I have a lovely new email address which is less than 10 months old and already I am receiving spam emails. Working in data protection means that I want to find out where the spammers are getting my email address so I can stop it. It also provides some insight into how little some companies understand the Data Protection Act.
Recently I have received emails from two different companies. Lets call them Good and Bad.
The first company, Good, sent me emails about advertising in the Daily Mail. They are registered with the Information Commissioners Office as a Data Controller. I contacted the company director to ask where they had got my email address and I was told they had bought my email address as part of a mailing list. To be fair, the emails they sent me did have an unsubscribe option, which I have used, and when contacted said they would remove me from that list and put a block on the email address appearing on other lists. The company director also told me that the list they buy they can use for a year but if a recipient doesn't open an email for 6 months they remove them from their list. Really good response and the company director could not have been more helpful.
The second company, Bad, sent me emails every week for 5 weeks at the same time of the same day each week, they also sent the same emails to my colleague at the same time. They are not registered with the Information Commissioners Office. In their emails, they claim that one of their colleagues mentioned my company and they think they can help me (yeah, right). They provide IT staff. There is no unsubscribe on their emails (thereby breaching the PECR). The phone number provided on the email rings out and having rung it at various times is not answered. Really not impressed. After a bit of research on the internet (you have to love it) I managed to find an office number to call. Left a message, still awaiting a call back (not holding my breath).
So company Good responded really well to my requests and questions, very helpful and understand I don't want to be contacted again. Company Bad would "really like to work with me" according to their emails but don't answer their phone, handle my data poorly and think that sending me emails at the same time each week wouldn't be considered spam. I know who I would rather share my information with.
Update: Company Bad have responded to my call. Apparently he noticed my missed calls but he gets lots of calls from companies wanting to sell him something so doesn't follow up, (this from someone sending me spam emails, spot the irony!). Apparently they only have 5 emails that they send out, so as I have had my five there is nothing to look forward to on Tuesdays at 8.36am (shame). They don't know where they got my information from, it could be from a colleague or LinkedIn (really?). They didn't think the Data Protection Act applied as the email address belongs to a company (wrong, as soon as that email is addressed to an individual it becomes personal information). As for being registered with the ICO, he wasn't aware who they are and had not heard of PECR. This is a worrying state of affairs given this company provides CIO's and IT Directors. Company Bad really need to up their game and do some research to comply. They had better hope that the ICO don't take an interest in their lack of registration, abuse of the PECR and inability to record where they obtain information.
Monday, 18 May 2015
Wednesday, 13 May 2015
Sending emails - Will the ICO be sending you to the naughty step?
On one of the forums that I belong to, a question was recently asked about what is considered a spamming email? The responses were very interesting.There was a lot of discussion about whether you can just add people to your mailing list because they gave you their business card. This really split people into two groups along the lines of "they wouldn't have given you their business card if they didn't want you to stay in touch" and "Just because I gave someone my business card, I wouldn't then expect to be out on their mailing list".

So here is the boring legal bit. Under the PECR (Privacy and Electronic Communications Regulations) people must give permission for you to add them to your mailing list, unless they have bought from you previously and the product you are promoting is something similar. If you don't do this and someone complains to the ICO, they could review your data protection practices and send you to the naughty step.
So how do you end up with spam emails? Well, someone you have given permission to have your email address has sold on their list. Yes they should have asked you first but many websites are unclear as to what they are going to do with your information and some companies have no idea that they should be getting your permission first. Many companies are now aware that we hate having our information sold to others and will make a declaration on their website that they never sell or pass on your information. My advice is always be aware when you are providing your email address what it is going to be used for and if it is used for anything else, either unsubscribe or make contact to correct their information.
So back to the business card discussion. Unless at the time you handed over your business card they asked whether you wanted to be on their list (yeah right!) and they noted your permission down, then they shouldn't have added you. More interesting is that the majority of people on the forum said they would unsubscribe immediately if someone did this. Would you?

So here is the boring legal bit. Under the PECR (Privacy and Electronic Communications Regulations) people must give permission for you to add them to your mailing list, unless they have bought from you previously and the product you are promoting is something similar. If you don't do this and someone complains to the ICO, they could review your data protection practices and send you to the naughty step.
So how do you end up with spam emails? Well, someone you have given permission to have your email address has sold on their list. Yes they should have asked you first but many websites are unclear as to what they are going to do with your information and some companies have no idea that they should be getting your permission first. Many companies are now aware that we hate having our information sold to others and will make a declaration on their website that they never sell or pass on your information. My advice is always be aware when you are providing your email address what it is going to be used for and if it is used for anything else, either unsubscribe or make contact to correct their information.
