Showing posts with label politics. Show all posts
Showing posts with label politics. Show all posts

Tuesday, November 26, 2019

DVLA Statistics - And How to Save £146m over ten years

Information is Free

Since becoming entangled with the DVLA, I'd raised a couple of Freedom of Information requests (FOIRs) and a subject access request (SAR). By law an authority is allowed 20 working days to respond to a FOIR, and can choose to either respond in full; respond in part (perhaps noting another authority which may hold the relevant information); or refuse to respond to the FOIR entirely.

In this last case authorities often hide behind the section 12 requirements, which detail the process to follow where the request exceeds the time or cost limits prescribed for different types of authority. I noted in my previous DVLA post in which instrument of law those limits are defined.

DVLA are set the ceiling of 4.5 man days or £600 - whichever is higher.

The scene is now set for each of the two FOIRs I raised.

FOIR #1 - Budget Information Relating to Physical Post

This should have been a fairly simple call to the DVLA accounts department, in order to get some basic information. I would have been fine with the more detailed item breakdowns being refused or declined, as long as the base figures were provided.

I asked the DVLA for figures relating to both the previous and current fiscal years:
- the DVLA budget for that year
- the amount spent printing documents to send to registered keepers e.g. fines, new V5Cs, reminders etc
- the amount spent on postage / delivery for these items

I expected the fiscal years for n-1 and n-2, rather than current (n) and n-1, as in-flight accounting is unlikely to be available. In the FOIR I was more specific as I thought it would help DVLA scope the request better, and leave less room for clarifications back to me. How wrong I was.

Initially the request was rejected under section 12 as being too onerous, until I pointed out that when working on programme budgets at most of my clients, I could get most of these numbers over the phone whilst I wait. I also pointed out that they'd already responded to my other request with the actual number of documents sent to drivers, which must have involved a similar amount of work (see the FOIR #2 section below).

I requested an internal review and DVLA responded with some of the information I'd asked for.

So the total spend on:
  • all stationary was £1.1m in 2017-18 & £1.2m in 2018-19
  • all postage was £25.9m in 2017-18 & £26.2m in 2018-2019
  • all printing was £14.4m in 2017-18 & £14.2m in 2018-2019
The total expenditure across these items was effectively £41.4m and £41.6m in 2017 and 2018 effectively. Yet they still essentially refused to supply their overall budget for those years. As I couldn't find a reference to this figure anywhere else on gov.uk I was reliant on this single public sector organisation for those numbers.

I then asked them to reconsider their position but expect them to walk away from this request. Their initial response was later than the FOIA allows, and their responses were evasive at best.

You can see the live FOIR here for reference.

FOIR #2 - Document Production and Delivery Statistics

This one went a little better and information was slightly more forthcoming. But it was still a struggle to get basic information from them.

I asked the DVLA to provide statistics / their records for the following:
- The number of physical documents sent to registered keepers
- The number of those documents sent via some form of recorded delivery
- The number of known tracked items that have a "missing", "undelivered" or similar category applied after they have left DVLA

Despite the specificity of the request, three weeks later the DVLA asked me to clarify what documents I was referring to. I clarified regardless and the final (late) response to the FOIR was received almost a month later.

It turns out that the DVLA sent 99,461,763 documents from Jan 2018 to 25th October 2019. Based on 662 days in that period and assuming the report was generated on the same day as the DVLA response letter; the average number of documents sent per day is 150244(.355).

That's a lot of documents. Only about 32k of those in that 622 day period were sent via some sort of recorded delivery, and the DVLA does not track how many of those tracked items were returned or otherwise undelivered. The DVLA did not disclose how much they spent on tracked / recorded delivery, so this is an assumed and unknown uplift on the cost-per-document-sent.

Now if we combine the responses of FOIR #1 and FOIR #2 we can say (quickly excusing my shoddy maths) that:
  1. In 2018-2019 DVLA spend £41,629,644 on document production (excluding 3rd party costs such as GSP)
  2. In 2018-2019 we can infer that in 365 days - and using the docs / day from earlier in this FOIR - the DVLA sent 54839189(.57) docs in this year
  3. Therefore the cost-per-item to the DVLA in 2018-2019 is £0.79
  4. This does not include the DVLA operating expenditure on the processes surrounding this document e.g. hiring staff to manage the processes, interact with the processes and operate processes where necessary, recorded delivery costs, heating, lighting, utilities and other standard OpEx items. The actual cost is probably between £1 and £2 (if the DVLA are operating efficiently).
In the same request I asked the DVLA to explain the QA processes which govern how they ensure the mail service providers (MSP) - UK Mail and Royal Mail - certify that they've collected all the documents produced.

