Showing posts with label legal. Show all posts
Showing posts with label legal. Show all posts

Tuesday, November 26, 2019

DVLA Statistics - And How to Save £146m over ten years

Information is Free

Since becoming entangled with the DVLA, I'd raised a couple of Freedom of Information requests (FOIRs) and a subject access request (SAR). By law an authority is allowed 20 working days to respond to a FOIR, and can choose to either respond in full; respond in part (perhaps noting another authority which may hold the relevant information); or refuse to respond to the FOIR entirely.

In this last case authorities often hide behind the section 12 requirements, which detail the process to follow where the request exceeds the time or cost limits prescribed for different types of authority. I noted in my previous DVLA post in which instrument of law those limits are defined.

DVLA are set the ceiling of 4.5 man days or £600 - whichever is higher.

The scene is now set for each of the two FOIRs I raised.

FOIR #1 - Budget Information Relating to Physical Post

This should have been a fairly simple call to the DVLA accounts department, in order to get some basic information. I would have been fine with the more detailed item breakdowns being refused or declined, as long as the base figures were provided.

I asked the DVLA for figures relating to both the previous and current fiscal years:
- the DVLA budget for that year
- the amount spent printing documents to send to registered keepers e.g. fines, new V5Cs, reminders etc
- the amount spent on postage / delivery for these items

I expected the fiscal years for n-1 and n-2, rather than current (n) and n-1, as in-flight accounting is unlikely to be available. In the FOIR I was more specific as I thought it would help DVLA scope the request better, and leave less room for clarifications back to me. How wrong I was.

Initially the request was rejected under section 12 as being too onerous, until I pointed out that when working on programme budgets at most of my clients, I could get most of these numbers over the phone whilst I wait. I also pointed out that they'd already responded to my other request with the actual number of documents sent to drivers, which must have involved a similar amount of work (see the FOIR #2 section below).

I requested an internal review and DVLA responded with some of the information I'd asked for.

So the total spend on:
  • all stationary was £1.1m in 2017-18 & £1.2m in 2018-19
  • all postage was £25.9m in 2017-18 & £26.2m in 2018-2019
  • all printing was £14.4m in 2017-18 & £14.2m in 2018-2019
The total expenditure across these items was effectively £41.4m and £41.6m in 2017 and 2018 effectively. Yet they still essentially refused to supply their overall budget for those years. As I couldn't find a reference to this figure anywhere else on gov.uk I was reliant on this single public sector organisation for those numbers.

I then asked them to reconsider their position but expect them to walk away from this request. Their initial response was later than the FOIA allows, and their responses were evasive at best.

You can see the live FOIR here for reference.

FOIR #2 - Document Production and Delivery Statistics

This one went a little better and information was slightly more forthcoming. But it was still a struggle to get basic information from them.

I asked the DVLA to provide statistics / their records for the following:
- The number of physical documents sent to registered keepers
- The number of those documents sent via some form of recorded delivery
- The number of known tracked items that have a "missing", "undelivered" or similar category applied after they have left DVLA

Despite the specificity of the request, three weeks later the DVLA asked me to clarify what documents I was referring to. I clarified regardless and the final (late) response to the FOIR was received almost a month later.

It turns out that the DVLA sent 99,461,763 documents from Jan 2018 to 25th October 2019. Based on 662 days in that period and assuming the report was generated on the same day as the DVLA response letter; the average number of documents sent per day is 150244(.355).

That's a lot of documents. Only about 32k of those in that 622 day period were sent via some sort of recorded delivery, and the DVLA does not track how many of those tracked items were returned or otherwise undelivered. The DVLA did not disclose how much they spent on tracked / recorded delivery, so this is an assumed and unknown uplift on the cost-per-document-sent.

Now if we combine the responses of FOIR #1 and FOIR #2 we can say (quickly excusing my shoddy maths) that:
  1. In 2018-2019 DVLA spend £41,629,644 on document production (excluding 3rd party costs such as GSP)
  2. In 2018-2019 we can infer that in 365 days - and using the docs / day from earlier in this FOIR - the DVLA sent 54839189(.57) docs in this year
  3. Therefore the cost-per-item to the DVLA in 2018-2019 is £0.79
  4. This does not include the DVLA operating expenditure on the processes surrounding this document e.g. hiring staff to manage the processes, interact with the processes and operate processes where necessary, recorded delivery costs, heating, lighting, utilities and other standard OpEx items. The actual cost is probably between £1 and £2 (if the DVLA are operating efficiently).
In the same request I asked the DVLA to explain the QA processes which govern how they ensure the mail service providers (MSP) - UK Mail and Royal Mail - certify that they've collected all the documents produced.

The response on this front have been unclear at best and plain evasive elsewhere. I part of their more recent response the DVLA state:

"Data is input into the DVLA’s systems in accordance with specific parameters,
depending on the type of transaction. This includes a quality assurance check, which allows for work to be appropriately batched ready to send out.
"

That's a very broad description without any specifics, that doesn't really tell us anything at all. What parameters? What QA check is actually performed? They also stated in the same response:

"When a document is printed, it is then tracked electronically through the mailing system. This supports integrity checks until the document is enveloped and transferred to the Quality Assurance (QA) section. Some items of mail may then require reprinting.

The DVLA then hands over the items for despatch to the respective Mail Service
Provider and is reconciled against control document
"

This is more related to the question, and sounds like a proper answer on the face of it. However the portions of sentences I've highlighted should draw attention to the subtle evasion here.

So a document is tracked (per-item?) through the mailing system, so that the QA section can verify it in its envelope. Are they checking every single of the one hundred million items the claim to have sent since Jan 2018?

Finally the point about the "control document" is very vague - is this the DVLA's control document, and one which the MSPs do not interact with? In order words how are the DVLA verifying each letter is accepted by the MSP, instead of just picking up a box or pallet of mail which hopefully includes all the items DVLA has "tracked" to that point?

In fact if we reference a FOIR from 2009, we can see the DVLA admit that the MSP do not verify each item in the batch. I've asked DVLA to clarify a point relating to this as the answer seems a bit more thought out than the one a decade ago. I suspect they have no way of verifying that the MSP is collecting all the items they've printed (so can't entirely blame the postie for lost mail).

You can see the live FOIR here for reference.

Next Steps

Even if my earlier assumptions for calculation were correct (which I know they aren't), the minimum being spent per item is 79p. It's far cheaper for the DVLA to send a prospective fine, on the chase they can intimidate someone into paying than it is to actually review the case properly. It's a cash generation game.

I've largely exhausted options with FOIR as DVLA are likely to essentially ignore further clarifications on the request. Together with their breach of the Data Protection Act (DPA) I'll be putting together a formal document for breaches of FOIA to the regulator, ICO. This complaint will hopefully ensure the DVLA directly answers any outstanding questions.

A grey area has formed between the FOIA and the DPA where automated decision making affecting a living person is at the forefront. GDPR Article 22 deals with ADM - more specifically ensuring that adequate protections are put in place. These protections are aimed at ensuring that an individual suffers no undue harm. In fact Article 22 Section 3 states: "...safeguard the data subject’s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision."

It appears the DVLA has breached this if ADM was at the core of the decision to fine and prosecute me originally. We cannot say that the DVLA has delivered on this requirement by virtue of pressing for prosecution in a case which it later manually determines not to have merit. This is not covered by the FOIA and must be considered by ICO.

