Showing posts with label employment. Show all posts
Showing posts with label employment. Show all posts

Monday, September 30, 2019

iProfile / Vertifi / Jobzooma at it **AGAIN**??? (Updated)

Updated 23rd November 2019; Originally posted 30th September 2019

Amazingly the Jobzooma team are still at it.

After tendering some applications for contracts earlier today I had an email from our old friends Jobzooma. I can find no trace of any connection between the potential clients I emailed or how they acquired my details, yet somehow I've sent them my CV???

Yeh but no
This isn't how to deal with consent - there's no opt-in, there's no request about whether I've asked for it. The email asks you to click a link to verify that they have the right data, which I'm absolutely not going to click. That could be interpreted as explicit consent for them to continue storing my data - I've never done any business with them!

Have sent chaser email but be warned - they're still at it. If you read the previously linked scam alert you'll realise why you're better off avoiding altogether.

I've asked them where and how they got the alleged CV and they've acknowledged receipt of the request. Will update when I have more but on the face of it appears to breach PECR and DPA 2018 [inc. GDPR 2018].

It's no good asking for consent after you've already acquired, stored and processed the data.

Updates

I finally received a response from ICO, in which they stated that:

"We have considered the information available in relation to this complaint and we are of the view that Jobzooma has not complied with their Data Protection obligations. This is because you did not receive an appropriate response to the data protection concerns you raised. We consider this to be an infringement of the legislation.

Subsequently, we have written to Jobzooma, via the Data Protection Officer, to explain that we expect the organisation to review your complaint and take action to resolve any outstanding matters.

We have issued guidance to Jobzooma as a result of your complaint and expect they will be in contact with you in due course. Thank you for bringing your concerns to our attention.

This complaint will be kept on file and this will help us over time to build a picture of Jobzooma’s information rights practices.  We keep a record of all the complaints raised with us about the way organisations process personal information.  The information we gather from complaints may form the basis for action in the future where appropriate.
"

I wasn't happy with this response because it isn't a strong enough message for a repeat offender, and also I've recieved no responses from Jobzooma at all. I asked the case officer to look into further evidence I provided, and examine the linkages evidenced between Vertifi, Talent Spa and Jobzooma.

I asked the case officer to then review the outcome and proceed with a publishable decision, so that Jobzooma would be the target of ICO enforcement should they offend again.

That reply to the ICO case officer was sent on 4th November 2019, and I have not yet received a response, other than the auto-acknowledgement.

However it is good to see ICO confirming my suspicions that Jobzooma are / were acting unlawfully.

I've noted further updates in November 2019 on the scam alert post on the portal.

Thursday, September 28, 2017

Mash Me A Spammer

Match Me A Job directors Ifran and Tahir

One thing my friends and family know for certain is that when they have issues with spam, data breaches or dodgy looking emails, they can always come to me for advice.

In some ways it's like being that member of the family who can "fix laptops" - something I've worked hard to disassociate myself from over the years. However when I get spam myself I'm often a little puzzled, having taken numerous steps to avoid subscribing, being implicitly opt-ed in to or otherwise engaging with spammers.

This particular case involves my use of Jobsite.co.uk - an online jobs board who seem to have struggled in the past with data protection (in comparison to platforms like Monster). I added my details as a contractor looking for work and regularly poke through the jobs listings for suitable contracts.

What I can reasonably expect from this is - and according the general terms and conditions of such boards - that recruiters advertising live roles might grab my details and notify me of roles they have. They might store my details so that if that role doesn't suit a future role they might have will. That's all above board as far as I'm concerned.

This is important - these roles are live roles offered by the agencies on behalf of organisations. The distinction is that a jobs board provides the interface between candidate and agency (or directly from hiring organisations).

The standard (happy path) use of jobs boards looks like something like this:

Normal jobs board process - Click to enlarge

The Washing Machine


Match Me A Job however - and apparently the directors' other companies - do not fit into this paradigm. They scrape candidates details from Jobsite.co.uk and then absorb them into their "client" database. This may possibly include the entire set of organisations related to the MMAJ directors. MMAJ are not yet approaching the same league as other idiots such as My Job Matcher - but they appear to be trying to make a quick buck in similar ways.

Interesting business model: Instead of marketing, getting exposure of your brand and working at improving the corporate identity through direct engagement... they're essentially scraping Jobsite's candidate database and using it to create a new jobs board / platform as a competitor. Easier to get private equity partners to buy your company with a much bigger candidate database...

Jobsite seemingly take little interest when companies like MMAJ and MJM steal their candidate DB are reported to them. Normally they tell me that "they have no control over what the recruiters might do with your data", apparently unconcerned about someone creating a competitor to them from their own data. Monster, however, take a much dimmer view and have sanctioned people in the past for the same. As do ICO.

Back to MMAJ.

They then use other jobs platforms - like jobg8.com - to mesh the candidate keywords with the jobs on those platforms. Any results are then sent to the candidate. Note: These are not live roles offered by MMAJ or jobg8.com - they are offered by other recruitment agencies, and I'm not convinced that some of the agencies know their job ads are on jobg8.com a lot of the time. MMAJ don't actually have live roles nor are they allowed to do this given the specific consent provided when I subscribed to Jobsite.co.uk.

The diagram below shows how the flow of actual consent (c.f. data protection and marketing consent from a data subject - from people like us) in this situation:
The reality - everything outside of the primary Jobsite.co.uk platform in this case is unlawful
These emails are sent from fictitious MMAJ recruiters who's names are manufactured from a list. None of the replies I ever sent back to them ever received a response and none of the filed accounts for the company reflect employing so many people (even on a contract basis).

In fact, when I sent various requests and notices to them via email I selected around 10 recipients plus their info@ and Irfan's email address - All but the info@ and Irfan's address returned "Recipient unknown" messages.

One might have expected that these unsolicited messages would actually be useful had all the roles actually been live - in fact all of them were expired by the time the links were sent. An example below shows a totally unrelated job role (I'm a Solutions / Enterprise / Business / Data Architect working mostly in the financial industry), from an agency who I've actually worked with in the past.

Url shows Jobg8.com and the mailshot shows MMAJ's logo. Link clicked within 10 minutes of receiving the email.

Example "job" link from MMAJ gets you something like this - Click to enlarge
If it's a bug, no-one could have reported it as all the MMAJ 'staff' email addresses return "recipient unknown". I suspect no-one reported it and no-one wanted it.

By this time though, your name, address, DoB, entire employment history and possibly other details (depending what you decide to share on your resume) are now in the hands of a string of organisations monetising said data. In fact if were being more cynical I might suggest that this is one of many data laundry enterprises, churning out data to be monetised.

When I was caught in this particular machine cycle I received over 100 emails in the space of a few weeks, all for roles that were almost completely unrelated and all unavailable.

After being the recipient of attempts to breach systems and data stores over the years I'm more inquisitive about emails from strangers that seem to know a lot about me.

Data Protection


MMAJ essentially refused to answer my SAR - the only time they actually attempted to fulfil it was after I lodged a case in the small claims court. That lack of response was a breach of the requirements of a DPA section 7 request / notice. 

