S2 Ep10: GDPR Radio: Data Protection News Of The Week
44m 16s
The podcast episode covers recent data protection news, focusing on two main incidents. First, a security breach at Companies House allowed unauthorized alterations to director information, raising concerns about data accuracy and the contextual risks of breaches, even with less sensitive data. Second, Reddit was fined £14.5 million by the ICO for inadequate age assurance mechanisms and failing to conduct a DPIA, reflecting stricter enforcement under the Online Safety Act to protect children from harmful online content. The conversation also explores the broader challenges of implementing effective age verification without over-collecting data, the critical role of DPIAs in managing risks like those associated with AI tools, and the ongoing need for organizations to strengthen technical safeguards and proactive compliance measures.
[Music] Welcome to the Data Protection Made Easy Podcast. I'm joined by myself, Holly and Kane. This is season two, episode ten. I had a really good session. Kane, how did you find it? Yeah, it was a great session. I always love talking about the news. It tends to be my favourite session in the week, actually. And I think it was a great session. A lot of going on in the news. It was very samey stuff, unfortunately, but I think there were some really good pieces that we picked out on that discussion about. I think probably namely the prize draw going on with Reform UK. And their lack of transparency, seemingly. And also maybe their lack of lawful grounds of processing. A little bit of a discussion about that. And I thought it was really, really interesting session. What about you, Holly? I very much agree. I also enjoyed talking about the recent fun that Reddit was given. And the finds from Offcom for 4chan. I thought that was quite an interesting topic. Yeah, absolutely. It was a very interesting piece and pieces of news in this session. But we won't give too much away and we'll let you jump right on. Happy Friday, everybody. And good afternoon. Welcome to another episode of the day of protection made easy podcast. We've got a GDPR radio session this week. We'll be looking at some of the news that's been happening over the past couple of weeks. Because I think admittedly it's been a while since we've done a GDPR radio session. Maybe maybe like up three weeks or so. I know we've had a couple of guest podcasts of spattered in and stuff. Couple topical ones as well. So it's nice to go back and have a little look at the news. A little bit of housekeeping bits before we press on. Obviously you guys know these sessions are recorded. Our lovely assistant evil. Hopefully we put in the producing of his into the chat or sharing a screen which ever works best for her. Just letting you know that these sessions are recorded. And that you can exercise any of your eyes as a man. It's if necessary. Make sure obviously you can contact us guys through that. I'm not obviously also as an additional note. The AI chat box again just to reiterate we do not allow them in the session. So evil be going through and removing them when she sees them. But as I say if there's an option to turn those on beforehand turn us off. I should I say or to deactivate himself that would be greatly appreciated. But if not they will just be removed. But on that note. How has the week in the news been feel Holly anything that has caught your eye? Couple of interesting bits I think we were discussing the company's house. We were yeah we we had a look for other news didn't we? And I suppose before we start actually apologies. I hope hopefully some of you guys know Holly. I've been really I really introduced her very well so apologies on that end. But some people may have recognized Holly from from a couple earlier podcast last year. I think she didn't want to too didn't you have in that right? You were on I think consent or pay models and cookies. So if you haven't listened to those is some really good sessions. If you want to have a little scroll back and maybe have a listen to some of those. But as I say we're joined by Holly who used to be one of our data protectionist offices. She's now one of our account managers so hopefully some people may recognize her from that. I think we're going to customers in the chat maybe seeing a familiar face but yeah just joined by Holly today which is nice nice nice. I'm refreshing it's nice to get loads of different people in and on the podcast because I'm sure people are probably a little bit. Maybe border see my maybe not case case of it smiley than my foot maybe border see in the same face every week. It's nice to it's nice to come back on as well and keep in the loop day protection wise. Yeah it's it's good and so but I digress will get we'll get back into the company's house. But so I think we saw that they had some issues following a major security breach that it had where the details of I think they put in numbers to around. You know couple million directors that their details were effectively left you to a security sort of bug that led information on company's house related to these directors