Showing posts with label email. Show all posts
Showing posts with label email. Show all posts

Sunday, 6 March 2016

Put on your dancing shoes - or not!

I have been receiving emails about dance classes for the last few months, I don't remember signing up for them and anyone who knows me will testify to the fact that I have no sense of rhythm at all.

Anyway, somehow I have been added to this mailing list for dance classes. I started receiving emails about three months ago and on average I get three a week. On occasion I have had two a day. There is no method to unsubscribe from the emails. Having got bored with receiving the emails I decided to respond to an email by asking to be removed from the mailing list. I did this on two occasions a week apart. I didn't receive a reply. The other day another email pinged into my email inbox and I decided I needed to take direct action so I rang the telephone number shown. It went to an answerphone giving me details of the classes available (Was there no escape?).

I decided I would call back again later. Just after I put the phone down, a text came in - guess what - it was a text to tell me about dance classes from the number I had just called. I was furious. I rang the number again, this time it was answered. I explained that I was very angry that I was receiving these emails and to receive a text was just too much - I had not given her permission to send me marketing by text message. The response - "Well people call me all the time wanting to know the times of dance classes so I don't answer the phone and send them a text" - really, you don't think that sending emails and the answer phone message giving information about dance classes is enough, you decide to send spam texts as well. "Nobody else has complained" (that old chestnut).

I asked about the previous emails asking to be unsubscribed and she told me she hadn't received them. I asked her to remove me from her mailing list, so I gave her my email address and she searched, only to tell me it wasn't there. I said it must be, you are sending me three emails a week on average. "Oh no that isn't possible as that would mean you were on three lists". She rechecks and finds I am on her database and on three lists (big surprise!). She said she had been hacked about a month ago and the hacker must have put me on the lists (so a hacker breaks into her email account and adds my name to three of her mailing lists so she can send me emails about dance classes, what a helpful hacker!). She tells me she cannot delete me from her database, "it won't let me". I reinforce the fact I wish to be removed from the mailing lists and how she does it is not my problem, I say goodbye and hang up. A little while later another email comes in from her to tell me she has removed me from her mailing lists but she had to remove 10 other people to be able to do it.

What did I learn?
- the dance class provider is not registered with the ICO - potentially a £5k fine and criminal record from not being registered.
- the emails she is sending breach PECR (Privacy and Electronic Communication Regulations) by not having a means to easily unsubscribe.
- Failing to remove me from her mailing list on the two previous occasions is another PECR breach.
- Sending me an unsolicited marketing text is a data protection breach - The ICO has recently fined a company £200k for unsolicited marketing texts.
- the most important thing to her was using the personal information she had gathered to further the spread of her message and the need for security and professionalism that comes from having a client list was lost on her.

If I was advising her, what should she be doing?
- Register with the ICO - a £35 annual fee
- Use a proper mailing package such as mailchimp, madmimi, constant contact etc so that she can properly manage her mailing list and those people who are desperate to unsubscribe can do so without the hassle I had.
- a proper mailing package would also be less likely to be hacked, providing she has a decent security password.
- Stop sending texts to people automatically, she is potentially raising the risk of the ICO investigating her. To be able to send marketing texts you have to have the specific permission of the individual.
- Think about the security of the information she is holding. Would she be happy with her personal information being dealt with in this way?

This is the worst case of failing to find out the requirements for running a business with a marketing list that I have come across in a while, that is unless you know better. Let me know.

Sunday, 28 February 2016

Bring your own device - and don’t lose data



Working from home and being able to take work out of the office makes working life easier but can be a nightmare for data privacy. With an estimated 56 per cent of employees reporting that they either very frequently or frequently stored sensitive data on their laptops, smartphones, tablets, and other mobile devices, the chances of confidential information getting lost or into the wrong hands are very high. 

Bring-Your-Own-Device (BYOD) is part of the modern workplace. It’s becoming more and more normal for business information to be stored in or accessed by devices that are not fully controlled by IT administrators, and the possibility of data breaches caused by personal devices that aren’t properly protected is also on the rise. 

Protecting business information on mobile devices can be as simple as encrypting files and/or password protecting the device - it won’t stop them being lost but IT admin will be able to selectively remove sensitive encrypted data and the chances of someone using stolen information maliciously are much smaller if it’s not possible to get straight into any files that may be sensitive. The issue is clouded when the device actually belongs to the employee and not the business, however.

Most businesses think nothing of allowing employees to use their own devices to access email, office calendars and contacts, and a strong BYOD policy is vital if company information is accessible on the go, via personal devices. 

Which devices are allowed?
It’s up to you to set the boundaries and specify what’s acceptable. If you only want to support employees’ personal Android devices and not iPhones or iPads, or vice versa, make that policy and stick to it. 