The response on this front have been unclear at best and plain evasive elsewhere. I part of their more recent response the DVLA state:

"Data is input into the DVLA’s systems in accordance with specific parameters,
depending on the type of transaction. This includes a quality assurance check, which allows for work to be appropriately batched ready to send out.
"

That's a very broad description without any specifics, that doesn't really tell us anything at all. What parameters? What QA check is actually performed? They also stated in the same response:

"When a document is printed, it is then tracked electronically through the mailing system. This supports integrity checks until the document is enveloped and transferred to the Quality Assurance (QA) section. Some items of mail may then require reprinting.

The DVLA then hands over the items for despatch to the respective Mail Service
Provider and is reconciled against control document
"

This is more related to the question, and sounds like a proper answer on the face of it. However the portions of sentences I've highlighted should draw attention to the subtle evasion here.

So a document is tracked (per-item?) through the mailing system, so that the QA section can verify it in its envelope. Are they checking every single of the one hundred million items the claim to have sent since Jan 2018?

Finally the point about the "control document" is very vague - is this the DVLA's control document, and one which the MSPs do not interact with? In order words how are the DVLA verifying each letter is accepted by the MSP, instead of just picking up a box or pallet of mail which hopefully includes all the items DVLA has "tracked" to that point?

In fact if we reference a FOIR from 2009, we can see the DVLA admit that the MSP do not verify each item in the batch. I've asked DVLA to clarify a point relating to this as the answer seems a bit more thought out than the one a decade ago. I suspect they have no way of verifying that the MSP is collecting all the items they've printed (so can't entirely blame the postie for lost mail).

You can see the live FOIR here for reference.

Next Steps

Even if my earlier assumptions for calculation were correct (which I know they aren't), the minimum being spent per item is 79p. It's far cheaper for the DVLA to send a prospective fine, on the chase they can intimidate someone into paying than it is to actually review the case properly. It's a cash generation game.

I've largely exhausted options with FOIR as DVLA are likely to essentially ignore further clarifications on the request. Together with their breach of the Data Protection Act (DPA) I'll be putting together a formal document for breaches of FOIA to the regulator, ICO. This complaint will hopefully ensure the DVLA directly answers any outstanding questions.

A grey area has formed between the FOIA and the DPA where automated decision making affecting a living person is at the forefront. GDPR Article 22 deals with ADM - more specifically ensuring that adequate protections are put in place. These protections are aimed at ensuring that an individual suffers no undue harm. In fact Article 22 Section 3 states: "...safeguard the data subject’s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision."

It appears the DVLA has breached this if ADM was at the core of the decision to fine and prosecute me originally. We cannot say that the DVLA has delivered on this requirement by virtue of pressing for prosecution in a case which it later manually determines not to have merit. This is not covered by the FOIA and must be considered by ICO.

In parallel to that I'll be raising complaints with DVLA directly, as was the suggestion of the DVLA prosecutor in the case I won. This complain will focus on recovering damages and distress.

IR35

I can't resist a poke.... the IR35 changes in 2018 will have killed off any IT projects at DVLA reliant on a contingent workforce of consultants. Those same consultants would have been able to build DVLA a digital presence which would remove the need for documents across a conservative estimate of 50% of use cases. A web-based dashboard with services to encapsulate authentication, authorisation and enable notifications to DVLA such as SORN. More and more people have access to the internet via smart-phones, less and less have no access at all - there are still post offices for the rest of the forms.

Eventually other businesses would want to integrate with DVLA data sources, as insurers already do via MID. The motorists data is already held by DVLA in order to support the production of drivers licenses, and therefore the authentication model should focus on driver-based logins. Data security will be key here considering the kinds of information involved. Ideally using MFA such as smartphone authenticator apps should provide a welcome layer of security, and open-source libraries are available to achieve this. The data layer is the most complete layer as it stands today.

