Feeds

Shops must use RFID with care

Information Commissioner checks it out

Security for virtualized datacentres

Shops which use RFID tags and CCTV cameras must tell shoppers every time an RFID tag is used and must tell shoppers how to remove them. The order comes in guidelines produced by the Information Commissioner's Office (ICO). RFID (radio frequency identification) tags are used for inventory management in many shops but are increasingly used on shop shelves to identify products. The ICO said that shops must comply with the Data Protection Act when RFID information is collected alongside personal identifying information, such as CCTV footage.

"Where personal data is collected, generated or disclosed using RFID either directly or indirectly, the Act will apply," says the guidance. "Those collecting personal data with RFID will have to give notice of the presence of RFID tags on products and of readers, and explain the implications. They will have to tell consumers what personal information is being collected, by whom, and for what purpose. It might also be necessary to tell customers how to disable or remove tags, for example if a tag has been left on a product after purchase."

The guidance also tells retailers that whatever data is gathered must be disposed of once it has been used, and that only an amount of data proportionate to the purpose for which it was gathered can be stored.

RFID chips are causing some privacy activists concerns as they enable retailers, state bodies and any other using organisation to gather information about people's product choices, movements and habits. One concern is about the security of the information, once gathered.

The ICO's guidance warns of skimming, cloning and eavesdropping on tags and the transmission of data between tags and readers. "The simplest way of addressing privacy concerns about RFID is to ensure that any tags on individual items are removed or disabled at the point of purchase," it said.

Meanwhile, California is about to introduce laws controlling the data kept on RFID cards. The Identity Information Protection Act has been passed by legislators in the state and awaits the signature of governor Arnold Schwarzenegger to become state law.

That state is using RFID in library cards and driver's licences and the new law will control how government and private organizations are allowed to deal with the information on cards. The Act orders the use of encryption technologies on cards.

"RFID technology is not in and of itself the issue," said Senator Joe Simitian, who proposed the bill. "The issue is whether and under what circumstances the government should be allowed to compel its residents to carry technology that broadcasts their most personal information." The US has recently taken the controversial decision to embed RFID chips in passports, prompting fears about the documents' long term security.

See: The Guidance (7-page / 44KB PDF)

Copyright © 2006, OUT-LAW.com

OUT-LAW.COM is part of international law firm Pinsent Masons.

Business security measures using SSL

More from The Register

next story
Hey, Scots. Microsoft's Bing thinks you'll vote NO to independence
World's top Google-finding website calls it for the UK
Phones 4u slips into administration after EE cuts ties with Brit mobe retailer
More than 5,500 jobs could be axed if rescue mission fails
Apple CEO Tim Cook: TV is TERRIBLE and stuck in the 1970s
The iKing thinks telly is far too fiddly and ugly – basically, iTunes
Phones 4u website DIES as wounded mobe retailer struggles to stay above water
Founder blames 'ruthless network partners' for implosion
Found inside ISIS terror chap's laptop: CELINE DION tunes
REPORT: Stash of terrorist material found in Syria Dell box
OECD lashes out at tax avoiding globocorps' location-flipping antics
You hear that, Amazon, Google, Microsoft et al?
Show us your Five-Eyes SECRETS says Privacy International
Refusal to disclose GCHQ canteen menus and prices triggers Euro Human Rights Court action
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.