to be amended. Now I think in the main it was just a name that contact details the address so what the date itself wasn't particularly sensitive obviously the volume of it was obviously quite quite dramatic I'm just curious. Are your thoughts on on something like this obviously we've data being sort of left in in the public view I don't know if you have any sort of like particular comments on on on this piece of news. I don't know I think I think you had to have an account and access. So it's immediately like there's not it's not it's not really public you had to have a certain amount of access. Before you could change the information still not great but there was yeah there was something there but I think. It does like you said earlier when we were speaking about it does pose a risk say you know if the certain director of a company has certain political views or something and it is quite public. Yeah I mean I think there's a sort of a perspective to be taken from that regard and I think more in the sense of politics I mean it tends to be more I think in America where companies tend to align a little bit more with like. Yeah particular stances and policies that maybe treat that in different ways but you know you could you could find that if you are a director of a particular company could be a group of individuals if if we're looking for the perspective of people maybe they don't agree with the nature of your business. Having something like your you know your potentially where you reside if it is your home address on there maybe it's not we could be. The potential impact of that could be quite significant you know if it's something that may be quite contentious maybe there's a particular maybe X member of staff due to some some complications that have gone on there that may. May cause some significant impact I mean and I think what what goes to show to me and I think something that I try to stress a lot when we look at personal data breaches is. The nature of the data subjects I think on and the context around that can matter a lot more than the personal data involved so to speak I think you know I think people are very quick and and Riley so I think from that perspective to look straighter this is what data is involved this is what the risks of this day of being in the spaces but. The day of protection is so context heavy even even more so with with personal data breaches and depending on who you are in the relationship of of who this data is is going to. Obviously depends massively on the impact I mean I don't know how many people would be going on and and amending sort of company house records I don't know who would have the time to go do who we would want to but there may be people out there that would do that I mean you you made a quite quite important point of. The accuracy element of it a little bit early when we're talking for the new yeah I mean if somebody did have the time of day to go and do that it would affect they are accuracy and for positions of power such as you know company direct is in such as that I think the data accuracy principles is more affected. It hung around the five months this system for it was during the next day and it wasn't notified for about. Which is I think I think they say was a tax expert that identified initially so maybe the implication is that there's not really been much access or alteration it doesn't really. Necessarily stay if there was much alteration it may apparently so if they've identified that something that could have happened but maybe not have been the case they did happen. But it's things like I'm simply in the chat was saying that she managed to see the issues herself in October it was connecting to the incorrect company is interesting I think what what's interesting as I suppose how long it may be taken them to. To identify that and maybe potentially stands towards their possible sort of technical measures over sort of auditing and keeping these these systems up today and secure in terms of sort of like running regular patches and bug fixes and stuff but maybe it's difficult to do when the day is out there in in the day as it is you know from from websites but I think when. Something is as accessible as it is if you only need to just make an account to actually access it is a real strong emphasis on on technical measures from that perspective on my side. Yeah definitely and it is quite scary in a way because the process to sign up I think you have to give you a passport and things such as that if if something like that can go unnoticed for so long. What's to say that more data could you know yeah I mean it could have been a lot worse could have been much worse you know potentially gone for so long again because nothing really happened off the back of it but the long something is out there in the space obviously the longer. The longer it is and the higher the impact of the risk would occur so you know it kind of depends is it seems like off the back of it it's. Maybe not reduced to anything particularly significant but definitely could have been and I think it's always like a little bit of a warning line that regards to.