Fines, penalties and reminders could all be dealt with in the first instance via the dashboard, with email notifications send to drivers when new 'documents' are sent to them by DVLA. Delivering these digital journeys will need the most engineering & testing effort. The DVLA claims its processes are largely automated so the integration architectures will need to be carefully designed - and probably brought up-to-standard. The DVLA already accepts payments for car tax online if you have a V5C or V11, so existing authentication and payment API's will need to be re-used and expanded upon.

A project of one feature team working on a digital dashboard, authentication model and microservices based on COTS would cost up to £750k for six months. That's a large feature team costing btw, probably one which would operationally be split into two agile teams sharing architect, BA & programme manager. Each team would have it's own scrum master, engineering and QA peeps. Software and licensing for SaaS, for example might stray into the £1m purchase, and £500k annual licence at worst for this kind of thing.

So making some wild assumptions and adding bloat as it's public sector, I did the following in LibreOffice Calc.

Large assumptions ahoy


I made the following assumptions for this:
- I don't know what architecture would be deployed that is compatible with Gov.uk strategy, so upped the IaaS costings for services, services and networks to 75k / year. This increased cost assumes redundancy and performance needed to support the traffic from potentially 90% of motorists in the UK
- I assume the Gov.uk is continuing with vendor-locked arrangements with Oracle, and Oracle are strong-arming Gov.uk as they are with anyone else. Ideally I'd focus on an open-source approach with something like RHEL, Apache, ELK and PostgreSQL, but I don't know how the x-charging works so assumed a DVLA-owned license cost of half a million per annum; plus new costs of authentication and integration of existing Gov.uk payment gateways
- Purchase of cloud and dedicated tin combinations, plus new infrastructure or services hosted for DVLA (assumed re-use from other Gov.uk departments such as MCOL or local government)
- A feature team costing based working over a two-and-a-half year delivery period; including 2 year build and test continual drops, with six months post-live warranty
- These are finger-in-air-estimates for design & development knowing nothing about what really goes on behind the scenes at DVLA

Any of the programme managers I've worked with at my past clients would've fallen off their chairs at those numbers and assumptions, but that's because they work in pragmatic, efficient and competent environments in the private sector.

So based against only a 50% reduction in printed documents - on the assumption that proportion of people register for paperless DVLA services - the DVLA expenditure on disclosed production would be £20,814,822 (ignoring increases with inflationary-associated costs). That's the cost of documents that no longer need to be printed and can be provided direct-to-drive with assured delivery. How many problems does that solve? :)

So the DVLA would save around £20m per annum OpEx, and expend £11m CapEx on rolling out the digital presence? Ok so those savings wouldn't be fully available until year 4. Over the ten year projection that's £145,703,754 cost savings on direct document production alone, versus a £7m run cost estimate over the same period. Still £137m can pay for a lot of tour buses for Boris Johnson.

How to achieve this? Get HMRC on a leash so they no longer exceed their authority under the law and stimulate what's left of the British economy by encouraging the vibrant, consultative small business.

Or keep flushing money down the drain and drive the skilled consultancy workforce out of the UK. You choose.

Monday, April 03, 2017

Side Effect: Snoopers Charter [Part 4]

It's been a wholly unsurprising journey to the Room of Truth with my CSP, only to be locked out of the final door.

After an online chat I finally got my request through to the legal department, only to be told that because it was a corporate account the DPA does not apply, and also; under Part 4 Section 93 of the IPA the CSP is not allowed to release the ICR data to me.

So I replied and re-iterated that the moment my SAR arrived identifying me, and linking me directly to the ICR data in question - also providing my authority as the account holders director - the DPA does apply as my name is linked to the internet usage [and that as my internet usage may contain specific records] and sensitive personal data.

Section 93 also refers to ensuring that the CSP puts adequate controls in place to retain the data in a secure manner. Nothing to do with disclosure. I can find no provision of the IPA which prevents the disclosure of ICR to the data subject(s) in question.

I'm the middle of designing and developing anti-spam security solution so frankly just don't have the time to focus on this at the moment. Whilst legal opinion appears to be that the IPA is not legal, I doubt the Prime Minister or Home Secretary are willing to have that "grown-up conversation". However ICO has enough of a fight ahead convincing the cabinet that it needs to keep parallel laws to keep trading with Europe.

Time to draw another spidergram and send the details to ICO - I can't imagine that the government regulator will do anything other than side with the government communications provider in this case.

I am Jack's total lack of surprise.

