Feeds

Experts: What ICO should know BEFORE your private info ends up in a skip

Businesses do need 'explicit consent' before outsourcing data protection – legal eagles

Gartner critical capabilities for enterprise endpoint backup

The view of the Information Commissioner's Office (ICO) that businesses do not require individuals' "explicit consent" in order to contract others to process their sensitive personal data is in contrast with the wording of data protection law, according to two experts.

A spokesperson for the UK's data protection watchdog told Out-Law.com that it is the ICO's view that there is "nothing within the Data Protection Act" that requires companies to obtain the 'explicit consent' of individuals in order to outsource the processing of sensitive personal data to other firms.

However, data protection law specialists Marc Dautlich and Christian Knorst of Pinsent Masons, the law firm behind Out-Law.com, have questioned the legal basis of the ICO's view.

The comments follow an issue raised in a report by The Independent newspaper last weekend. The report detailed the concerns of medical practitioners that individuals had not consented to the processing of their benefits claims forms by Royal Mail staff on behalf of the Department for Work and Pensions (DWP). DWP is the Government department responsible for assessing individuals' welfare and benefits claims.

According to the report, Royal Mail staff open and sort mail for DWP relevant to individuals' benefits claims in order to direct the mail to the "appropriate processing centre". The mail can contain information revealing sensitive health information about those individuals. The outsourcing arrangement is governed by a contract and a number of measures have been put in place to ensure data security requirements are met, DWP said.

The ICO told Out-Law.com that organisations do not need to obtain individuals' explicit consent to outsource the processing of those individuals' sensitive personal data. Such data refers, among other things, to details of individuals' medical health or condition.

The watchdog has issued guidance on outsourcing of personal data processing. The guidance contains a number of 'good practice' recommendations for businesses but does not advise them to inform individuals if they contract others to processing those individuals' personal data on their behalf. The guidance does not contain a single reference to 'sensitive personal data'.

Under the UK's Data Protection Act (DPA) all personal data must be processed fairly and lawfully and for specific, explicit and legitimate purposes only.

However, under the DPA organisations generally need the "explicit consent" of data subjects in order to be able to process those individuals' sensitive personal data. This general rule is subject to a number of strict exceptions that set out circumstances in which consent is not required.

Rules around non-sensitive personal data processing are less restrictive. They provide organisations with a greater scope to process personal data without the need to obtain individuals' consent to do so.

One example where consent to personal data processing is not required is where the activity is "necessary for the purposes of the legitimate interests" organisations are pursuing, as long as the processing is not "unwarranted in any particular case by reason of prejudice to the rights and freedoms or legitimate interests of the data subject."

The ICO said that when organisations obtain individuals' explicit consent to process sensitive personal data they can then outsource some or all processing activities to others without the need for individuals to consent to those arrangements.

The ICO said that businesses' outsourcing arrangements must comply with sections 11 and 12 of the DPA.

Under the DPA data controllers are required to take "appropriate technical and organisational measures" to ensure against the "unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data".

When outsourcing personal data processing to others, data controllers are required to select processors that can provide "sufficient guarantees" that they can properly meet the "technical and organisational measures" requirement and that they will "take reasonable steps" to "ensure compliance".

The data controllers must establish a written contract with data processors specifying that the processor may only undertake processing activities that the controller tasks them with, whilst the contract must also hold the processors to comply with the "technical and organisational measures" requirements under the DPA. Data controllers are also responsible for any failure of processors in meeting those personal data security standards.

Further rules apply to outsourcing of personal data processing where that processing takes place outside the European Economic Area.

However, Dautlich and Knorst said that those sections contain rules governing the processing of personal data by contractors only, and do not account for the special rules around sensitive personal data.

"Whilst it is positive that the ICO has sought to take a pragmatic approach to the outsourcing of sensitive data, it is unclear upon what legal basis they have done so," Dautlich said. "Before outsourcers rely on what seems to be a very pragmatic understanding and liberal interpretation they would be well advised to identify exactly what grounds they could rely on in order to outsource sensitive data without explicit consent."

Christian Knorst, a data protection law expert based in Pinsent Masons' Munich office, added: "It is fair to say that also under German law a transfer of health data without the explicit consent of the affected person may only be made under very strict preconditions. One cannot say that an outsourcing with respect to health data is in general possible without consent."

The DPA in the UK and German data protection laws are based on the implementation of the EU's Data Protection Directive. The Directive is set to be replaced by a new general Data Protection Regulation, but Dautlich said that the reforms, which are still being negotiated, are likely to require that businesses generally obtain individuals' consent to outsource the processing of their sensitive personal data.

"It is difficult to see on current progress that the new Regulation could countenance such an approach even assuming that the ICO's liberal interpretation is possible under the existing Directive and its implementation in the DPA," Dautlich said.

DWP said that CCTV is used to monitor staff sorting mail, and that at least two staff must be present in order for mail to be opened, according to the Independent's report. DWP said that it has a contract with Royal Mail that requires sorting office staff "abide by the same data protection and security checks as any DWP employee."

However, Dr Tony Calland, chair of the British Medical Association ethics committee, criticised the processing arrangements and said the security measures in place were irrelevant, according to the Independent.

"We are very concerned that a Government department could even contemplate allowing such sensitive and confidential medical data to be handled by a third party without the person's consent," he said.

Copyright © 2012, Out-Law.com

Out-Law.com is part of international law firm Pinsent Masons.

Gartner critical capabilities for enterprise endpoint backup

More from The Register

next story
'Stop dissing Google or quit': OK, I quit, says Code Club co-founder
And now a message from our sponsors: 'STFU or else'
Ex US cybersecurity czar guilty in child sex abuse website case
Health and Human Services IT security chief headed online to share vile images
Don't even THINK about copyright violation, says Indian state
Pre-emptive arrest for pirates in Karnataka
The police are WRONG: Watching YouTube videos is NOT illegal
And our man Corfield is pretty bloody cross about it
Felony charges? Harsh! Alleged Anon hackers plead guilty to misdemeanours
US judge questions harsh sentence sought by prosecutors
Oz biz regulator discovers shared servers in EPIC FACEPALM
'Not aware' that one IP can hold more than one Website
Apple tried to get a ban on Galaxy, judge said: NO, NO, NO
Judge Koh refuses Samsung ban for the third time
prev story

Whitepapers

Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Backing up distributed data
Eliminating the redundant use of bandwidth and storage capacity and application consolidation in the modern data center.
The essential guide to IT transformation
ServiceNow discusses three IT transformations that can help CIOs automate IT services to transform IT and the enterprise
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.