Showing posts with label data breaches. Show all posts
Showing posts with label data breaches. Show all posts

Thursday, August 21, 2014

"State must be more mindful of your private data"

I've waited a while to quote Fr. Dougal McGuire in the national press, but finally got my chance in the Independent:
Last week the Irish Independent revealed further abuses of private files in the Department of Social Protection. The abuses ranged from private investigators illegally accessing personal information, to one male employee who spent up to two hours per day looking up information on women and their partners... The response of the department - that it constantly reviews its internal controls - is reminiscent of Father Dougal McGuire's promise: "As I said last time, it won't happen again".
 Full text.

Monday, April 30, 2012

Record numbers of complaints, data breaches and more (all on a shoestring budget)

The Data Protection Commissioner's 2011 Annual Report was published today. While the whole document is well worth reading, a few highlights struck me as worth particular attention.

Resources

Unsurprisingly - particularly in the light of the ongoing Facebook investigation - the report starts by saying that the financial and personnel position of the Office has become unsustainable in light of increased demands, with the warning that failing to remedy this will jeopardise investment in Ireland:
The scope of our responsibilities has changed significantly in the past 3 to 5 years. This arises in particular from the success of the Industrial Development Authority in attracting to Ireland companies conducting significant processing of personal data. We have worked with these companies to help them understand their obligations under EU data protection law towards all EU users of their services.

The legislative proposals presented by the European Commission1 in January of this year, if passed into law, will involve increased responsibilities for our Office under the so-called “one-stop-shop” arrangement for multinational companies providing services to EU users from an Irish base. While the exact division of labour between data protection authorities has yet to be finalised, it clearly will involve a greater degree of responsibility for our Office in relation to multinational companies which choose Ireland as an EU base. Failure to adequately discharge this responsibility will carry significant reputational risks for the country...

The implications of our increased European responsibilities were brought home to us forcefully in relation to our audit of the activities of Facebook-Ireland. Facebook- Ireland had unambiguously placed itself under our Office’s jurisdiction through changes in its contractual arrangements with its EU users and the establishment of clear responsibility for the processing of their data. We therefore included them in our programme of audits for 2011. This was the most complex audit ever undertaken by our Office, involving about a quarter of our staff resources for 3 months and external technical assistance from University College Dublin (UCD)...

We clearly cannot maintain a similar level of commitment in relation to other multinational companies without additional resources. I am confident that this message is understood by the Government and would hope to be allocated additional resources in the course of this year. [All emphasis added.]
Number of incidents

Complaints reached a record high last year with 1,161 complaints under the Data Protection Acts and 253 complaints under the ePrivacy Regulations (dealing with unsolicited texts messages, etc.). Remarkably, data breach notifications outnumbered both types of complaints with 1,167 notifications during the year from 186 different organisations (up from 119 in 2009 and 410 in 2010). This seems to reflect greater awareness of the obligation to notify, rather than any increase in breaches, and presumably will plateau in coming years - but the sheer volume of notifications presents its own challenges.

Unsolicited marketing prosecutions

One area where the DPC has been particularly successful is in relation to unsolicited marketing text messages and telephone calls, where there now seems to be a well-oiled machine in place for prosecuting repeat offenders. In relation to communications providers alone, in 2011 successful prosecutions were brought against:

* Eircom: one unsolicited telephone marketing call, Probation Act applied, €2,000 donation made to charity;
* Vodafone: four unsolicited telephone marketing calls, one text message, total of €3,850 in fines imposed;
* o2: one unsolicited text message, Probation Act applied, €2,000 donation made to charity;
* UPC: eighteen charges relating to unsolicited telephone marketing calls, total of €7,100 in fines imposed.

Political spam now prohibited

Until recently there was an extensive exemption for political direct marketing - one which was arguably incompatible with the requirements of the ePrivacy Directive. This has now been amended, which will no doubt be a relief to Irish voters in the run up to the Fiscal Treaty referendum:
A second issue of concern which I commented on in 2009 was the direct marketing exemption which excluded from the scope of the Data Protection Acts any direct marketing carried out for political purposes by political parties or by candidates for election to political office. I expressed my dissatisfaction then that I was unable to launch investigations into complaints which I received from voters who received unsolicited SMS messages, emails or phone calls even when they had made it clear that they did not wish to be contacted in that way. Had such unsolicited marketing contact been made to members of the public by any other entity, such as a commercial business, there would be no restriction on my investigating the matter. I expressed doubts in my 2009 Annual Report about the consistency with EU Directives of the exemption in this country for such political activities.

