Showing posts with label dpa. Show all posts
Showing posts with label dpa. Show all posts

24 August 2015

Haringey Council got themselves into a mustard pickle



Those lovely people at the Campaign for the Freedom of Information have kindly provided some information to Mr Mustard about how Haringey Council should have handled his request.

The CFOI are battling on our behalf to keep FOI free and wide in scope and they need money to do that. Please visit their website and donate to help the cause.

The CFOI also provide training to councils, like Haringey, and perhaps instead of jerking Mr Mustard around, they might like to invest money in high quality training (there is of course the possibility that messing with the mustard is council policy)

 So here is what the experts say:

  
It actually doesn't matter what legislation you cite in the request, the authority should handle it under the appropriate legislation, whether that be the FOIA, DPA or both. The ICO advises:

Dealing with freedom of information requests for the requester’s personal data.

As mentioned above, a valid SAR may, at first sight, appear to be something else. It is not uncommon, for example, for the request to state that it is a freedom of information (FOI) request. If, in reality, it relates to the requester’s personal data, you must treat it as a subject access request.

If it is clear that the requester is merely asking for their own personal data, but they have cited FOIA, you should do the following:
• Deal with the request as a SAR in the normal way. The requester does not need to make a new request. You may need to ask for payment of any necessary fee or ask the individual to verify their identity.
• If your organisation is a public authority, the requested personal data is, in fact, exempt from disclosure under FOIA or the EIR. Strictly speaking, you should issue a formal refusal notice saying so. In practice, however, we would not expect you to do this if you are dealing with the request as a SAR.
• It is good practice for public authorities to clarify within 20 working days (the time limit for responding to FOI requests) that the request is being dealt with as a SAR under the DPA, and that the 40-day time limit for responding applies.

If the request relates to information that cannot be requested by means of a SAR (eg it includes a request for non-personal information) then, if your organisation is a public authority, you should treat this as two requests: one for the requester’s personal data made under the DPA; and another for the remaining, nonpersonal information made under FOIA. If any of the non-personal information is environmental, you should consider this as a request made under the EIR.


Simple then really. At the start Haringey Council should have just asked for £10 (or waived it as the cost of processing exceeds £10) proof of ID and got on with it. If they had done that, they would not have created a mini blog-fest dedicated to themselves.

Yours frugally

Mr Mustard
 


23 May 2012

Special warblings - The omnidatashambles

the latest in a long line of Mayors - Brian Schama
From: Adams, Nikki P.A. to Nick
Sent: 18 May 2012 15:42
To: AllStaff
Subject: Weekly Message from the Chief Executive 99% of staff probably hit delete when this lands in their inbox
Tuesday evening was Annual Council meeting. Cllr Schama was confirmed as Mayor for the Municipal Year 2012-13. The mayoralty remains a significant part of life here in Barnet undertaking hundreds of visits to groups, special events and representing the Borough at London wide events. Given that this is Jubilee and Olympic Year I’d expect Cllr Schama to have an even busier schedule than usual. Mr Mustard expects that Cllr Schama will be a good mayor and his only concern that Cllr Schama has high standards of what he expects from officers and the time available for him to bring his non-nonsense commonsense why aren't we walking before we try to run view to committee meetings will be much limited.

Alongside the ceremonial aspects of Annual Council there is also important political business to transact as appointments for the coming year are confirmed. The only substantial change to the Cabinet was that Cllr Dean Cohen replaces Cllr Brian Coleman as Cabinet Member for Environment. Cllr Coleman has in turn been appointed Chair of the Budget and Performance Overview and Scrutiny Committee. Why the chairman gets £15,333 for chairing that will be the subject of a future blog.
 
The Opposition Labour Group also nominates a Shadow Cabinet and there have been more changes here. Cllr Cooke becomes Shadow Cabinet Member for Resources, Cllr Houston becomes Shadow Cabinet Member for Children and Education, Cllr Schneiderman becomes Shadow Cabinet Member for Environment, Cllr Brodkin becomes Shadow Cabinet Member for Crime and Policing and Cllr Julie Johnson Shadow becomes Cabinet Member for Housing and Regeneration. A little table would have been easier presentation to absorb.
 
You can find more details about Committee Memberships on the Council and Democracy pages of the website. But not about allowances which are more deeply buried.
 
However Annual Council is really all about the mayoralty and the outgoing Mayor spoke with pride about her time in office. Amongst the many highlights she outlined was a day when she had visited places of worship representative of every major faith. Her pride and the on-going enthusiasm of a very diverse community for civic recognition were obvious for all to see. Longer than the longest Oscar speech to all accounts.
 
And of course in the background are our outstanding Mayoral Team, the Mayor’s drivers, including the never flustered Lewis, and the admin team led by Angela. The out-going Mayor thanked them for their support and I wanted to join her in doing so this week. Finding a way through the protocols, diary clashes and traffic can be a nightmare but the team do it extremely well.
 