Enforce strict security rules
People don’t like having complicated passwords and lock screens - they get in the way of fast access to their devices and longer, more effective passwords are also easier to forget. If they are using their own mobile devices for work however, you can’t afford to leave them on a swipe and go setting. If your staff members want to be able to use their own gadgets for work too, they will just have to accept that they need to use a complex password to access them.

Banning apps
This also applies to corporate devices - social media browsing apps, email applications and VPNs or other remote-access software need careful consideration when you’re formulating a data protection policy. Although the devices are people’s own, they will have to consider business needs if they want the convenience of using them for work, and that includes not using apps or settings that could potentially compromise data security.

Businesses also need to consider what could happen if an employee leaves the company - you will have to have an agreed policy in place allowing you to remove any access tokens, e-mail, data and other access permissions.

Does your organisation have a BYOD policy? Do you have permission from your employees to delete information from their personal devices remotely when they leave, or if it’s lost/stolen? What safeguards are in place to ensure that staff don’t store sensitive information remotely? If you need advice on setting BYOD policies that keep your sensitive data safe, contact me and I will be delighted to provide you with guidance and advice.


Sunday, 7 February 2016

What's your score out of ten?

The ICO have recently issued an enforcement notice to the Alzheimers Society for various breaches of the Data Protection Act. There are 10 issues which the Alzheimers Society has six months to remedy. Although these need to be actioned by the Alzheimers Society, they apply to all businesses processing personal information. So here is the test, how many are you already doing?

1. Information is not kept for longer than necessary. Do you have a process in place to identify information which is no longer necessary and can be destroyed? Do you have a retention policy and a secure method of destroying all information that is no longer required?

2. There is mandatory data protection training for staff (and volunteers) who have access to personal information and refresher training at least every two years.

3. The training that is undertaken is monitored and recorded. You should be able to identify the staff who have attended and what the training course covered.

4. Policies and procedures relating to data protection and information governance are brought to the attention of staff (and volunteers) who have access to personal information. Do you have comprehensive data protection policies and procedures and can you demonstrate that they have been effectively communicated to all those staff (and volunteers) who have access to personal information?

5. Portable and mobile devices including laptops, mobile phones, memory cards and other portable media used to transmit and store personal data, the loss of which could cause damage or distress to individuals are all encrypted using encryption software which meets the current standard or equivalent.

6. Secure email accounts are provided for all staff (and volunteers) who use email to transmit personal information. This means a business account is available for all staff (and volunteers) and they are not using their personal email accounts for business purposes.

7. Secure storage is available for staff (and volunteers) who need to hold hard copy records which contain personal information. Is there lockable filing space for hard copy records?

8. Penetration testing is undertaken on the website on a regular basis and any weaknesses highlighted are remedied.

9. Appropriate security is implemented to protect information from being disclosed to those who do not need to have access to it, this includes to staff members, contractors, visitors and volunteers. This includes passwords, lockable cabinets, encryption, etc.

10.Where processing of personal information is carried out your behalf, for example, by a subcontractor, (IT support, HR, payroll etc) you must have a written contract in place which clearly states that the subcontractor will take steps to protect the information from accidental loss, damage or destruction. The contract should also cover the role of the subcontractor, what they can do with the information, what happens when the information is no longer required and that they will only act on your instructions. You need to make sure that any contract you enter into clearly states the responsibility for data protection.

So what's your score? How many of the above do you need to action to protect the personal information you hold and your company's reputation?

Monday, 18 January 2016

Did you attend a training course? Whoopee, lets share your details!

I have been on a couple of business training courses over the last week. Both of them were signed up to online and neither told me what they would do with my information, so that's the first mistake!

When I got to the training courses, both provided an attendee list which showed name, business name and a brief outline of what the business does.

A few days later I received an email from the training company asking if they can share my contact details with the other attendees. If I do not wish to share my information I have 24 hours to send an email opting out. Mistakes 2 and 3.

The email requesting that I share my contact details does not tell me which contact details they are planning to share. They may have my postal address but definitely have my email address and mobile number as a minimum so are they planning on sharing all my contact details or just some of them and if so which ones?

Also by requesting that you respond by opting out, they run the risk of sharing someone's contact details who may not have had time to review their emails and respond within the timescale laid down but who doesn't want to share their information. They should have asked people to opt in.

So how could this have been done more effectively?
1 - When they collected the information, they should have said how they are going to hold that information and for how long.
2 - Will I be on a mailing list?
3 - Stating that it will be on an Attendee list.
4 - What information they plan to share with other delegates and seeking permission to do so.
All of this could have been completed at the time of sign-up.

It would have been more straightforward to tell all the attendees to find each other on LinkedIn and connect that way. Needing no facilitation by the training company. 

So with a bit of planning and some knowledge of Data Protection requirements, life could have been a lot easier for the training company. 