I am pleased to report that the Minister for Communications, in framing S.I. 336 of 2011, removed the exemption relating to direct marketing for political activities in the context of marketing communications carried out by electronic means – such as SMS messages, faxes, email and telephone calls. As a result, I am no longer restricted from investigating complaints in this area. Accordingly, in my role as Data Protection Commissioner, I am obliged to investigate any such complaints in this area.

In this respect, arising out of the Presidential Election which took place following the commencement of SI 336 of 2011 on 1 July, I have already issued a warning to a political party about the sending of unsolicited marketing text messages in the course of the campaign. A second such incident is likely to lead to a prosecution. [Although not identified in the Annual Report, the Sunday Times has named Sinn Fein as the offending party.]
Department of Social Protection Audit

One of the greatest offenders against individual privacy has been the Department of Social Protection, formerly the Department of Social Welfare, which has a long and ignominious track record of staff abuse of personal information. (One recent example.) Worryingly, however, the Annual Report confirms earlier reports that Social Protection databases may be open to abuse externally as well as internally - by other state entities which have access to the departmental systems:
Also included in the list of the audits is an INFOSYS investigation. This refers to an in-depth examination of the use of INFOSYS – a database of social welfare data administered by the Department of Social Protection. The INFOSYS investigation focused on the authorised use of INFOSYS by a whole range of external third parties, including local authorities and state agencies. Initially INFOSYS was a ‘desk audit’ entailing extensive correspondence in the second and third quarter of 2011 between my Office and external users of INFOSYS. It was my intention to comment extensively on this investigation in this report but this has not proven possible, given the resources needed, to complete it to a suitable level. However, the interim findings have caused my Office to engage with the Department of Social Protection and the large number of entities authorised to access the system to address the deficiencies identified so far.
Guthrie Cards / Heel Prick Samples

One of the most important issues dealt with by the report is the (long delayed) destruction of illegally-held blood samples taken from all newborns. The full discussion is too long to excerpt here, but one important point (which the media don't appear to have picked up) is that the Minister for Health and the HSE appear to have attempted to evade the Data Protection Commissioner in their efforts to create a national DNA database, by freezing out the DPC from a "review" of the decision to destroy the samples:
A final issue that emerged can essentially be summarised as that it would be useful to continue to hold the millions of samples involved to form the basis of a national database which could be used for health-related genetic (DNA) analysis We were obliged to point out that the creation of such a database, without the consent of the persons involved (or their parents/guardians as appropriate) would be a clear breach of the Data Protection Acts. It would also run counter to the spirit (if not the letter) of the Disability Act 2005 – which requires individual consent for the carrying out of genetic tests – and of the Marper judgment of the European Court of Human Rights in relation to the retention of DNA samples in a criminal context However, in light of concerns expressed around such issues, we understand that the Minister for Health asked for a full review of the decision taken by the HSE to destroy the samples on the terms agreed with this Office. We were not a party to this review but it is now completed and at the time of writing the Minister had approved the position previously agreed including the publicity campaign for people to seek earlier deletion or continued retention depending on their own particular preferences.
Security cluelessness

Finally, although it's not an issue of any great significance, I was amused by case study 7 in which insurance company Allianz chose to use three pieces of publicly available information for their "security questions":
Allianz informed us that it introduced three ID security questions consisting of date of birth, mother's maiden name and place of birth. It stated that these questions were introduced to ensure that it was keeping its customer's personal information safe and secure and to prevent any unauthorised disclosure. As previously outlined in my 2009 Annual Report it is our view that the use of questions such as date of birth and mother's maiden name for the purpose of ensuring security of data is not an adequate safeguard against disclosure to a third party. Such questions may in fact be a security vulnerability as this type of information is publicly available upon payment of a fee to the General Register Office and is therefore of limited value on its own as a security feature.