In parallel to that I'll be raising complaints with DVLA directly, as was the suggestion of the DVLA prosecutor in the case I won. This complain will focus on recovering damages and distress.

IR35

I can't resist a poke.... the IR35 changes in 2018 will have killed off any IT projects at DVLA reliant on a contingent workforce of consultants. Those same consultants would have been able to build DVLA a digital presence which would remove the need for documents across a conservative estimate of 50% of use cases. A web-based dashboard with services to encapsulate authentication, authorisation and enable notifications to DVLA such as SORN. More and more people have access to the internet via smart-phones, less and less have no access at all - there are still post offices for the rest of the forms.

Eventually other businesses would want to integrate with DVLA data sources, as insurers already do via MID. The motorists data is already held by DVLA in order to support the production of drivers licenses, and therefore the authentication model should focus on driver-based logins. Data security will be key here considering the kinds of information involved. Ideally using MFA such as smartphone authenticator apps should provide a welcome layer of security, and open-source libraries are available to achieve this. The data layer is the most complete layer as it stands today.

Fines, penalties and reminders could all be dealt with in the first instance via the dashboard, with email notifications send to drivers when new 'documents' are sent to them by DVLA. Delivering these digital journeys will need the most engineering & testing effort. The DVLA claims its processes are largely automated so the integration architectures will need to be carefully designed - and probably brought up-to-standard. The DVLA already accepts payments for car tax online if you have a V5C or V11, so existing authentication and payment API's will need to be re-used and expanded upon.

A project of one feature team working on a digital dashboard, authentication model and microservices based on COTS would cost up to £750k for six months. That's a large feature team costing btw, probably one which would operationally be split into two agile teams sharing architect, BA & programme manager. Each team would have it's own scrum master, engineering and QA peeps. Software and licensing for SaaS, for example might stray into the £1m purchase, and £500k annual licence at worst for this kind of thing.

So making some wild assumptions and adding bloat as it's public sector, I did the following in LibreOffice Calc.

Large assumptions ahoy


I made the following assumptions for this:
- I don't know what architecture would be deployed that is compatible with Gov.uk strategy, so upped the IaaS costings for services, services and networks to 75k / year. This increased cost assumes redundancy and performance needed to support the traffic from potentially 90% of motorists in the UK
- I assume the Gov.uk is continuing with vendor-locked arrangements with Oracle, and Oracle are strong-arming Gov.uk as they are with anyone else. Ideally I'd focus on an open-source approach with something like RHEL, Apache, ELK and PostgreSQL, but I don't know how the x-charging works so assumed a DVLA-owned license cost of half a million per annum; plus new costs of authentication and integration of existing Gov.uk payment gateways
- Purchase of cloud and dedicated tin combinations, plus new infrastructure or services hosted for DVLA (assumed re-use from other Gov.uk departments such as MCOL or local government)
- A feature team costing based working over a two-and-a-half year delivery period; including 2 year build and test continual drops, with six months post-live warranty
- These are finger-in-air-estimates for design & development knowing nothing about what really goes on behind the scenes at DVLA

Any of the programme managers I've worked with at my past clients would've fallen off their chairs at those numbers and assumptions, but that's because they work in pragmatic, efficient and competent environments in the private sector.

So based against only a 50% reduction in printed documents - on the assumption that proportion of people register for paperless DVLA services - the DVLA expenditure on disclosed production would be £20,814,822 (ignoring increases with inflationary-associated costs). That's the cost of documents that no longer need to be printed and can be provided direct-to-drive with assured delivery. How many problems does that solve? :)

So the DVLA would save around £20m per annum OpEx, and expend £11m CapEx on rolling out the digital presence? Ok so those savings wouldn't be fully available until year 4. Over the ten year projection that's £145,703,754 cost savings on direct document production alone, versus a £7m run cost estimate over the same period. Still £137m can pay for a lot of tour buses for Boris Johnson.

How to achieve this? Get HMRC on a leash so they no longer exceed their authority under the law and stimulate what's left of the British economy by encouraging the vibrant, consultative small business.

Or keep flushing money down the drain and drive the skilled consultancy workforce out of the UK. You choose.

Wednesday, November 06, 2019

DVLA

A Bit of History

After almost a year of DVLA-driven (ha ha!) nonsense, it's now safe to discuss in the open.

Last year my employer adjusted it's approach to national travel, and essentially allowed me to use rentals to cover the lengthy journeys to / from client site. At that point we were working with a client in Norwich, which isn't very easy to get to on public transport - it was far easier to commute once a week by road.

Everyone's a winner - I get a nice new-ish car every week I'm supposed to be on site, and hand it back when I get back to the Midlands. I don't have to pay for wear and tear on my own car, and it's very slightly cheaper for the company.

So I had my own car sitting on the drive almost entirely unused for a couple of months in the lead up to xmas - what's the point of paying tax and insurance on a vehicle I literally don't use? None. So the obvious route is to SORN the vehicle and let my insurance policy lapse at the end of the year. Of course because the DVLA are involved nothing is that simple - when we moved house a few years ago they failed to send me the new V5C, and only occasionally send me V11s... 2018 was a no-V11 year as it turns out.

What does that mean? Well I can't use the limited digital facilities provided by the DVLA to register the SORN, and - using their own instructions - get a V890 hard copy ready to send. Simply paying for tax requires all sorts of documents, which prevents Samaritans simply paying random vehicle tax (which would happen all the time of course), but SORN is equally baffling. Why not use the license ID of the registered driver? The DVLA have this information too.

From the DVLA website


Of course being a paperless business we've no printers so I have to get to [Insert High Street Stationary Brand] and get the forms printed. Already cost me a quid because the DVLA can't deliver documents properly!

We were off on a holiday to see family in Australia for most of December and some of Jan, so I wrote a letter to accompany the V890 and we dropped the envelope in the postbox on the way to the airport. Of course not being familiar with the process I was expecting no further paperwork

And So It Begins

We had a great time catching up with family in Oz, and returned refreshed (but shivering) back to the UK in early Jan. Back to work, off to client site and so on. Until about the 15th of Jan, when by some miracle a DVLA letter arrived. I was vexed and perplexed, however, that they were claiming my insurance had lapsed and they hadn't gotten their cut.

I just assumed that my original V890 & letter were probably being used to mop up a coffee spill on someones desk in the Enforcement department, and sent a duplicate V890 and letter back to them, carefully stating that I'd already sent one on the 14th of December.

It all went quiet.

Too quiet. Watched too many films to not know that was perfect time for an ambush. January flies past, as does February.

Then at the beginning of March I get another envelope from the DVLA, which contained a nice little SORN acknowledgement slip; I didn't think much of it at the time but the SORN effective date was 14th December 2018, but the printed date on the slip was 8th March 2019. I simply assumed that some paperwork took them a while.

Of course by the time the unexpected SORN acknowledgement had arrived, I was considering selling the car due to it's lack of use. No further carrier pigeons arrived from Swansea and I eventually sold the vehicle a few months later in August. The new keeper got their V5C - I wasn't bitter about not getting mine over the last few years - and the transaction was complete.

The Back Swing

It was never going to be that simple, was it? I'd returned from a trip to London on Friday 13th September at around lunchtime, to find David Wills stood leaning against his white van on our driveway.

"Are you the owner?" he asks.

"Who are you?" I ask.

He keeps asking if I'm the owner and I keep asking who he is - all of a sudden I'm thinking of the time I worked at a debt management business for some reason. I smile and suggest he introduce himself, which he then does. We shake hands and start talking.

