<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Data Protection Strategy</title>
	<link>http://www.openrightsgroup.org/consult/data-protection-strategy/</link>
	<description>Protecting your rights in the digital age</description>
	<pubDate>Fri, 29 Aug 2008 18:28:28 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3</generator>
		<item>
		<title>By: Harry Metcalfe</title>
		<link>http://www.openrightsgroup.org/consult/data-protection-strategy/#comment-51</link>
		<dc:creator>Harry Metcalfe</dc:creator>
		<pubDate>Wed, 26 Sep 2007 18:30:01 +0000</pubDate>
		<guid>http://www.openrightsgroup.org/consult/data-protection-strategy/#comment-51</guid>
		<description>I really like this idea in principle, although fixing appropriate criteria for such accreditation would be difficult. If that could be done, though, it would be brilliant:

"Only have your gas appliance serviced by a CORGI registered engineer"
"Only supply your personal data to an ICO accredited data controller"

Marvellous!</description>
		<content:encoded><![CDATA[<p>I really like this idea in principle, although fixing appropriate criteria for such accreditation would be difficult. If that could be done, though, it would be brilliant:</p>
<p>&#8220;Only have your gas appliance serviced by a CORGI registered engineer&#8221;<br />
&#8220;Only supply your personal data to an ICO accredited data controller&#8221;</p>
<p>Marvellous!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Harry Metcalfe</title>
		<link>http://www.openrightsgroup.org/consult/data-protection-strategy/#comment-50</link>
		<dc:creator>Harry Metcalfe</dc:creator>
		<pubDate>Wed, 26 Sep 2007 18:27:49 +0000</pubDate>
		<guid>http://www.openrightsgroup.org/consult/data-protection-strategy/#comment-50</guid>
		<description>Yes -- this is really important. See earlier comment on informed choice.</description>
		<content:encoded><![CDATA[<p>Yes &#8212; this is really important. See earlier comment on informed choice.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Harry Metcalfe</title>
		<link>http://www.openrightsgroup.org/consult/data-protection-strategy/#comment-49</link>
		<dc:creator>Harry Metcalfe</dc:creator>
		<pubDate>Wed, 26 Sep 2007 18:25:52 +0000</pubDate>
		<guid>http://www.openrightsgroup.org/consult/data-protection-strategy/#comment-49</guid>
		<description>Both!</description>
		<content:encoded><![CDATA[<p>Both!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Harry Metcalfe</title>
		<link>http://www.openrightsgroup.org/consult/data-protection-strategy/#comment-48</link>
		<dc:creator>Harry Metcalfe</dc:creator>
		<pubDate>Wed, 26 Sep 2007 18:17:43 +0000</pubDate>
		<guid>http://www.openrightsgroup.org/consult/data-protection-strategy/#comment-48</guid>
		<description>The ability for people to make an informed choice is very much dependent on the information available to them when they supply personal data. 

For example, are Nectar/Tesco et al complying with DPA Schedule 1 2.1(1)? This says that personal data must be processed fairly, and that regard must be given to whether information was obtained from a person who was deceived or misled as to the purpose for collecting the information. Are Tesco/Nectar really explaining clearly what they do with cardholders' personal data? Are they misleading their customers by couching such explanations in small-text marketing lingo that doesn't really describe what they are actually doing?

I suspect that most people are completely unaware of the scale of the data mining undertaken by these companies. Perhaps data controllers should be obliged to be a bit more forthcoming? Freedom of choice is very important, but is rather meaningless unless an informed choice can be made.</description>
		<content:encoded><![CDATA[<p>The ability for people to make an informed choice is very much dependent on the information available to them when they supply personal data. </p>
<p>For example, are Nectar/Tesco et al complying with DPA Schedule 1 2.1(1)? This says that personal data must be processed fairly, and that regard must be given to whether information was obtained from a person who was deceived or misled as to the purpose for collecting the information. Are Tesco/Nectar really explaining clearly what they do with cardholders&#8217; personal data? Are they misleading their customers by couching such explanations in small-text marketing lingo that doesn&#8217;t really describe what they are actually doing?</p>
<p>I suspect that most people are completely unaware of the scale of the data mining undertaken by these companies. Perhaps data controllers should be obliged to be a bit more forthcoming? Freedom of choice is very important, but is rather meaningless unless an informed choice can be made.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Harry Metcalfe</title>
		<link>http://www.openrightsgroup.org/consult/data-protection-strategy/#comment-47</link>
		<dc:creator>Harry Metcalfe</dc:creator>
		<pubDate>Mon, 24 Sep 2007 16:59:47 +0000</pubDate>
		<guid>http://www.openrightsgroup.org/consult/data-protection-strategy/#comment-47</guid>
		<description>Two things come to mind:

As noted by Becky, the ICO should have the power to inspect data controllers at will -- like the HSE. This is crucial.

Second, where companies are involved in violations of the DPA which are egregious -- like leaks of large amount of personal information -- there should be a duty to disclose this to the ICO. See the HoL Personal Security Online report.</description>
		<content:encoded><![CDATA[<p>Two things come to mind:</p>
<p>As noted by Becky, the ICO should have the power to inspect data controllers at will &#8212; like the HSE. This is crucial.</p>
<p>Second, where companies are involved in violations of the DPA which are egregious &#8212; like leaks of large amount of personal information &#8212; there should be a duty to disclose this to the ICO. See the HoL Personal Security Online report.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Becky Hogge</title>
		<link>http://www.openrightsgroup.org/consult/data-protection-strategy/#comment-41</link>
		<dc:creator>Becky Hogge</dc:creator>
		<pubDate>Mon, 24 Sep 2007 15:18:17 +0000</pubDate>
		<guid>http://www.openrightsgroup.org/consult/data-protection-strategy/#comment-41</guid>
		<description>No mention of US in this paragraph, which is weird since it is such a data protection black hole.</description>
		<content:encoded><![CDATA[<p>No mention of US in this paragraph, which is weird since it is such a data protection black hole.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Becky Hogge</title>
		<link>http://www.openrightsgroup.org/consult/data-protection-strategy/#comment-40</link>
		<dc:creator>Becky Hogge</dc:creator>
		<pubDate>Mon, 24 Sep 2007 15:16:38 +0000</pubDate>
		<guid>http://www.openrightsgroup.org/consult/data-protection-strategy/#comment-40</guid>
		<description>This request should be noted in the response and, as far as possible, ORG should provide evidence as well as argument ;)</description>
		<content:encoded><![CDATA[<p>This request should be noted in the response and, as far as possible, ORG should provide evidence as well as argument ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Becky Hogge</title>
		<link>http://www.openrightsgroup.org/consult/data-protection-strategy/#comment-39</link>
		<dc:creator>Becky Hogge</dc:creator>
		<pubDate>Mon, 24 Sep 2007 15:14:58 +0000</pubDate>
		<guid>http://www.openrightsgroup.org/consult/data-protection-strategy/#comment-39</guid>
		<description>How realistic is this expectation? Has it proved unrealistic in the past?</description>
		<content:encoded><![CDATA[<p>How realistic is this expectation? Has it proved unrealistic in the past?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Becky Hogge</title>
		<link>http://www.openrightsgroup.org/consult/data-protection-strategy/#comment-38</link>
		<dc:creator>Becky Hogge</dc:creator>
		<pubDate>Mon, 24 Sep 2007 15:10:04 +0000</pubDate>
		<guid>http://www.openrightsgroup.org/consult/data-protection-strategy/#comment-38</guid>
		<description>ICO penalties are weak and weakly enforced. Public and private sector should be penalised when they expose people to data protection risk.</description>
		<content:encoded><![CDATA[<p>ICO penalties are weak and weakly enforced. Public and private sector should be penalised when they expose people to data protection risk.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Becky Hogge</title>
		<link>http://www.openrightsgroup.org/consult/data-protection-strategy/#comment-37</link>
		<dc:creator>Becky Hogge</dc:creator>
		<pubDate>Mon, 24 Sep 2007 15:08:14 +0000</pubDate>
		<guid>http://www.openrightsgroup.org/consult/data-protection-strategy/#comment-37</guid>
		<description>Or should we emphasies that no technology ensures privacy?</description>
		<content:encoded><![CDATA[<p>Or should we emphasies that no technology ensures privacy?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