Thursday, April 07, 2011

Data breach law in Ireland - the current state of play

I had a very interesting morning at McCann Fitzgerald who were kind enough to invite me in to give a legal update on data breaches - here's a copy of the handout I provided:Lessons from laptop loss: Legal consequences where organisations lose personal data

Monday, March 28, 2011

Consultation on implementation of Telecoms Reform Package

There are just a few days left if you wish to comment on the Department of Communications proposals for implementation of the Telecoms Reform Package.

While there's quite a lot contained in the five sets of proposed regulations, the portions of most interest to me are the proposals regarding the revised E-Privacy Directive (.doc) which will implement a requirement for data breach notification along with new rules regarding cookies.

Curiously enough, there hasn't been much public debate in Ireland about the impact of the new rules regarding cookies - unlike the UK, where a similar implementation (which essentially copies and pastes text directly from the Directive) has been particularly controversial. This may be because the proposed Irish text is more business friendly in explicitly stating that browser settings can be used to show that users consent to cookies. However, it's still not entirely clear from the draft regulations whether this means that the technically unsavvy user will be taken to have consented where they fail to adjust their browser settings from what is (usually) the default "accept all cookies" option. (The Article 29 Working Party, for example, have taken the view that failure to adjust default settings does not amount to an affirmative consent.)

Update: The Department has now confirmed that it has extended the deadline for submissions to 15 April.

Friday, February 25, 2011

Subject access requests up by 25% as employees seek to see HR files

Elaine Edwards has an interesting report from the Irish Computer Society Annual Data Protection Conference:
THE NUMBER of complaints from people seeking access to personal information held on them increased last year due to the economic downturn, with many people concerned about potential or actual dismissal from their jobs.

Data Protection Commissioner Billy Hawkes said yesterday the top item for complaints to his office in 2010 was about failure to respond adequately to requests for access to personal data.

Individuals have a right under the Data Protection Acts to be given this data. “In past years, the top spot was always occupied by unsolicited direct marketing,” Mr Hawkes said. “I think with the economic downturn we are currently suffering, we’ve seen increasing use of the right of access by people who are fearful that they are going to lose their jobs or, who sometimes may have lost them.

“They are using the right of access to see what exactly is going on in relation to them within a particular organisation, or to see was it justified that they should have been picked out for dismissal from the company.”
Daragh O'Brien has also put up a screencast of his presentation at that conference.

Update: Elaine Edwards has more from the conference here, discussing the need for reform of data breach reporting.

Sunday, February 20, 2011

Judge's report reveals allegations that Garda used phone records to spy on her ex

Mark Tighe has an important story in today's Sunday Times about apparent abuse by a garda of the data retention system. Unfortunately it's behind a paywall, but I've taken the liberty of scanning the hardcopy and placing it here as it raises a number of fundamental questions about the safeguards which are in place against abuse and the likelihood of further abuse now that the 2011 Act has extended data retention to internet use also.
Garda accused of bugging her ex-boyfriend

Mark Tighe

A FEMALE garda suspected of obtaining the phone records of her ex-boyfriend has been reported as the first person who may have breached phone-tapping rules introduced in legislation in 1993.

The case is highlighted in a report prepared by Iarfhlaith O'Neill, a High Court judge designated to monitor the state's phone-tapping activities.

Security sources say that the case involves a garda who was stationed in the force's crime and security division, which carries out spying and intelligence services. The garda is accused of obtaining phone records of her former boyfriend to track his movements and activities after they separated. The man became suspicious and complained to gardai because his ex-girlfriend allegedly knew s details of calls he had made.

In a report to the Oireachtas earlier this month, O'Neill said that he investigated a number of alleged breaches of Section 64(2) of the Criminal Justice (Terrorist Offences) Act 2005. Under Section 64(2) no garda below the rank of chief superintendent can request an individual's phone records from a service provider to aid investigations of criminal offences.

O'Neill said: "These breaches are alleged to have been committed by a member of An Garda Siochana."

"As a result of my investigations, I was concerned that these breaches may have occurred. These alleged breaches are now the subject matter of a criminal investigation and also disciplinary proceedings under the garda disciplinary code."

O'Neill said that the extent of the alleged non-compliance with the 2005 Act had been "rigorously investigated and fully understood". He said all appropriate steps had been taken to ensure future compliance with the act.

The rest of O'Neill's report states that on November 18 last year he attended garda headquarters, then army headquarters in McKee Barracks and later the Depart¬ment of Justice offices on St Stephen's Green.