of make sure that we're consistently scanning for system errors like this. Because obviously I think we're in a position right now, especially in the news where a lot of the stuff that we're hearing about is in relation to issues with websites, on websites not having appropriate controls. I think there's going to be a couple of news pieces that we're talking about today that are all kind of relevant to those points in particular. And obviously that largely comes with things like the online safety act. And I think the care and the particular consideration of coming is giving these things. But it seems like there's a real desire more than ever for people to sort of have a parish around a website and have a view of if it is secure. And if you do have that appropriate sort of data protection by design and default approach, which I think is clear from this next piece. Now, I don't know if we spoke about this before. I can't remember. Memory fails me, but maybe I was off a couple of weeks ago. So it might have been discussed then. But we had the incident that obviously occurred with Reddit and the potential issues and scrutiny that they were receiving from the ICO. They've recently published a monetary penalty notice of 14.5 million against Reddit. So the ICO found that the social media company violated ICO 685 and the UKGP. No matter the breach occurred to fail an implement appropriate age, assurance, mechanisms and did not do a DPA to assess and mitigate the risks to children. Now, this is interesting. I'm sort of keen to get your thoughts on this, because I suppose we talk about or at least we talk about on on top of my and the the implications of the online safety act and appropriate controls in relation to what can be accessed. I'm keen to get your view on this case in particular. And what you think the impact of that is, because Reddit is an interesting site, isn't it? Yeah, it is. I don't know if it acts more of a chat forum or a social media platform, but I think that defining that is quite important. I think if it is more considered a forum, then the age controls should be more strict and maybe you should have to upload your ID for that, but as a social platform, maybe it should have strict controls on the explicit content that it puts out. I think that's what it is, isn't it? I think from what I can understand, I think from what I know about Reddit is predominantly, it does have the forums, the set, which is in a sense, is social mediano people are sort of sharing thoughts and providing advice. And I think the only other time I've ever used Reddit is I think I was like stuck on a game once. I think Reddit helped me. I've used it for that before, but I know there's also the other side of it where it can be used for things like the, but they're not safe for work. I think that's what they categorize it as. Yeah. Yeah. And then that can be a little bit more sensitive and particularly sort of like a little potentially a little bit more darker, which is where obviously the need for these appropriate controls is spanning from. And it's clear that obviously Reddit, which is a massive, massive company, a massive social media platform, trying to get to purposes, haven't taken the appropriate diligence. And the said that they've been in breach of agriculture, 6am, 35, obviously, eight linked children, six related awful basis, which is interesting. 35, but a lack of a DPI air now. I suppose from your perspective, maybe not as an account manager, but maybe just holistically with all the customers we speak to. Do you think there is a good appetite for businesses? Obviously, you don't really know businesses like Reddit for businesses in general for doing their protection impact assessment? Absolutely. I think it's huge, especially with the uptick of AI and specific, in specific. I get a load of customers come to me and say, we're starting to use a chat GPT co-pilot for these different purposes. What do we do? And they'll just say, do a DPI. And we have had some issues on employees uploading personal data to AI as well. And that, it just makes it so much more tricky, but yeah, DPI is becoming quite. It's a risk. I think for me, maybe it's something that I think a couple of years ago, when I've sort of looked at these things, I think some people were utilising DPI's in the wrong way. I think sometimes in some essence, they still are. I think you're right. I think AI is a big trigger for people doing more DPI's. I think sometimes maybe the folks on the DPI is on the wrong thing now. But seeing a complete lack of one is interesting. Yeah, concerning is right, I think. It is interesting, but obviously I think we are from our perspective. Obviously we see it from the perspective of our customers. But some big, sort of social media platforms, things with public access to information, things that are likely to be accessed by children. I'd find it very hard to believe that Reddit doesn't have some sort of data protection team, or someone sort of trying to stare that foundation. Maybe it's the suitability of the DPI itself, but I think from it said, "Oh, no, just did not conduct one." The full stop in terms of what the news says. So that's really interesting and a little bit of an oversight. I mean, I'm having a little bit of a significant in this case, and I think more so than ever, I think when we're working with people who are deploying websites that are likely to be accessible by children, I think you've kind of got to expect now that the off-comer are going to be ruined around. And there's maybe what people need to actually maybe get a little bit of a need to then go and maybe revisit that DPI or go and create one if you've realised that you don't have one and it's time to start looking at those things a little bit more proactively because I don't think it's going to, you know, I think it's already showed this year how much news we've sort of had on off-com and the appropriate measures for children. But I think it's only going to be more so. I think DPI is usually, I see this more often, just a tick-bock exercise for some people and it's not really done properly. And then if the risk is too high, there will still conduct a process and activity. I would have thought that that would have been the case here, but I just not having one at all is a bit. Yeah, it is strange. It's an interesting sort of landscape with the online safety act stuff. I think it's revealing a lot of data protection failings for a lot of bigger organisations. I do wonder because I