Tuesday, March 07, 2017

Side Effect: Snoopers Charter [Part 3]

Last month I was curious about the effects of recent legislation on my internet usage. Since then I've had some conversation tennis with support teams at my ISP but no traction or movement.

Up until this morning I'd suspected that nothing was being done - I'd send an email from an account I use tracking systems with, get a response back within a few hours telling me that email address wasn't authorised for the support ticket, then I'd send a reply from the original email address authorising the second email address with the ISP... and then getting nothing in reply.

Twice.

I know the emails were opened in India and read twice each time within a few hours of sending. All other responses or communications were simply being swallowed up into a black hole.

This morning I tried using the live chat on the ISPs website and got a far better response (even if it wasn't what I wanted to hear).

Despite repeated requests to get status or answer any outstanding queries I've had nothing. The live chat support person, Linda, was able to tell me that the original recipient of the request fobbed me off onto the wrong department then closed the support ticket. And it's been that way ever since the 19th of January. 

Not really surprised but I pushed Linda to forward the request onto either their legal or compliance team. A bit of confusion - it sounds like their usual section 7 requests are for case notes, not ICR data - easily clarified. Now although Linda refused to re-open the support ticket she did promise to forward the request onto legal after I explained that the ISPs legal team would have had to review & sign-off the Snoopers Charter implications. This would involve them understanding the request and its terms.

However we're now over the 40 day limit for a SAR and there is no response other than acknowledgements that the ISP have received the request - it's going to be interesting to see how they respond from this point. Recent legal updates have included a major setback to the Investigatory Powers Act at ECJ level and some inevitable challenges to it's implementation; especially relating to the requirement to implement 'back doors' in all CSP platforms. Note emphasis there on CSP platforms, not anti-virus software or encryption software.

Whether or not this will really affect peoples daily lives or not is another matter, but I'd be concerned that local councils, HMRC, the Dept. for Education and other similar level government departments will inevitably use this type of information for purposes other than 'detection of a crime'.

'Detection' will easily slip into 'Prevention', and then we're in the tin-foil hat territory akin to Minority Report. I don't have government-level actors trying to hack my devices but if there is a method of access available, criminals will find it - and that's enough of a cause for concern for me. Just a quick glance at how busy ICO are with government departments and you begin to understand the scale of the data-protection problem: Here's a list of decision notices - when this article went live they were all councils on the receiving end of complaints.

Click to see larger image

Monday, February 06, 2017

Side Effect: Snoopers Charter [Part 2]

Last month I sent a rather well-known international internet provider a subject access request (SAR) - since that post (which you can recap on here) I've had some rather less entertaining communiques with them.

I'm not going to name the ISP just yet for security reasons but suffice to say that the following are true:

  1. They ask that a cheque is sent in the post to them for £10 as part of the SAR process; yet do not accept cheques as a form of payment for any of their services
  2. They do not advertise the email details for any legal department inbox, nor do they extend their current online issue registration capabilities to include SAR or similar filings
  3. This is a company who sell themselves on high technological value (and do so on multiple continents) yet fail to provide a simple means for lodging a SAR - which is an individuals right under the law here in the UK [and EU]
After the last post I had received an assurance from the member of staff that she would contact the original member of staff to find out why it was [erroneously] passed to her department, and that she would call me back within 2 hours.

I've heard nothing since the 19th and 20th of January.

I've sent two follow-up emails to the ISP to which they have failed to reply within 48 hours - which is their SLA for business customers. I sent another further update request from an email address embedded within a tracking system.

This email got a response within 3 hours saying that the update request was "...not sent from the email address you used in your initial enquiry", and that "...for security reasons, we cannot provide an update unless you use the same email address that you originally used to contact us".

Actually I'm happy with that response as it's a verification of identity - the tracking system uses a completely separate domain and I'd be asking for the same verification from any of my customers too. So I sent back a message from the original email address used to the effect that yes - it was me, and that they should enact this second email address with the appropriate authorisation to deal with this issue.

That was the 2nd of February and there's been no further communication since.

So I repeated the latter part of the exercise and got the same response today - also read and responded to within 3 hours of being sent.

So what is clear is that the ISP are receiving the requests for update and essentially refusing to provide an update. As I've had adequate responses directly from the ISP staff they have received and acknowledged the request, and I've asked specifically how I can pay the £10 SAR fee without a cheque book.

