Feeds

Code for handling personal data is muddled, says lawyer

Further confusion in an already bewildering area

Build a business case: developing custom apps

A code of conduct for handling personal data was launched in London yesterday. But the document is inconsistent on the need for consent when collecting personal data, according to a data protection expert. Sometimes consent is not necessary, he said.

The Personal Data Guardianship Code was published jointly by the British Computer Society and the Information Security Awareness Forum (ISAF) in response to the number of high profile data breaches in recent years. Its aim is to change the culture of organisations towards the handling of personal data.

According to its authors, the Code "follows on the success of the BCS petition objecting to the changes in the Coroners and Justice Bill which would have seen drastic changes to the way in which government departments could have used personal information."

In March the Ministry of Justice announced that, in response to criticism from many groups, it would scrap plans that featured in the draft legislation to allow Government departments to share citizens' personal information with each other and with the private sector.

The new Code is intended to help organisations and the people in them who handle personal data to understand their individual responsibilities. It aims to promote best practice and provide 'common sense' guidance, and also lays out information for the data subject.

However, William Malcolm, a specialist in data protection law at Pinsent Masons, the law firm behind OUT-LAW.COM, described the Code as muddled.

"The Code's high-level guidance on the data life-span, stewardship and accountability is helpful but very much echoes existing guidance from the Information Commissioner's Office and Government," he said. "It's an alternative approach but it's certainly not a new approach."

Malcolm added that some references to the need for consent were wrong.

"The guidance on consent seems inconsistent and therefore muddled," he said. "The initial 'Principles' section [of the Code] suggests consent should be obtained where appropriate, which is the correct position. But the other sections seem to suggest that consent should be collected as a matter of course in a variety of situations."

The 'Principles' section of the Code states: "Individuals should be given as much control as is possible over how their personal information is used and disclosed. This means giving them clear information about this when they provide their personal data and seeking their consent where this is appropriate."

Malcolm says this is consistent with the Data Protection Act and with existing guidance from the ICO.

Another section, though, implies that consent is always required when collecting data. Under the heading 'Responsibilities of the data handler' the Code states: "Data handlers tasked with the collection of personal data should verify that the consent of the data subject has been obtained for the personal data collected."

Malcolm said that notification will suffice in many cases.

"Consent is one ground for processing data, but it is not the only ground. In many cases an organisation only needs to notify individuals that it will be processing their data – it does not need their consent," he said. "As the 'Principles' section of the Code notes, the focus should be on giving clear information about how data will be processed at the point of collection."

Louise Bennett, Chair of the BCS Security Forum, said that the Code is the culmination of two years' work. "The consultation work we've undertaken in that time exposed the need for practical help in changing culture to embed good data guardianship principles in all organisations," she said.

"This is the equivalent of the Highway Code for motorists – it will help all those involved in the management of personal data understand their role and enable them to carry out their jobs better."

Another guide to data protection compliance was launched today. British Standard BS 10012, Data protection – Specification for a personal information management system has been developed to establish best practice and aid compliance with data protection legislation. It is the first standard from BSI for the management of personal information. OUT-LAW will report on BS 10012 shortly.

The code can be downloaded from here. (Link to pdf)

Copyright © 2009, OUT-LAW.com

OUT-LAW.COM is part of international law firm Pinsent Masons.

The Essential Guide to IT Transformation

More from The Register

next story
iPad? More like iFAD: We reveal why Apple fell into IBM's arms
But never fear fanbois, you're still lapping up iPhones, Macs
Sonos AXES support for Apple's iOS4 and 5
Want to use your iThing? You can't - it's too old
Philip K Dick 'Nazi alternate reality' story to be made into TV series
Amazon Studios, Ridley Scott firm to produce The Man in the High Castle
You! Pirate! Stop pirating, or we shall admonish you politely. Repeatedly, if necessary
And we shall go about telling people you smell. No, not really
Too many IT conferences to cover? MICROSOFT to the RESCUE!
Yet more word of cuts emerges from Redmond
Joe Average isn't worth $10 a year to Mark Zuckerberg
The Social Network deflates the PC resurgence with mobile-only usage prediction
Chips are down at Broadcom: Thousands of workers laid off
Cellphone baseband device biz shuttered
Feel free to BONK on the TUBE, says Transport for London
Plus: Almost NOBODY uses pay-by-bonk on buses - Visa
Amazon says Hachette should lower ebook prices, pay authors more
Oh yeah ... and a 30% cut for Amazon to seal the deal
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
The Essential Guide to IT Transformation
ServiceNow discusses three IT transformations that can help CIO's automate IT services to transform IT and the enterprise.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.