know there is a, I think the key was is that there was, you had to verify your edge to get on the site. I think there wasn't, I think the thing was that there was an obvious work around, I believe. Yeah, I think it was just, are you over the age of like 13 or something? Yes, then you're in. I think it was something similar to that. It just wasn't good enough. Yeah, I mean, well, how far do you go, I guess? How far do you go based on what your platform is? I suppose some platforms are bound to be more sensitive than others. And we know that if content is harmful to children, that we need to prove their agents in kind of way. I know that there was the talks around the sort of facial recognition software and the age-guessing sort of thing. You take the picture, it kind of has a guess, a flying guess at your age, how it works out. Reliable. I mean, yeah, I mean, how you even work out the accuracy of that. I'm not completely certain. I don't, maybe a little bit offensive slightly as well, you know, if it's on the adverse, if I'm 14, as tell me that dialogue of age might be a bit offended, but I would be really intrigued to how they have to turn that, you know, what makes an individual look older than they are, you know, unless it's really obvious, I think it's very hard to tell his bound to be inaccurate, but ticking a box is obviously not enough. It's not, it's not deal jam, I'm not sure if that's what they do, but I will take you word for it because I don't know. I think it was something similar to that, like it was just a statement and then you were in. I mean, I remember being a child and seeing stuff like that come up on websites and just, yes, I'm in a certain age. Definitely used to be like that, didn't it? Yeah. Obviously, I'm in a don't now, so I guess I don't really see that stuff as often or if I do obviously maybe come through the process, I'll think about this process a lot more, but I do remember you outright, a lot of them was like, I confirmed that I am of ex-age, but I think that's probably more around the sense of like liability of just making sure that the own risk is then basically on the on the child for lying, I guess, but now with the online safety out there's gotta be a lot more care towards the way that we're treating things that are accessible by children and to find line, I think, between over collection of data and actual appropriate identification of age because you know, you want to do like a path part or something like that, that comes with its own risks, definitely, undoubtedly so, right, because then the impact of a breach may be more significant considering that there are also children as well, you know? Yeah, absolutely. You know, 14-year-old could have bloated their passport to Reddit then and then not only is it, you know, the data of, you know, a 14-year-old that's been breached if that should happen, but you know, they're at risk, I identify, identity fraud, it could just be too much, but I mean, what's the alternative really? No, I mean, I suppose you're right, but I guess Reddit does touch on some particularly dark elements, also. You know, I'm glad to see that we're still utilising enforcement action, good to see the I show for some finds in
in a certain direction, it's good to see, hoping to see a little bit more of it. It's gonna be an interesting year for enforcement for the ICO. And I think maybe the focus on children's data and things being accessible to children is, is a necessary step and that. I think I'm hoping that people will see cases like this and then start to take this thing a little bit more seriously, but as I think we, especially me and Kate have discussed because I know Kate is very particularly sort of like passionate about the topic of children's data, is around like how do we then educate and then form children to make the right decisions because we can do as much as we can, but it's clear that there are tools that kind of back end a lot of solutions, with things like, I think VPNs probably being the biggest sort of work around at the moment, isn't it, in terms of people sort of overlapping the security controls because of the VPN, I'm not 100% sure how it does sort of skip that security element on make it easier. I don't know how that would work in the general thing of it, but I think it skips the need of it. - I'm gonna have those age limits. - Oh, I see. - Like alternative site for that country. So you say your VPN was set to like Albania and they didn't have the equivalent of an online safety act to a, you know, - Oh, okay, understand. And then the children can just bypass and go to the sites directly without having to upload their identifications. - Let's see, interesting, okay. I think a lot of a similar case, as well in relation to age verification violations, as well, which we weren't touch upon. And as much detail, it's probably a very similar nature. So, off-com, this time, I'd find an online discussion board known as Faw Chan, 450,000 for failing to implement age verification checks, which is obviously required in the online safety act to prevent children from accessing pornography, which, so, you know, evidently, this discussion board is something that is obviously explicit in nature. Again, I can't say I've heard of it before. Most of the things that end up on these news pieces now about discussion boards and forums and stuff, maybe feel very old because I don't, I don't really know what any of these things are. - Yeah, I never used, never heard of Faw Chan or anything like that. - Yeah, I don't know. I guess the implication is that issues for pornography, so maybe it's a good thing that we're not saying. - Yeah, I thought that we don't remember it. - It's the controversial conversation. And, you know, like, how red it has a dark side. I think that is just Faw Chan. - Oh, okay. And that is an essence what it is. - Yeah. - Yeah, okay. Interesting. I mean, they've been told that they need to implement effective age assurances immediately effectively, so they have to the second of April's in it out of a lot of time. Our face apparently daily penalties, which is very interesting. So basically incurred penalty for every day, they are over the mark, which is, you know, really gonna force them to get these, to get these in place or effectively shut it down. And they also find Faw Chan in an additional 50,000, are failing to assess the risk of a legal material appearing on this platform. And then on top of that, another 20,000 for failing out is term to service how it protects