As they're refusing to respond does that mean they're waiving it? Forgetting the fact that the fee was designed in the 1980's to cover the cost of postage of the potentially large printed documents to answer the SAR, I'm not sure how relevant that price is versus the cost of doing business - which the all businesses must acknowledge if they conform to the Data Protection Act.

I can show that each of the requests for information have been received, opened and read (all in India), yet have little to show in terms of meaningful response. I found another part of the same ISP - well it's a law firm that says it's part of this ISP and I'm going to send them a copy of these posts as well as the original request.

Expect another post in coming weeks as the time limit on the SAR (40 days) means the statutory limit expires on the 28th of February. At that point the ISP will be in breach of the DPA.

Thursday, January 19, 2017

Side Effect: Snoopers Charter [Part 1]

On the 6th of January 2017 the Investigatory Powers Bill came into effect. At this point all CSPs (ISPs such as TalkTalk, Vodafone and BT) must start collecting internet connection records - or ICRs.

I'm not going to get into the morality or the why's and wherefores but, according to the IPB these must contain the details of websites each internet connection connects to, but not the full URL or details of every page visited.

So how are they intending to collect that information? There's several ways to do that. Perhaps a form of DNS caching silo-ed to each household and business; perhaps packet inspection?

Whichever way this will be achieved the focus now shifts to the ICRs themselves - which of course are chunks of information stored about a person.

Wait... *sound of rustling paper* ...that means that under the Data Protection Act these ICRs come under the definition of personal data (section 1 I think states that but it is also referenced in schedule 2). But surely that would mean we could see what's being collected then? We each have the right to see all our data and meta-data to ensure that it is correct and being processed correctly.

Time for an exploration into some of these grey areas to see what will happen if I SAR my ISP for ICRs. The complication here is that I use a business account wired to my home address; but that isn't so much of a complication when you consider that when you inform someone that a Thing is personal data, you are associating your name with that Thing ... and therefore it becomes personal data (assuming it is about you). So... The ISP doesn't have an open email inbox although this makes sense - they'd just get spam.

Instead I have to log a request via the support system or send a *shudders* letter. My ISP also mandates that I should send them a cheque for £10 in the post before they'll deal with the SAR... but a) that's *shudders* basically a letter and b) I don't have a cheque book any more and and and and c) my ISP themselves don't accept cheques in payment for their services.

So I call cow poo on that one.

So this morning I logged the following support ticket - please feel free to take this and shape it to your own personal needs if you wish:

"Please pass this request to your legal department. It has been logged as a support request for tracking purposes.

This is a subject access (a section 7) request under the Data Protection Act.

As the internet services provided by this business account are also used for personal / home reasons, this SAR essentially ties the internet connection records (ICR) to my name, and therefore expands the scope of "personal data" to include the ICR themselves by association.

I am also the authorised person on the business account and am happy to be verified as such.

With that in mind, please provide copies of all data - in electronic format - and associated meta-data for the ICRs collected as required by the Investigatory Powers Bill - related to me.

As I do not have a cheque book it is impossible to follow your privacy guidelines about how to pay the £10 DPA-mandated fee, so ask that you contact me directly to provide alternative payment details."


Updates to follow (although bearing in mind the ISP involved, it won't be any time soon). I'm expecting some attempt to wiggle out of it either by admitting that they're not up-and-running with it yet, or that they try and claim a DPA exemption.

Update 1: Jan 19th, 2pm

Expected this sort of thing.
So the ISP has called a couple of times, the foreign call centre handler then immediately passed me through to their billings complaints department. After 10 mins of me telling them the reference number from their own email (and them claiming it wasn't a valid reference number), they agreed to speak to the call handler who had passed my call to them. They're now speaking to him and will call me back later.
I'm still a little surprised that this ISP (a large multinational) has live chat on the website, a ticketing system for non-standard queries and a web portal for account management still requires postal methods for a SAR. Seems an overly obstructive approach and making it almost dissuasive for most people.

The next few updates deserved a post of their own, check for new posts in coming days...

Friday, September 25, 2015

The 3 R's: Rinse, Repeat, Re-sell


Earlier this year I had the misfortune of coming into contact with MyJobMatcher; they'd essentially bought peoples personal data from data traders around the world to artificially inflate their candidate database, rather than work on gaining direct subscribers. They settled my claim for breaches of the DPA and PECR out of court with no associated admission of liability.

