Experian vows to drag UK's Information Commissioner's Office to court after being told off for data-slurping practices
- Reference: 1603891794
- News link: https://www.theregister.co.uk/2020/10/28/experian_ico_marketing_data_investigation/
- Source link:
Instead of issuing a monetary fine, however, the data regulator wrapped up a two-year probe yesterday by merely insisting Experian tweaks its online privacy policies and informs consumers it acquired data about them.
"The ICO found that significant 'invisible' processing took place, likely affecting millions of adults in the UK. It is 'invisible' because the individual is not aware that the organisation is collecting and using their personal data. This is against data protection law," said the ICO.
It added: "Some of the [credit reference agencies] were also using profiling to generate new or previously unknown information about people, which is often privacy invasive."
In an aggressive response, Experian chief exec Brian Cassin claimed the ICO enforcement notice against his employer "risks damaging the services that help consumers, thousands of small businesses and charities, particularly as they try to recover from the COVID-19 crisis."
The ICO investigation into data brokers-cum-marketing agencies was triggered by campaign group Privacy International, which hailed its "achieved result" by saying: "Data brokers are key actors in the hidden data ecosystem. The data they collect and later sell can be used for a range of different purposes, from commercial advertising to political campaigning, and in some worrying instances, law enforcement. Most people will never have heard of the these companies, as most data brokers are not consumer facing or household names."
Two other agencies, Equifax and TransUnion, were said to have changed their practices before the ICO investigation finished, while Experian dug its heels in and insisted it was doing nothing wrong.
Experian's Cassin claimed the agency's data-harvesting practices consisted of hoovering up information from the electoral register, censuses and "market research data" before developing "statistical models from data to infer insights useful to businesses and public bodies in order that they can function more efficiently".
Cassin also said that local councils, NHS organisations, fire brigades, and charities had all been buying this marketing data from Experian, allegedly "to get help and support to the most vulnerable during the crisis".
Experian said it would be appealing against the ICO's formal enforcement notice. Companies targeted by the ICO since 2018 have a strong incentive to play hardball with the regulator in tribunals and courts: the GDPR and the Data Protection Act 2018 so far have few precedents that either the regulator or industry can point to. Setting early legal precedents that constrain the ICO is therefore vital for companies determined not to let data protection law impede their operations.
British Airways was mostly successful in this, [1]negotiating a proposed £183m data breach fine down to just £20m after two years of intense legal discussions. ®
Get our [2]Tech Resources
[1] https://www.theregister.com/2020/10/16/british_airways_ico_fine_20m/
[2] https://whitepapers.theregister.com/
Helping consumers?
Pull the other one, it's got bells on ya fekkin shites.
The three main credit reporting agencies hoover up our private data, use a black box algo to give us a score, then use that score to ruin our lives. "It's so companies can know your credit worthiness" is bullocks. It's so they can profile us, stick us in a slot, then monetize us for every last drop of blood.
We aren't given any means of telling them not to EVER profile us before they've amassed gigatons of PII that then gets spaffed all over the place like a horny bull shooting his load at an orgy. If we don't "agree" to them doing their profiling then companies refuse to do business with us. How is that NOT extortion?
Dear credit reporting agencies. Fuck you. Repeatedly. With a spinning chainsaw.
Re: Helping consumers?
"...risks damaging the services that help consumers, thousands of small businesses and charities, particularly as they try to recover from the COVID-19 crisis."
I think he doth protest too much. What he is really worried about is Experian's bottom line and his resultant bonus.
These characters are leeches. They suck up everything they can find and sell it to the highest bidder. All without the people whose data it is either being asked or recompensed. They are bottom feeders without a shred of integrity.
I truly hope that they will get their arses well and truly kicked and thereby set a precedent which reins in some of the excesses we are seeing.
So why?
Is the IC not going after the banks for passing them our data without our permission in the first place? Oh right, banks are based here, have ex cabinet ministers on their boards and friends in office.
This is just the start
Grab some popcorn as NOYB are going after the Credit Reference Agencies' core business under GDPR, in that none of us are able to remove consent to them processing our data. I should be able to buy electricity without some 3rd party being fed the date and time of my payments.
See also CRIF in Poland making up credit scores for people they had no record of! https://noyb.eu/en/credit-scoring-negative-credit-rating-generated-without-data
It's a pretty good strategy right now to threaten to overwhelm the ICO's legal budget.