PECR paragraph 22 requires that an entity acquiring personal data for the purposes of direct email marketing must first acquire the explicit consent of the subject; prior to the sending of any unsolicited marketing messages (which a job alert is). Because I subscribed to a specific jobs board with the expectation to receive messages from recruiters about their own live vacancies, no consent was in place for MMAJ.

Even the DPA requires explicit consent to acquire, store and process personal data (many sections in the Act to refer to) and MMAJ failed to acquire this consent for the purposes they actually enacted.

The regulator, ICO, also enforces non-compliance with registration as a data controller - two of the companies operated by the MMAJ directors are registered (ZA110541, ZA110536) but not MMAJ itself. One of my companies is a registered DC because of the personal data that is sometimes acquired during the course of investigation - I know from experience that regular information and update mail shots are available directly from ICO, and you have an option to sign up when you first register as a controller.

A company who routinely scrapes, stores and shares personal data should certainly be registered. MMAJ's directors operate companies which had been registered for some time.

Any which way you want to spin that, the directors are responsible and aware of their obligations.

MMAJ's Position


Only in their filed defence did MMAJ reveal their process and essentially answer the SAR I sent:
  • They admitted scraping the personal data from jobsite.co.uk - although they claim it was for the purpose of "recruitment", not offering live job roles themselves; and despite effectively entering me into a subscription process which I had no say in until some time after the fact
  • They claimed I did not avail myself of the unsubscribe link; however they didn't have consent as per PECR in the first place to send the emails with the links in them, nor is it best practise to click links in emails you've received from persons unknown
  • They claimed I'm not a genuine job seeker - which was amusing. In fact they claimed I'm a sadistic opportunist. As a contractor of nearly 20 years experience I suppose some would consider me mercenary; I'm quite an aggressive racer when I compete in a kart too, but MMAJ clearly wanted to avoid the actual issues and enter into a mud slinging competition
  • They ignored my emailed SARs and NBA for months but replied when the paperwork was served; yet claimed to be essentially pro-active in their response
There's always a case for reasonable exception - that's the whole point of a legitimate jobs board. What we should not have to stand for is being subscribed to services (and spammed as a result) which we do not want, nor were consulted about.

The entire defence seemed to be based around the total lack of accountability for which a company handling personal data should have. The law apparently doesn't apply to them - they're special.

B2C-style recruiters are the more typical business models, but the most concerning development of late is B2B recruiters. They're outsourced agency staff who may not even work inside the EU (therefore breaking the stringent data protection laws of the EU and UK). Agencies out source their searches to other agencies, who presumably take a small percentage for candidates that eventually get a contract or role.

Corporate Entities


From the companies related to the two directors of MMAJ, Irfan Lohiya and Tahir Islam, seem to exchange recommendations for each other and share infrastructure. Not unusual and a good cost mitigation option.

Tahir's LinkedIn profile lists him as a case handler for Lloyds Bank, although he may just be a silent / investment partner. All correspondence relating to the litigation was signed by Irfan who seems thick with links to recruitment - working for agencies as per his LinkedIn profile whilst running his own. Nothing really wrong with that though.

Astoria Green Executive Search, Jobm8 (not jobg8.com),Total Jobs, Green Recruitment Solutions, Top Resourcing, Proficient Outsourcing Ltd and MMAJ are the companies one or both directors own / operate - only Jobm8 and MMAJ are nominally shared.

That's a lot of very small companies - question marks for me arise relating to; if MMAJ has my data, who else does? With idiots like MMAJ you shouldn't rule anything out.

Summary


In the end I had an issue with the postal deliveries, meaning I missed a lot of paperwork relating to the case. I couldn't therefore press the claim home and the last I'd heard MMAJ refused to engage in mediation pre-trial. It's a shame because I'd created a retrospective data consent agreement and wanted to see it enforced at district level. Of course, there's no guarantee but I could easily disprove each statement of the defence - some of which by using their own evidence.

The amount of time you have to spend on these things is immense - unless you're a lawyer being paid to write and argue the case there's virtually no financial benefit to it. What I do for a living is investigate (in other fields) - and that's where the commonality is for me, and that the regulator is often swamped with other cases from local government.

But also because there are so few - if any - people actually raising awareness of the growing problem in data protection.

It took direct legal action to force MMAJ just to answer my SAR, and even then it was without any acceptance that they'd actually broken the law. If someone hold their hands up and says, "Ok - yeah. We were wrong - really sorry and it won't happen again" it's generally a reasonable situation which needs no further prodding.

In May 2018 the British equivalent of GDPR comes into force so the additional weighting in favour of explicit / DS enacted consent; the types of activity MMAJ admitted to (or were observed enacting in cases where they denied it) would net them massive fines and potentially criminal convictions. Had I engaged ICO over the matter they could have invoked their powers within the law to review criminal prosecution against MMAJ (if they'd had the time amongst their already mountainous case loads).

I've worked with a lot of recruiters over the last 20 years and there are some real diamonds out there. Recalling past conversations with recruiters I've known for years as well as new firms who made a silly mistake with their data handling - all it takes is a five minute phone call to resolve. However there's also some real used car salesmen holding the reputation of the industry back.

There's so many of them though.

Wednesday, November 30, 2016

Trial Result: UK Apollo Group


In a surprise ruling, the judge decided that I could not prove the claim against Apollo.

The reason? I'd forgotten to include in evidence the documents that showed UK Apollo group scraping email addresses from the rest of job seeker data in my bundle. This was necessary as the initial spam was sent to an encoded email address (e.g. jobsite.<date>@<domain>).

So essentially it was not the case where the defence was robust and proven, it was simply an error on my part which failed to cement the facts of the case. UK Apollo would not be able to refer to this year long legal entanglement as a 'victory' as a result, and they also disclosed a lot of facts in a court of law - facts that would be of interest to regulators and in future SARs.

Furthermore, the judge refused to accept evidence of spam emails received after the submission of the date of the claim, which included readily identifiable email addresses. He also noted - but failed to act on - the fact that the first defence was submitted unsigned, and an alleged re-write of the defence was never served to the claimant.

In fact the trial was the first time I'd heard that Apollo had even adhered to the application to strike / re-write judgement.

Despite a number of breaches of CPR by the defendant (duly noted but not enacted by the judge) the defence - such that it was - was allowed to stand, despite a submission related to Denton & others. I even submitted a revised bundle for the second trial after the court ushers directed me to the wrong floor in the first trial - but the judge claimed not to have it in front of him. Good thing I got delivery receipts then.

Very interesting - almost as interesting as the very personal remarks made by the defendants rep, Keith Taylor. He was very angry! He couldn't actually apply a robust defence at all and I'll share the highlights of the comedic vitroil once I get the trial transcribed. You shouldn't laugh too much in a court. At one point he claimed that ICO was getting the law changed to help his company continue to spam people. Of course, no evidence was presented to substantiate any of these statements.

Keith even claimed he charges his time at £1k per day, although judging by the posted accounts none of the companies seem to be charging for many of his consultancy days. Most of the people associated with Apollo appear to have many other jobs too....

Also of note was the defence at one point admitting liability at two points, saying "just find me guilty, m'lud and fine me£200 so we can all go home.". In court, on record.