The end of the story? Lessons learned? Of course not. I got an email recently from MJM claiming that SpellJobs.com had suggested I would be interested in MJM's services. Anyway so if I want to log in and...Wait. What?

So one jobs board is passing on candidates to another competitor? After unlawfully acquiring my details from the original jobs board that'd I'd actually used? Of course. All of this makes perfect sense. Who the hell are SpellJobs.com? Their contact page just goes to a PHP error and the about us page is tellingly blank.
Karen - what have you done?
The shopping basket doesn't work either. I've had a look in between the lines at spelljobs.com and it appears to allow the general public to search and scrape job seeker data. The T's and C's look suspect to say the least too. I may add this to the LSP R&D portal as a new scam alert depending on how the SAR pans out.

Due to the no-contact agreement I'm currently in conversation with Mr Lawrence Weeks of Birketts LLP, representing MJM, and they've disclosed the contact details they use in their commercial relationship with SpellJobs.com. Although after doing a bit of digging it looks like SpellJobs.com isn't a registered business but it is either associated with Job Circle Ltd or Datasource Computer Employment Ltd. I've already knocked on that door with another SAR. I'd already sent Job Circle and another apparent linked entity a SAR each to cover all bases.

After my initial SAR to MJM via Birketts I've had a number of automated emails from MJMs systems saying that they are sorry to see me go but my account has been closed.

However now Birketts are asking me if I can supply other emails so they can be de-listed from MJM systems in future. But isn't that missing the point by a very wide margin? Surely they should stop their unlawful data and unsolicited communications practices to prevent them acquiring data they had no consent for in the first place?

Updated

It looks like their parent company haven't filed accounts but are still active (someone has applied to have the compulsory strike off suspended) and part equity sold to GMC Ltd. - MJM directors are directors of parent companies and other recruitment or data analysis firms.

After lodging a new claim in the courts against MJM we successfully negotiated a settlement to end this - and hopefully - future disputes.

Sunday, May 17, 2015

Progress Part 2

After starting to get responses back from MJM support the picture had become clearer. Being nice with your SARs goes a long way - in fact if you were to be as rude and obstructive as most organisations receiving SARs are, a court would not look kindly on your summons.

So whilst they were being helpful I congratulated them on their approach and noted a couple of things to myself:
  1. The resume attached was from 2007
  2. When I went to their website and password-reset-logged-in I found contact and personal information also dating back to 2007
  3. Whilst writing this section of the blog post I checked to see if I could download the attachment again three months later....and I can; despite MJMs insistence that it would be removed in due course
 These simple facts completely countermanded the response statement; which I assume is partly a canned reply / policy statement. In short, it demonstrated a complete disregard for anything approaching respect for privacy or data. Have a look at this ICO guidance document if you don't believe me.

My Job Matcher did confirm that Manz Online (part of the RecSmart Recruitment Ltd fold) was the source. Of course not only had I never heard of them but I'd certainly be able to prove the lack of consent or chain of privilege from me to their databases.

Quick bit of research showed that Manz is based in Lahore and does not fall under the remit of the Data Protection Act (UK) or Privacy and Electronic Communications Regulations (EU). This is of course just conjecture but it would almost seem like the use of offshore lead generation firms was intentional to inflate subscriber numbers; which would mean a greater appeal to investors or other job seekers in the market perhaps. That is a rather pessimistic opinion but one that was suggested by another MJM spam-ee.

Of course 360 Resourcing are UK based and would therefore be under purview of DPA and PECR; had MJM acquired my details from someone like 360 I could then take action against both MJM and 360 after some investigation.

If you were in a similar situation with Manz Online feel free to get in touch with their director Zak Ahmed on Google+. It's a dead-end to the search for data sources.

On To Part 3 Or Back to Part 1

Sunday, April 19, 2015

Test & Learn



The last few years have been a really interesting adventure for me - I've set up two businesses and things are moving in the right direction. Along the way I've made some mistakes but more importantly; learnt from them.

Hopefully :)

This one relates to B2B late payments and lessons learned in preventing the situation. It's definitely worth getting a background in your monetary rights from UK Plc too.

When I first started it would have been fair to say that I was a novice in the world of contracting and it's nuances - Only good advice from my accountants and contractor colleagues really got me moving. However it was soon clear that even that wouldn't solve the underlying problem: What do you do if the customer doesn't take your invoice due dates seriously?