Monday, 4 January 2016

Thinking of selling your email list? - think again

I have had an enquiry this week from a business owner who has been approached to sell their email list. Sounds simple doesn't it?

It is simple if you have collected the information in the right way and sought permission to share the information with other companies. If you haven't it can be a costly mistake to make, as Pharmacy2U found out. Pharmacy2U was fined £130,000 for selling its mailing list and other details without having the correct permissions to do so. A sobering and costly exercise.

So how do you know if you can sell your list? Broadly, when you collected the information, did you ask the subscriber whether they would be happy to have their information passed to a third party? If you didn't, then you shouldn't be selling the information. If you did and they agreed to the information being shared, then you can. I would suggest that you get a professional Data Protection Officer to review how the information was collected before you go through with the sale just to be sure that you have the correct permissions. You wouldn't want a request for £130,000 dropping through the letterbox.

If you need to discuss how you are collecting information, please contact me.



Sunday, 13 December 2015

Email, your biggest problem? - it could be!

I had a query from a client this week regarding a subject access request from one of their employees. The employee had resigned and subsequently put in a subject access request for emails mentioning them in the previous six months. The client's belief is that the employee is hoping to find something in the emails which will show some prejudice against them by their manager.

As knowledge of the Data Protection Act increases, the many uses of it are being explored for lots of different reasons. It is increasingly being used by disgruntled employees to seek information which would support a claim for unfair treatment.

Regardless of whether the employee is right or not, every business should consider the consequences of staff putting comments (an opinion) of any sort into an email, unless it is a professional opinion which can be backed up.

So what's the upshot of this case? If there is anything that is contentious in the emails, the employee may have a case against the organisation and resolving that could be a costly exercise both in terms of time and money. How many organisations can afford to defend a claim in these circumstances?

Ultimately, this is about ensuring that staff have adequate training to ensure that they are not putting themselves or the organisation at risk of litigation. The amount that it costs to get the staff trained with regard to email etiquette as opposed to the amount that will need to be paid out in compensation or legal defence costs is minimal. Contact me if you would like to talk about our training programmes. 





Sunday, 29 November 2015

What is your process for checking outgoing email attachments?



This case really showcases the importance of keeping track of all of the information that comes from your business!

On 2 August 2011 a member of the public reported that they had received an email from HMP Cardiff with a file accidentally attached that contained the details of 1,182 inmates. As if that wasn’t bad enough, it wasn’t the first time the mistake had been made - on 4th and 5th July 2011 the prisoner details had been sent to two other unintended recipients who hadn’t yet contacted the data controller or the prison. 

A total of three emails with the attachment had been sent to three different individuals, after a new prison booking clerk had been arranging the prison visits. The clerk had only meant to email a family member about a visit but had accidentally pasted the text file as an attachment. All three mistakes were made by the same clerk, doing the same thing by accident. Because the file had to be manually cut and pasted on a daily basis onto a disk, and then saved onto a database, the paste action had picked up the last file from the clipboard instead of the correct one and accidentally sent the sensitive data - three times.

Once the mistake had been discovered, the police became involved and each recipient was asked to confirm in writing that the message had been deleted and not shared. The police even accessed their email accounts to make sure that it had been fully deleted. 

HMP Cardiff has since put in place measures to stop this ever happening again; existing training and on-going support is now topped up with monthly checks and the data transfer procedure has been changed so that rather than a disc, an encrypted memory stick is used for data transfer. And instead of copying and pasting it to the stick, staff are told they have to locate the text file and use the ‘send to’ function, which stops it being left on the clipboard to be pasted where it ought not to be.

Most of us would cringe, just thinking about a mistake like this - how many times have you attached the wrong document to an email or not attached it at all? When you’re dealing with sensitive data though, the repercussions can be extremely serious. The National Offender Management Service was fined £140,000 for the breach.

This error, made by an inexperienced member of staff, would not even have come to light if the third person who had received it hadn’t realised the seriousness of the mistake and reported it. Is it possible that this sort of thing could happen to you? What measures do you have in place to prevent sensitive data being accidentally shared with the wrong people?

Do you have a contingency plan in place for emails, and for protecting sensitive information? If you need advice on procedures and policies that keep your information safe, contact me and I will be delighted to provide you with guidance and advice.

Sunday, 22 November 2015

Email - the equivalent of an electronic postcard - really it is

I have had a couple of conversations with organisations recently about email security.

Sending an email is like sending an electronic postcard, anyone can intercept it and read the content. We all know when we write a postcard that the postman reads it before he delivers it. That's why so many postcards go along the "wish you were here" line.

Email is no different, it can be intercepted and read. Talking with a range of organisations recently, you would be surprised what they will put in or expect to be put in an email that is unencrypted.

