Brit cops rapped over app that recorded 200k phone calls
- Reference: 1681825088
- News link: https://www.theregister.co.uk/2023/04/18/ico_surrey_sussex_police/
- Source link:
The Information Commissioner's Office (ICO) [1]said today it was made aware in June 2020 that Surrey Police and Sussex Police were given access to the Another Call Recorder app that recorded all incoming and outgoing conversations.
Some 1,015 staff downloaded the software on their work phones and made more than 200,000 records of phone chats, which the regulator reckons was likely with "victims, witnesses, and perpetrators of suspected crimes" and were "automatically saved."
[2]
However, the ICO thinks it probable that the app captured a range of personal information during these calls, and the "processing of some of this data was unfair and unlawful. The police officers were themselves unaware that calls would be recorded and so were the people on the other end of the line," the watchdog added.
[3]
[4]
The app was first made available in 2016 and was intended to be used by a small subset of specific officers, yet the Sussex and Surrey forces made it open for all staff to download. It's no longer used and the recordings, save for those containing evidential material, were destroyed.
The ICO could have issued a £1 million ($1.24 million) fine to both forces, which represent two counties in the south of England, but instead opted for its revised public sector approach in which it seeks to help entities learn from their mistakes, hence the reprimand.
[5]
In a statement, Stephen Bonner, ICO Deputy Commissioner, said: "People have the right to expect that when they speak to a police officer, the information they disclose is handled responsibly. We can only estimate the huge amount of personal data collected during these conversations, including highly sensitive information relating to suspected crimes.
"The reprimand reflects the use of the ICO's wider powers towards the public sector as large fines could lead to reduced budgets for the provision of vital services. This case highlights why the ICO is pursuing a different approach, as fining Surrey Police and Sussex Police risks impacting the victims of crime in the area once again."
[6]Marketing biz sent 107 million spam emails... to just 437k people
[7]Criminal records office yanks web portal offline amid 'cyber security incident'
[8]UK data watchdog slaps Ministry of Justice with Enforcement Notice for breaking GDPR law
[9]UK police lack framework for adopting new tech like AI and face recognition, Lords told
In a [10]joint statement , Surrey Police and Sussex Police said the app was meant to be used by a small number of specialist hostage negotiators to support kidnap and crisis negotiations. They said the app was used on 432 phones and 1,024 officers downloaded the app, according to their findings.
"There was no means at that time of restricting use of the app and, unintentionally, it was enabled for all staff to download without appropriate guidance in place. When enabled, the app records and stores all phone calls made in the mobile device.
"The forces took immediate action when the error was identified in March 2020 including removing access to the app, securing evidence and self-referring the breach to the relevant regulators."
[11]
"At no point was any risk or harm to any data subject identified," they added.
New governance was put in place to ensure news app are compliant with existing legislation, and all staff now have instructions on data protection for the use of apps. ®
Get our [12]Tech Resources
[1] https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2023/04/ico-reprimands-surrey-police-and-sussex-police/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZD6@ouLhQRE@ij5i3R@kqQAAAEo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZD6@ouLhQRE@ij5i3R@kqQAAAEo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZD6@ouLhQRE@ij5i3R@kqQAAAEo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZD6@ouLhQRE@ij5i3R@kqQAAAEo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2023/04/17/ico_spam_email_fine/
[7] https://www.theregister.com/2023/04/06/acro_security_incident/
[8] https://www.theregister.com/2022/01/19/ico_slaps_ministry_of_justice/
[9] https://www.theregister.com/2022/01/19/uk_police_lack_framework_for/
[10] https://www.sussex.police.uk/news/sussex/news/force-news/police-respond-to-ico-reprimand-following-unauthorised-use-of-data-recording-app/
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZD6@ouLhQRE@ij5i3R@kqQAAAEo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://whitepapers.theregister.com/
ACR - I used that. It's one of the few (2) apps I actually paid for.
Sadly crippled by the Chocolate Factory. Unless any regtards know better, there is now no call recording for Android (or iOS) ?
PITA as it was one of the few reasons for using a mobile to make calls.
Now running a VOIP app to allow call recording. Because it's always useful to head off the "you can't prove that" line of corporate denial with
Me: "let's listen to your call recording"
Them: "That could take up to 28 days, and we may not have recorded that conversation".
Me: "No problem, let's listen to mine then"
Re: ACR - I used that. It's one of the few (2) apps I actually paid for.
IANAL, but I understand that in the UK it's perfectly legal to record telephone conversations without disclosing that you are doing so. There are limits to what you can do with those recordings, although if you make all parties aware beforehand ( "This call may be recorded for Training & Monitoring purposes..." ), then those limits are reduced.