The first example is from my time working as a contractor for Woodrow Mercer. I don't think the recruiters themselves are really at fault but that doesn't excuse the accounting department. Most agencies seem to have rude and unprofessional accounts department staff - with few exceptions - and they frequently seem to attempt to bully or turn their nose up at contractors.

One agency, ERG, were particularly bad at this back in 2012 - I was sent threatening emails from senior recruiters and directors when I terminated the contract with them. They made wild [incorrect] guesses about where I'd taken the next contract and on recruiter even attempted to get in touch with relevant hiring managers. It was all bluster, aiming to play on the submissive psyche normally present in technical people. However I just prepared the particulars of claim document I'd need to take them to court for non-payment - they paid before the deadline to pay expired though.

Woodrow Mercer failed to pay on time on three separate occasions - the worst thing about this was that the client involved were such a nice bunch to work for. Really well gelled group of people who enjoy what they do. The second time payments were missed there was no excuses or apologies from WM so I called them.

They sent me an abrupt email saying that they'd pay one invoice but the other would have to wait - regardless of the fact that they were legally obliged to pay on both invoices due dates. In that scenario they did pay, but one week late on one and two weeks late on the other invoice.

The third time they missed payments I'd had enough of being passed off with bluster and excuses - Had a word with the client manager and respectfully noted that I would not be returning to site until the invoices were settled. One invoice is still outstanding 11 months on although for a relatively nominal fee. They've since stated that they will "...rigorously defend.." any claim in the courts - I may update that with another approach depending on some parallel research.

Wind the clocks forward a year or so and two other agencies have attempted to bully their way out of late payments. In both cases both the contract and the invoice T's and C's supported an instant late charge along with interest growing daily.

Uniting Ambition fell short of the mark after neglecting to pay the final invoice on due date (I would have been fine with it had their been discussion beforehand, some reasonable negotiation solves a lot). They attempted to negotiate a portion of the fines but then paid in full when I delivered a "notice before action". If it was the first time they'd paid late I might have let it slide but they'd failed to pay every single contractor at that client (~30 people) on the first invoice date. No apology was given and only a few vague excuses. An inexcusable attitude.

In all cases a reasonable discussion up front prevents any of this - Just a phone call to say there's payment problems and that your invoice will be 5 days late will make a huge difference to your planning. Having said that consistent late payments should give you all the indication you need. Try doing some research first and getting a credit check of the company before you sign a contract with them. That's often due cause for respectfully requiring them to change the payment terms on your contract. Talk to your bank about their B2B credit checking offering. You can throw the payment terms on any contract they offer back at them if they telling you they do 30 days payment but their credit rating barely supports 7.

Normally a lot of contract terms in the UK make it very tricky in relation to IR35 - never mind just getting paid. Lots of unprofessional agencies initially reject requests to change the contract; "it's a standard contract we use for everyone and do not change it". It's all bullshit. A contract review by your accountant or legal representative is worth every penny.

I work with other types of organisation directly and although some of these problems are common elsewhere, the attitude towards invoice due dates is not. You've worked hard for your rate and perhaps even worked far away from home to do so, why should getting paid be a struggle?

The Sting Of Chlorine


We often take the kids swimming and one of the pools is in Harbone. Facilities are good, kids have fun and we get to do some lengths too. However I made the mistake of buying some replacement goggles from the pool shop in the leisure centre - leading to a standoff in the reception area.

During the swim the goggles leaked and no matter what grip or band settings I tried they just kept leaking. After we'd finished I took them back to the reception desk and explained what the fault was (I just wanted either a replacement or a refund).

However the staff claimed that they could not refund the value of the goggles as they were not defective, and that they were not obliged to do so. I pointed out that my statutory rights as a consumer, plus those of standing legislation meant that as I was not happy with the product I could get a full refund. I also pointed out that I would not move from the desk and allow them to serve anyone else until the matter was resolved.

Whilst the staff went into the office for a huddle - I felt a little sorry for them having to deal with their employer's misguided principals - and the queue behind me grew. This is a good way of ensuring that retailers acknowledge their responsibilities and speeding a resolution; it's too easy to email or write letters and take no ownership or involvement due to the dissociative nature of words on paper.

However I got caught out - distracted whilst updating the Twatterverse on minute-by-minute changes to the situation (as if anyone was actually reading my twitter feed), the manager asked me to step over to another area to talk about the resolution.... fell for it.