However because the district judge excluded the emails following the initial claim document they are not considered part of the claim that has now been judged by the court. One of those spam emails was to an account I have listed as <firstname>.<surname>@<domain> - which is personal data in itself.

I think I can see why the judge did what he did and I've decided not to appeal for a number of reasons (not least the additional costs liability if I get something wrong). So I sent Apollo a shiny, brand new SAR last week - they've read it twice but are yet to respond. He awarded a £55 cost for the defendant - which should cover his petrol home.

Wednesday, May 18, 2016

UK Apollo Group (Updated)

The Claim
The Entire Defence (v1)
I don't blog about cases unless there are exceptional circumstances and this is certainly one of those. Of all my cases this is probably the most ridiculous attitude towards data protection and information assurance I've seen yet.

Over the course of 2015 I've spent a lot of time speaking to people in and around data protection and those who've been taking spammers to task. Within a group of people there are different motivations and slightly differing goals but one key factor is common: Spam fatigue and being fed-up with personal data being sold, re-sold and profited from without any kind of consent or reparation.

If you sign a EULA with Microsoft, Apple, Google and many others and read enough of the small print (yes - I'm one of them, sorry...) you'll discover that you haven't actually bought the Thing in your hand or the Thing installed on your device. You've paid for license to use that Thing on your device. Your use of that Thing can be terminated at any time by the owner - you (the licensee) have rights to use the Thing but you don't actually own it.

In legal terms personal information is not property [yet] and so this doesn't necessarily follow in the literal sense of authorised ownership / resale. However in the terms of an agreement where you license an entity to use your personal information for a given purpose you have the right to withdraw that consent at any time.

Since 2014 I've started using a mechanism which allows me to trace the path of personal data from capture to spam; there are edge cases where data traders may be between the capture point and the spammer but it's up to the spammer whether or not to "'fess up" and disclose those sources. Incidentally, disclose of source is a statutory duty under the Data Protection Act if requested to do so under SAR.

I agreed / licensed the use of my information (arguably a product in itself) to Monster.co.uk for the purposes of finding a job. I'm a contractor and am "client cycling" on a semi-regular basis so use jobsites fairly often. However Monster's own T's and C's - as well as the consent conditions I agreed to - do not allow anyone to acquire this jobseeker profile information for anything other than recruitment for a live job role.

That means you cannot acquire this data arbitrarily on the promise of a future job role being created nor can you scrape this data and monetise it via offering products or services - whether they are relevant or not.

When I started getting spam which used email addresses only added to Monster profiles from Taylor CVs advertising their CV writing & design services it was pretty clear that it wasn't by mutual consent. I spoke to Monster's abuse team and they agreed with me.

After one of the most insane SAR-based email exchanges with them I've ever borne witness too I raised a claim in the courts for their blatant breaches of statutory duty, the DPA and the PECR. It didn't take long to find some really extreme examples of Apollo's persistent offences. In one case one of their representatives posted a very personal email from a complainant to attempt to belittle their criticism of Apollo - not only an abhorrent breach of data protection but a galling breach of privacy.

I wouldn't have considered this course of action (normally some polite emails to ask them to adjust their policies and perhaps a blog post or two to help others dealing with the same situation) but the attitude of some organisations really hacks me off. Had they put their hands up and said "Ok, we did something we shouldn't and we're sorry" I would probably have left it at that and added a note for future reference.

By they didn't - they actually tried to tell me I'd consented and that I'd subscribed via their Executive Partnership brand (since shut down). They tried to weasel out of it and I suspect they know exactly what they're doing wrong.

What's worse I know from other witnesses that they have no way of tracking which sources they compile their central lists from as they don't have the infrastructure to manage it - even if they did care.

In this case I applied to the court to force the Apollo to re-write their defence so that it was coherent and actually answered the claim - as you can see from the photos at the top of this article the defence looks like it was written with the same attitude that Apollo spoke to me directly with: through arrogance and ignorance.

TL;DR - Re-write the defence. Another CM hearing to see if it's worth an actual hearing
Apollo have until 4pm today (15 mins from the scheduled publish time of this post) to file a proper defence and the court then has a case management hearing to determine whether or not Defence v2 will actually answer the case or not. I've already raised the issue with ICO and the ASA as Apollo have spammed me more than eight times since "deleting my data from their systems".

ICO's response was essentially: "Yes, they're very wrong and need to improve their data compliance but we're not going to do anything about it". Considering they know I'm taking action directly I think that's reasonable but I think a decision notice would be applicable as it's not a first offence.

It's beyond a joke and as no-one else - especially the regulators - seem interested in doing something about it much outside of the public sector...but why should it be up to people like me to force these companies into compliance with the law? Surely that's not the way it should be?

If you have views or concerns please feel free to get in touch directly (secure contact details open in new window).

Update 25th July

There was a mishap at the Birmingham County Courts resulting in being sent to the court rooms on the wrong floor. Because there was no usher that day there was no way of easily finding out how to correct the mistake until 10 mins into the hearing. Case dismissed as the claimant (yours truly) didn't attend - despite being less than 10 metres away the ushers in the district court area didn't use the tannoy.

Application submitted to have the dismissal set aside, hearing fee paid and awaiting a date for the hearing. Apollo have also spammed me since the original post - four times.

Friday, September 25, 2015

The 3 R's: Rinse, Repeat, Re-sell


Earlier this year I had the misfortune of coming into contact with MyJobMatcher; they'd essentially bought peoples personal data from data traders around the world to artificially inflate their candidate database, rather than work on gaining direct subscribers. They settled my claim for breaches of the DPA and PECR out of court with no associated admission of liability.

The end of the story? Lessons learned? Of course not. I got an email recently from MJM claiming that SpellJobs.com had suggested I would be interested in MJM's services. Anyway so if I want to log in and...Wait. What?

So one jobs board is passing on candidates to another competitor? After unlawfully acquiring my details from the original jobs board that'd I'd actually used? Of course. All of this makes perfect sense. Who the hell are SpellJobs.com? Their contact page just goes to a PHP error and the about us page is tellingly blank.
Karen - what have you done?
The shopping basket doesn't work either. I've had a look in between the lines at spelljobs.com and it appears to allow the general public to search and scrape job seeker data. The T's and C's look suspect to say the least too. I may add this to the LSP R&D portal as a new scam alert depending on how the SAR pans out.

Due to the no-contact agreement I'm currently in conversation with Mr Lawrence Weeks of Birketts LLP, representing MJM, and they've disclosed the contact details they use in their commercial relationship with SpellJobs.com. Although after doing a bit of digging it looks like SpellJobs.com isn't a registered business but it is either associated with Job Circle Ltd or Datasource Computer Employment Ltd. I've already knocked on that door with another SAR. I'd already sent Job Circle and another apparent linked entity a SAR each to cover all bases.

After my initial SAR to MJM via Birketts I've had a number of automated emails from MJMs systems saying that they are sorry to see me go but my account has been closed.

However now Birketts are asking me if I can supply other emails so they can be de-listed from MJM systems in future. But isn't that missing the point by a very wide margin? Surely they should stop their unlawful data and unsolicited communications practices to prevent them acquiring data they had no consent for in the first place?