In each location he reviewed documents relating to phone tapping and phone records and spoke to people involved in the operation of the act. He said that all his queries were answered to his satisfaction.

"As a result of the forgoing, I am satisfied that there is, as of the date of this report (November 26, 2010) full compliance with the provisions of the above acts," he said.

A spokesman for the Data Protection Commissioner (DPC) said that gardai had informed it of the apparent data breach last June.

Gardai refused to comment on the case.

Gardai and the Department of Justice have refused to release details of how many requests for phone records or how many phone taps are authorised each year. They say that such information is sensitive.

The Labour party has called for a review of the powers given to gardai to access personal records and said they should only be used in exceptional circumstances.

In 2007 the DPC said that, based on audits of phone companies, it estimated gardai were making 10,000 requests for citizens' phone records each year. Security sources say the figure is now likely to be closer to 15,000 as gardai regularly seek phone records to aid investigations.

Despite its resistance to publishing details about requests to access the phone records of private citizens, Ireland may be forced to do so by a 2009 European Council directive.

The directive requires member countries to legislate to provide their data protection commissioners with the number of requests made for phone records and the legal justification invoked.
Some quick thoughts:

The references to bugging and phone-tapping are misleading - what is alleged here (as I understand it) is that the garda accessed the phone records of her ex rather than actually listened to the contents of telephone calls.

There are, unhelpfully, no details given in the report as to how the abuse came to light or what changes will be made in future to prevent further abuses. (Continuing a fine tradition of opacity.) But a number of questions spring to mind.

When did the alleged abuse take place, and how long did it take before it was uncovered? Was the abuse discovered purely by chance? Is there an adequate internal audit trail of requests which are made? If so, who is responsible for reviewing that trail? Does the designated judge access a sample of requests from the preceding year to ensure that the surveillance was appropriate? If the designated judge will not provide this level of detail in the annual report then the Minister for Justice must do so to the Oireachtas if the public are to have confidence in this system. While the particular details of this case cannot be discussed until any criminal trial is concluded, it is remarkable that there is absolutely no discussion of the systems-level controls which are (or are not) in place.

Finally, when data breach notification is finally introduced as a legal obligation (whether under the revised e-Privacy Directive or the Data Protection Commissioner's Code of Practice) will it include a right to be notified of this type of breach also? Note that the Directive appears to impose a notification obligation on telcos only.

For more background on the allegations behind this story, see this Mail on Sunday piece from last year.

Monday, February 14, 2011

Want to know how much your neighbour owes on his credit card? Try the Companies Registration Office

Edited 21/2/11: The story behind this post has since been removed from the Sunday Business Post from its site and a clarification printed:
In an article published on February 13 under the headline "Debtors’ personal details posted online by debt collection firm", we said that Cash Flow Services (CFS) had made personal details of almost 1,100 credit card holders available on the internet, through the Companies Registration Office.

We have been asked to point out, and are happy to clarify, that neither CFS nor any party acting on its behalf listed the names or outstanding debts of MBNA customers in any documents filed in the Companies Registration Office, nor did CFS post any debtors’ personal details online.

The Sunday Business Post apologises to CFS and its directors for any misunderstanding or confusion caused.

Friday, January 14, 2011

Data breach notification - ENISA study released

ENISA - the European Network and Information Security Agency - has just published a study (PDF) on data breach notification. The research was carried out as part of the process of implementing the notification requirement in the revised e-Privacy Directive, and aims to develop consistent guidelines throughout Europe for the technical and procedural issues surrounding breach notification. Some highlights from the summary (text in [brackets] is my own interlineation):
[Views of telecoms operators]

The telecommunications sector recognises that data breach notifications have an important role in the overall framework of data protection and privacy. Nevertheless, operators are seeking support and guidance on an EU and local level over a number of issues, which if clarified, would better enable European service providers to comply effectively with data breach notification requirements. Key concerns raised by telecom operators include the following:

● Risk prioritisation – The seriousness of a breach should determine the level of response. In order to prevent ‘notification fatigue’ for both the operator and the data subjects, breaches should be categorised according to specific risk levels.

● Communication channels – Operators want assurances that notification requirements will not negatively impact their brands. It is important for operators to maintain control of communications with relevant data subjects, as much as possible, to ensure that operators can effectively manage any impact on brand perception brought about by the data breach and subsequent notification.

