Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider policy on informing people when we get requests for their personal information #814

Closed
RichardTaylor opened this issue May 18, 2021 · 5 comments
Labels
stale Issues with no activity in over a year

Comments

@RichardTaylor
Copy link

Requests could be:

  • Court orders
  • Police requests under PACE
  • Subject Access Requests by third parties, where third party data is mixed up with the requester's personal data.

We sometimes get notices of proposed requests/orders prior to the requests/orders themselves.

We may not legally be able to provide notice to those whose data is involved straight away.

@garethrees
Copy link
Member

Somewhat related to #815.

@RichardTaylor
Copy link
Author

Example of how Apple informed one of their users about a request from the FBI for their personal information:

https://twitter.com/ringo_ring/status/1390782451140767749

@RichardTaylor
Copy link
Author

Section 47.8 of the The Criminal Procedure Rules 2020 states those who may apply to vary or discharge an investigation order (including a production order under the Police and Criminal Evidence Act 1984) are: an applicant; the respondent; or a person affected by the order.

If those affected by the order are not informed of it they can't avail themselves of their right to challenge it.

@RichardTaylor
Copy link
Author

There was a previous case in 2015 where we received correspondence from a legal firm acting behalf of a private client seeking a user's personal information for the purpose of taking action in respect to an allegation of defamation.

We pointed the legal firm to the user-user messaging system and suggested they contact the user (this is something we often do in such cases as it often negates the need to request user data from us).

We alerted the user to what had happened, and what we'd done, and advising them on how the user-user messaging system worked.

That was a rare case of us alerting a user to a request for their personal information - handled under our policy of considering such requests on a case by case basis.

@HelenWDTK HelenWDTK added the stale Issues with no activity in over a year label Nov 17, 2024
@HelenWDTK
Copy link
Contributor

This issue is being closed due to a lack of discussion or resolution for over 12 months. Should we decide to revisit this issue in the future, it can be reopened.

@HelenWDTK HelenWDTK closed this as not planned Won't fix, can't repro, duplicate, stale Nov 17, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
stale Issues with no activity in over a year
Projects
None yet
Development

No branches or pull requests

3 participants