Updated

It looks like their parent company haven't filed accounts but are still active (someone has applied to have the compulsory strike off suspended) and part equity sold to GMC Ltd. - MJM directors are directors of parent companies and other recruitment or data analysis firms.

After lodging a new claim in the courts against MJM we successfully negotiated a settlement to end this - and hopefully - future disputes.

Sunday, May 17, 2015

Progress Part 3

...carrying on from Part 2:

After a fair amount of digging and acquisition of evidence via SAR, I now had enough to make an informed decision on whether or not to take legal action.

To me this was a serious and significant breach far in excess of a normal situation. It was above and beyond the usual spam scenario as I had been subscribed to services I had not consented, and been forced into subscription policies I had not reviewed (or even known about). Essentially as a self-employed worker my resume is my sales pitch - if my competition gets a hold of it they could refactor parts of my resume approach into their own and I would potentially lose my competitive edge (my unique selling points) and therefore lose revenue. Having some unknowns in Pakistan scraping these details from jobs boards for free, then selling them on to the highest bidder beggars belief.

What really pushed the decision for me was when another person with whom I'd had contact reported that another flurry of negative Twitter-verse activity had occurred that week - for exactly the same reason as in December and January. Even after all the correspondence and negative feedback they were still doing it. Someone had to do something.

If you find yourself in a similar situation and decide to press for damages in the courts take the following points into consideration:
  • Have a list of items for damages, each with supporting evidence
  • Make sure you can explain each item on this list to the courts - who may not necessarily share your understanding of data, it's management or ownership
  • Be prepared for legal aggression from the outset. A standard trick across all specialisms of law seems to be an initial threat of return action
  • If there is a clear and describable breach of the DPA and / or PECR with evidence the defendant is still breaking the law, so do not take the defendants legal representatives threats as fact
  • A number of people I know in law - including relatives - have reminded me that there are guidelines for dealing with aggression. The Law Society has this LiP page, of particular interest is section 3.1
  • Get a copy of the consent form you signed for the organisation in question to hold your data. They won't be able to provide this of course, because you never gave your consent
I had some very good opinions from a lawyer I found online who specialises in this particular area of law. Although he was clear that he could not provide guidance or advice he gave me some good, solid facts and great reference material.

So the chain of events was a breach of the DPA and PECR, confirmed with evidence in writing from the defendant. I also maintained a list of damages covering the initial damage claim (£500, plus £35 costs) which was in excess of £1000. The aim were was to provide the courts with a list of items and the courts would decided which of these was recoverable. After no response for four weeks to a Notice-Before-Action (NBA) notification I raised papers via MCOL - which took less than 10 minutes.

I claimed nominal damages from My Job Matcher and we settled for £400 (plus court costs). Most of the time the defendant will try and get you to sign a gag order - it'll have some covenants such as deleting tweets, blog posts or publications, and a form of no-contact directive.

I negotiated the settlement with MJMs legal team (Birketts) without the gag order - One thing I should make clear in the interests of fairness is that they settled without admitting liability to the claim. Whilst I was fully prepared for the day in court it was a relief to settle.

My Job Matchers Twitter profile no longer seems to be under heavy fire from complainants but still sees the occasional "WTF?" sent to it, after a few weeks the SEO team at MJM just stopped replying to them all anyway. I know I'm not the only person to litigate against MJM so perhaps our objective was achieved (update: apparently not).

It's just a shame people have to resort to this to stop the illegal re-use of their personal details; however taking a more aggressive approach is having a substantial effect on my inbox. I'm not going to suggest that direct legal action should be your first approach - in fact it should be your last resort. ICO is almost entirely ineffective from what I've seen so far but the ASA appears to be able to apply some more pressure. I've even involved trading standards in one case.

I got the following email from MJM shortly after the settlement cheque cleared (others got a "How did we do?" support service email), and after the no-contact agreement was exchanged. The irony again here wasn't the email recipient wasn't the account they'd stolen from 2007, nor was it the one from the support email chain.



Progress Part 2

After starting to get responses back from MJM support the picture had become clearer. Being nice with your SARs goes a long way - in fact if you were to be as rude and obstructive as most organisations receiving SARs are, a court would not look kindly on your summons.

So whilst they were being helpful I congratulated them on their approach and noted a couple of things to myself:
  1. The resume attached was from 2007
  2. When I went to their website and password-reset-logged-in I found contact and personal information also dating back to 2007
  3. Whilst writing this section of the blog post I checked to see if I could download the attachment again three months later....and I can; despite MJMs insistence that it would be removed in due course
 These simple facts completely countermanded the response statement; which I assume is partly a canned reply / policy statement. In short, it demonstrated a complete disregard for anything approaching respect for privacy or data. Have a look at this ICO guidance document if you don't believe me.

My Job Matcher did confirm that Manz Online (part of the RecSmart Recruitment Ltd fold) was the source. Of course not only had I never heard of them but I'd certainly be able to prove the lack of consent or chain of privilege from me to their databases.

Quick bit of research showed that Manz is based in Lahore and does not fall under the remit of the Data Protection Act (UK) or Privacy and Electronic Communications Regulations (EU). This is of course just conjecture but it would almost seem like the use of offshore lead generation firms was intentional to inflate subscriber numbers; which would mean a greater appeal to investors or other job seekers in the market perhaps. That is a rather pessimistic opinion but one that was suggested by another MJM spam-ee.

Of course 360 Resourcing are UK based and would therefore be under purview of DPA and PECR; had MJM acquired my details from someone like 360 I could then take action against both MJM and 360 after some investigation.

If you were in a similar situation with Manz Online feel free to get in touch with their director Zak Ahmed on Google+. It's a dead-end to the search for data sources.

On To Part 3 Or Back to Part 1

Progress Part 1


Background

Back in April I mentioned on another blog that I'd encountered a more extreme example of breach of DPA / PECR and would be taking the matter more seriously.

Now the dust has settled I can speak more about it and add details / guidance principals.

In most cases I'm more than happy to rifle through company details, back-check organisation structures and determine the actual origin of the spam. Often it reveals that someone somewhere is trying to make a fast buck from your personal information without consent - and without compensating you for the pleasure.

Usually a combination of ASA and ICO complaints ensure that you'll never hear from the spammers again but occasionally someone really takes the biscuit.

Hand In The Cookie Jar

Twitter is an enourmously useful tool as it can augment your own opinions on a brand, organsiation, person or fact with a vast variety of 140 character masterpieces. When I started getting unsolicited emails from MyJobMatcher in January 2015 I noticed that there was a large group of people in the same situation - having been emailed job adverts from a company we'd never heard of, never subscrubed to and never given any kind of consent for any of the above.

So...no accounts had been compromised but personal information had. Maybe a recruiter got hacked or a jobs board?

Others have also blogged about the specifics of the privacy breach so I'll leave you to read their posts
There were many more simply questioning the approach....
But simply search Twitter for MyJobMatcher from early January to April for more of the same.

I got in touch with MJM with an initial Subject Access Request (SAR) to find out who they were and what personal information they had....And although I got an auto-response from their support system to say the message had been received (v. useful in DPA / PECR cases) I heard nothing for a week, yet continued to get spam about jobs that had very little relevance.