people from criminal content. So seems like there's evidently some very, very, very risky and, you know, sort of unsafe content out there. - Yeah. - How far have you gone? - Yeah. - I mean, not suitable for children. - Oh, okay. Yeah, I mean, it is interesting. I don't want to do on it too long, because I think we spend, you know, a good bit of time looking at the age verification stuff. But it seems like there are obviously still some sites that are kind of, you know, ignoring some of these obligations. And I suppose, because it's so, I don't have to say easy, but I suppose because anyone can settle like something like this, of this van, if you're able to build it. I guess there's probably gonna be a lot of, and it's gonna be a hard work, a hard job for off-com to kind of regulate all of these different websites, because how easy is it for them to just pop up again, you know, under a different name, under a different sort of location. - Leading by example, with the huge reddit find, I think that's the only way to kind of whip them in shape, you know? - Yeah, I mean, it seems like off-com and I'm the eye show working quite diligently on it. And it seems to be a particular target in a similar vein in the marketing stuff, and the pack of breaches was, you know, again, another focus on website related stuff. So it's quite interesting, really. How the owner seems to be on websites and things that are on websites. I think the biggest piece of news, or the most, I think the most interesting piece of news, was a piece of news around the reform pie. So reform UK, I'm sure obviously you all know as a political party. I've effectively been offering or discussing, I'm not sure if it's actually something that they're doing, implementing a rise draw, lottery draw to pay an individual's energy bill. Now that face value, you may not, I suppose, think too much about the issue with it potentially. So Nigel Farad wants to do this to promote party policy and requires the entrance to disclose their names, contact details, and along with their past voting habits and future voting intentions. So I suppose before we get into the potential problematic in nature of it, as we know, political details or details related to your political opinions is special category data. And it seems that in this statement, we've had one of the, I believe his name is Mariano, who's a legal and policy officer at Open Rights Group, said that reform are asking the public to handle a sensitive data about their voting habits, without being transparent about how it will be used, which is a clear breach of the transparency obligation under the UK data protection law, because nothing in their privacy policy suggests that they are not acting unlawfully in many other ways. So that is a quote from that individual. So it's, there's a few things, things loaded. The first thing is one, it's evidently not in the privacy in the way. I mean, you went and had a look at that in your whole again. -Much, and there was a section specifically for, like prize draws, and in that section, it just said that they're gonna collect name and contact details and additional information for administrating purposes. Now, the biggest thing I had with that is, what does your past voting habits or future intentions have for admin purposes for processing? -Definitely. -I just don't think it falls under the scope and I think it's just-- -Well, what's the need to collect it? Because, you know, when we're talking, I was like, I wonder if it's like a demographics thing. I wonder if we'll collect a gauge of demographics, and then maybe use that to identify, okay, this person for with labor, prize, person for, services or green, and this is, you know, maybe where we may have some potential. New voters, who may come there, they're not really sure, but it's clear that they're not trying to collect at least from what we can see here. -Yes, there's no information saying it's not really true. -Exactly. There's a real lack of information that is out there in terms of what they're gonna do with it, which is, of course, a problem in itself. Now, what I could only understand the implication of being of it is that they're trying to identify who is voting for reform. And I think there's been discussions in that it is trying to persuade individuals to vote for reform. And I think those discussions, whether it was a potential breach of sort of like political law in terms of trying to-- -Yes, something along those lines, and trying to coerce individuals to want to vote to reform because we see the nature of sort of cost of living at the moment. I'm sure individuals-- -Of course, yeah. And I appreciate it for that sentiment. I think whilst they've shown that it's not potentially a breach of that infringement in our regard in the literature, law or law, I think the concern around special category data is and the lack of transparency. It's a real key importance, really. -Absolutely. It is concerning. Why are they collecting it at the day out? Is it just for them to say, oh, they vote reform in the past? Maybe they'll be injured like they'll be a winner? -Or I think I had on that section of the privacy policy, there was nothing to do with an article nine basis either. -Well, I wonder what the article nine basis-- -The article two. -B, to collect this information. Article six, I'm the article nine. And I'd be in tree to see how they would justify it. It's for me, I'd be only sort of possible basis, I see, is explicit. However, that in itself provides so many open questions. There is the element of the fact that it is a prize draw. So giving consents with prize draw in itself could never be freely given. Because if I'm having to give my special category data because of the incentive of a prize, sort of dangling a carrot, then of course, that's not going to be freely given. It's clearly not informed either. -It's not informed because there's no information on why they're going to be using that data or the reason they're collecting it, they're not transparent enough. -Exactly. And James is absolutely right in the chat, sort of alluding to my point in a little bit, is that linking it to the prize draw itself is consent would never apply. Don't give his special category data. Don't be part of the draw. And I suppose that in itself is-- there's probably a lot of individuals who are going to apply for the draw anyway, because they are kind of putting this sort of-- kind of rocking a hard place where you sort of give up the special category data.