[If operators want to avoid negative impact on their brands it might be more productive to avoid data breaches in the first place.]

● Support – In preparation for mandatory notification requirements, operators are looking for support in terms of guidance on procedures. In particular, guidance should provide a methodology for categorising types of private data and combinations of private data, as well as how to proceed with notifications based on the level of risk attributed to each breach.

[Views of Data Protection Authorities]


Data protection authorities (DPAs) take varied approaches to enforcing data protection and privacy. Some follow EC Directives closely, while others take on additional responsibilities beyond those outlined in the Directives. Although there are exceptions, the majority of DPAs surveyed in this study support mandatory notifications for telecom operators. Those that did not support mandatory notifications mostly indicated that budgetary limitations were a key factor in influencing their opinion. As notifications are not yet mandatory in most countries, regulatory authorities have little experience in handling notifications. Since regulatory authorities have a number of responsibilities, there are concerns that additional duties must not interfere with pre-existing responsibilities. Notifications are not viewed as a number one priority for most authorities. A smooth transition to mandatory notifications will consequently depend on a resolution to a number of factors, outlined here:

● Resources – Budgetary allocations for regulatory authorities should reflect new regulatory responsibilities. Concern has been raised that resources at some regulatory authorities are already occupied with other priorities. Bandwidth for additional responsibilities is limited.

● Enforcement – DPAs indicated that sanctioning authority enables them to better enforce regulations. Data controllers will be less incentivised to comply with regulations if regulatory authorities do not have sufficient sanctioning powers. Some authorities indicated that financial penalties are seen as the most effective tool for pressuring data controllers to comply, while others indicated that public criticism and black lists could be effective too.

● Relevant authorities – Local legislation will determine who the relevant authority is for regulating data breach notifications in the telecommunications sector, when mandatory notification requirements are transposed into local legislation. Although many data protection authorities indicated they are communicating effectively with other authorities already, it is important for legislation to clearly delineate relevant responsibilities, in order to mitigate or prevent potential conflicts.

● Technical expertise – In some cases, businesses have a high level of technical sophistication, which allows them potentially to conceal valuable information regarding breaches from regulatory authorities, which do not have comparable resources and expertise. Hiring new staff with relevant expertise is important in order for regulatory authorities to remain effective.

● Awareness raising – A high public profile is an important element in demonstrating the influence of regulatory authorities. A common strategy in communicating the importance of data protection to the public could be useful in better educating data subjects about their privacy rights, and the role of notifications in the overall framework of data protection.

[Areas of conflict]


Smooth implementation of data breach notification procedures requires close cooperation between data controllers at the service providers and the relevant regulatory authorities. While most operators and regulatory bodies surveyed recognise the importance of notifications, there are a number of issues where interests of the parties involved might conflict.

● Undue delay – Regulatory authorities want to see a short deadline for reporting breaches to authorities and data subjects, in order to prevent controllers from concealing evidence and also to give data subjects ample time to protect themselves. Service providers, however, want their resources to be focused on identifying if the problem is serious and solving the problem, instead of spending time reporting details, often prematurely, to regulatory authorities.

[This is an important point which is sometimes overlooked. In some breaches - such as those of credit card details - it will be essential that individuals be notified immediately so that they can e.g. cancel cards. Other breaches - such as those of healthcare information - may be just as serious but aren't likely to be as time sensitive. However, the fact that the affected individuals may not need to be notified immediately must not become an excuse for failure to notify the relevant DPA as soon as possible.]

● Traffic monitoring – Private data belonging to employees or customers running over a corporate network remain a challenging issue for both regulatory authorities and operators. Telecom operators are often requested to monitor and analyse traffic data on behalf of their customers, particularly in cases where companies want to monitor the actions of their employees. In this context, regulatory authorities see traffic monitoring as a privacy risk, due to the fact that employers may be exchanging private information on the corporate network, to which the employers would then have access.

● Content of notifications – The content of the notifications can have a direct impact on customer relations and retention. Operators want to make sure that the content of the notifications does not impact negatively on customer relations. Regulatory authorities, however, want to see that the notifications provide the necessary information and guidance in line with the rights of the data subjects.

