Privacy policy/DPA

tomd

Free Member
Oct 17, 2009
19
0
I am setting up a website to support a software product, which will include discussion forums about the product.

The site isn't intended to gather personal information. It will log IP addresses, deleting them after 3 days.

If users choose to register (as required to post to the forums), they will need to supply a user name, valid email address and password, but not their real name, age etc.

Session cookies will be used to track logged in users (but only for the purpose of knowing that they are logged in).

Some users are likely to be under 18, but that information isn't stored by the site.

Does any of this mean I need to register under the DPA?

What would be required in my privacy policy? Is the information above sufficient?
 
Hi - from the description you have given below it is unlikely that you are required to register under the DPA. You can undertake an online annonymous check with the ICO by going to the following link http://www.ico.gov.uk/for_organisations/data_protection/notification/need_to_notify.aspx

If you are a small business, registration only costs £35 so it might be worthwhile to register anyway. Irrespective of whether you register or not you will still need to comply with the data protection principles. However if you fail to register and you are required to then you could face a fine.

In relation to your Privacy Policy, this needs to state that you will be using cookies. On May 25th the law will be changing in the UK and will require that you obtain your customers consent to the use of cookies. Further guidance will be released on this in the next few weeks and the ICO have stated that they do not intend to take any action immediately against website owners until it becomes clear how the new regulations will operate. I can provide you with a template Privacy Policy which should meet your requirements - www.mckennahughes.co.uk. You can also read more about the cookies rule on the site.

Best of luck.
 
Upvote 0
You WILL need to register (its called 'notification'). I interviewed the Assistant Data Protection Commissioner in 1999 for an article on an old internet law site I ran and he confirmed that an email address alone can come within the definition of 'personal data' and thus requiring notification of any business that collects and stores addresses. The reason is because the definition of 'personal data' is data from which a living individual can be identified. An [email protected] address will not be personal data but [email protected] will be since it is likely to be Fred Smith of Smith and Co and the company, and thsu which Fred Smith, can be identified from its domain.

Now whilst some addrsses are not personal you are bound to collect some that are. In any event, even with an anonymous address, it only takes the person who uses it to post a message on the Forum identifying himself to make that address itself then come within the definition of personal data. The Forum messages themselves can be personal data to the extent that people identify themselves.

I would be pleased if Mairead could post a link to any statement by the ICO to back up what she says as their advice on the ico site says the opposite (emphasis added):-

"You need to take steps now to prepare and ensure you are ready to comply" and

"if the ICO were to receive a complaint about a website, we would expect an organisation's response to set out how they have considered the points above and that they have a realistic plan to achieve compliance. We would handle this sort of response very differently to one from an organisation which decides to avoid making any change to current practice. The key point is that you cannot ignore these rules. "

So you cannot sit back and do nothing for the 'next few weeks' until further guidance is issued as suggested. You have to get to understand the new rules now and whilst you may not have to implement immediately you have to satisfy the ICO you have planned what to do with your website. If you have no detailed oplan then they will take action. If you think it unlikley to come on their radar, don't forget competitors or people with complaints can shop you.

In any event, enforcement is not just up to the ICO but individuals can claim compensation for any breaches as from May 26th (not the 25th)

Old privacy Policies need firming up as well as site content and navigational and button changes to ensure you can prove opt-in consent not default consent through absence of opt-out.

I am putting together a webinar if anyone is intersted - email me
 
Last edited:
Upvote 0
On May 25th the law will be changing in the UK and will require that you obtain your customers consent to the use of cookies.

Just noticed this and to avoid any confusion, the law has always (since the DPA 1998) required the obtaining of consent to the use of cookies. What the new change is about is that it will no longer be enough to simply use the words of a privacy policy to obtain it by default. You have to prove positive and informed consent. The only area of implicit consent is in certain uses where the browser allows a cookie consent setting,but as not everyone will use such browsers you still need to provide for any that do not.
 
Upvote 0
Just to clarify a few points here - the holding of personal data does not of itself require notification under the DPA. There are a number of other factors which have to be taken into account when deciding whether registration is required such as whether you are a data controller, how you process the data and the purpose for which you are processing the information. The best way to establish this is to undertake the check on the ICO site as mentioned previously http://www.ico.gov.uk/for_organisations/data_protection/notification/need_to_notify.aspx.

Prior to yesterday, 9th May, the only guidance issued by the ICO on the new cookies rule was the following - http://www.ico.gov.uk/news/current_...1/dpo_conference_2011_workshop_i_q_and_a.ashx. The e following is an exact quote from this press release
"In conclusion it was stressed by the ICO that, although the new law will come into force on 25 May 2011, there will be no immediate enforcement action for websites that do not comply with the new ‘cookies’ rule, as considerable work needs to be done in this area and can only usefully be implemented once the shape of the UK Regulations is clear."

The ICO issued new guidance yesterday in the following press release http://www.ico.gov.uk/~/media/docum...regulations_advice_news_release_20110509.ashx which is what the previous commentator is referring to.

Individuals have had the right to bring action against organisations which have breached the DPA for sometime now.

As the previous commentator has stated the new rule requires explicit consent to the use of cookies as opposed to implicit consent. You will therefore need to demonstrate that you have obtained that consent as previously stated.


 
Upvote 0
Just to clarify a few points here - the holding of personal data does not of itself require notification under the DPA. There are a number of other factors which have to be taken into account when deciding whether registration is required such as whether you are a data controller, how you process the data and the purpose for which you are processing the information.

Yes but all that is a given here. If the data is personal he needs to register for the purposes he explained.

"In conclusion it was stressed by the ICO that, although the new law will come into force on 25 May 2011, there will be no immediate enforcement action for websites that do not comply with the new ‘cookies’ rule, as considerable work needs to be done in this area and can only usefully be implemented once the shape of the UK Regulations is clear."



OK - although that goes back to the consultation period and the shape has been clear for some while. It was a strangely worded statement in that the lack of shape at that time could not justify future non enforcement once the wording became clear and it was bound to become clear by the time it comes into force. Anyway yesterday's statement shows they have hardened up their act.



Individuals have had the right to bring action against organisations which have breached the DPA for sometime now.

I agree - my reference to the date was to the new changes we are talking about, ie that even if there is a delay by the ICO that does not affect what individuals might do under the new law.
 
Upvote 0
I take the view, in the real world that in most cases the £35 spent registering is less expensive than the time it takes debating the finer details. Positive consent for many businesses is obtained for a number of communications and privacy policies can have an opt in section to cover the use of cookies - we also advise on alternatives technological solutions to tracking clients in this way. Happy to chat to you further about your needs for the web site including the DPA changes and how they may effect your business.
 
Upvote 0
The interesting sentence in the ICO document is

The only exception to this rule is if what you are doing is ‘strictly
necessary’ for a service requested by the user.


Would a simple cookie used to store the fact that a user is logged in be exempt? Without it, the user would have to log in again each time they moved to another page of your website.
 
Upvote 0

Latest Articles