BA got their fine down to about 5% of the original I think.
Experian can probably the force the ICO to bend over and hand over all our data with a smile.
" insisting Experian [...] informs consumers it acquired data about them"
Appealing against an official order to comply with the statutory obligation of transparency ( inter alia GDPR Principle 1 and Articles 13 and 14)?
If the appeal is granted, personal data protection is finally dead.
Data is the new oil - isn't that how it is put these days. As has been expressed in posts above, far too many companies collect far too much data on individuals these days and too few people realize this or can even be bothered to consider the consequences. Just because we are taught to expect this kind of behavior in this digital age isn't a sufficient excuse to cover the sorts of Data Theft and Data Trading that goes on! Worse, the very fact that we live in an age so heavily reliant on digital data and it's storage creates an humongous target for criminals to go after and or lock-up and demand a ransome for!
I don't have an answer to the problem as a whole, except that widely educating folk about this and raising their awareness of it must be a good place to start. The ICO is but a mere sticking plaster just so those in high office can use it as an example to make us all believe they are actually doing something!
Grrrr . . .
Data is the new snake oil - as long as you can sell them to gullible execs who really believe it can boost their sales.
I have always been baffled how credit reference companies can even exist alongside GDPR. As others have said, I have never explicitly given permission for my data to be passed on to them. The whole point of GDPR was to remove the implied consent of signing up for a service and then having these things hidden in the terms and conditions that your data will be sent left, right and centre to various other companies to hoover up.
Likewise, I have never given Experian, Equifax et al. permission to store or share my data with other companies.
In theory, open banking should be able to replace much of what the credit reference companies do today, rendering them obsolete.
" insisting Experian [...] informs consumers[...]" UPDATE
It turns out that there's much more to the enforcement notice than just "update your privacy policy. See the (redacted) [1]enforcement notice for full details. It runs to 55 pages of closely argued challenge under five heads, albeit one of these is being resolved (controller/processor status w.r.t. Article 5(1)(a) (Principle 1) and one other considered to have been resolved (Right to Object under Article 21). The outstanding three are apparently fair and transparent processing under Article 5(1)(a), failure to notify data subjects under Article 14 (Information to be provided where personal data have not been obtained from the data subject), and lawfulness of processing under Articles Article 5(1)(a) and 6(1) (lawful basis for processing).
Couldn't be much worse overall, except for a "privacy policy" we've encountered that consisted only of Lorem Ipsum body copy text.
[1] https://ico.org.uk/media/action-weve-taken/enforcement-notices/2618467/experian-limited-enforcement-report.pdf
Credit Reference Agencies ------
Ahh, I was waiting for the time these agencies would be dragged over the coals.
I've had the pleasure/displeasure of actually assessing one of these companies and visiting the associated data centre.
I was actually gobsmacked at how much processing was done, at what scale, and how you and I, as data subjects, are monetised for considerable profit, to other companies based on some spurious algorithms that produce "results" which are sold on to whomever thinks it will make their lives easier.
As an example, someone I know, was sent a letter from out of the blue suggesting they have been claiming a particular benefit they weren't entitled to, by the council local to them. I was asked my opinion and I suggested a CRA had probably concluded this by analysis of records on given addresses. I told them the options open to them and suggested they tell the council to go poke their allegations where the sun doesn't shine.
I would suggest processing of your data is one thing, but taking it to another level, such as the one above goes way beyond what you and I would deem to be acceptable, never mind the fact that you don't want to be used as a pawn in someone else's game of monetising data.
Good luck to anyone who can bring these parasitical companies in line.
It wouldn't be so bad if they didn't believe they were above the law.
They already hold far too much information on us....
The likes of Experian hold far too much information on all of us!
I have first hand experience of the information that they held about a mortgage was completely inaccurate being at least 10 years out of date! Secondly the security startup is was working for was acquired into a much larger org. I was told they they wanted to run a background check on me which I had expected. They sent me an email with a link to provide the required information. It was Experian’s site. I read the information/terms presented and noted that it said the information I provided would be used elsewhere not just for this check (don't recall exact wording but that was the gist of it). I was unhappy with this idea so went back to HR and explained that I was OK with providing the information for them(my employer) to do the background check but was not happy with providing the information to Experian and especially the statement about the data being used elsewhere. That was the last I heard of it….no more communication from HR…..I was in the job till I chose to move on. I suspect Experian had all the information anyway but it was the principle.