Some of you will have seen news coverage that the Council has been fined £70k by the Information Commissioner for a breach of the OPA. OPA? Don't you read anything Nick or is your P.A. not conversant with the DPA as in the Data Protection Act - actually that seems to be endemic. The loss occurred when a member of staff was burgled and a laptop (encrypted) and papers containing personal data were stolen. Another £70,000 of tax payers' money wasted by Officers. Slippery stuff this data eh Nick? You forgot to mention your previous in this regard when the details of 9000 children slipped out of the council's care in March 2010 and you had to sign a letter promising to be more careful in future. Funny isn't it how closely guarded papers are about the One Barnet programme but data about kids is left lying around. So slow implementing change that another loss occurred. These things tend to come along in threes. What next?
 
The ICO criticisms focus on the paper record handling policies of the Council. I therefore think it worthwhile reminding staff what current policies, accepted by the ICO, are.
 
These are:
  • There is a general presumption against taking off-site personal or other confidential data contained within paper records/hard copy material.
  • Personal or other confidential data contained within paper records/hard copy material should only be taken off-site when it is a necessity and not a convenience.
  • Line management approval must be obtained before personal or other confidential data contained within paper records/hard copy material is taken off-site. The approval request must provide details of the personal or other confidential data proposed to be taken off-site and the necessity for doing so and the relevant times.
  • Where personal or other confidential data contained within paper records/hard copy material is taken off-site it should be kept to a minimum both in terms of content and duration. Why don't we provide a fire safe at the home of people who have to take confidential papers home sometimes? Only £30
  • Whilst off-site and temporarily in the home of an employee (or other person covered by the policy), paper records/hard copy material containing personal or other confidential data, that is not being actively worked upon, must be kept secure and separate from any valuable items such as laptops. So that hopefully the laptop gets stolen and the paperwork is left behind.
  • Where personal or other confidential data contained within paper records/hard copy material is taken off-site and is in transit from one location to another, it should be transported in a way that mitigates against the risks of theft or loss. Computers should be chained down at all times when outside work. It's easy and cheap.
  • This means that, insofar as possible, all necessary steps should be taken to seek to ensure that the paper records/hard copy material are/is not mistaken for a laptop, other electrical device or valuable item by a thief and should be transported in a separate container to such items. Tut tut, hard copy paperwork is a valuable item.
Furthermore where paper records containing personal or confidential information are taken off site, staff must ensure they have made a log of the removed/copied papers. This is to ensure that the council can appropriately risk assess the level of harm likely to be caused should a loss of data occur. Why not just scan and encrypt them in the first place and put them on the hard drive?
 
A full copy of the policy is available on the intranet and staff must ensure they are familiar with it. If you have any concerns in meeting the requirements of the policy, these should in the first instance be raised with your line manager. The onus is placed on the employee. Will managers check?
 
If you require further advice or guidance on Data Protection or Data Security, please email data.protection@barnet.gov.uk
 
Nick
Nick Walkley
Chief Executive
London Borough of Barnet, North London Business Park , Oakleigh Road South , London N11 1NP
Tel: 020 8359 7001
Barnet Online: www.barnet.gov.uk

Sorry if you are really bored with these non-stick messages. Why should the staff suffer alone?

Yours frugally

Mr Mustard
 

9 January 2012

Thinkpublic Ltd are NOW registered under the Data Protection Act

Readers will be familiar with Barnet Council's attempt to get Mr Mustard into hot water with the Information Commissioner for not being registered under the Data Protection Act which ended up with Barnet Council put back in their box.

It is will known that procurement and the issuing of contracts and monitoring of suppliers are well below par at Barnet Council.

After the council's attack Mr Mustard had a quick look around their supplier list and checked if suppliers, in possession of and processing data from Barnet Council, were themselves registered. Mr Musatrd chose to look at Thinkpublic Ltd who have been running Barnet's so-called Big Society Innovation Bank for the council.

Having asked Thinkpublic if they were registered they said yes and that there was something wrong with the register. Possible but unlikely.

Mr Mustard checked with the ICO who keep the register. You can search it here. On 15 December 2011 the ICO said that there was not a current or pending registration. The application form must have landed at about the same time as if you put Thinkpulic into the search box you now find that they have a register entry from 12 December 2011.

Mr Mustard reaches the conclusions that:

1. Barnet Council didn't check Thinkpublic Ltd out properly before they agreed to use them and 
2. that Thinkpublic have now registered thanks to his intervention. 

Don't both rush to thank him for nudging you onto the right road and for not trying to be as beastly as the council were.

Motto of the story: Don't mess with Mr Mustard.

Yours frugally

Mr Mustard

20 December 2011

A Barnet Council house out of order !

Readers will recall that Barnet Council reported Mr Mustard in a cowardly and underhand manner to the Information Commissioner because they claimed he should have been registered under the Data Protection Act, and he wasn't. they were sent away with a flea in their ear, twice.

Naturally, Barnet Council's house was 100% in order ? (well that is what you would expect but it might not be the case?).