It turns out he represents Marstons and is here to collect on a debt. We have a professional and calm conversation - he allows me to take photos of the information he has on his tablet and but has no paperwork to show me. Turns out I'd been convicted of a motoring offence in March or May and a fine had been levied.
 
A little advice for you if you find yourself in this situation - if you're 100% certain there's a mistake, you've not received any of the paperwork yet and you'll be getting a refund back, pay the bailiff and explain you'll be having the conviction set aside. They will have to refund the entire amount and it's dealt with there and then.

If you're not 100% confident and you haven't received any of the notices in the post, ask to see the warrant. If the bailiff can't produce the warrant, ask for the phone number for head office and speak to someone there. Don't open the door or get your keys out. If at all possible walk away and don't return to your door for another few hours.

If they don't have a warrant to seize goods on them (which they usually don't until after the first visit is unsuccessful), or won't prove it you shouldn't let them in. However if you've ignored any notices it's already too late.

I was furious at potentially having a serious issue getting my security checks failed and (if this matter had gone to a county court for recovery) potentially failing a credit check too. My SIA license might get cancelled or blocked from renewal. This would be disastrous for employment as no client would allow me on site. It wasn't David's fault, he's just the guy in the van today.

I also knew with absolute confidence that there had been a breach of proceedings and that I would be able to get the conviction set aside somehow. More on that later. I got home about £660 lighter then started prepping and researching.

More worrying to me was that I couldn't tender any new bids for work for my company out of fear that the BPSS / CBR / CC checks would fail. That would fail the bid instantly, and likely ruin any potential future relationship with parties involved, which could be disastrous for my business.

Fighting Back

After stewing and ranting over the weekend I got my extra strong coffee from the top shelf Monday morning, and set to work.

First up was a call to Marstons head office - partly to put them on notice not to spend that cash, and partly to see what information they could provide. They talked me through the details they had - an original balance (fines) of £350, their fees of £310; a sentencing on 13th May 2019 and on 29th of August Marstons allegedly sent me a notice of enforcement.

What's chilling here is that I can live without the car tax rebate check arriving and I expect physical post to be largely unreliable; but I don't expect to lose so much critical post. I honestly don't believe it's the postie as there's huge organisation behind him with many faults. On the flip-side of that I also realise that with the details Marstons had been provided by DVLA, they could have found more reliable contact details within sixty seconds on a web search. My name is unusual and unique so there's an extremely high probability a PM on Twitter is reaching the right person. e.g "Are you [my full name]? If you are could you call us please so we can verify who you are and talk about a serious situation."

It's also interesting that I suspect the collection agents were originally going to probably look to seize the vehicle as payment, but when I sold it at the beginning of August unaware of all the events that had happened, that loophole was closed. I wonder if that precipitated the doorstep visit?

Regardless I got the details of Hereford magistrates court and tried a call to them and "HMCTS". Hereford clerks first tried to pass me to the county courts, which just isn't appropriate in a criminal case. Then I asked them about HMCTS and they didn't know what I meant. Some google-fu later and I'm speaking to HMCTS. In Birmingham.

A real legal tour of the region.

The clerks there were pretty patient, probably happy to speak to someone who wasn't in tears or swearing I suspect, and helped me file for a statuatory declaration (SD). The SD is the medium by which a conviction and and following actions are unwound. If you've simply ignored the situation I'm afraid this isn't going to do you any good - it's designed for those scenarios where communication has broken down and service has not been delivered.

The last thing I had time for on the Monday was to venture into more familiar territory; raise a SAR and a FOIR. The SAR was simply to get the DVLA to send - in electronic format to avoid delivery "issues" - all events, documents and details associated with myself and the VRN (whilst I was the registered keeper of course) from November 1st 2018 onwards. Key bit of information we'll come back to that data point.

The original FOIR gave me an opportunity to ask the DVLA how many items are produced and "sent" to registered keepers over a given time frame (since Jan 2018); how many are tracked and how many go missing. Around 0.03% of all items appear to be tracked and they simply don't keep records of how many of the tracked items are returned as "undeliverable". The request isn't yet complete and I've asked for clarification after the authority dodged some questions e.g. what QA is done to ensure the produced documents are all collected by the mail service provider (MSP), and where in the overall process are the most documents lost.

DVLA have committed to some form of response by the 25th of November, and you can see the request in full here.

Back to my week of investigation w/c 16th September; and over the next couple of days I'd spoken to HMCTS in Brum, and had managed to get an SD hearing in for the 27th of September. I was still livid at the DVLA.

I also thought about the follow-on activities of the SD, which I intended to plead "not guilty" and have to mount a defence. I couldn't find much through the usual research channels other than to some cases reported in the press, where the DVLA had lost during the application of common sense by the courts. Not sure they're precedents at that level and the DVLA didn't appeal so they're anecdotal at best. However to me it highlighted that similar situations were happening in 2010 as are today. One of the cases involves someone else using FOIR to forcibly extract the facts from the DVLA too.

Most interesting to me out of all of these is a FOIR made by James Collins in 2009, for almost exactly the same set of circumstances as I've seen. In fact the DVLA appear to have even lost items sent by recorded delivery - after they've been signed for by DVLA. I was impressed that Mr Collins had held DVLA to account but also amazed that the net result showed the DVLA were unable to ensure produced documents get delivered - and that received documents are processed outside of relevant QA processes. For me this was key to the whole problem.

In his case, Mr Collins was found not guilty with the court agreeing that he had fulfilled his obligations; that the DVLA has no statutory powers to compel drivers to chase paperwork sent in. It is firmly the DVLAs responsibility to apply common sense rather than prosecute. Even in 2009 there were calls for the DVLA to become transparent and provide an independent appeal system.

Clearly nothing has changed a decade later. At this point I'm beginning to see the scale of the problem and create a second FOIR focusing on how much the DVLA spends on all its postage and stationary. I wanted to understand how much of the DVLA budget is spent on sending and receiving (processing inbound) documents in order to balance the initial assessment on their document processing errors.

I asked the DVLA to provide their budget for the previous and current financial periods; as well as a breakdown of items such as envelopes and document printing relating to registered keepers. On the 25th of October, the DVLA belatedly respond attempting to claim the information was too difficult to acquire. I call cow poo.

I know that if I'm defining costs or doing programme budget projections for my clients and need some stats from their finance teams, I can get almost all details whilst I wait over the phone. I challenged the DVLA to reconsider their response with an internal review and you can see the latest on this one here.

The Defence

So a couple of months on in November and progress has been made. The Birmingham Magistrate agreed my SD, entered my "not guilty" plea and had the previous conviction and fines set aside. The moment I explained that I'd sent the V890 in twice and even had a back-dated acknowledgement the atmosphere in the courtroom changed. Immediately the intention was to set up a case management hearing, rather than go straight to the trial hearing. The magistrate was even kind enough to delay this CM until after the dates the DVLA claimed it would respond to my SAR and FOIRs.

The DVLA eventually responded to my SAR using a secure email system - quite why they don't use this for more use cases including replacing postal SORN's is mind-blowing. Of most interesting to me was that whilst they provided the copies of the documents specifically associated with the case (and nothing else), they provided the timeline as a reference.

This in itself is damning. They acknowledge receiving my duplicate SORN on 21st January 2019. The next date is the 1st of March... where they note that the V890 was ..."resent to Vehicle Input [sic] as they may not have been sent as previously stated.". Quoi???

