• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
  • Home
  • Good Books
  • Tools
  • Blog
  • Darren
  • Contact
  • Hire Me
Small Biz Geek

Small Biz Geek

Small Business Design, Marketing & Technology Journal

Solving small business design, marketing & tech problems

  • The Internet
  • Marketing
  • Graphic Design
  • Web Dev
  • Web Design
  • Social Media
  • Privacy & Security
  • Tech
  • Misc

Privacy and Data Protection is a Matter of Life and Death ☠️

Published: May 22, 2018; Updated: September 13, 2023 Filed Under: Internet, Legal, Security

A data protection failing can threaten everything from a person’s bank account to their life. At the very least, it may cause damage and distress.

Elizabeth Denham

The private information of individuals is as valuable as currency itself, which is why the cybercrime industry was worth $450 billion in 2016. 

Yes, you’re busy. You’ve got other things to think about besides data protection and legal compliance, but if you’re running a business in the 21st century this is what you’ve got to deal with. 😐

Banks, credit card companies, pension providers, social media companies and any other business, public authority or organisation should be taking steps to protect the data of individuals. 💽👇

Examples of Data Protection Failings

Here are just a few stories serving as examples of the issues we face where the accessing of personal data is concerned, whether it is accessed illegally or withheld from those to whom it belongs:

  • The Panama Papers data leak might have seemed like a victory for those opposed to the tax-avoiding cash management schemes of the mega-wealthy, but suppose those personal details had belonged to vulnerable members of society, like orphans, whistleblowers or witnesses of serious crime?
  • And then this happened: Details of at risk children under court protection accidentally sent to Leicester taxi firms.
  • The Windrush scandal saw legal British residents denied access to their own personal data.
  • Facebook. Cambridge Analytica. Enough said.
  • Sheffield Credit Union tried to downplay a serious case of hacking for public relations reasons.

The UK’s Data Authority: The Information Commissioner’s Office

The Information Commissioner’s Office (ICO) is the UK’s data protection authority, functioning as a public body, reporting to parliament and funded by the Department for Digital, Culture, Media and Sport. 📄🖇️

They uphold the rights of individuals who want to keep control of their personal information. 🛡️🧐

The ICO’s work includes (in the most serious circumstances) financially penalising wrongdoers with fines reflecting the risks associated with the failings of the organisation. ⚖️🪙

Examples of Fines Handed Out

Here are a few examples of fines handed out in severe situations, unsurprisingly, to larger organisations and businesses: 

  • In 2014 a British abortion charity was fined by the ICO after a hacker accessed the BPAS website (which stored details of pregnant women seeking advice on termination) and threatened to leak the information online.
  • The Carphone Warehouse was fined £400,000 by the ICO for failing to maintain their WordPress website software, resulting in a security vulnerability and unauthorised access to customer and employee data.
  • Crown Prosecution Service fined £325,000 after losing victim interview videos

GDPR: An Update to Data Protection Law

The 25th May 2018 saw a European-wide legislative update to the Data Protection Act 1998 become enforceable. It’s called the General Data Protection Act, and is overseen by the ICO in the UK. 👀

Regardless of Brexit, this law applies to the UK. ⚠️

In fact, the law applies to any business, charity or organisation anywhere in the world if they want to collect and processes information about individuals in the European Economic Area. 💻👤📋📊

The Data Protection Act of 1998 was based on the Data Protection Directive 1995 and is sorely in need of an overhaul given the changes in technology and commerce ever since. 😓

It’s strange to think that most of us carry a tiny computer (your smartphone!) which processes vast amounts of personal data, and yet still, many are unconvinced that data protection is a worthwhile pursuit. 😐📱

Here’s one of the former information commissioner, Elizabeth Denham, making an address in April 2018:

Watch video on YouTube

John Edwards began his term as the new UK Information Commissioner in January 2022.

“Data” is the New “Oil”

If you’ve been following the news lately, you’ll know the ICO have been investigating Facebook and their involvement with Cambridge Analytica.

Cambridge Analytica, the data-mining company, was paid millions to manipulate and seduce voters with non-factual information using highly-targeted Facebook advertising campaigns. 🤥🎯🗳️

On hidden camera, they inadvertently revealed their role as purveyors of fake news, abusers of Facebook data and as self-confessed agents of entrapment and political smear. 🤨

They gained access to 50 million Facebook users’ data using an online personality quiz.

Those who took the quiz exposed everyone in their Facebook friends network to the data harvesting agenda of the app. 🌽🙄😮🤦

The story came to the world’s attention after a Channel 4 news TV report exposed the dealings of CA with undercover footage from their sting. It was the culmination of a year’s worth of investigation and research by Guardian journalists. 🕵️‍♀️🕵️‍♂️🎣

Watch video on YouTube

What Small Businesses Must Do

To bring this back down to earth, let me remind you that if you’ve been respectful, conscientious and transparent with the personal data of individuals up till now, you’ve got far less to worry about than the big companies we’ve seen exposed in the media for their various gaffes. 🤜

Familiarise yourself with your obligations, such as registering with the ICO (you may or may not have to) and creating an easy-to-understand privacy notice explaining exactly what you do with a person’s information.