Or you receive a potential benefit that is obviously of great value to some individuals. And obviously it's easy to get sort of caught up in the nature of that. But I think it's clear that I think there are sort of general sort of grounds of processing concerns for me because I don't as far as I'm aware, or just could think of maybe off the top, my head, think of another article nine condition that they could rely on. I don't think there's any way that they'll. Do you think they're actually getting explicit consent in that nature as well? I've been intrigued to see the actual maybe I should have tried to answer. I don't know how you would. I just knew that they'd probably say consent wouldn't they probably would say it's consent. But we don't know and that's the problem. And clearly an issue. I think there's an element of maybe transparency obligations being neglected in some cases slightly. And so in terms of informing individuals about how their data is used in some circumstances because I seem to be seeing this more and more with like real lackluster privacy information, especially if we are looking in the realm of consent, it is more important than ever to make sure that you're being as transparent as possible because if not, you are not me in those conditions for a consent effect of what? No, definitely. And I think in this case as well, like whilst they're not in breach of, well they might not be in breach of any coercion or electoral laws. I think they are in breach of, you know, the GDPR principles, the data minimisation, transparency, accountability. I think it's just, it's not a thorough process and it's not reflected in the privacy notice but the doing with that information. Yeah, I mean, it is, you know, but if forcing an individual to tax access as well, the ICO frame is a service down there, but even they are quite clear on not being able to me as conditions. Maybe we should have had a poker run and tried to enter the draw because I am really keen now to understand how long it works. Yeah. Well, I probably won't go the way with, with completing it because I don't want to, I don't really want to get that kind of information. But still, I would be keen to see how they would do that and it's a, I don't think I've ever seen that political part utilised that before. I can't imagine it's a very, it seems like a little bit of a frowned upon. Yeah, I think. Potentially. But personally, it's just a little bit too much of a grey area. Yeah, no, definitely. And then obviously it seems like there's some data protection concerns in that regard for them and I think as people start to treat their privacy a little bit more seriously. These things will also be a factor in, and you know, considering these kind of things. But definitely something that people should be aware of, I think, obviously I don't know how specific I think maybe is something that they might just end up scrapping or might be something that they end up revisiting. But that seems like where it is at the current point in time. So, the sort of led me on that, I suppose, I was sort of thinking, I don't really like talk about the collection of political opinions very often. We don't see it very often. No, I suppose not in the sectors that we work in. I don't know where it would be relevant, I suppose. But I just, unless you are like a political party in itself, I'll sort of like a government body. I don't know where that would ever be relevant. But it made me think about the potential risks actually in terms of personal data breaches on misuse of data. And it made me, obviously, I've got a special catch, that's a great day. So it's always going to be significant. But I definitely think now so more than ever with how important politics is having grained in people's life and their decision-making. It can have a real detriment. I mean, I think we saw off the back of some elements in terms of what's been on the news, how people react to certain sort of things that have been happening in the world of politics and potentially information getting out in terms of how you vote and how you're due to vote could definitely lead to some potential impact in terms of harm, whether that's purely just distress or maybe even something more significant than that in terms of actual harm to the individual. I definitely agree. I think if that type of information was breached, in this day and age where politics is so important and I think tensions are really high at the minute all across the UK with different parties anyway. If that information was breached, it could pose a risk. No, definitely. It's just an interesting sort of conversation point, I suppose. Maybe we should start branching out into political parties. Maybe we should. Maybe we should. It's probably an interesting area of collection of data. I imagine they probably collect quite a lot of it. And potentially, if the same to this is the case, then she's quite sensitive data as well. Constantly article nine. So there must be some sort of condition that works around the kind of process in that they're doing. I know that reform has sort of contested their position from the perspective that they think the competition is legal, but I think that's from the respect to electoral law and they don't think they've really touched much under the debt protection considerations side of things. It's ultimately very important and I think it is something that needs to be treated, but