There's no legal basis for crippling this functionality in the UK (or in many other jurisdictions, presumably), but Google decided to force this change on the entire world just to play it safe.
Re: ACR - I used that. It's one of the few (2) apps I actually paid for.
In the UK, it is legal provided one of the parties to the call is aware it is being recorded. If you are recording your own calls, then you are a party to the call and you know you are doing it, so it is legal. If you installed the software on a family member's phone, or an employee's phone, and they didn't know it was there, then it would be illegal.
Re: ACR - I used that. It's one of the few (2) apps I actually paid for.
You are right in a way. It *is* legal, but *both* parties need to be aware that they are being recorded, and the purpose of that recording.. This is why when you call some tech support or sales lines, before you even speak to a human, you are sometimes told that your call may be recorded for training purposes (or whatever purpose it may be used for).
The Data protection regulations also require that the recordings be held securely, and only be stored as long as they are needed for., and stored within the European Union, or a country with equivalent Data Protection regulations.
https://www.ereceptionist.co.uk/blog/legal-to-record-phone-calls-uk#:~:text=Yes%2C%20it%20is%20legal%20to,is%20for%20their%20own%20use.
Re: ACR - I used that. It's one of the few (2) apps I actually paid for.
Why not a link to the actual law ? Oh, because there isn't one. Not for *personal* uses. Which was what the PP was referring to.
Re: ACR - I used that. It's one of the few (2) apps I actually paid for.
Recording personal calls and recording business (or in this case police) calls are very different things.
This story is about calls recorded by police officers and police employees in the course of their business and nothing to do with personal calls. So introducing a moan about not being able to record personal calls is entirely irrelevant.
FWIW Google have not crippled call recording for the entire planet and even if they happed to have done so in your territory there are plenty of apps around which allow you to record calls.
Re: ACR - I used that. It's one of the few (2) apps I actually paid for.
I've just scoured the Play Store (in the UK) and noticed that all of the "apps" have some bad feedback - mainly about not working.
A colleague has just noticed that his Samsungs inbuilt phone app (as promoted by Google) also doesn't do call recording.
It's starting to look a lot like "mate said"
Re: Google decided to force this change on the entire world just to play it safe.
I bet it was more so that Google could monetise the feature at some point.
These are the sort of people I want to be reading all me WhatsApp, Signal, SMS etc. What could go wrong ?
https://www.openrightsgroup.org/campaign/save-encryption/
The way the police force is telling it it just seems to have happened spontaneously.; nobody made a decision.
Well, it may be true that nobody made and informed decision but that was lack of due diligence.
It's no good just reprimanding the force although this is the appropriate procedure for a public body. The expectation should be that having been reprimanded the public body will take career-affecting disciplinary action against whoever landed them in that situation however far up the command chain that goes. And far up the command chain is very probably appropriate because that's where the organisational culture will have been set. Sacegoating wouldn't be appropriate Without consequences there's no assurance that things will be done right, just an assumption.
The likelihood, of course, is that it'll be reported that whoever was to have been disciplined has retired.
The Tapes, the Tapes!
200k telephone calls recorded and nobody noticed the log files filling up, and the backup tapes filling up?
Oh, hang on, we've graduated from 1/2 inch reel-to-reel tape drives haven't we?
As for anyone in a UK Police Force actually being disciplined, I mean, L O L, that's a good one, made me chuckle.
"The police officers were themselves unaware that calls would be recorded and so were the people on the other end of the line"
The police officers didn't know that an app with "call recorder" in the name would record calls? In which case plod are more stupid than most people think. However I think that in this case it's the regulator who is being dumb, I'm sure the police knew the calls were being recorded, but were ignorant of the fact that it would be a breach of more than one regulation. Ignorance is however no excuse in law - as I am sure PC plod is well aware.
In other words, this is what always happens.
1. Police see a shiny thing.
2. Police use the shiny thing with no guidance or framework whatsoever, trusting that...
3. The Home Office will change the law as appropriate if it turns out there's some problem with the shiny thing when it's uncovered two years down the line.
Commercial Facial Recognition Apps too...
I wouldn't be surprised if police are doing the same with CCTV camera footage and standard commercial facial recognition apps, uploading images of 'friends' (potential suspects) to 'name' those in the CCTV stills/footage, and sort to content automatically.
This in itself should be an ICO investigation, because it's something is that is clearly possible with the technology available, so it's likely been used, and it's totally unregulated and unauthorised use of the technology, because of the potential for false-positives.
Why do these type of public disclosures always have to result in a complaint first, the potential compensation payments for this are massive.
Regulators need to start getting pre-emptive, so this doesn't happen in the first place.