Feeds

Santa putting children's information at risk, warn experts

Kriss Kringle failing to comply with data protection laws

The Essential Guide to IT Transformation

Santa Claus could be breaking privacy laws in his collection and use of data about British children, experts have warned. Yuletide cheer-bringer Claus could be putting the personal data of millions of children at risk.

Data protection laws lay down strict conditions for the use of personal data and there is no evidence that Claus has an adequate compliance programme in place.

Children across Britain who write letters to Claus with a list of gift requests are not told for how long that data is kept, or if it will be used for other purposes such as marketing by third parties.

The Data Protection Act stipulates that data should not be kept for longer than necessary, which would mean 25 December, though Claus may argue that he needs to keep the letters for six years to use in any gift-related lawsuits.

"There is a stream of questions Santa has yet to answer," said William Malcolm, a data protection specialist at Pinsent Masons, the law firm behind OUT-LAW.COM. "Is this information used for anything other than present giving? Information passes out of the EU, so does Santa check the letters for unambiguous, specific and informed consent to this overseas transfer?"

OUT-LAW's attempts to put the questions to Claus were hindered by the lack of an office chimney. Eventually, the questions were put up a domestic chimney but no response was received by time of publication.

The Data Protection Act says that you must inform someone when you are collecting data about them, and tell them what the purpose of collection is.

"What about the naughty/nice database?" said Malcolm. "Are children given notice that behavioural data is being collected about them throughout the year? And does it qualify as covert monitoring, which would breach Article 8 of the European Convention on Human Rights?"

People can make a subject access request of databases holding their personal information, but the database operator has 40 days in which to respond. Children are now too late, therefore, to find out before Christmas if they are on the naughty or nice section of the system.

Tomorrow: OUT-LAW exposes Claus's cavalier approach to consumer protection.

Copyright © 2007, OUT-LAW.com

OUT-LAW.COM is part of international law firm Pinsent Masons.

Build a business case: developing custom apps

More from The Register

next story
14 antivirus apps found to have security problems
Vendors just don't care, says researcher, after finding basic boo-boos in security software
'Things' on the Internet-of-things have 25 vulnerabilities apiece
Leaking sprinklers, overheated thermostats and picked locks all online
iWallet: No BONKING PLEASE, we're Apple
BLE-ding iPhones, not NFC bonkers, will drive trend - marketeers
Only '3% of web servers in top corps' fully fixed after Heartbleed snafu
Just slapping a patched OpenSSL on a machine ain't going to cut it, we're told
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Secure microkernel that uses maths to be 'bug free' goes open source
Hacker-repelling, drone-protecting code will soon be yours to tweak as you see fit
Israel's Iron Dome missile tech stolen by Chinese hackers
Corporate raiders Comment Crew fingered for attacks
Tor attack nodes RIPPED MASKS off users for 6 MONTHS
Traffic confirmation attack bared users' privates - but to whom?
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Backing up Big Data
Solving backup challenges and “protect everything from everywhere,” as we move into the era of big data management and the adoption of BYOD.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.