Hang on so they received my second V890 and admit it took them nearly six weeks to pass it from the Enforcement department to their own VI department to update the record? Hmmm. More interesting is that, a week later when VI actually process the V890, this update is either not noted by the Enforcement department in charge of working with DVLA prosecutors, or automated decision making (ADM) is at play. 

Bear in mind that there are provisions of data protection law which require safeguards in ADM for example GDPR Article 22 section 4 generally, and DPA 2019 Part 2 section 14(2) relating to "significant decisions".

Therefore either the DVLA have failed to deliver an ADM solution with safeguards it is required to by law, or the staff of it's enforcement division are trained to focus on fines and revenue rather than the application of common sense. DPA-breaching systems or inadequate staff?

According to the timeline, the DVLA prosecutor then appears to continue with prosecution in my case, as I hadn't paid a fine I had no idea at the time was allegedly due. For an infringement the DVLA had already acknowledged did not exist by pre-dating my SORN to 14th December 2018.

My defence centred around the fact that I am not obliged to chase the DVLA, nor do they have any statutory power to compel me to possess a valid V5C (as long as the registered keepers details are up-to-date) - for which they charge £25 for replacements. Which they lost to start with. I even sent them a request for a new one with cheque a couple of years ago. Cheque wasn't cashed and I didn't receive a new V5C either. So the only route left open to me was the postal route I'd used. Their direction, not mine.

The evidence provided by the DVLA themselves paints a picture of a disorganised and unreliable document processing approach, which is far from fit for purpose.

I also focused on the fact that the prosecution could not say with any certainty that the warnings, notices & service documents had actually been sent - nor could they or their MSP's prove that they had.

To the contrary - the DVLA appeared to employ bullying tactics with the sole aim of increasing revenue, rather than applying a pragmatic approach which allows an independant review & challenge process - without utilising debt collectors and the courts. I collated a 23 page document of skeleton arguments and evidence, which contained numerous admissions by the DVLA that they simply had no idea how many documents were either received by their recipients; or processed correctly once received in Swansea.

Therefore the prosecution had failed to adequately notify or serve single justice forms, after losing my original SORN and attempted to criminalise me for their mistake.

After review from a legal professional, the situation looked extremely promising for my plea of not guilty to succeed. I expected to be in a position to ask the court to make a costs order in my favour if I won. I also expected that if I lost arguing my own case, I would request leave to appeal on the grounds that there was such a substantial amount of documentation to support the case that I would need a proper lawyer to organise and represent it properly (essentially the appeal would rely on evidence not seen previously thusly new evidence). Cases on appeal can unlock awards for legal fees amongst other things, which can be a useful weapon to wield.

Outcomes & Reflections

Ultimately I never got the chance to have my day in court.

I'm not sure if word had reached the prosecutors office of the FOIRs and SAR, or they could just plainly see that the Enforcement department had tied themselves in knots. They withdrew the charge - although the Birmingham Magistrate said I "must attend" the case management hearing in Redditch, and I wasn't about to start trusting the DVLA when they claimed I "did not need to attend".

So I turned up on 4th November 2019, and the usher let me know the case had been discontinued. I was able, however, to speak to the DVLA prosecutor John [Dursely / Dyson? - Apologies I didn't take note of your name]. He brought his laptop in and confirmed some of the details, explaining that a colleague had reviewed the case after the SD was cleared and decided that the "pragmatic approach" - seeing that I had submitted the SORN after all - was to withdraw the charge. When the prosecutor attempted to show me that they'd sent warnings in December 2018, it occurred to me that the SAR response had omitted a lot of events, documents and data. It took the prosecutor all of a few seconds to find this information whilst we were talking.

I only got a brief look at his screen but it appeared to be either an Oracle Forms or VB application judging by the button implementation and layout.

I didn't say much in the room at the time but I suspect they realised I wasn't going to drop it, and show that they were just as culpable as they had been ten years ago in a public courtroom. Perhaps Mr. Collins' case has stuck in their memory. Better to spend their time on a case where actual criminality may have occurred.

HMCTS sent me cheques for the refunded fines and fees; I sent Martsons an invoice for the rest which they transferred back to me in relative short order. However I spent just under five man-days working on the investigation, putting together my own defence; around an entire working day traveling to-and-from various hearings; around £60 on printing my legal documents for the hearings and so forth. I haven't received a rebate on prorata-ed car tax from December 2018 nor August 2019 from the DVLA.

In all likelihood I'll  raise a complaint and offer the DVLA the opportunity to compensate me for damages and distress caused; I'll have to think about the potential loss of earnings. I wonder how many of the tens (hundreds?) of contract notification emails I'd watched throughout September, unable to apply a bid and the resulting potential loss of revenue.

I'm also still waiting for the rest of the information I asked for in my SAR. Two chasers and no further response. So that's one refused FOIR (assuming DVLA refuse to revisit), one failed SAR and a questionable data practice to discuss with ICO in coming weeks too. I've won the case but I'm not going to drop the data protection issues.

The DVLA are always so forthright with us motorists yet seem unable to discharge their responsibilities under the law. I get the distinct impression that had I not fought it I would have been fined for no reason.

I'm not sure how much they spend on filing fees for cases they don't win, possibly something for a FOIR on another day, but this appears to be a massive overspend of taxpayers money. Why not have an independent arbitration panel that gives motorists a fixed period to challenge a fine? If prosecution is the result the date of the offence won't change. Mind you, it won't make a difference if you don't ensure the documents are delivered. Why aren't they storing the email we give them for notification of successful payment of tax, for use with warnings and similar?

The DVLA really do not have any legal power to compel you to chase them - once you've fulfilled your responsibilities properly everything that follows is their own doing. I'm not suggesting you take any chances but certainly don't let their bullying tactics over fines sway you, their inbound call centre is apparently only there for payments and collections. Not SORNs ironically.

Challenge them all where challenge is due. Although if you've genuinely just messed up then I'm afraid that's on you!

Working in digital and IT industries, I'm also amazed that the DVLA hasn't provided a more efficient and sustainable approach to document management. Some things you literally cannot do online or in the post office.

Perhaps this is a good time to note that the disastrous IR35 Intermediaries legislation decimated the pools of project-based consultants in public sector organisations; which may explain why their IT hasn't moved on much in years.


Monday, September 30, 2019

iProfile / Vertifi / Jobzooma at it **AGAIN**??? (Updated)

Updated 23rd November 2019; Originally posted 30th September 2019

Amazingly the Jobzooma team are still at it.

After tendering some applications for contracts earlier today I had an email from our old friends Jobzooma. I can find no trace of any connection between the potential clients I emailed or how they acquired my details, yet somehow I've sent them my CV???

Yeh but no
This isn't how to deal with consent - there's no opt-in, there's no request about whether I've asked for it. The email asks you to click a link to verify that they have the right data, which I'm absolutely not going to click. That could be interpreted as explicit consent for them to continue storing my data - I've never done any business with them!

Have sent chaser email but be warned - they're still at it. If you read the previously linked scam alert you'll realise why you're better off avoiding altogether.

I've asked them where and how they got the alleged CV and they've acknowledged receipt of the request. Will update when I have more but on the face of it appears to breach PECR and DPA 2018 [inc. GDPR 2018].

It's no good asking for consent after you've already acquired, stored and processed the data.