Before raising an ICO or ASA complaint it's better to check what details are involved and how they arrived at their destination. I can say with confidence that I don't subscribe to newsletters nor do I enter prize draws so know the usual flagrant response of "...you must have signed up for it somewhere..." won't fly.

First up someone on Twitter suggested getting in touch with Mandrill at help@mandrill.com - they were nice as pie and sorted out the spam straightaway. I coul dhit "unsubscribe" but it's better to hit the distributor so they know there are other issues with a particular client. In other cases I've been involved with companies have been banned from using marketing distributors entirely because of this.

I'm going to ramble on a fair bit so will break the posts down into chunks.

On to part 2

Sunday, April 19, 2015

Test & Learn



The last few years have been a really interesting adventure for me - I've set up two businesses and things are moving in the right direction. Along the way I've made some mistakes but more importantly; learnt from them.

Hopefully :)

This one relates to B2B late payments and lessons learned in preventing the situation. It's definitely worth getting a background in your monetary rights from UK Plc too.

When I first started it would have been fair to say that I was a novice in the world of contracting and it's nuances - Only good advice from my accountants and contractor colleagues really got me moving. However it was soon clear that even that wouldn't solve the underlying problem: What do you do if the customer doesn't take your invoice due dates seriously?

The first example is from my time working as a contractor for Woodrow Mercer. I don't think the recruiters themselves are really at fault but that doesn't excuse the accounting department. Most agencies seem to have rude and unprofessional accounts department staff - with few exceptions - and they frequently seem to attempt to bully or turn their nose up at contractors.

One agency, ERG, were particularly bad at this back in 2012 - I was sent threatening emails from senior recruiters and directors when I terminated the contract with them. They made wild [incorrect] guesses about where I'd taken the next contract and on recruiter even attempted to get in touch with relevant hiring managers. It was all bluster, aiming to play on the submissive psyche normally present in technical people. However I just prepared the particulars of claim document I'd need to take them to court for non-payment - they paid before the deadline to pay expired though.

Woodrow Mercer failed to pay on time on three separate occasions - the worst thing about this was that the client involved were such a nice bunch to work for. Really well gelled group of people who enjoy what they do. The second time payments were missed there was no excuses or apologies from WM so I called them.

They sent me an abrupt email saying that they'd pay one invoice but the other would have to wait - regardless of the fact that they were legally obliged to pay on both invoices due dates. In that scenario they did pay, but one week late on one and two weeks late on the other invoice.

The third time they missed payments I'd had enough of being passed off with bluster and excuses - Had a word with the client manager and respectfully noted that I would not be returning to site until the invoices were settled. One invoice is still outstanding 11 months on although for a relatively nominal fee. They've since stated that they will "...rigorously defend.." any claim in the courts - I may update that with another approach depending on some parallel research.

Wind the clocks forward a year or so and two other agencies have attempted to bully their way out of late payments. In both cases both the contract and the invoice T's and C's supported an instant late charge along with interest growing daily.

Uniting Ambition fell short of the mark after neglecting to pay the final invoice on due date (I would have been fine with it had their been discussion beforehand, some reasonable negotiation solves a lot). They attempted to negotiate a portion of the fines but then paid in full when I delivered a "notice before action". If it was the first time they'd paid late I might have let it slide but they'd failed to pay every single contractor at that client (~30 people) on the first invoice date. No apology was given and only a few vague excuses. An inexcusable attitude.

In all cases a reasonable discussion up front prevents any of this - Just a phone call to say there's payment problems and that your invoice will be 5 days late will make a huge difference to your planning. Having said that consistent late payments should give you all the indication you need. Try doing some research first and getting a credit check of the company before you sign a contract with them. That's often due cause for respectfully requiring them to change the payment terms on your contract. Talk to your bank about their B2B credit checking offering. You can throw the payment terms on any contract they offer back at them if they telling you they do 30 days payment but their credit rating barely supports 7.

Normally a lot of contract terms in the UK make it very tricky in relation to IR35 - never mind just getting paid. Lots of unprofessional agencies initially reject requests to change the contract; "it's a standard contract we use for everyone and do not change it". It's all bullshit. A contract review by your accountant or legal representative is worth every penny.

I work with other types of organisation directly and although some of these problems are common elsewhere, the attitude towards invoice due dates is not. You've worked hard for your rate and perhaps even worked far away from home to do so, why should getting paid be a struggle?

Sunday, October 19, 2014

Job Board Analysis


I've been working on a blog post relating to the barter of personal information, most of it is unsurprising really but the flagrant disrespect for personal identity seems to be widespread.

An economy of scale where your information is bought and sold is inevitable - whether its your personally identifiable information, the email address you used to sign up to a newsletter or the details you forgot to remove from public access on a social networking site.

This isn't the place for that full post but an offshoot of that research unveiled something that may be of use to others. This year I started using a new sequence of mechanisms designed to trace the flow of information whilst I use the job boards - they're an essential business tool because as a contractor / freelancer it's the easiest way to find clients.

However these sites often require registration and up front disclosure of details - meaning you're essentially putting your details in the hands of a 3rd party. Most of the sites automatically create an account for you the minute you apply for a role, and - despite best efforts from your side - automatically subscribe you to 3rd party offers, newsletters, etc, etc.

Once you've applied for a job you have to log in, uncheck the relevant spam mailer and distribution options and hit the apply button. That, in my view, is unacceptable as it essentially puts you on the spam lists before you get a chance to opt out. Most job sites are guilty of it - most notably JobServe and TechnoJobs.

So you've now applied for a job but at least two organisations have your details - the job website data owners and the recruitment agency. That assumes that your details haven't already gone to a 3rd party for re-use too.

TL;DR

Of the three distinct phishing attempts made in October, they all came from PII which indicates it was skimmed from CwJobs applications or profiles. Had it all come from only one of the accounts I'd make a guess that it had come from compromised data at Harvey Nash but other permutations disproved this.

All three phishing attempts came from CwJobs email addresses which have only been used on that site, which means that either the recruiters or CwJobs - or both - aren't protecting personally identifiable information correctly.

Looking at it objectively it's more likely that the spammers are creating recruiter accounts on these boards and simply harvesting the details, capturing new job seeker update feeds, or acquiring the data more directly. Either way I've stopped using CwJobs altogether.

We cannot guarantee that other jobs boards aren't already compromised but hopefully the dragnet will either help ICO take the case forward or provide incentive to the site owners to review their validation procedures.

I've sent a copy of the blog post to the listed email address of the lawyer named in the spam, as well as the spammers "personal" email address to invite them to respond.

Phishing Explained

You really don't need to read this section if you're already aware, this is more aimed at people who have less experience with the web and email. I'm not writing this to extol any knowledge virtues but because I'm tired of answering the same questions from friends and relatives. Now I can just give them a URL to read.

So...

The aim of phishing is to get you to give up some personal details in order to access your account and get some money - or better, get you to give them money directly and save them the extra leg work. It's not about anything else.

I've got a dead relative in Malaysia and I should contact the Malaysian barrister using his Russian personal email address. Obviously if you want to check the address then having a poke around for the office on street view will show you where they are.

Of course it turns out this particular legal firm actually exists and uses a different gmail account, but that's just paperwork.