So back to the business card discussion. Unless at the time you handed over your business card they asked whether you wanted to be on their list (yeah right!) and they noted your permission down, then they shouldn't have added you. More interesting is that the majority of people on the forum said they would unsubscribe immediately if someone did this. Would you?
Saturday, 31 January 2015
Is your information safe with car dealerships?
Over the last 8 months I have been fortunate(!) enough to visit three car dealerships, each representing a different marque of vehicle. None have handled my information correctly so chances are they are not handling yours correctly either.
I visited dealership A in April 2014, dealership B in June 2014 and Dealership C in October 2014. Here's the run down of errors made by the dealerships
Dealership A was not registered with the ICO when I visited. They subsequently became registered in June 2014.
Dealerships A and B have notified me that the MOT is due on the respective vehicle. Both dealerships got the date wrong. Dealership A is out by 6 months and Dealership B is out by 3 months. Given the MOT information can be obtained from the DVLA website they should be keeping that information up to date as required by the DPA. Of more interest is where they got the MOT information from as neither dealership asked me and I have been MOT'ing my car at a local garage rather than the dealership so neither had any MOT records for my vehicle.
Dealership A has been using my email address for publicity purposes without actually seeking my permission to do so.
Dealership B made marketing calls to me without asking my specific permission for this to take place.
Dealership C has been sending me marketing texts again without seeking my permission to include me on their mailing list and the format of the texts does not meet the requirements of the DPA.
Dealership C managed to lose my bank account details, they know not where. Really unimpressed.
My thoughts are that none of the dealerships I have dealt with have a clue how to comply with the requirements of the DPA in even the most basic way. None of the dealerships sought my information in a way that they could use is on an on-going basis, yet chose to do so anyway. As for contacting me about the MOT, that is just sloppy record keeping on their part.
I have contacted all the dealerships, so far only one has replied and their response was that they were fully accredited by the UK distributor of the car make and their processes regularly reviewed as part of the accreditation process. Surely this makes matters worse, that a car manufacturer is justifying the poor information security practices of its dealerships. I would be interested to know if I am alone in this experience so would love to know what your observations are.
I visited dealership A in April 2014, dealership B in June 2014 and Dealership C in October 2014. Here's the run down of errors made by the dealerships
Dealership A was not registered with the ICO when I visited. They subsequently became registered in June 2014.
Dealerships A and B have notified me that the MOT is due on the respective vehicle. Both dealerships got the date wrong. Dealership A is out by 6 months and Dealership B is out by 3 months. Given the MOT information can be obtained from the DVLA website they should be keeping that information up to date as required by the DPA. Of more interest is where they got the MOT information from as neither dealership asked me and I have been MOT'ing my car at a local garage rather than the dealership so neither had any MOT records for my vehicle.
Dealership A has been using my email address for publicity purposes without actually seeking my permission to do so.
Dealership B made marketing calls to me without asking my specific permission for this to take place.
Dealership C has been sending me marketing texts again without seeking my permission to include me on their mailing list and the format of the texts does not meet the requirements of the DPA.
Dealership C managed to lose my bank account details, they know not where. Really unimpressed.
My thoughts are that none of the dealerships I have dealt with have a clue how to comply with the requirements of the DPA in even the most basic way. None of the dealerships sought my information in a way that they could use is on an on-going basis, yet chose to do so anyway. As for contacting me about the MOT, that is just sloppy record keeping on their part.
I have contacted all the dealerships, so far only one has replied and their response was that they were fully accredited by the UK distributor of the car make and their processes regularly reviewed as part of the accreditation process. Surely this makes matters worse, that a car manufacturer is justifying the poor information security practices of its dealerships. I would be interested to know if I am alone in this experience so would love to know what your observations are.
Thursday, 1 January 2015
NHS and Data Protection - Are you using the same strategies?
I was unfortunate to have an accident recently which required a visit to two hospitals. The NHS has always been an interesting visit from a Data Protection point of view. How to preserve individuals rights under the Act whilst still conducting the services required. I was really impressed with the the advancement that has been made.
I was admitted via A+E and from the moment I arrived, I was labelled (not sure that's the right term) and given a different name so that even when staff were talking about me it wasn't obviously me as they used my code name. I quite liked being "sierra" (place in the US, rather than a Ford car). Once I was admitted, I noticed a huge change from the last time I was in hospital (back in 2003), firstly no medical notes on the end of the bed. These were kept in a cabinet accessed by the medical staff on the ward. I was also referred to by my bed number when medical staff were discussing me away from the bedside I found this quite reassuring.Obvioulsy I wouldn't want to spend the rest of my life being referred to as "bed 14" but when medical staff are discussing me I was happy with it. I can see how some poeple might feel offended and to be fair to the staff they always used my name when addressing me at the bedside, so I had no problems with the situation at all.