Updates

I finally received a response from ICO, in which they stated that:

"We have considered the information available in relation to this complaint and we are of the view that Jobzooma has not complied with their Data Protection obligations. This is because you did not receive an appropriate response to the data protection concerns you raised. We consider this to be an infringement of the legislation.

Subsequently, we have written to Jobzooma, via the Data Protection Officer, to explain that we expect the organisation to review your complaint and take action to resolve any outstanding matters.

We have issued guidance to Jobzooma as a result of your complaint and expect they will be in contact with you in due course. Thank you for bringing your concerns to our attention.

This complaint will be kept on file and this will help us over time to build a picture of Jobzooma’s information rights practices.  We keep a record of all the complaints raised with us about the way organisations process personal information.  The information we gather from complaints may form the basis for action in the future where appropriate.
"

I wasn't happy with this response because it isn't a strong enough message for a repeat offender, and also I've recieved no responses from Jobzooma at all. I asked the case officer to look into further evidence I provided, and examine the linkages evidenced between Vertifi, Talent Spa and Jobzooma.

I asked the case officer to then review the outcome and proceed with a publishable decision, so that Jobzooma would be the target of ICO enforcement should they offend again.

That reply to the ICO case officer was sent on 4th November 2019, and I have not yet received a response, other than the auto-acknowledgement.

However it is good to see ICO confirming my suspicions that Jobzooma are / were acting unlawfully.

I've noted further updates in November 2019 on the scam alert post on the portal.

Thursday, September 28, 2017

Mash Me A Spammer

Match Me A Job directors Ifran and Tahir

One thing my friends and family know for certain is that when they have issues with spam, data breaches or dodgy looking emails, they can always come to me for advice.

In some ways it's like being that member of the family who can "fix laptops" - something I've worked hard to disassociate myself from over the years. However when I get spam myself I'm often a little puzzled, having taken numerous steps to avoid subscribing, being implicitly opt-ed in to or otherwise engaging with spammers.

This particular case involves my use of Jobsite.co.uk - an online jobs board who seem to have struggled in the past with data protection (in comparison to platforms like Monster). I added my details as a contractor looking for work and regularly poke through the jobs listings for suitable contracts.

What I can reasonably expect from this is - and according the general terms and conditions of such boards - that recruiters advertising live roles might grab my details and notify me of roles they have. They might store my details so that if that role doesn't suit a future role they might have will. That's all above board as far as I'm concerned.

This is important - these roles are live roles offered by the agencies on behalf of organisations. The distinction is that a jobs board provides the interface between candidate and agency (or directly from hiring organisations).

The standard (happy path) use of jobs boards looks like something like this:

Normal jobs board process - Click to enlarge

The Washing Machine


Match Me A Job however - and apparently the directors' other companies - do not fit into this paradigm. They scrape candidates details from Jobsite.co.uk and then absorb them into their "client" database. This may possibly include the entire set of organisations related to the MMAJ directors. MMAJ are not yet approaching the same league as other idiots such as My Job Matcher - but they appear to be trying to make a quick buck in similar ways.

Interesting business model: Instead of marketing, getting exposure of your brand and working at improving the corporate identity through direct engagement... they're essentially scraping Jobsite's candidate database and using it to create a new jobs board / platform as a competitor. Easier to get private equity partners to buy your company with a much bigger candidate database...

Jobsite seemingly take little interest when companies like MMAJ and MJM steal their candidate DB are reported to them. Normally they tell me that "they have no control over what the recruiters might do with your data", apparently unconcerned about someone creating a competitor to them from their own data. Monster, however, take a much dimmer view and have sanctioned people in the past for the same. As do ICO.

Back to MMAJ.

They then use other jobs platforms - like jobg8.com - to mesh the candidate keywords with the jobs on those platforms. Any results are then sent to the candidate. Note: These are not live roles offered by MMAJ or jobg8.com - they are offered by other recruitment agencies, and I'm not convinced that some of the agencies know their job ads are on jobg8.com a lot of the time. MMAJ don't actually have live roles nor are they allowed to do this given the specific consent provided when I subscribed to Jobsite.co.uk.

The diagram below shows how the flow of actual consent (c.f. data protection and marketing consent from a data subject - from people like us) in this situation:
The reality - everything outside of the primary Jobsite.co.uk platform in this case is unlawful
These emails are sent from fictitious MMAJ recruiters who's names are manufactured from a list. None of the replies I ever sent back to them ever received a response and none of the filed accounts for the company reflect employing so many people (even on a contract basis).

In fact, when I sent various requests and notices to them via email I selected around 10 recipients plus their info@ and Irfan's email address - All but the info@ and Irfan's address returned "Recipient unknown" messages.

One might have expected that these unsolicited messages would actually be useful had all the roles actually been live - in fact all of them were expired by the time the links were sent. An example below shows a totally unrelated job role (I'm a Solutions / Enterprise / Business / Data Architect working mostly in the financial industry), from an agency who I've actually worked with in the past.

Url shows Jobg8.com and the mailshot shows MMAJ's logo. Link clicked within 10 minutes of receiving the email.

Example "job" link from MMAJ gets you something like this - Click to enlarge
If it's a bug, no-one could have reported it as all the MMAJ 'staff' email addresses return "recipient unknown". I suspect no-one reported it and no-one wanted it.

By this time though, your name, address, DoB, entire employment history and possibly other details (depending what you decide to share on your resume) are now in the hands of a string of organisations monetising said data. In fact if were being more cynical I might suggest that this is one of many data laundry enterprises, churning out data to be monetised.

When I was caught in this particular machine cycle I received over 100 emails in the space of a few weeks, all for roles that were almost completely unrelated and all unavailable.

After being the recipient of attempts to breach systems and data stores over the years I'm more inquisitive about emails from strangers that seem to know a lot about me.

Data Protection


MMAJ essentially refused to answer my SAR - the only time they actually attempted to fulfil it was after I lodged a case in the small claims court. That lack of response was a breach of the requirements of a DPA section 7 request / notice. 

PECR paragraph 22 requires that an entity acquiring personal data for the purposes of direct email marketing must first acquire the explicit consent of the subject; prior to the sending of any unsolicited marketing messages (which a job alert is). Because I subscribed to a specific jobs board with the expectation to receive messages from recruiters about their own live vacancies, no consent was in place for MMAJ.

Even the DPA requires explicit consent to acquire, store and process personal data (many sections in the Act to refer to) and MMAJ failed to acquire this consent for the purposes they actually enacted.

The regulator, ICO, also enforces non-compliance with registration as a data controller - two of the companies operated by the MMAJ directors are registered (ZA110541, ZA110536) but not MMAJ itself. One of my companies is a registered DC because of the personal data that is sometimes acquired during the course of investigation - I know from experience that regular information and update mail shots are available directly from ICO, and you have an option to sign up when you first register as a controller.

A company who routinely scrapes, stores and shares personal data should certainly be registered. MMAJ's directors operate companies which had been registered for some time.

Any which way you want to spin that, the directors are responsible and aware of their obligations.