there's the same kind of seriousness, but I'd be intrigued to see what happens in relation to that because it seems like from a transparency perspective, they are in breach of the principles and I would say potentially from an article six, there may be an article seven percent as well. If it comes in, is the basis they've chosen to identify? Yes. I very much agree. I'm glad. I'm very much glad. So we've got, I suppose, maybe enough time for one more piece of a news unless there's anything else particularly pertaining that you want to bring up. Now I think I'm happy to talk about the police. The police, I mean, not the band. No, not the band. Maybe that would have been a more interesting conversation. But as we've already kind of known about the police recently in the news is that they're looking to deploy facial recognition technology. And it's actually really sort of like a sharp air of news because I don't think it really says too much. I do think it is important to talk about this and this topic in general is effectively that something was written recently just basically to explain why data protection is so important for police when using facial recognition technology. So effectively, they're talking about how the police force is must ensure that they do not jeopardize civil liberties and that the primary concern is around introducing proper safeguards in place. So the issue is looking to produce a report later this year to share its findings across the forces to ensure that this successful implementation of the technology is still strong on governance, which I think is a positive thing in the main that they're keeping a close eye on it because I think it's going to be a really interesting topic in the law. And a very difficult one to ensure that it's done in a particularly compliant manner. There's going to have to be a lot of detail that is taken and considered for this really to consider it in my eyes, compliant. I think there's a lot of open questions, a lot of question marks. I think there being left in relation to facial recognition in particular. And the implication, when we think about the actual use of the AI, automated means significant legal effects definitely. If we think about the possible implications of being potentially accrued for crimes or prosecuted for crimes, not that they necessarily get all prosecuted but they may get potentially brought in for discussions may be arrested. But it leaded me to sort of a brief thought that I had that has quite a, I don't even know how relevant of a link but I wanted to make the link when I initially thought of it. Recently in the world of sort of football and namely, name leaps out of Premier League football. Is there looking to utilize more and more automated means of technology in order to basically decisions on on games of football, including when off sides are, when the corners are even bowels off sides are, tends to already all be automated. Now, and I think what that's led to and people may disagree and people also may not care that I'm talking about football. So I'm trying to be very quick in my statement. Is that I believed you to the overreliance on technology is led to certain officials potentially not being as, I suppose, consider it as before and potentially maybe a little bit overreliant on some of the technology. And the point I raised in this is that I wouldn't want it to be something that I feel that UK police forces have become overreliant on in relation to the processing that they do where it becomes a mass being that is necessary and evident to the role. If it can supplement it and support it in a real significant way, then great, but I think they need to be really, really sure. I definitely agree. I think I read something that the Essex police force implemented this facial recognition technology and then a couple of tests were done and loads and loads of gaps were found. I don't know if any arrests were made as a result of this technology, but I do know that they
they got to tell enough basically because of their rush to implement it. And it is a bit scary that they're so ready to put these things in place without the appropriate testing. I mean, the risks are, I don't know, false arrests. Yeah, of course. I mean, that's the biggest one, isn't it? Ah, I'm then good at the minute before. They're in such a rush to put this in place. I think we need to take it quite slow. Yeah, I mean, if you think about the significant impact on the potential backlash of an inappropriate arrest due to fitting a profile due to recognition, I mean, individuals do look similar to one another, you know, how they will be able to identify and distinguish with very key and specific accuracy must be very, very hard. I'm not sure of how mature or how intelligent this AI is in terms of being an opto identified. I'd be lying if I said I understood fully how that would work. But I find it in my head really, really hard to believe that facial recognition to that degree for the purpose of potentially identifying perpetrators is going to ever be something that is like more so than like 90% right half of the time. It's, it's got to be gaps. That your point that it has to be supplementary. Super important. I think they've got to have a strict established procedures that say, okay, maybe we use this facial recognition technology just on the first instance, then it is all human afterwards. I just don't understand how