Showing posts with label collecting information. Show all posts
Showing posts with label collecting information. Show all posts

Sunday, 15 May 2016

Back to Basics - Collection Notices

One of the keys to collecting information in line with the Data Protection Act is to ensure that you are telling the person providing the information a few key things. Collection notices aren't properly understood and are sometimes overly complicated.

So here are the basics, a collection notice must tell the person providing their information:
(a) who the organisation collecting the information is
(b) what the information provided will be used for
(c) how the information will be stored and for how long
(d) whether the information will be shared with another organisation or organisations

The wording does not have to be formal, you can just write in plain english the information required.

Collection notices should be provided on both paper and electronic forms. Frequently individuals do not remmebr signing up for something or when they gave information so to ensure that you stay off the ICO's naughty step you should record when the information was collected and this should be retained for the life of your relationship with the individual. Additionally, if it is a paper form you either need to hold the hard copy or have a scanned copy for your records. This will all help with proving that you are protecting the individuals privacy should you need to.

Remember that regardless of whether you are registered with the ICO you have to comply with the Data Protection Act so any forms that you use for the collection of information MUST have a data collection notice on it. Without a valid collection notice you are breaking the law! 

Sunday, 14 June 2015

Paper Forms - Do you have the basics in place?

It's been a busy week and whilst I have been out and about I have needed to complete some forms. I completed three different forms and not one of them met the requirements of the Data Protection Act with regard to collection notices.
Most of the forms were collecting basic details -  the usual - name, address, DOB. The forms were being used by a health professional, charity and college.

So what did I learn this week. Ultimately most of the organisations who collected information about me did not even meet the basic requirements of a collection notice on the form. A collection notice tells the person providing the information what their information will be used for, how it will be stored and for how long and if it is going to be shared with anyone. I have asked each of the organisations for whom I have completed a form what they intend to use my information for. It is worrying that if an organisation cannot even collect the information properly, how are they storing it and who has access to it. Given the significant rise in identify theft, I have provided enough information for this to happen.

Remember that regardless of whether you are registered with the ICO you have to comply with the Data Protection Act so any forms that you use for the collection of information MUST have a data collection notice on it. Without a valid collection notice you are breaking the law!

If you need help to produce a collection notice or require a review of your forms, please contact me.


Monday, 25 May 2015

How big is yours?

Your mailing list I mean.....

There is lots of talk of how big your mailing list is and this can be a wonderful addition to your business but only if you have collected the information in the right way. I have been talking to a couple of companies recently who are growing their mailing list by adding people to it, without asking their permission.

Generally they are people who have done business with the company before so have some history with them but the company didn't ask the individual if they wanted to receive further information. This usually boils down to a couple of reasons; the company thinks its OK to add people, they think the person might say no but they want the numbers on the list to increase or they didn't understand the benefits of asking the individual.

I would always advocate asking someone if they want to receive further information from you. Firstly it opens the discussion as to how staying in touch can help them keep informed of new events, etc. It also tells them that you will be adding them to a list and they can expect an email at some point in the future. Gives them something to look forward to! Also asking whether you can stay in touch indicates some thought for the persons privacy.

Finally it is always useful to show whether you intend to share the personal information with other companies, I always look to see, when I am providing my information, who it is going to be shared with. Lots of companies now state that they will not sell or share your information with other companies. (Good for them)


Wednesday, 13 May 2015

Sending emails - Will the ICO be sending you to the naughty step?

On one of the forums that I belong to, a question was recently asked about what is considered a spamming email? The responses were very interesting.There was a lot of discussion about whether you can just add people to your mailing list because they gave you their business card. This really split people into two groups along the lines of "they wouldn't have given you their business card if they didn't want you to stay in touch" and "Just because I gave someone my business card, I wouldn't then expect to be out on their mailing list".

So here is the boring legal bit. Under the PECR (Privacy and Electronic Communications Regulations) people must give permission for you to add them to your mailing list, unless they have bought from you previously and the product you are promoting is something similar. If you don't do this and someone complains to the ICO, they could review your data protection practices and send you to the naughty step.

So how do you end up with spam emails? Well, someone you have given permission to have your email address has sold on their list. Yes they should have asked you first but many websites are unclear as to what they are going to do with your information and some companies have no idea that they should be getting your permission first. Many companies are now aware that we hate having our information sold to others and will make a declaration on their website that they never sell or pass on your information. My advice is always be aware when you are providing your email address what it is going to be used for and if it is used for anything else, either unsubscribe or make contact to correct their information.

So back to the business card discussion. Unless at the time you handed over your business card they asked whether you wanted to be on their list (yeah right!) and they noted your permission down, then they shouldn't have added you. More interesting is that the majority of people on the forum said they would unsubscribe immediately if someone did this. Would you?




Saturday, 31 January 2015

Is your information safe with car dealerships?

Over the last 8 months I have been fortunate(!) enough to visit three car dealerships, each representing a different marque of vehicle. None have handled my information correctly so chances are they are not handling yours correctly either.

I visited dealership A in April 2014, dealership B in June 2014 and Dealership C in October 2014. Here's the run down of errors made by the dealerships

Dealership A was not registered with the ICO when I visited. They subsequently became registered in June 2014. 

Dealerships A and B have notified me that the MOT is due on the respective vehicle. Both dealerships got the date wrong. Dealership A is out by 6 months and Dealership B is out by 3 months. Given the MOT information can be obtained from the DVLA website they should be keeping that information up to date as required by the DPA. Of more interest is where they got the MOT information from as neither dealership asked me and I have been MOT'ing my car at a local garage rather than the dealership so neither had any MOT records for my vehicle.

Dealership A has been using my email address for publicity purposes without actually seeking my permission to do so.

Dealership B made marketing calls to me without asking my specific permission for this to take place.

Dealership C has been sending me marketing texts again without seeking my permission to include me on their mailing list and the format of the texts does not meet the requirements of the DPA.

Dealership C managed to lose my bank account details, they know not where. Really unimpressed.

My thoughts are that none of the dealerships I have dealt with have a clue how to comply with the requirements of the DPA in even the most basic way. None of the dealerships sought my information in a way that they could use is on an on-going basis, yet chose to do so anyway. As for contacting me about the MOT, that is just sloppy record keeping on their part.

I have contacted all the dealerships, so far only one has replied and their response was that they were fully accredited by the UK distributor of the car make and their processes regularly reviewed as part of the accreditation process. Surely this makes matters worse, that a car manufacturer is justifying the poor information security practices of its dealerships. I would be interested to know if I am alone in this experience so would love to know what your observations are.

Monday, 5 May 2014

How to collect personal information

When you collect personal information, whether it is about staff, customers, volunteers, or potential customers you must tell them how the information will be used and give them (in most cases) the opportunity to opt out.

The easiest way to do this is to put a "disclaimer" on the bottom of any forms.You need to be clear about the wording as this indicates what you plan to use the information for. You also need to be consistent with any opt in or opt out boxes.

If you are collecting information over the phone you need to still ask permission and when adding the information to your database, you should show the date and method of agreement. This is so that in future, if someone asks where you got their information, you have a record of it.

If you need help with the wording for a disclaimer, please contact me at Lesley@audit-and-risk.co.uk or  07828 124 588.