MMAJ's Position


Only in their filed defence did MMAJ reveal their process and essentially answer the SAR I sent:
  • They admitted scraping the personal data from jobsite.co.uk - although they claim it was for the purpose of "recruitment", not offering live job roles themselves; and despite effectively entering me into a subscription process which I had no say in until some time after the fact
  • They claimed I did not avail myself of the unsubscribe link; however they didn't have consent as per PECR in the first place to send the emails with the links in them, nor is it best practise to click links in emails you've received from persons unknown
  • They claimed I'm not a genuine job seeker - which was amusing. In fact they claimed I'm a sadistic opportunist. As a contractor of nearly 20 years experience I suppose some would consider me mercenary; I'm quite an aggressive racer when I compete in a kart too, but MMAJ clearly wanted to avoid the actual issues and enter into a mud slinging competition
  • They ignored my emailed SARs and NBA for months but replied when the paperwork was served; yet claimed to be essentially pro-active in their response
There's always a case for reasonable exception - that's the whole point of a legitimate jobs board. What we should not have to stand for is being subscribed to services (and spammed as a result) which we do not want, nor were consulted about.

The entire defence seemed to be based around the total lack of accountability for which a company handling personal data should have. The law apparently doesn't apply to them - they're special.

B2C-style recruiters are the more typical business models, but the most concerning development of late is B2B recruiters. They're outsourced agency staff who may not even work inside the EU (therefore breaking the stringent data protection laws of the EU and UK). Agencies out source their searches to other agencies, who presumably take a small percentage for candidates that eventually get a contract or role.

Corporate Entities


From the companies related to the two directors of MMAJ, Irfan Lohiya and Tahir Islam, seem to exchange recommendations for each other and share infrastructure. Not unusual and a good cost mitigation option.

Tahir's LinkedIn profile lists him as a case handler for Lloyds Bank, although he may just be a silent / investment partner. All correspondence relating to the litigation was signed by Irfan who seems thick with links to recruitment - working for agencies as per his LinkedIn profile whilst running his own. Nothing really wrong with that though.

Astoria Green Executive Search, Jobm8 (not jobg8.com),Total Jobs, Green Recruitment Solutions, Top Resourcing, Proficient Outsourcing Ltd and MMAJ are the companies one or both directors own / operate - only Jobm8 and MMAJ are nominally shared.

That's a lot of very small companies - question marks for me arise relating to; if MMAJ has my data, who else does? With idiots like MMAJ you shouldn't rule anything out.

Summary


In the end I had an issue with the postal deliveries, meaning I missed a lot of paperwork relating to the case. I couldn't therefore press the claim home and the last I'd heard MMAJ refused to engage in mediation pre-trial. It's a shame because I'd created a retrospective data consent agreement and wanted to see it enforced at district level. Of course, there's no guarantee but I could easily disprove each statement of the defence - some of which by using their own evidence.

The amount of time you have to spend on these things is immense - unless you're a lawyer being paid to write and argue the case there's virtually no financial benefit to it. What I do for a living is investigate (in other fields) - and that's where the commonality is for me, and that the regulator is often swamped with other cases from local government.

But also because there are so few - if any - people actually raising awareness of the growing problem in data protection.

It took direct legal action to force MMAJ just to answer my SAR, and even then it was without any acceptance that they'd actually broken the law. If someone hold their hands up and says, "Ok - yeah. We were wrong - really sorry and it won't happen again" it's generally a reasonable situation which needs no further prodding.

In May 2018 the British equivalent of GDPR comes into force so the additional weighting in favour of explicit / DS enacted consent; the types of activity MMAJ admitted to (or were observed enacting in cases where they denied it) would net them massive fines and potentially criminal convictions. Had I engaged ICO over the matter they could have invoked their powers within the law to review criminal prosecution against MMAJ (if they'd had the time amongst their already mountainous case loads).

I've worked with a lot of recruiters over the last 20 years and there are some real diamonds out there. Recalling past conversations with recruiters I've known for years as well as new firms who made a silly mistake with their data handling - all it takes is a five minute phone call to resolve. However there's also some real used car salesmen holding the reputation of the industry back.

There's so many of them though.

Thursday, September 07, 2017

Très Européen


(Before anyone says / thinks anything - I'm Pro-EU. Post title not a dig at Brexit insanity)

Europcar sit within an industry which makes it's money but getting people to pay more than the cost of a car for borrowing it. It's a good business model even with the shadier parts of it's industry. They're relentless spammers too - they provide no option to explicitly opt-in to marketing messages when you purchase or sign-up for their services (not even an explicit opt-out until after the fact). We'll come back to PECR in a moment.

Background


Back in 2015 I rented a car from Europcar - there was no issue with payment, no problem picking up the car, nor returning it at the end of the rental.

All well and good it seems? We've used them since on holidays in Cornwall too. Again... all seemed fine.

Last year I needed the same service whilst my own car was in the shop - booked the rental online, paid upfront, scheduled the pick up date for the Sunday afternoon before I travelled and thought nothing more of it.

When I arrived on the Sunday afternoon expecting to pick up the Merc E-class (*or similar) I was told that the vehicle was no longer available.Which was interesting because I could see the receipt on my phone, and could see the set of vehicles out back that matched the description.

I asked "Do you not have the vehicle class available?".

"Yes", the member of staff said, "but we cannot provide it to you".

Well that was always going to peak my curiosity. After various different attempts at rewording the question "Why the hell not?" in different ways to try and get an answer, they offered me a vehicle the size of my shoe.

Nope.

Drive to and from Norwich in a hand basket? No thanks. 322 miles of tall-person-comedically-cramped-into-a-hatstand? Double nope.

So I cancelled the rental and got a refund ... but no-one could tell me why. I know from past experience in that same office that they were happy to explain to me why another customer was not able to rent one of their vehicles - their staff explained why the argument started to attempt to keep my business I guess.

But they couldn't tell me - to my face - what the problem was.

I sent them a SAR later that week (oh come, on, what else did you expect from me eh?). No reply. Sent a follow up over 40 days later. This isn't to some obscure email address incidentally, this to the email address advertised on their own support, contact and T's and C's pages.

No response. Now I'm irked and have had to explain to a client why I couldn't travel to client site for the week in question. So in an NBA went...again..no response. Nothing at all. Normally that gets a "Oh sorry we lost your email in all the spam, let us sort your SAR out now". But not this time.

The Case


So I try a claim in the small claims court for failure to respond to SAR - because:
  1. my website booking completed - they accepted my money and my details and we entered into a deal
  2. they failed to notify me of a problem until after I'd travelled by train to their pick-up office
  3. they refused to tell me why they were no longer honouring my booking
  4. they spammed me every time I buy something without actually acquiring express / explicit consent. Even after telling them to piss off directly
  5. they had ignored my subject access request
  6. they continued to spam me after rejecting my custom, and without asking me whether I wanted it or not
All reasonable so far - so I alleged that they'd failed to respond to SAR, added the breaches of PECR for the spam and filed it. About 4 pages of particulars / witness statements on essentially a very simple claim.

This is their filed defence:

That's the whole defence btw
As there's almost nothing to it I'll explain why this is a strange defence to file.

Paragraph 1 & 2: In terms of the consent for marketing; I agree with a more general legal opinion that "Consent by definition requires some sort of positive action on behalf of the recipient." - PECR section 22 also infers a direct and explicit action on the part of the potential recipient of unsolicited marketing in order to opt-in to it. There was also no consent statement on the page when I hired any cars - so there's no reasonable effort from Europcar at all.

Europcar's approach of burying this consent and then relying on the "purchase of goods or services" exception doesn't really wash - if the explicit opt-in was available as it should be, and the customer does nothing they are indicating they have no desire to get spammed. GDPR levels the playing field and requires explicitly activated opt-in for spam (amongst other things). Roll on May 2018.