From my experience, the NHS at this particular hospital have achieved compliance with the DPA, whilst still providing an excellent service and care for their patients. Can you say that your business is compliant with the DPA?
I was admitted via A+E and from the moment I arrived, I was labelled (not sure that's the right term) and given a different name so that even when staff were talking about me it wasn't obviously me as they used my code name. I quite liked being "sierra" (place in the US, rather than a Ford car). Once I was admitted, I noticed a huge change from the last time I was in hospital (back in 2003), firstly no medical notes on the end of the bed. These were kept in a cabinet accessed by the medical staff on the ward. I was also referred to by my bed number when medical staff were discussing me away from the bedside I found this quite reassuring.Obvioulsy I wouldn't want to spend the rest of my life being referred to as "bed 14" but when medical staff are discussing me I was happy with it. I can see how some poeple might feel offended and to be fair to the staff they always used my name when addressing me at the bedside, so I had no problems with the situation at all.From my experience, the NHS at this particular hospital have achieved compliance with the DPA, whilst still providing an excellent service and care for their patients. Can you say that your business is compliant with the DPA?
Sunday, 7 December 2014
Here's how to deal with an information security breach......
| We all hope that we will not be the subject of an informations ecurity breach but the chances are that all organisations will have a form of data breach at some time. Your effective response to an information Security Breach may have an impact on your company's public profile and the costs involved with the breach. |
|
|
|
|
|
|
|
|
|
Sunday, 9 November 2014
ICO warns organisations about cyber security. Could you be at risk?
The Information Commissioners Office has suggested that organisations
need to act to ensure that the information collected via their websites
is secure. This is after a hotel booking website was hacked and the
details of 3814 customers were accessed. You can read the full ICO
comment here.
This isn't the first incident of websites being hacked for their customer details. In May 2014, Ebay was the subject of hackers and they advised all their account holders to change their password.
In April 2012, the British Pregnancy Advise Service website was hacked the name and logon details of the administrator leaked. At the time the ICO said “Ignorance is no excuse. It is especially unforgiveable when the organisation is handing information as sensitive as that held by the BPAS. Data controllers must take active steps to ensure that the personal data they are responsible for is kept safe."
Ernst and Young have researched cyber attacks and produced a report. Ernst and Young report. Cyber threats are regularly reported in the media and this indicates that attacks are becoming more sophisticated and persistent. If your organisation has not experienced an attack yet, it will no doubt be targeted.
PWC reports that cyber attacks have increased 41% over the last year and the report shows that most attacks are undertaken by a current employees.
Both the PWC and Ernst and Young report are interesting and show the importance of ensuring appropriate security and policies are in place.
If you would like some help identifying any potential weaknesses, please contact me at Lesley@audit-and-risk.co.uk. I shall be happy to help.
This isn't the first incident of websites being hacked for their customer details. In May 2014, Ebay was the subject of hackers and they advised all their account holders to change their password.
In April 2012, the British Pregnancy Advise Service website was hacked the name and logon details of the administrator leaked. At the time the ICO said “Ignorance is no excuse. It is especially unforgiveable when the organisation is handing information as sensitive as that held by the BPAS. Data controllers must take active steps to ensure that the personal data they are responsible for is kept safe."
Ernst and Young have researched cyber attacks and produced a report. Ernst and Young report. Cyber threats are regularly reported in the media and this indicates that attacks are becoming more sophisticated and persistent. If your organisation has not experienced an attack yet, it will no doubt be targeted.
PWC reports that cyber attacks have increased 41% over the last year and the report shows that most attacks are undertaken by a current employees.
Both the PWC and Ernst and Young report are interesting and show the importance of ensuring appropriate security and policies are in place.
If you would like some help identifying any potential weaknesses, please contact me at Lesley@audit-and-risk.co.uk. I shall be happy to help.
Tuesday, 28 October 2014
Printer problems?
HP produced a very interesting article on printer security and the potential risks, particularly with a network printer. The link below will take you to the article.
http://h20435.www2.hp.com/t5/HP-BusinessReady/Is-your-printer-putting-sensitive-data-at-risk/ba-p/89690#.VEVg3fl4rtw
http://h20435.www2.hp.com/t5/HP-BusinessReady/Is-your-printer-putting-sensitive-data-at-risk/ba-p/89690#.VEVg3fl4rtw
Subscribe to:
Posts (Atom)