Now if by this point you still think this is a potentially viable email with genuine offers you need to re-read the last few paragraphs carefully. Make sure you follow the links in this post (not in your spam / phishing email) and think about it. Any email that asks you for personally identifiable information - Full name, date of birth, mothers maiden name, shoe size, etc... just delete it. If it's a bona fide conversation they'll be sending you a letter or calling you to make contact first. Don't give out any details over email to anyone you don't actually know.

I've included the entire email text in case anyone out there is searching for the same problem, and can get an indexed response based on content.

Thursday, September 27, 2012

Commodity Update

It seems that it's a two-way street - After writing a post this week about tips for handling tricky recruiters, a large section of the recruitment industry itself has outed one particular individual.


Tuesday, September 25, 2012

Information *Is* The Commodity


You're about to set out from the world of permanent employment and embark on contract work. Awesome! You know your tech-stuff and are chomping at the bit to ply your trade as a gun for hire...but are you savvy when it comes to negotiation and recruiters? Sure, you're confident in your technical skills, but do you know how to be a top-class salesperson too?

It struck me recently that there are perhaps less experienced people being taken for a ride by the seedier agents out there. If you've been doing this for some time or have also read the Toe-Rag Recruiter Playbook™ you probably won't be interested in what follows.

All I'd like to do with this post is provide a few tips and explain why some agents might ask some seemingly innocuous questions. After a number of years learning from my own mistakes I've built some very good relationships with particular agents I trust - They've even helped my out by explaining some of these areas, and over the years a few have even become mates.

It should also be pointed out that not all recruiters are used car salesmen, generally it's more likely to be one or two people at a handful of agencies here and there. We each have our own personal preferences about who we like to work with and who gets us the best rate, so I'm not going to insult your intelligence by telling you who to use and who to avoid.

This isn't about naming and shaming either - It turns out the Del Boy stereotypes out there are known to all anyway. A mate of mine (a recruiter) also pointed out that the recruitment industry is there to make peoples lives better - via career and monetary advancement. He's right and he also pointed out that, like anyone, there's bills to pay and sometimes people stoop low to keep the wolves at bay. There's plenty of good websites where people can share their views such as Contractor UK - some particularly good advice across a range of topics and forums.

Before we start though, don't start treating recruiters like cold war-era spies trying to steal the toast off a grannies breakfast plate. Treat recruiters with the same professionalism and respect you'd use for clients or potential new bosses (it doesn't matter whether it's returned, just stay positive and professional). Remember: recruiters are your friends, they're most likely to be the people that'll get you that next job.

Terms and Conditions

Make sure you fully understand the implications of payment terms before you sign a contract. When are time-sheets due? How often are invoices processed and paid? What happens if you miss a time-sheet & invoice deadline by an hour? Are the agency willing to be flexible once or twice?
Ideally look for an agency who accept weekly invoices, pay weekly and don't stipulate daft paperwork requirements like "your time-sheet and invoice have to be in on the Friday lunchtime for the same week".
Once you've signed that contract you can't change it until renewal time looms.
Sometimes you have to compromise to get that rate or a contract to get you commercial experience with something. It all swings in roundabouts.
Another discussion here which may give you some more ideas.

LinkedIn Contacts

Ah, such a good idea.
Ever noticed that pretty much only recruiters write updates on LinkedIn? Sure there's big companies selling stuff, job openings and some great groups but most of the time that recruiter who's just massaged your ego a bit will shortly send you a LinkedIn request.
What you may not realise is that following that they'll probably work their way through your contact list and find your current boss, your previous bosses, colleagues who may be hiring and other potential candidates (i.e. your competition).
It shouldn't have surprised me so much I guess, but when I hid my contacts the next few agencies who sent connection requests called or emailed less than thirty minutes later asking if any of my colleagues were also hiring. Pretty much because they discovered they could't access my contacts or associated profiles.
Hide your contacts list on LinkedIn from everyone and control the flow of information as you see fit. Hide the "Viewers of this profile also viewed..." box in the same way too. It's only used for the same purpose.
This one is up to you, you're potentially offering up information on your own competition.

Job Specifications

This one's a bit trickier as not all vacancies will have a formal job spec. For example, there might just be a company telling a recruiter to find them a Java developer with WebSphere experience. Just be aware that agencies advertising a role that doesn't have a job spec *may* not actually have that role on their books. It's not always the case but they may have used any number of methods to try and get their foot in the door, firing across some prospective candidates to a potential client.
Mind you, there's nothing to stop the agency amalgamating a few existing job specs into one fictitious one so there's plenty of ways around it.
They may also just be trying to fish for candidates to represent for roles that haven't fully materialised yet. Either way ask for a job spec and confirmation of rate / package - If they claim not to have one yet and you've not worked with that particular agent before, be a little cautious.

References

One particularly annoying ploy for a hiring manager is when you get cold calls / emails from an agent you've never worked with, asking what sort of candidate you're looking for with regards a vacancy either you've just filled or have never advertised. How did they find out?
You always get genuine agents you actually want to work with buried under all sorts of tat and unrelated connection requests.
One tactic is to advertise a fictitious role and asked for references from applicants. Maybe a day or so later that role "magically" gets either withdrawn, filled by another agency or the agent "can't get hold of the client" - usually it didn't exist in the first place. However, in that time, the applicant is sent a job spec for another role...But the agent's now got their foot in the door with a new potential client or contractor directed by your references. Granted, that is a worst-case scenario but it does happen.
They may ask your referee for the reference but will tag on a business enquiry offering their services on the end. They may tell you it's a requirement to validate candidates; honest conversations between agencies and hiring managers usually end up with an agreement that an agency can only screen technical candidates so far, the rest is up to the interviewer to assess (i.e. references often have little to do with it).
Bear in mind that this isn't always the case - Speculative applications are very different to applying for live roles. In this scenario if you already have recommendations or testamonials, supply these to the agency omitting the names and organisations of the referees. Often those agencies working on a more pro-active basis will like to create a sales pitch about you, backed up with real-world opinions. This is a great approach for speculative applications on your behalf and has worked well for me in the past.
There is no company in the UK (possibly Europe too) who requires references with an application from an agency. Even government or security-cleared roles with checking processes have a more direct approach to references which are far more formal.
Usually the person at the client organisation interviewing you will ask for references if they're needed at all - It varies, some hiring processes require it post initial interview, some don't at all.
Professional networking sites often have a recommendations feature which is a reasonable compromise (most people are happy to act as referees if they just don't want to make a public recommendation).
You may get into a situation where the agent tells you that they can't submit you for a role without references as it's "a requirement from the client". This is cow poo. Challenge them: Ask them if they're happy for you to approach the client directly as you understand they cannot represent you in this instance due to their own processes.
You'll be surprised how often "all of a sudden" they find a loophole and your resume is on the clients desk for review. More importantly, if that doesn't happen don't reconsider and don't dwell on it. You're almost certain to have a conversation with that agent straight afterwards about another role which "may also suit". If you don't, there's a hell of a lot of agencies out there who will work with you.
Tell agencies who've asked you for this that you'd be very happy to supply a list of referees *directly* to their client when the time comes.