Paragraph 3 & 4: I use a different email address for each purchase so that - when a company inevitably gets hacked or stupidly decides to sell it's customer database - I can tell who the idiot was. To say there was "no information to suggest that [I] the claimant has requested ... not be used for [spam]" is a massive lie - they'd failed to acquire consent at all.

Paragraph 5: By post?! I'd sent a number of messages (including serving the particulars of the claim) via email and they try to reply by post? Surely that's just trying to hide away from making a simple effort of sending an email? Unfortunately whomever actually received this letter must have rejected it on the basis that delivery was attempted at the wrong address. I regretfully never had the opportunity to reject it.

The Result


The defendant claimed never to have received any of the documents - the same documents they were reading in order to file a defence incidentally.

The defendant also claimed that they never received the emailed SAR or NBA.

That changed the moment I produced their own auto-responders for each message I'd sent; and they subsequently settled for a menial amount. I've still not received a response to my SAR but they agreed to cease spamming me. I just wanted to know why they went back on their word.

Because no-one apparently reads the emails from their customer service inbox; if you have similar issues with Europcar in future I'd recommend to contact their relations officer, John Cooper, directly. This ensures there's no misunderstandings in communication - it is 2017 after all. Email john.cooper@europcar.com or via phone on 0116 217 3422.


Don't expect a welcoming conversation or any admission of wrongdoing - even when their error is as plain as the nose on their faces.

Monday, April 03, 2017

Side Effect: Snoopers Charter [Part 4]

It's been a wholly unsurprising journey to the Room of Truth with my CSP, only to be locked out of the final door.

After an online chat I finally got my request through to the legal department, only to be told that because it was a corporate account the DPA does not apply, and also; under Part 4 Section 93 of the IPA the CSP is not allowed to release the ICR data to me.

So I replied and re-iterated that the moment my SAR arrived identifying me, and linking me directly to the ICR data in question - also providing my authority as the account holders director - the DPA does apply as my name is linked to the internet usage [and that as my internet usage may contain specific records] and sensitive personal data.

Section 93 also refers to ensuring that the CSP puts adequate controls in place to retain the data in a secure manner. Nothing to do with disclosure. I can find no provision of the IPA which prevents the disclosure of ICR to the data subject(s) in question.

I'm the middle of designing and developing anti-spam security solution so frankly just don't have the time to focus on this at the moment. Whilst legal opinion appears to be that the IPA is not legal, I doubt the Prime Minister or Home Secretary are willing to have that "grown-up conversation". However ICO has enough of a fight ahead convincing the cabinet that it needs to keep parallel laws to keep trading with Europe.

Time to draw another spidergram and send the details to ICO - I can't imagine that the government regulator will do anything other than side with the government communications provider in this case.

I am Jack's total lack of surprise.

Tuesday, March 07, 2017

Side Effect: Snoopers Charter [Part 3]

Last month I was curious about the effects of recent legislation on my internet usage. Since then I've had some conversation tennis with support teams at my ISP but no traction or movement.

Up until this morning I'd suspected that nothing was being done - I'd send an email from an account I use tracking systems with, get a response back within a few hours telling me that email address wasn't authorised for the support ticket, then I'd send a reply from the original email address authorising the second email address with the ISP... and then getting nothing in reply.

Twice.

I know the emails were opened in India and read twice each time within a few hours of sending. All other responses or communications were simply being swallowed up into a black hole.

This morning I tried using the live chat on the ISPs website and got a far better response (even if it wasn't what I wanted to hear).

Despite repeated requests to get status or answer any outstanding queries I've had nothing. The live chat support person, Linda, was able to tell me that the original recipient of the request fobbed me off onto the wrong department then closed the support ticket. And it's been that way ever since the 19th of January. 

Not really surprised but I pushed Linda to forward the request onto either their legal or compliance team. A bit of confusion - it sounds like their usual section 7 requests are for case notes, not ICR data - easily clarified. Now although Linda refused to re-open the support ticket she did promise to forward the request onto legal after I explained that the ISPs legal team would have had to review & sign-off the Snoopers Charter implications. This would involve them understanding the request and its terms.

However we're now over the 40 day limit for a SAR and there is no response other than acknowledgements that the ISP have received the request - it's going to be interesting to see how they respond from this point. Recent legal updates have included a major setback to the Investigatory Powers Act at ECJ level and some inevitable challenges to it's implementation; especially relating to the requirement to implement 'back doors' in all CSP platforms. Note emphasis there on CSP platforms, not anti-virus software or encryption software.

Whether or not this will really affect peoples daily lives or not is another matter, but I'd be concerned that local councils, HMRC, the Dept. for Education and other similar level government departments will inevitably use this type of information for purposes other than 'detection of a crime'.

'Detection' will easily slip into 'Prevention', and then we're in the tin-foil hat territory akin to Minority Report. I don't have government-level actors trying to hack my devices but if there is a method of access available, criminals will find it - and that's enough of a cause for concern for me. Just a quick glance at how busy ICO are with government departments and you begin to understand the scale of the data-protection problem: Here's a list of decision notices - when this article went live they were all councils on the receiving end of complaints.

Click to see larger image

Monday, February 06, 2017

Side Effect: Snoopers Charter [Part 2]

Last month I sent a rather well-known international internet provider a subject access request (SAR) - since that post (which you can recap on here) I've had some rather less entertaining communiques with them.

I'm not going to name the ISP just yet for security reasons but suffice to say that the following are true:

  1. They ask that a cheque is sent in the post to them for £10 as part of the SAR process; yet do not accept cheques as a form of payment for any of their services
  2. They do not advertise the email details for any legal department inbox, nor do they extend their current online issue registration capabilities to include SAR or similar filings
  3. This is a company who sell themselves on high technological value (and do so on multiple continents) yet fail to provide a simple means for lodging a SAR - which is an individuals right under the law here in the UK [and EU]
After the last post I had received an assurance from the member of staff that she would contact the original member of staff to find out why it was [erroneously] passed to her department, and that she would call me back within 2 hours.

I've heard nothing since the 19th and 20th of January.

I've sent two follow-up emails to the ISP to which they have failed to reply within 48 hours - which is their SLA for business customers. I sent another further update request from an email address embedded within a tracking system.

This email got a response within 3 hours saying that the update request was "...not sent from the email address you used in your initial enquiry", and that "...for security reasons, we cannot provide an update unless you use the same email address that you originally used to contact us".

Actually I'm happy with that response as it's a verification of identity - the tracking system uses a completely separate domain and I'd be asking for the same verification from any of my customers too. So I sent back a message from the original email address used to the effect that yes - it was me, and that they should enact this second email address with the appropriate authorisation to deal with this issue.

That was the 2nd of February and there's been no further communication since.

So I repeated the latter part of the exercise and got the same response today - also read and responded to within 3 hours of being sent.

So what is clear is that the ISP are receiving the requests for update and essentially refusing to provide an update. As I've had adequate responses directly from the ISP staff they have received and acknowledged the request, and I've asked specifically how I can pay the £10 SAR fee without a cheque book.

As they're refusing to respond does that mean they're waiving it? Forgetting the fact that the fee was designed in the 1980's to cover the cost of postage of the potentially large printed documents to answer the SAR, I'm not sure how relevant that price is versus the cost of doing business - which the all businesses must acknowledge if they conform to the Data Protection Act.

