ICO enforces GDPR against Canadian company

28 November 2018

In one of the first enforcement steps it took under GDPR, the ICO issued an order in October against a Canadian company, AggregateIQ Data Services (ADS), which required it to delete all personal data held by it on UK residents.  The order was issued in the context of the ICO’s ongoing action in relation to […]

Read more

Brexit update

16 November 2018

The draft EU withdrawal agreement published on 17 November will (in the –possibly unlikely – event of UK Parliament ratification) preserve the status quo during the Transitional Period (which runs to 2020), during which time there will be negotiation of a longer term arrangement.

Read more

Prison sentence for rogue employee

16 November 2018

A rogue employee has received a six month prison sentence, using powers under the UK’s Computer Misuse Act 1990.   This is the first time that the ICO has used this legislation, and it is noteworthy that the penalty is against the individual, not his employer.  The case involved a car repair garage employee accessing a […]

Read more

ICO penalty for spam overturned

29 October 2018

A fine imposed by the ICO on a company accused of sending millions of unsolicited emails was overturned last month by the Appeal Tribunal[1]. The ICO had initially issued the fine against Xerpla Ltd, for a breach of regulation 22 of the Privacy and Electronic Communications Regulations (PECR) against unsolicited communications. In brief, this regulation […]

Read more

Personal data: a global commodity subject to regional rules

14 September 2018

The introduction within the EU of the General Data Protection Regulation (GDPR) led to frantic scrambles in the EU to achieve compliance. Such behaviour is understandable, given how easily a complaint may be made to a supervisory authority about organisations which allegedly breach data protection rules: in Britain, the Information Commissioner’s Office (ICO) has provided […]

Read more

WhatsApp: We won’t share your data with Facebook… for now

16 March 2018

Following an investigation by the Information Commissioner’s Office (ICO), the UK’s data protection watchdog, WhatsApp has signed a public commitment not to share personal data (i.e. data which identifies individuals) with Facebook until data protection concerns are addressed. Facebook acquired WhatsApp in 2014, and the ICO’s investigation commenced in August 2016 to address concerns being […]

Read more

Brexit and planning for the unknown in IT

26 October 2017

As is beginning to become apparent, Brexit has wide-ranging consequences in many commercial and business areas. This is equally true in the sphere of data protection, where much of the applicable legislation has developed at an EU level. This is readily understandable, given (i) the wide-ranging technological advances that have occurred since the UK joined the European Communities in 1973 and (ii) the quintessentially cross-border nature of these developments.

Read more

Royal Assent received for the Digital Economy Act 2017

26 May 2017

New legislation introduced to extend digital connectivity, regulate direct marketing and protect consumers from unexpected phone bills and ticket bots. The Digital Economy Act 2017 (Act) has officially made its way into UK law. The Act addresses some of the many issues arising in conjunction with the surge in use of technology, digital media and […]

Read more