● Audits – One service provider indicated that it performed its own security audits internally, with the aim of detecting and solving any potential vulnerabilities that could result in data breaches. The operator believed that its internal expertise were sufficient to ensure it was using the latest techniques for securing data and compliance with regulations, suggesting its expertise surpassed that of the national regulatory authorities. Regulatory authorities, however, indicated that their ability to perform audits and spot checks provides the authority necessary to enforce compliance.

[Extension of notification to other sectors]


While the recent telecoms reforms make notifications mandatory for telecom operators, there remains ongoing debate about extending mandatory notifications to other sectors.

● Telecommunications operators: In comparison to other sectors, regulatory authorities indicated that telecommunications operators ranked high in terms of their security measures and ability to limit data breaches.

Telecom operators have at their disposal some of the top networking, communications and security experts. But this is true mostly for the larger operators. Smaller alternative operators and local ISPs do not necessarily have resources comparable to the large international companies and incumbent operators.

● Finance sector: Finance institutions are considered to be at great risk, due to the sensitive nature of the data they possess. Nonetheless, financial institutions are already subject to regulations across Europe, with regulations being enforced by various bodies, including central banks. Consequently, extending data breach requirements to financial institutions would require careful coordination with other responsible authorities, which may already require incidents of data breaches to be reported.

● Healthcare: Data protection authorities regularly pointed to the healthcare sector as an area of high risk. Due to the large amount of very sensitive private data stored on doctors’ and nurses’ laptops, which are often unencrypted, there is high risk for exposure or leaks.

● Small businesses: Small businesses pose a major challenge. Collectively, they have a lot of personal data, but individually they do not have resources or know-how to secure their data. Due to the sheer number of small businesses, regulation would prove challenging. Educating and making businesses aware would require significant efforts and resources. As more and more small businesses develop online strategies, the risk for exposure is increasing.

Sunday, January 10, 2010

Children's hospital lost data on 1m patients

In a follow up to his excellent story about Temple Street Children's Hospital storing DNA samples of over 1.5 million people without any legal basis, Mark Tighe has a piece in today's Sunday Times revealing that the hospital also lost two servers full of information about patients in 2007:
Two computer servers containing the records of almost 1m patients were stolen from the Children’s University hospital in Temple Street in 2007 and have never been recovered.

The data were far more than that lost on stolen bank laptops in recent years. The theft was investigated by the data protection commissioner (DPC) and the gardai after being reported by the Dublin hospital in February 2007. The organisations had decided that there was no need to inform the public, believing there was little chance of the thief being able to access the data.

Patients’ details, including names, date of birth and reason for admission are thought to have been included.
Interestingly, there's no mention of the servers having been encrypted, making it unclear on what basis it was decided that the data couldn't be accessed.

There's also an update indicating that there has already been some official interest in accessing the DNA records:
In Australia and New Zealand, hospital databases have been accessed by police using DNA in their investigations.

Asked if it had allowed gardai access to the database, Temple Street said it had “one tentative enquiry” by an agency but this was not followed up.

"Our patient confidentiality policy will continue to dictate the response and no access to samples will be granted," a spokeswoman said.

Sunday, October 18, 2009

Data breach consultation paper now out

The Data Protection Review Group has now published a consultation paper (pdf) on reforming Irish law on notification of data breaches. Pages 33-38 on possible regulatory options are particularly useful, though the group is clearly hampered by the fact that any national reforms might soon be out of date as a result of changes at European level.

Garda databases still open to abuse?

From today's Sunday Business Post:
A garda undermined a series of major anti-crime surveillance operations by passing details of car registrations belonging to undercover detectives onto a gang of armed robbers.

The garda is the subject of an internal investigation which is looking into a number of officers who are suspected of being on the payroll of separate Dublin criminals. The garda was in regular contact with a crime figure who is facing charges related to serious criminal activity.

When the criminal gang suspected that they might be under surveillance, they supplied the garda with a list of car registrations they had encountered. The garda checked the car details on the force’s Pulse IT system and informed the gang if the cars were part of the Garda fleet.

In several cases, the garda was able to identify vehicles that were being used by an undercover Garda unit. To avoid detection, the officer got junior uniformed gardaí to log into the Pulse system using their own passwords - as the system records a digital imprint of every log-in by a member using their unique password, The Sunday Business Post understands.
Update (8.11.09) - The Sunday Independent has more on abuse of Garda databases.