I can show that each of the requests for information have been received, opened and read (all in India), yet have little to show in terms of meaningful response. I found another part of the same ISP - well it's a law firm that says it's part of this ISP and I'm going to send them a copy of these posts as well as the original request.

Expect another post in coming weeks as the time limit on the SAR (40 days) means the statutory limit expires on the 28th of February. At that point the ISP will be in breach of the DPA.

Thursday, January 19, 2017

Side Effect: Snoopers Charter [Part 1]

On the 6th of January 2017 the Investigatory Powers Bill came into effect. At this point all CSPs (ISPs such as TalkTalk, Vodafone and BT) must start collecting internet connection records - or ICRs.

I'm not going to get into the morality or the why's and wherefores but, according to the IPB these must contain the details of websites each internet connection connects to, but not the full URL or details of every page visited.

So how are they intending to collect that information? There's several ways to do that. Perhaps a form of DNS caching silo-ed to each household and business; perhaps packet inspection?

Whichever way this will be achieved the focus now shifts to the ICRs themselves - which of course are chunks of information stored about a person.

Wait... *sound of rustling paper* ...that means that under the Data Protection Act these ICRs come under the definition of personal data (section 1 I think states that but it is also referenced in schedule 2). But surely that would mean we could see what's being collected then? We each have the right to see all our data and meta-data to ensure that it is correct and being processed correctly.

Time for an exploration into some of these grey areas to see what will happen if I SAR my ISP for ICRs. The complication here is that I use a business account wired to my home address; but that isn't so much of a complication when you consider that when you inform someone that a Thing is personal data, you are associating your name with that Thing ... and therefore it becomes personal data (assuming it is about you). So... The ISP doesn't have an open email inbox although this makes sense - they'd just get spam.

Instead I have to log a request via the support system or send a *shudders* letter. My ISP also mandates that I should send them a cheque for £10 in the post before they'll deal with the SAR... but a) that's *shudders* basically a letter and b) I don't have a cheque book any more and and and and c) my ISP themselves don't accept cheques in payment for their services.

So I call cow poo on that one.

So this morning I logged the following support ticket - please feel free to take this and shape it to your own personal needs if you wish:

"Please pass this request to your legal department. It has been logged as a support request for tracking purposes.

This is a subject access (a section 7) request under the Data Protection Act.

As the internet services provided by this business account are also used for personal / home reasons, this SAR essentially ties the internet connection records (ICR) to my name, and therefore expands the scope of "personal data" to include the ICR themselves by association.

I am also the authorised person on the business account and am happy to be verified as such.

With that in mind, please provide copies of all data - in electronic format - and associated meta-data for the ICRs collected as required by the Investigatory Powers Bill - related to me.

As I do not have a cheque book it is impossible to follow your privacy guidelines about how to pay the £10 DPA-mandated fee, so ask that you contact me directly to provide alternative payment details."


Updates to follow (although bearing in mind the ISP involved, it won't be any time soon). I'm expecting some attempt to wiggle out of it either by admitting that they're not up-and-running with it yet, or that they try and claim a DPA exemption.

Update 1: Jan 19th, 2pm

Expected this sort of thing.
So the ISP has called a couple of times, the foreign call centre handler then immediately passed me through to their billings complaints department. After 10 mins of me telling them the reference number from their own email (and them claiming it wasn't a valid reference number), they agreed to speak to the call handler who had passed my call to them. They're now speaking to him and will call me back later.
I'm still a little surprised that this ISP (a large multinational) has live chat on the website, a ticketing system for non-standard queries and a web portal for account management still requires postal methods for a SAR. Seems an overly obstructive approach and making it almost dissuasive for most people.

The next few updates deserved a post of their own, check for new posts in coming days...

Wednesday, November 30, 2016

Trial Result: UK Apollo Group


In a surprise ruling, the judge decided that I could not prove the claim against Apollo.

The reason? I'd forgotten to include in evidence the documents that showed UK Apollo group scraping email addresses from the rest of job seeker data in my bundle. This was necessary as the initial spam was sent to an encoded email address (e.g. jobsite.<date>@<domain>).

So essentially it was not the case where the defence was robust and proven, it was simply an error on my part which failed to cement the facts of the case. UK Apollo would not be able to refer to this year long legal entanglement as a 'victory' as a result, and they also disclosed a lot of facts in a court of law - facts that would be of interest to regulators and in future SARs.

Furthermore, the judge refused to accept evidence of spam emails received after the submission of the date of the claim, which included readily identifiable email addresses. He also noted - but failed to act on - the fact that the first defence was submitted unsigned, and an alleged re-write of the defence was never served to the claimant.

In fact the trial was the first time I'd heard that Apollo had even adhered to the application to strike / re-write judgement.

Despite a number of breaches of CPR by the defendant (duly noted but not enacted by the judge) the defence - such that it was - was allowed to stand, despite a submission related to Denton & others. I even submitted a revised bundle for the second trial after the court ushers directed me to the wrong floor in the first trial - but the judge claimed not to have it in front of him. Good thing I got delivery receipts then.

Very interesting - almost as interesting as the very personal remarks made by the defendants rep, Keith Taylor. He was very angry! He couldn't actually apply a robust defence at all and I'll share the highlights of the comedic vitroil once I get the trial transcribed. You shouldn't laugh too much in a court. At one point he claimed that ICO was getting the law changed to help his company continue to spam people. Of course, no evidence was presented to substantiate any of these statements.

Keith even claimed he charges his time at £1k per day, although judging by the posted accounts none of the companies seem to be charging for many of his consultancy days. Most of the people associated with Apollo appear to have many other jobs too....

Also of note was the defence at one point admitting liability at two points, saying "just find me guilty, m'lud and fine me£200 so we can all go home.". In court, on record.

However because the district judge excluded the emails following the initial claim document they are not considered part of the claim that has now been judged by the court. One of those spam emails was to an account I have listed as <firstname>.<surname>@<domain> - which is personal data in itself.

I think I can see why the judge did what he did and I've decided not to appeal for a number of reasons (not least the additional costs liability if I get something wrong). So I sent Apollo a shiny, brand new SAR last week - they've read it twice but are yet to respond. He awarded a £55 cost for the defendant - which should cover his petrol home.

Tuesday, October 25, 2016

UK Apollo Group (Further Updates)

In an earlier post I talked about some particularly flagrant spammers and data traders, UK Apollo Group a.k.a Taylor CVs, run by Keith Taylor.

After a mix up at the courts I applied for a re-hearing and - what a surprise, the defence failed to attend. Although even if they had I'm not sure it would have made any difference as I barely spoke at all.

The judge asked for 20 minutes for additional reading time, having been passed the case from another judge. After I'd sat down he simply stated the conditions under which a re-trial would be granted and that he was not there to deal with the other submissions. In under five minutes he worked his way through the reasoning for allowing the application - even noting that he was not there to decide the case, even though he deemed the defence as 'flimsy at best'.

The new trial is listed on the 21st November 2016 and I'll provide more updates nearer the time. However in the time between the last post and the application heading the defendant has spammed be yet again.

Not only that but Monster.co.uk have confirmed - after I provided them all the details of the web of companies holding UK Apollo together - that they've spoken directly to the defendant and advised them that what they're doing not only breaches the terms and conditions of their contract with Monster, but is breaking the law.

I'm yet to hear any kind of conciliatory tones from Kieth Taylor, nor do I expect to. Perhaps having a CCJ listed against his company for the next 6 years will adjust his attitude towards stealing personal data for profit.