The spell broken and the other waiting customers started getting to the desk. Bargaining position lost and hat tipped for being bettered.

All I could get was a credit note for the value of the goggles bought that day and the heartfelt promise of a phone call when they had the goggles in stock next. Maybe they're still waiting for the next batch? Either way I'll go to Amazon in future - even if I can't stand at the sales desk and stop other people getting served before they sort out my purchase.

Trotter Lettings Esq.

I had the misfortune to take up residence in a flat managed by Reed Residential last year. The flat itself wasn't bad as a property - although it would have been better had there been heating during winter.

And therein lies the comedy.

The problem with the heating was reported to them during the xmas holidays so the first delay in response was simply due to no-one being in office. As the weeks past though, and as my continued phone calls started being deflected by "Oh I'm sorry, Adam isn't at his desk right now", or "Adams in a meeting at the moment, can I take a message?".

I started imagining that Adam was printing out my emails and then using the paper copies to fuel an open fire - whilst wearing shorts and a t-shirt because of the heat produced - whilst I was shivering under jumpers, paying a premium rent for the pleasure.

Estate agents are a known quantity so it wasn't a Herculean leap of the imagination to realise that the primary contact - Adam - was simply avoiding my calls. There was a visit from an engineer to size up replacements, then the landlord wasn't sure if he wanted to replace them. Then he was getting other quotes, then the engineer visited again to get other measurements.

Nothing was moving in any direction other than a fob off and Adam seemed to be to focused on using my emails for firewood. Until February.

Then I cancelled the rent monthly standing order  and waited. By this point I'd had enough and was moving out but I thought it would be interesting to see how long it took Adam (or anyone else at Reed Residential) to get back to me and start playing nicely.

The response was simply astounding - Almost two days after the rent was due I got two emails and four phone calls (three of those on a Saturday)...of course this wasn't to apologise for months of refrigeration / premium rents; nor was it to ask if there was anything they could do. No - it was simply to chase for missing rent. So I explained that once the flat was in a condition befitting the rent and inventory I would be happy to pay full rent but in the mean time I'd deducted an appropriate amount retrospectively [i.e. since the problem first occurred]- meaning no rent was due that particular month.

And now everything changed - suddenly radiator replacements were being flown in by winged chariots piloted by Valkyrie smoking Romeo y Julieta's; there had been no delay, simply a misunderstanding and should I not pay rent I would be taken to court and flayed by their eight storey tall lawyers.

Of course I'd already moved out at this stage so it was just for my own entertainment (causing them the same inconvenience they caused me).

The net result was that they kept the deposit and probably just about broke even, someone at Reed Residential was apparently relieved of their job (the eponymous Adam) and the world continued unabated. However the real comedy occurred a couple of months later and really highlighted the care taken for all of their customers and tenants.


Now its entertaining astounding for a number of reasons:
  • The apartment doesn't have a microwave, I had my own and never mentioned it to anyone at Reed
  • I'd moved out on 28th February and this email arrived 22nd April
  • I made no request relating to anything other than the basics. Like heating.
  • Pretty sure they're talking about a different apartment
  • Pretty sure that email should have gone to someone else
  • Someone else probably got angry at Reed for not delivering on their promises

Wednesday, September 24, 2014

Council Tax: The Saga Continues

So despite being promised a response with 15 working days by Lisa Atkins ... I've received nothing. Perhaps they want to sweep the whole affair under the carpet? No-one likes seeing their ineptitude blogged about.

I may prod them next week after I've finished laughing about the "new" iPhone.

Tuesday, August 12, 2014

Blogger Behind The Times

Just tried to log in to Blogger on Win 8.1 / IE 11 to be greeted by a "Browser not supported" message. Seems that the Googlers are still supporting IE 9, but not IE 11 - Not sure that's compatible with Microsofts own support lifecycle though...?

The only reason I'm curious is that Aviator won't let me add comments to Blogger posts via Google+ - probably either being a bit too paranoid or having conflicting rules dictating the combination of cookies and popups. So you on Aviator you can log in to the Google ecosystem, but when you view your own blog and try to comment.... it does nothing :)

Seems to work just fine in IE though. Happy days.

Thursday, September 27, 2012

Commodity Update

It seems that it's a two-way street - After writing a post this week about tips for handling tricky recruiters, a large section of the recruitment industry itself has outed one particular individual.