A common request is credit card details. One charity I worked with used to relay credit card details across the organisation via email. Not only is this a breach of PCI DSS (the credit card security standard) but means that those credit card details are insecure. And its not just small organisations that have this misconception. A large hotel chain recently asked me to confirm a booking by sending my credit card details back by email.

Next is the transmission of personal information across an organisation. How often does an organisation send a spreadsheet of personal information within an organisations without protecting it? If you send personal information, take steps to protect it.

A common misconception is that sending an email internally means it is secure as the perception is that it doesn't go outside the organisation. Most emails go outside the organisation and then come back in again, just because you are sending it within the organisation does not make it any more difficult to read.

Finally there is the scope to send the email to the wrong person. With the ability to store numerous email addresses in an email programme, it can be very easy to select the wrong name from the list especially if you have a lot of one name. How many Richard's are there on your list? (there are four on mine). Do you always get the right one? Always check before sending that you have the correct addressee.

So here are a couple of basics
- Email is like a postcard, treat it as such and think of it in this way. Would you put that information on a postcard?
- Sending an email with personal information in it - password protect it ( and don't send the password in the same email as the information!).
- DO NOT PUT CREDIT CARD DETAILS IN AN EMAIL. It leaves the information vulnerable to theft.
- Always make sure that you are sending the information to the correct person.
- Have an email policy which outlines the organisations expectations, it means staff all understand the rules of email. 



Wednesday, 24 June 2015

How good is your mailing company?

Just had an interesting phone call with a company about their spam emails. This company has emailed me about one of their "special offers", needless to say I never signed up to receive said offers. When I rang to ask to be removed from the mailing list, the person answering the phone said they had received lots of complaints about the emails. Apparently I have been lucky because I only have two emails, some of the people they have been emailing have been receiving 2 an hour for days! According to the company, they outsourced their email marketing to a company in China and they haven't been following the instructions they were given. A number of people who have been getting the emails have been complaining to the ICO.

So where has this company gone wrong (this is my speculation based on the phone call).

1. Breach 1 - I never gave them permission to email market to me. Never heard of them before the email came through so definitely didn't sign up. You need to have a persons permission to be able to electronically market to them. You should also record where the sign up information was gathered. Lots of people don't remember signing up and the ICO, if they investigate, will look for confirmation you have permission.

2. Breach 2 - The emails did not have an unsubscribe option on the bottom, so gave me no choice but to call to cancel it. Given the person didn't take my email address, I expect more emails from them in the future. There is certain criteria that has to be met when email marketing, one of which is that there is the ability to unsubscribe from future contact. It is an offence to fail to remove someone from your mailing list when they ask.

3. Potential Breach 3 - IF I had given them permission for email marketing, did they also ask my permission to send my details outside of the EEA (to their marketing company in China), probably not. If you are sharing personal information outside the EEA, you have to tell the provider of the information at the time of collection. 

4. Potential Breach 4 - Sending the information to China, which is not an approved country, the company needed a specific clause in place to protect individuals information. As China is not an approved country for data transfers, they company needed a specific clause and contract in place. Seems unlikely in this case that they complied.  https://ico.org.uk/for-organisations/guide-to-data-protection/principle-8-international/

Needless to say this company is already getting attention from the ICO regarding the level of complaints. If you need help to avoid a similar situation, contact me to discuss how we can help. ask@audit-and-risk.co.uk




Wednesday, 13 May 2015

Sending emails - Will the ICO be sending you to the naughty step?

On one of the forums that I belong to, a question was recently asked about what is considered a spamming email? The responses were very interesting.There was a lot of discussion about whether you can just add people to your mailing list because they gave you their business card. This really split people into two groups along the lines of "they wouldn't have given you their business card if they didn't want you to stay in touch" and "Just because I gave someone my business card, I wouldn't then expect to be out on their mailing list".

So here is the boring legal bit. Under the PECR (Privacy and Electronic Communications Regulations) people must give permission for you to add them to your mailing list, unless they have bought from you previously and the product you are promoting is something similar. If you don't do this and someone complains to the ICO, they could review your data protection practices and send you to the naughty step.

So how do you end up with spam emails? Well, someone you have given permission to have your email address has sold on their list. Yes they should have asked you first but many websites are unclear as to what they are going to do with your information and some companies have no idea that they should be getting your permission first. Many companies are now aware that we hate having our information sold to others and will make a declaration on their website that they never sell or pass on your information. My advice is always be aware when you are providing your email address what it is going to be used for and if it is used for anything else, either unsubscribe or make contact to correct their information.

So back to the business card discussion. Unless at the time you handed over your business card they asked whether you wanted to be on their list (yeah right!) and they noted your permission down, then they shouldn't have added you. More interesting is that the majority of people on the forum said they would unsubscribe immediately if someone did this. Would you?