Who Was....

I hate these questions. It's like they're cringing with embarrassment at the other end of the phone for even asking it, just to see if they can get away with it.
You'll be asked who you worked for (sometimes tied in with requests for references), who you worked with, whether they're hiring at the moment or how the business is doing in general.
Don't mention names - or even job titles - This is just another ploy to generate leads / new business by contacting the people you mention in this scenario. It won't make any difference to your application for a role at all.
When you have an interview arranged via another agency be honest about the fact - Just don't disclose which company it's with or who you're going to be interviewed by. Always let them know how it went and where the land lies going forward though. See point #5 in the summary below.

You Don't Want To Work There...

Often when a recruiter knows you're going for an interview they'll ask who it's with, who you're meeting, what kind of role it is, what the interviewers favourite colour is, how many fingers they have....

However, often that follows with something along the lines of:
[Agent] "Well good luck with the interview, I'm sure they'll hire you after spending any length of time speaking to you. If you don't mind me asking, who's it with?"
[Candidate] "It's an interview with Daves Websites Plc in Exeter"
[Agent] "Oh ok, I've heard of them - who's interviewing you?"
[Candidate] "Erm, I think it's a guy called Horatio Hornblower."
[Agent] "Ah right. That's interesting."
-Oscar winning pause and change of tone-
[Agent] "Just so you're aware, I've heard some interesting things about DW Plc, lots of people have left there recently because of the environment"
[Candidate] "What do you mean? Is it really that bad?"

At that point even if you don't believe them it starts making you think. Score one for Johnny Recruiter. It's an age-old tactic and a lot of agents try this at one time or another. For me I see it as an unprofessional mechanism to steer candidates back to their own vacancies. It's a *real* annoyance when you're trying to hire people.
Even if it is the same thing as politicians running negative campaigns against one another,  they're in business to make money from you, the product, so gloss over it and keep the relationship positive. It's just one of those things that's to be expected and it's no big deal.
Try speaking to contacts and getting first-hand opinions if you're getting concerned. For permanent jobs, carefully phrase some difficult questions about working practises during interiews. Disguise questions about how many people have left / joined with topics on how fast the teams are growing, how often people stay late at work and why the role is open in the first place.

If you're a recruiter reading this who's actually tried the steering tactic: Bad dog. No biscuit for you.

Tips and Summary

So as an overview, eight points to consider - Remember it's not a rule book or a doctrine but just some suggestions:

  1. Hide your contacts list from everyone on LinkedIn (or any other professional networking product). Do the same with the "Viewers of this profile also viewed" box too
  2. Never give references to agencies, only ever directly to a potential client. It doesn't benefit you in any way to do otherwise no matter what the recruiter might tell you
  3. Always get a job spec before you hand across too much information
  4. Never disclose who your line manager was, who's job title was what, which directors deal with what, which other managers deal with which area of the business....It's just lead generation. You can always use this info as a bargaining chip if you like as an incentive to get the agent working for you, but that's your choice
  5. Don't disclose the organisation or name of the contact for interviews you will be attending. It's none of their business (they get shirty when you disclose their clients to other agents so it shouldn't work the other way round either). Do let them know you have irons in the fire though, that can help move things along
  6. Any time an agent tells you to avoid or be wary of a particular company, press them for the source of the references and take with pinch of salt. Also realise you should have followed point #5 and slap yourself in the face for not doing so
  7. Never discuss your rate with anyone but the agent and your accountant. Not even your mates or your boss (even though your boss should already know). Bad for business and come negotiation time it'll only hurt you. You never know who your mates' mates are, or who *their* mates know either (the "it's a very small world principal")
  8. Most importantly, be honest with recruiters about yourself, your skill set, what sort of roles you're currently capable of and whether you've been submitted before. You'll only make them look bad and less likely to talk to you again if you don't. That trust relationship works both ways.
If you're reading this and strongly disagree, I'd love to hear from you. The topic is an open book based on both my own experiences and [horror] story swapping with peers.

Conversely, if you're reading this and have your own experiences to add it'd be great to hear from you - Please keep it constructive and informative though :)

Wednesday, August 29, 2012

Preservation, Physics and Psychology


Make sure you're kit is in good order for that time you'll really need it

I've had some time to think and reflect since the frenetic pace of my last permanent role and I thought I'd share some of the lessons learnt over the years. These thoughts relate to hiring and expectation management - Numerous other hiring managers adopted the process I developed due to it's success in finding the right people; I've even been recommended because of it. I spent a lot of the beginnings of my career working at consultancies so I got to see a lot of different IT & development departments.

I took those experiences into the latter half of my career and built on them in ISV's and online gambling & gaming firms. After I left my last employer a number of people there approached me about grumbles and for career advice so maybe if you're thinking about getting on your bike, some of these observations from the last 15 years may help you make sure that bike's in good working order before you need it...

So What's Physics Got To Do With It?

Relax, I'm not about to yell "In the NAME of SCIENCE!!", wave a sword in the air and the lead nerd equivalent of the charge of the light brigade. In simple terms, inertia is simply defined as "a body's resistance any change in motion". So if a body is already moving, that body won't change direction unless something forces it to. For example, if there was no gravity or air-resistance on a tennis ball, Nadal's returns would never bounce in but just continuing to  travel on at their fantastic speed.

That's some pretty boring tennis.

In terms of the people that you have working for you right now, at what point does their reluctance to change career direction become inferior to the options, choices or influence to move to the next stage? They will be the forces that eventually inspire them to change course and jobs, their inertia overcome.

For example, we've probably all worked for companies at one point or another that fail to deliver on promises and end up only inspiring dissent. I'm sure we've all see the kind of offices I'm talking about - The last drops of enthusiasm drain away at around 10am on Monday mornings, where senior management just weren't interesting in keeping you happy, would often take credit for yours & your teams achievements as their ideas - often right in front of you. The kind of places where it's very difficult to conceal what's happening from your team. Your superiors are making your job even more difficult then criticising you for not hitting those moving targets. But hey - that's the same in any company to a greater or lesser extent so we just learn to deal with it better!

A simple exercise in shared ownership and expectation setting for team members can mean that what the seniors do above you is irrelevant to your team members. It can also ensure that senior management get the ammunition to laud amongst their peers and their seniors whilst your people further build a sense of achievement and self-worth.

So let's look at inertia, and that seeming reluctance to take that next step. The deciding factor there is levels of personal happiness.

Happiness Is Not An Illusion

Even your own happiness shouldn't be measured by short-term pressures such as "how do I keep my boss from getting angry?" or "how do I make sure I don't get fired?". Both those questions conceal underlying issues about your relationship with your line manager that you need to review. Maybe you need to think about how to set expectations more realistically, or maybe that boss refuses to have his or her expectations set any differently and you need to define delivery plans differently.

No-one is going to fix it for you - you've got to take charge and do it yourself. Your boss will be impressed if you resolve a problem via initiative anyway and relying on other people for your own happiness is a bad idea.

For example, I could define my own happiness at work measured against certain criteria. So if those criteria included whether I can be in a position where I'm learning something new (or how to do something I already knew better) and I'm able to contribute to the organisations mission statement, that satisfies my own happiness criteria. There's nothing complicated there and it's pretty easy to keep that learning mode switched on.