What information do you collect about people in order to run your business? How do you collect it and why? 📊

If you take a look at my privacy notice you’ll see it is informal(ish) and uses easy to understand language. I’m still working on it and see it as a long-term project. ✍️

The ICO has more information on privacy notices but I prefer Heather’s presentation slides on the subject.

Summary: Don’t Just Comply with Privacy Laws – Understand Them

Data protection in the EU is considered a fundamental human right whereas in America, it is thought of as a feature.

It’s rare to see an American organisation voluntarily take personal data protection seriously because they think it makes them less competitive and therefore less profitable. 😶💵

Don’t conflate EU data laws as a slight on British sovereignty, though. 📜☔

Continental Europe knows all too well what happens, for example, when an entire race of people without adequate protection is targeted for extermination. 

Yep. The Nazis located, arrested and murdered many Jews on the basis of their birth records. Personal data. 🔖🫵

To emphasise the point about data snooping, it sounds like president Donald Trump has a list of who the USA considers “undesirable” owing to the fact that an innocent family were pulled out of an airport queue and questioned. Their data had been obtained and was being used against them. 👾

None of us can predict the future but history has taught us to expect power to corrupt and personal data to leak, be stolen and misused. 🔢🔡🔓💧

As a small business, let your customers know you’re diligent, trustworthy and principled. Let the wider world know you have the public interest in mind by communicating your privacy policy in significant detail, and live by it. 👌


More on Data Protection

☎️ Future Privacy Regulations: How Will These Affect Telemarketers?

🎲 Cookies, Privacy and Permission: Is Your Website Legal?

📜 UK Businesses Electronically Processing Data Are Legally Required to Register with the ICO

👀 Theresa May’s Snoopers’ Charter Gives Unprecedented Legal Surveillance Power to Spooks

🔓 How Safe Is Your Password from the $450 Billion Cybercrime Industry?

You Might Also Be Interested In...

  • What I Learned as a Google Search Engine “Rater” 🔍
  • Browser Ad Blockers are Destroying Website Functionality and Killing Content 🛑
  • Link Bait Specific CommentLuv Blog Posts to Market Your Website

Filed Under: Internet, Legal, Security Tagged With: breaches, cybercrime, Data, data protection, Elizabeth Denham, ePrivacy, EU, fraud, GDPR, ICO, individuals, Information Commissioner's Office, Law, Legal, PECR, personal data, UK, USA

About Small Biz Geek

I'm Darren, helping small businesses with design, marketing & tech.

Small Business Website Design

Do you need help with something web related?

Hire Me

Reader Interactions

Subscribe to Blog Feed by Email

Your email address won't be shared. You'll never be spammed. Check your inbox to confirm opt-in.

Add Your Thoughts Cancel reply

Your email address is safe and will NOT be shared with anyone else.

Hateful, spammy or abusive comments will not be tolerated.

For more information please see the comment policy.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Primary Sidebar

Search Website

Latest Blogs

  • Is Generative Engine Optimisation (GEO) the Answer to the Future of Search? 🎨
  • How Hiding Your Phone Number and Using a Booking System Repels Time Wasters and Helps “Positioning” 🗓️
  • “Fucking Good Content” – Dan Kelsall (Book Review) 📘
  • Scam Poetry: The Time I Was Recruited to the Cult of Amway ⚠️
  • A Story of Seductive Social Media Success and Neglected Email Strategy 🏚️
  • The Classic Social Media Trend Destined to Ruin Your Business 😭
  • Looking for Online Work? Don’t Fall for this Fake Hays Recruitment WhatsApp Scam ⚠️
  • Cream of the Crap: How Fake Reviews, Bad Businesses and Dangerous Products Rise to the Top 💣
  • Exposed: The Hong Kong Investment “Fraud Recovery” Scammer Deceiving Victims 🤑
  • Computer Says No: Does Your Website Work for People with Disabilities? ♿
  • Chinese Tinder Profiles Are Using Photos of Pretty Girls to Scam “Investors” 💋
  • Small Biz Owners “Trapped” Using Email Addresses Belonging to Internet Service Providers 🪤
  • In the Pandemic, QR Codes are Finally Proving Worthy in the West 😷
  • Small Businesses Finally Start Marketing… and All It Took Was a Global Pandemic 🏁

Footer

Primary Navigation

Home
About Darren
Good Books
My Tools
Blog Posts
Hire Me
Contact Me

Derby & Nottingham Area

The Internet
Marketing
Graphic Design
Website Development
Website Design
Social Media
Technology
Miscellaneous
Privacy & Security

Let’s Connect

Twitter
YouTube
LinkedIn
RSS

Small Business Blog · Privacy Policy · Commenting Policy · Website Disclaimer · ICO number: ZA305900


Written and designed by Ilkeston Web Design

  • Home
  • Good Books
  • Tools
  • Blog
  • Darren
  • Contact
  • Hire Me