Feeds

Experts: What ICO should know BEFORE your private info ends up in a skip

Businesses do need 'explicit consent' before outsourcing data protection – legal eagles

Secure remote control for conventional and virtual desktops

The view of the Information Commissioner's Office (ICO) that businesses do not require individuals' "explicit consent" in order to contract others to process their sensitive personal data is in contrast with the wording of data protection law, according to two experts.

A spokesperson for the UK's data protection watchdog told Out-Law.com that it is the ICO's view that there is "nothing within the Data Protection Act" that requires companies to obtain the 'explicit consent' of individuals in order to outsource the processing of sensitive personal data to other firms.

However, data protection law specialists Marc Dautlich and Christian Knorst of Pinsent Masons, the law firm behind Out-Law.com, have questioned the legal basis of the ICO's view.

The comments follow an issue raised in a report by The Independent newspaper last weekend. The report detailed the concerns of medical practitioners that individuals had not consented to the processing of their benefits claims forms by Royal Mail staff on behalf of the Department for Work and Pensions (DWP). DWP is the Government department responsible for assessing individuals' welfare and benefits claims.

According to the report, Royal Mail staff open and sort mail for DWP relevant to individuals' benefits claims in order to direct the mail to the "appropriate processing centre". The mail can contain information revealing sensitive health information about those individuals. The outsourcing arrangement is governed by a contract and a number of measures have been put in place to ensure data security requirements are met, DWP said.

The ICO told Out-Law.com that organisations do not need to obtain individuals' explicit consent to outsource the processing of those individuals' sensitive personal data. Such data refers, among other things, to details of individuals' medical health or condition.

The watchdog has issued guidance on outsourcing of personal data processing. The guidance contains a number of 'good practice' recommendations for businesses but does not advise them to inform individuals if they contract others to processing those individuals' personal data on their behalf. The guidance does not contain a single reference to 'sensitive personal data'.

Under the UK's Data Protection Act (DPA) all personal data must be processed fairly and lawfully and for specific, explicit and legitimate purposes only.

However, under the DPA organisations generally need the "explicit consent" of data subjects in order to be able to process those individuals' sensitive personal data. This general rule is subject to a number of strict exceptions that set out circumstances in which consent is not required.

Rules around non-sensitive personal data processing are less restrictive. They provide organisations with a greater scope to process personal data without the need to obtain individuals' consent to do so.

One example where consent to personal data processing is not required is where the activity is "necessary for the purposes of the legitimate interests" organisations are pursuing, as long as the processing is not "unwarranted in any particular case by reason of prejudice to the rights and freedoms or legitimate interests of the data subject."

The ICO said that when organisations obtain individuals' explicit consent to process sensitive personal data they can then outsource some or all processing activities to others without the need for individuals to consent to those arrangements.

The ICO said that businesses' outsourcing arrangements must comply with sections 11 and 12 of the DPA.

Under the DPA data controllers are required to take "appropriate technical and organisational measures" to ensure against the "unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data".

When outsourcing personal data processing to others, data controllers are required to select processors that can provide "sufficient guarantees" that they can properly meet the "technical and organisational measures" requirement and that they will "take reasonable steps" to "ensure compliance".

The data controllers must establish a written contract with data processors specifying that the processor may only undertake processing activities that the controller tasks them with, whilst the contract must also hold the processors to comply with the "technical and organisational measures" requirements under the DPA. Data controllers are also responsible for any failure of processors in meeting those personal data security standards.

Further rules apply to outsourcing of personal data processing where that processing takes place outside the European Economic Area.

However, Dautlich and Knorst said that those sections contain rules governing the processing of personal data by contractors only, and do not account for the special rules around sensitive personal data.

"Whilst it is positive that the ICO has sought to take a pragmatic approach to the outsourcing of sensitive data, it is unclear upon what legal basis they have done so," Dautlich said. "Before outsourcers rely on what seems to be a very pragmatic understanding and liberal interpretation they would be well advised to identify exactly what grounds they could rely on in order to outsource sensitive data without explicit consent."

Christian Knorst, a data protection law expert based in Pinsent Masons' Munich office, added: "It is fair to say that also under German law a transfer of health data without the explicit consent of the affected person may only be made under very strict preconditions. One cannot say that an outsourcing with respect to health data is in general possible without consent."

The DPA in the UK and German data protection laws are based on the implementation of the EU's Data Protection Directive. The Directive is set to be replaced by a new general Data Protection Regulation, but Dautlich said that the reforms, which are still being negotiated, are likely to require that businesses generally obtain individuals' consent to outsource the processing of their sensitive personal data.

"It is difficult to see on current progress that the new Regulation could countenance such an approach even assuming that the ICO's liberal interpretation is possible under the existing Directive and its implementation in the DPA," Dautlich said.

DWP said that CCTV is used to monitor staff sorting mail, and that at least two staff must be present in order for mail to be opened, according to the Independent's report. DWP said that it has a contract with Royal Mail that requires sorting office staff "abide by the same data protection and security checks as any DWP employee."

However, Dr Tony Calland, chair of the British Medical Association ethics committee, criticised the processing arrangements and said the security measures in place were irrelevant, according to the Independent.

"We are very concerned that a Government department could even contemplate allowing such sensitive and confidential medical data to be handled by a third party without the person's consent," he said.

Copyright © 2012, Out-Law.com

Out-Law.com is part of international law firm Pinsent Masons.

The essential guide to IT transformation

More from The Register

next story
Hello, police, El Reg here. Are we a bunch of terrorists now?
Do Brits risk arrest for watching beheading video nasty? We asked the fuzz
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
UK government accused of hiding TRUTH about Universal Credit fiasco
'Reset rating keeps secrets on one-dole-to-rule-them-all plan', say MPs
Caught red-handed: UK cops, PCSOs, specials behaving badly… on social media
No Mr Fuzz, don't ask a crime victim to be your pal on Facebook
Felony charges? Harsh! Alleged Anon hackers plead guilty to misdemeanours
US judge questions harsh sentence sought by prosecutors
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Yes, but what are your plans if a DRAGON attacks?
Local UK gov outs most ridiculous FoI requests...
EU justice chief blasts Google on 'right to be forgotten'
Don't pretend it's a freedom of speech issue – interim commish
This'll end well: US govt says car-to-car jibber-jabber will SAVE lives
Department of Transportation starts cogs turning for another wireless comms standard
Munich considers dumping Linux for ... GULP ... Windows!
Give a penguinista a hug, the Outlook's not good for open source's poster child
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.