ANNOUNCEMENT : ALL OF ROYAL MAIL'S EMPLOYMENT POLICIES (AGREEMENTS) AT A GLANCE (Updated 2021)... HERE

ANNOUNCEMENT : PLEASE BE AWARE WE ARE NOT ON FACEBOOK AT ALL!

Alleged Breach of Data Protection Act

Got a question for a CWU Rep? And all CWU related matters.
TrueBlueTerrier
FORUM ADMINISTRATOR
Posts: 72713
Joined: 30 Dec 2006, 10:29
Gender: Male
Location: On my couch

Alleged Breach of Data Protection Act

Post by TrueBlueTerrier »

A member has asked me to post the following so that they can remain anonymous.

Royal Mail, it is alleged, have apparently breached the Data Protection Act by forwarding emails containing highly sensitive case notes and deliberations. They concerned an appeal against dismissal for alleged gross misconduct, the now infamous tried and trusted "delay to mail" method of sacking someone. The emails were allegedly sent from an RM business account to a shared account for printing out on a printer.

At least one formal complaint has been made to the ICO Information Commissioners Office and is currently under investigation.

However there are indications that this practise of forwarding and printing emails relating to Appeals cases is allegedly a routine everyday practise - and may be not an isolated incident.

Has anyone else has similar experiences.
All post by me in Green are Admin Posts.
Any post in any other colour is my own responsibility.
If you like a news story I posted please click the link to show support Any news stories you can't post - PM me with a link
My sharing of news articles should not be interpreted as an endorsement or condemnation of any particular viewpoint or the issues presented. I share them solely for informational purposes.
Talell
MAIL CENTRES/PROCESSING
Posts: 227
Joined: 16 Aug 2010, 22:31
Gender: Male

Re: Alleged Breach of Data Protection Act

Post by Talell »

Erm... That is not necessarily a data protection infringement. It depends on whether the data was secure for the entire time.

For example, the appeals manager, in this instance, could be working from home, working on an encrypted laptop, so the data is safe. They then need to print it out for audit purposes, keeping a paper trail. They shouldn't use their home printer, as the data was not being properly protected and is at a high risk of being compromised. However by sending it to the "shared account", to be printed out at the workplace (a secure environment) the data could remain secure. So all RM have to do in this example is show that the information was secure in that shared account.

Of course the above is dependant on the fact that the "shared account" is still an internal email used for the above purpose.

That's all that the data protection act covers iirc, I don't know anything about "eyes only" documents, but I don't think that the ICO would have any jurisdiction over that.

That's what I know based on my, admittedly basic, understanding of DPA.

I'll see what I can dig up.
TrueBlueTerrier
FORUM ADMINISTRATOR
Posts: 72713
Joined: 30 Dec 2006, 10:29
Gender: Male
Location: On my couch

Re: Alleged Breach of Data Protection Act

Post by TrueBlueTerrier »

Talell wrote: Of course the above is dependant on the fact that the "shared account" is still an internal email used for the above purpose.

I have been advised by the source that the printer/email account were not on or part of Royal Mails secure (or even insecure) network. They were both home based rather than business based.
All post by me in Green are Admin Posts.
Any post in any other colour is my own responsibility.
If you like a news story I posted please click the link to show support Any news stories you can't post - PM me with a link
My sharing of news articles should not be interpreted as an endorsement or condemnation of any particular viewpoint or the issues presented. I share them solely for informational purposes.
Talell
MAIL CENTRES/PROCESSING
Posts: 227
Joined: 16 Aug 2010, 22:31
Gender: Male

Re: Alleged Breach of Data Protection Act

Post by Talell »

Well RM have a major problem, because they have broken the data protection act in several places.

This is a really big issue because it is an appeals manager, I think they handle gross misconduct, attendance etc all in one. Simply due to the fact that they are handling information about your health, which has its own section in the law, and are not keeping it secure they face huge fines.

Plus they have doubled their infringements on every account due to: 1. giving the data to a 3rd party that does not have the privilege of having the data (the personal email provider) and 2. having the information in an unsecured enviroment (e.g. using their printer at home).

Another angle to think about it at is whether it is policy, whether local to that unit specifically, or nationally. It goes without saying that the fines are larger when a larger scope is involved. However I have never heard of that policy, at a local level, but it is plausible that it is in place for middle management (including middle managers) and above.

Just to keep any speculation in line, anything that is on royal mails network, be it a word document or an email, is classed as secure. This is because royal mail has appropriate countermeasures and policies in place to prevent and detect possible data theft, e.g. encryption of all data on the network, email monitoring, limiting access to only those who need the information and even just the fact you have to sign onto a computer before you can use it.