I've been fortunate enough to work for two great organisations in the last six years who have enabled a massive personal leap forward in both technical and business acumen. My reasons for leaving both organisations were to springboard into a specific career channel on my own for the next ten years, and I'm incredibly grateful to both companies for the immense wealth of experience gained. 

For my personal happiness the problem at my most recent employer was that it's a thankless, hard-working environment where politics are constantly at play - There's someone trying to pull the rug from under your feet all the time, listing all of your smallest shortcomings alongside none of your major achievements to the heads of department and above. Most of the senior management originated at the same group of companies and there's little longtitudinal career travel. However, the amount I learned and the various performance and security concepts I got exposure to combined with the great technical people I was fortunate to work with outweighed all those negatives instantly. Overall I'd actually describe the entire experience as extremely positive and constructive but then I'm known for having a very optimistic approach!

On one project we worked from October through to January missing out Christmas and New Year entirely. We got the project live with 30 seconds to spare (failure would have meant the company ceasing trading in certain countries) and I finally celebrated xmas / new year with friends in February. I really enjoyed the vibrancy and energy across the teams but the level of effort isn't sustainable for any length of time. Some of the developers involved were getting serious grief from wives and partners as a result, others just reaching the end of their tether entirely. Around five percent of the department handed their notices in over the following eight months.

Of course, whilst I could have stayed at my present employer for many years there was nothing there to provide any kind of objectives or markers of success. Crucially, the exposure to new things or improving things stopped over the course of a quarter. I'd already learnt how to do push-ups in space and I'd be stuck in the same career situation for the foreseeable future; fantastic experience but no longevity. It's a shame because the business itself is a global success.

If you've ever read Soul of a New Machine by Tracy Kidder you'll get an idea of what the environment could be like in places. Sometimes the development department delivered requests even the CTO thought impossible to implement, other times we'd fix live security issues that few people seem to have ever heard of. All sorts of people wanted to consult with us ranging from a very large software company from Seattle to security departments in national government. The company has it's own patents, creates relationships with specific ISV's in order to get feature requests and help develop those products. Almost all the companies in the same market sector viewed this organisation as the target to aim for and we were used to building software that would come under attack every minute of every day.

So the inertia here - the reluctance to move on - was big but the force enacting a change in career direction was much bigger. It took quite a lot to make me think about moving on despite an extremely tough working environment with a very high turnover of staff but after going through two or three relationships and having all your friends make some very unsubtle comments your perspective is adjusted. Forest. Trees.

It's a personal thing and defining your own happiness is very much up to you. 

Moving on from recent examples, some places do have an entrenched management structure that all used to work together at whichever organisation(s) they all came from - usually only creating glass ceilings for everyone else, or bring in people who won't question them. It's very difficult to make your way through that structure although it is possible with the right strategy. There's an element of that in most organisations to a greater or lesser extend though, more so in family-run businesses.

A good friend of mine whom I've known for many years went from working in a call centre to working in banks, then on to being an accountant. In his case, happiness is defined as caring about the people you do business with (as well as being able to use his brain!). He couldn't do that in a call centre, and banks generally have too much internal politique for good people like him. It took years but he's happy - it's still hard work but it's the sense of achievement and associated rewards that provide him the next objective.

That inertia was overcome by a desire to improve himself and his quality of life combined with the determination to succeed - An admirable level of tenacity.

Should I Stay Or Should I Go?

Perhaps it's more about the Psychology of Staying - At what point do you assess your own happiness and realise that your current situation falls far short of your expectations? How many times will you grumble about leaving then never get round to it because "the time isn't right"? How many holiday requests will get refused before you (and your partner) start having serious issues?

I think we've all had difficult situations motivating staff where they've seen the grass on the other side (especially when you have contractors as well as permies) and are struggling to justify their current life choices as a result. Your aim should be to take care of their best interests and create more feathers for their cap. Give them something "for free", like a new programming technique or methodology, and you'll see an increase in enthusiasm. They're going to get that "new thing" one way or another, so you may as well get the perceived credit.

An occasional pat on the head, perhaps a bonus or a payrise a little over the rate of inflation may keep someone quiet for a while but eventually it'll be the same situation and same grumbles again. Remember that no pa-yrise is the same as a pay-cut and there's no such thing as a "job for life" in information technology so don't assume long-term loyalty. As an employer, the people that come to you threatening resignations unless they get a pay-rise will only do the same to you again in a year. Making your people feel valued is worth far more than any pay-rise or bonus in the long term (although they can help), assuming your paying fairly for the market to start with. 

Beating people with a stick then criticising them for not being stick-proof is not a good approach. I remember on a particularly large and difficult project being told that I wouldn't be given any project management or architectural resources. I spent some time with my boss explaining that growing the perm team by another 50% in six months, taking care of the BAU tasks and covering live issue support was plenty (along with my actual day job). Doing all the project planning and architectural support within the team wasn't possible at that stage, and wouldn't be until we could hire or promote some senior developers. A massive redevelopment project, in a proprietary development environment on bespoke frameworks was going to be tough enough on everyone..Never mind doing it on our own.

Both myself and members of the team had to work 60-80 hour weeks for over a year to make sure we got the job done. I was denied requests to promote within the team or find senior developers on the market so nominated technical leads to perform the senior dev functions. Kudos to the guys I put in those roles, they achieved an incredible amount and it's a huge credit to them that the products and frameworks were delivered.

Following what became a tricky product delivery I was ironically pulled up for planning and architectural criticism. Don't take that as shifting blame though, it was my responsibility to ensure delivery and mine alone. By the way, that taught me that "I told you so" comments need to be very carefully phrased :)

Back in the world of physics, impulse is defined as force multiplied by time. Essentially, a large force for even a short time creates the same amount of change as a smaller force for a much longer time.

In people-terms, impulse is far more dangerous. One person leaves and starts telling their former colleagues about the benefits (the "grass is always greener" effect). They start making impulsive decisions about their futures that you have no control over and cannot convince otherwise. All it took was a little extra nudge to focus those existing thoughts and ideas. 

It's a visible indicator of your working practises when your people start leaving in numbers, especially in the current market where perm developers can almost name their price.

Sound-Bite Summary

In order to get closer to that state of equilibrium, start at the beginning; the recruitment cycle for your growth or replacement phase. Usually it's better to wait to find the right people - the people that have a particular vocation or love of a job - to fill a vacancy than shoe-horning in a bad fit. Long term it'll save you (and them) a lot of pain. No-one checks all the boxes but if you can find someone with an attitude that fits your working environment and is hungry for it, the situation will be more constructive for both sides. In fact, far more constructive than a star player [prima donna] who needs to be the centre of attention all the time (and whom the rest of your team will probably hate).

Contractors don’t matter - they're just there to see you through until you've built your teams the way you'd envisioned it. That's not being mean or heartless, I'm a contractor myself coming from a  development management and development background and I know where I stand.

Whilst the axiom of "A happy workforce is a productive workforce" rings true, what you're really doing is preparing and training people for their next job. The only choice you have to make is whether or not that next job is going to be within your organisation or your competitors.

Which would you prefer?