like last month's solution. I am sure it would have been useful in the previous phase but it looks like Coronavirus is here for a long duration now. Tracing isn't a scalable solution for management of the virus for the next decade.
Assuming that society evolves to minimise airborne transmission (presumably masks), the primary vector is going to be either intimate personal contact or touching shared surfaces. Neither of which will have much use for a tracing app. It is looking like it is too late to be an effective tool, and is now just turning into a technological solution looking for a problem.
And the limited tracing resources that will be available are going to be overwhelmed for the next year by 1st workplace outbreaks, and 2nd crowd outbreaks (concerts, football matches, etc). It is clear the government cannot disallow either of those in the long term and neither is helped by an app.
Any epidemiologists here who can explain what I have missed?
Re: Last month's solution?
Epidemiologists put a lot more faith in accurate testing than inaccurate tracking. A daily test method for everyone would virtually eliminate Covid-19 in a couple of months.
Re: Last month's solution?
A daily test method for everyone
67 million accurate, reliable tests per day? Not practical.
Not to worry, some enterprising young hacker will release the data long before Dido does.
Conspiracy time?
When countries like Singapore/Korea and Oz/NZ come out of this quickly with effective tracing and testing - the UK govt can blame it's total failure of test/trace on a bunch of Guardian reader social justice types using European GDPR legislation to block vital tracing app.