Readers will be well aware of the so called Barnet Innovation Bank. It isn't a bank and it isn't really that innovative. Many charitable organisations have seen their budget slashed and instead we have the Innovation Bank which doles out grants to many of the old names that we have seen before. They are, in the main, deserving cases and one, at least, is innovative although how much can be achieved with £4,150 is open to debate.

So, one of the main partners in the "Innovation Bank" is Thinkpublic Ltd. They were instrumental in the Innovation Bank. What do they say on their website ( they registered the website for the Innovation Bank ), click to see. There is no doubt that they have been processing the data of applicants for grants as otherwise they could not do their job.

Mr Mustard assumed they would be registered under the Data Protection Act ( how could they not be with all the works they had been doing. See their own website ). He searched by their name and by their postcode. What did he find.Nothing.

Oh dear he thought. Shall I report Thinkpublic Ltd to the Information Commissioner and try and get them fined £5,000 like a spineless council might? No, he thought, follow the advice on the Information Commissioners website and give them a nudge. So Mr Mustard gave them a nudge as follows.

8 November 2011


Dear Sirs


I think you should be registered under the Data Protection Act as, for instance, you are processing data on behalf of Barnet Council for their Innovation "Bank"


Please let me know if you agree and if you make an application to register.


Yours sincerely


Mr Mustard

Mr Mustard didn't get an answer within 2 weeks so he wrote again.

21 November 2011


Dear Sirs


I think you should be registered under the Data Protection Act as, for instance, you are processing data on behalf of Barnet Council for their Innovation "Bank"


Please let me know if you agree and if you make an application to register.


Yours sincerely


Mr Mustard

Once nudged, Thinkpublic rumbled into life

22 November 2011

Dear Mr Mustard

Thank you for your message.

Thinkpublic is indeed registered with the ICO, although I notice the registration is not appearing on the online public register, which we will look into.

Yours sincerely

Richard Owen


Mr Mustard was pleased that a supplier to Barnet Council was duly registered under the DPA and that this was a simple matter of administrative error. Polite as ever, Mr Mustard wrote back to Thinkpublic

22 November 2011


Dear Mr Owen


Thank you for letting me know that thinkpublic is registered.


When you find out why you don't appear in the on-line register please can you tell me what the problem was as I rely on the register and knowing the reason for the problem will be of assistance.


Yours sincerely


Mr Mustard

Two more weeks passed. Mr Mustard thought that a matter which was so important that EU case law needed to be quoted ought to be cleared up more quickly than this, so he emailed again.

8 December 2011


Dear Mr Owen


is there any news about your registration please as you still do not appear on the Register and I would have thought that if you were properly registered that this omission by the ICO would be fixed in no time at all


Yours sincerely


Mr Mustard

Mr Mustard was not impressed by the correspondence from Thinkpublic Ltd so he thought he would cut out the middleman. He write directly to the ICO; very nicely I think you will agree; certainly not the sort of aggressive behaviour that we have seen from Barnet Council; he merely tries to establish the facts.

8 December 2011


Dear Sirs


You will see what has been said by a representative of Thinkpublic below. They still do not appear on the register.


Have they ever been registered under the Act ( as far as your records go back anyway ) or is there an application now pending please?


The company:
thinkpublic ltd
Studios 38-40, Fruit & Wool Exchange
56 Brushfield Street, London, E1 6EU
0207 247 2255


This is merely an enquiry; not a complaint.


Yours sincerely


Mr Mustard

The ICO took only 7 days to reply, as follows:-

15 December 2011

Dear Mr Mustard

Further to your email below (now above of course), from the information you have provided we are unable to find a registration (current or pending) for Thinkpublic Ltd.

Regards,

Notification Department

Mr Mustard is keen to see fair play. He sent that reply to Thinkpublic, as there is always the possibility of administrative error, as follows:-

15 December 2011


Dear Mr Owen


Please can you tell me why you think you are registered and why the Information Commissioner says that you are not and haven't even applied?


Yours sincerely


Mr Mustard

OK, so only a week has gone by but if you are innocent and are accused of not complying with some basic legislation, and have had in fact, since 8 November 2011 to come up with the goods, then surely you could manage it by 20 December 2011?

Will you report yourselves to the ICO then Barnet Council, for giving data to an unregistered processor, or will we just let the ICO read this blog and then call you in for a chat?

Your choice Barnet Council, but don't be long about it. Please do copy Mr Mustard into your correspondence with the ICO.


Yours frugally

Mr Mustard

1 December 2011

Hypocrites

Readers will be well aware that in June 2011 Barnet Council reported the Mr Mustard blog to the Information Commissioner for failure to comply with the Data Protection Act ( by not registering ) for which in the Magistrates Court the maximum fine is £5,000. Just like other bloggers, he had no need to register; it was just the council throwing their toys out of the pram.

Just look at the internal audit report which is going to the Audit Committee next week. 

click to enlarge; back to return






So just to be clear, whilst busy trying to get Mr Mustard into hot water you were in the soup yourselves. That is deeply unimpressive behaviour.

Hypocrites.

Now Mr Mustard must go and prepare a question for the Audit Committee.

Yours frugally

Mr Mustard