they're going to be able to do it, obviously. It's got to be sort of meaning for human interaction. Oh, yeah. So so far. And I'd be really, really, I'm really sure you'd see the idea of report when they do it. And I think the fact that the idea of show has already got the rise on it probably means that they're working with the police in some regard, potentially. Does that build that up? I think they're looking at sort of testing the systems to look at how discriminatory its outcomes are and looking at whether it can comply with the principles. I think it's going to be a hard task, but potentially it's something that's feasible, namely if they are working with the ICO. They know the ICO is watching on it. So at least to me, I feel a little bit more comfortable in the fact that people will be more diligent naturally because the ICO is being clear that they're taking an approach on it. As Holly's rightly said, obviously, yes, that police have already got a little bit of a slap on the wrist in that regard in terms of being too quick to implement. So I'm hoping it means that this care being taken, but obviously with some of the news that we get occasionally in relation to police forces and use of this technology, sometimes it's the perspective of, you know, they'll tell the great to good. And I don't necessarily always know how effective lives. The standard, all, you know, national security and things such as that. But I think in this case of mass surveillance, the ICO needs to have eyes on it before anything gets implemented. That's that's how I feel anyway. I think it's just it's too big of a thing. And I think on an organizational level, these forces are going to really struggle to conduct the proper risk assessment or make sure the right policies and procedures in place that actually use this technology as it should be used. Well, this is where like keycombs and I'm doing that really good deep. I like I spoke about the key to so many good processes and things and then film secure and what you do really come off the back of the super solid DPA that you have full faith in. And whilst that takes time and it is a difficult task, the benefits of it, it's so significant, so significant. But some of the minute will definitely be watching very closely among our sort of time within the year. But I think we're just about at that time. So we hope you all enjoyed the session this week. Thank you very much Holly for joining us of course. I'm not sure what we're talking about next week actually, but I think it will be back to me and Kate. I feel like it's been a while so it'd be nice for me and Kate to get back into the event and talk about some bits. But we hope you enjoyed. Wish you all a happy Friday and our B.E. Of course again, those who are celebrating. Have a great weekend. (gentle music)
Podcast Summary
Key Points:
Companies House experienced a security breach allowing unauthorized changes to director details, highlighting risks to data accuracy and the importance of context in assessing breach impact.
Reddit received a £14.5 million ICO fine for failing to implement proper age verification and not conducting a Data Protection Impact Assessment (DPIA), underscoring heightened scrutiny under the Online Safety Act.
The discussion emphasizes the growing necessity for robust DPIAs, especially with AI adoption, and the challenge of balancing effective age assurance with data minimization for protecting children online.
Summary:
The podcast episode covers recent data protection news, focusing on two main incidents. First, a security breach at Companies House allowed unauthorized alterations to director information, raising concerns about data accuracy and the contextual risks of breaches, even with less sensitive data. 5 million by the ICO for inadequate age assurance mechanisms and failing to conduct a DPIA, reflecting stricter enforcement under the Online Safety Act to protect children from harmful online content.
The conversation also explores the broader challenges of implementing effective age verification without over-collecting data, the critical role of DPIAs in managing risks like those associated with AI tools, and the ongoing need for organizations to strengthen technical safeguards and proactive compliance measures.
FAQs
The episode discussed recent data protection news, including a security breach at Companies House and a fine against Reddit for failing to protect children's data.
Companies House had a security breach where details of around two million directors were exposed due to a bug, allowing unauthorized changes to names, contact details, and addresses.
Reddit was fined £14.5 million for violating UK GDPR by failing to implement appropriate age assurance mechanisms and not conducting a Data Protection Impact Assessment (DPIA) to protect children.
A DPIA helps assess and mitigate risks to personal data, especially for high-risk activities like AI usage or processing children's data, ensuring compliance with data protection laws.
The Online Safety Act emphasizes the need for websites to have appropriate controls, such as age verification, to protect children from harmful content, aligning with data protection principles.
Challenges include balancing over-collection of data with accurate age identification, as simple tick-box methods are insufficient, while methods like passport uploads pose privacy risks.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.