On 25th May 2018 the General Data Protection Regulations (GDPR) will become law across Europe. The regulations appear to be an attempt to reign in the irresponsible behaviour of some multi-national companies who harvest huge amounts of personal data for commercial purposes. As with most legislation of this type it isn’t tailored to one particular organisation so everyone who either controls or processes data is affected in some way or other.
It’s hardly surprising that licensee Pubwatch members have raised some concerns about whether they will be able to continue to share data. Particularly when they see almost daily news articles focusing on storylines such as the ‘right to be forgotten’ or they are being bombarded by companies wishing to sell their latest ‘GDPR compliant’ training package. And of course there are other organisations who look down their noses at licensee run schemes and are very eager to offer to handle your data for you – but at a price.
Do you have to take the new regulations seriously? Yes of course you do; but we don’t think you should panic unnecessarily. Much of the existing Data Protection Act 1998 legislation will be found within the new GDPR. So if you already operate to existing DPA principles then you may only have to tweak your policies and practices to ensure compliance.
I say ‘if’ because just putting something in writing will mean nothing if the Pubwatch members or your own door and bar staff do not understand and take seriously their personal responsibilities. Let’s imagine a fictional scenario:
A known drug dealer; we’ll call him Micky Brown, is detained by door staff at the ‘Go To Café Bar’ having been found in possession of a quantity of illegal drugs. Police are called and he is arrested. He is charged with being in possession of drugs with intent to supply and later pleads guilty at court and is given a suspended custodial sentence.
A meeting of the local Pubwatch scheme takes place and they discuss the incident and decide to ban Micky for 12 months. The police liaison officer confirms that Micky was arrested and that they have a photograph which they are willing to provide to the Pubwatch for a policing purpose i.e. to detect or prevent crime. The police subsequently update their photographic poster with Micky’s image and it is circulated to Pubwatch members. So far so good?
A Pubwatch member later pins the poster up in private rest room of his pub, so that his door and bar staff can see who is currently banned. One of his young bar staff knows Micky and thinks he’s a real loser. As a joke he takes a picture of the poster on his mobile phone and shares with his mates by posting it on his private Facebook page. One of his friend’s thinks this is a really funny and worth sharing with the wider world so he copies the post and ‘tweets’ it to his wide circle of friends and the message is then passed on exponentially to more and more people. It’s only a small community so Micky soon learns that his police photograph is being shared. Does he:
A) Bask in his new found celebrity status; joins a popular TV reality series and makes a fortune selling copies of his own designer tee shirt which features his police mug shot?
or
B) Claims the Pubwatch has denigrated his ‘good name’, infringes his human rights and contacts the Information Commissioners Office (ICO) to make a formal complaint?
You may think the scenario is highly unlikely, but with social media becoming more pervasive in our day to day lives it’s not inconceivable that someone could undermine your legitimate interests in a similar way. So how do you prepare for GDPR and assure the ICO that you are working within the rules?
Users of our services will know that we already provide ‘good practice’ documentation that can be adapted to your local scheme. We are currently reviewing this documentation to take account of GDPR and it will be available to you should you need it. It is not my intention to provide a comprehensive review of GDPR but here are a few key point to consider in the context of running a Pubwatch scheme:
• You should register your scheme with the ICO. It’s quite easy to do so on-line and should only cost approximately £35 a year. We suggest that Pubwatch schemes are ‘controlling’ personal data (and this can include ‘processing’ the data) for their own ‘legitimate interests’ i.e. they are trying to prevent crime and disorder in their premises and the controlling of Micky Browns name and police image is a legitimate way of warning their members the he has been excluded from the schemes premises. Registration with the ICO is not a ‘get out of jail free card’ you still have to comply with the regulations but it does show that you are trying to be open about your activities.
• The Pubwatch scheme will need to document their ‘decisions’ under ‘legitimate interest’, so they can demonstrate compliance under the new GDPR. What does that mean? Well from my perspective Micky Brown is not voluntarily giving you his data, but you are definitely recording his personal details because of the decision to ban him for 12 months and in some form you will be making that banning decision available to members. The ICO would like organisations to keep a ‘schedule’ of this type of decision making; but most schemes are unlikely to be dealing with significant amounts of personal data and will keep formal written minutes of their meeting and will maintain a ‘banning list’ anyway, so that’s a good starting point. As long as you regularly review and minute your decisions and update the banning list then you should be able to easily provide evidence should the ICO decide to audit your activity.
• Individuals have a right to know how their personal data is being processed and the identity and contact address of the data controller. Most schemes will already provide this type of information because they will be sending out banning letters. But let’s unpick some of the issues.
We all know of instances where someone who is disgruntled about being banned, has focused their anger onto a single licensee who they perceive to be responsible for their plight. So firstly I can hopefully set your mind at rest that it’s the ‘Pubwatch’ that is controlling the data, not any one named individual who happens to be a member of the scheme; and it follows therefore that you don’t have to give Micky Brown your personal contact details. You obviously need to provide a Pubwatch address that Micky can contact but again that doesn’t have to be your personal home or work address. There are many ways of overcoming this problem; for example some schemes manage their correspondence through a Pubwatch PO Box number or a third party such as a local brewery or Business Improvement District etc. which might be providing administrative support.
Secondly you may not know where Micky Brown lives. It’s unlikely that the scheme members will know or wish to know where the banned person lives and they will rely on the police to deliver or post the banning letter on their behalf. But it would be unreasonable to believe that the ICO would hold a Pubwatch to account if Micky Browns current address is unknown or he has decided to avoid delivery, in the mistaken belief that by doing so he in some way stalls the banning process. As long as you take reasonable steps to fulfil this obligation it should be sufficient evidence of compliance.
Thirdly, what type of information do you provide Micky Brown? Well obviously you will be telling him that the Pubwatch had decided to ban him for a period of 12 months, because of an incident at the ‘Go To Café Bar’. But this letter is also your opportunity to tell Micky why his personal data is being processed, who is receiving his personal data and his rights – which includes the right to lodge a complaint with the ICO. We are currently reviewing the NPW generic banning letter available to Pubwatch members to include this type of information.
• Individuals have the right to have their personal data rectified if it is inaccurate or incomplete. It’s not unusual for people to challenge their Pubwatch ban and they will often question the decision making process or the licensees right to exclude them under Common Law because it infringes their human rights. However this relates purely to the recorded ‘data’ that your scheme controls.
So if Micky Brown demands to know what personal information you hold on him you are obliged to provide him with a copy. This will usually relate to a copy of the Committee minutes and the banning list. However be careful that you only provide information relating to him alone as anything relating to a third party, and I would suggest that includes names of persons attending the meeting, must be redacted, because you wouldn’t have their permission to share the data.
Just because Micky might disagree with the circumstances which led up to his being banned does not mean that have misused his personal data. And if you are satisfied that the incident took place, then it would usually be sufficient to note in your records that Micky disagrees with the characterisation of the incident or his behaviour.
Any Police photograph shared with the Pubwatch scheme remains the property of the Police force who supplied it; so you are not at liberty to share that image without their permission. They will have their own procedures in place to respond to such requests and they will have to justify their reasons for sharing the data with the Pubwatch scheme.
• That brings us onto the somewhat thorny issue of what happens if you have a data breach. In the fictional scenario I demonstrated what could go wrong. The problem is that you can have very strong policies and procedures and data storage facilities in place but it’s usually the unthinking human error or malicious act that exposes you to scrutiny.
So what appropriate measures have you in place in the event of a data breach and how will you identify whether it requires notification to the ICO and individual concerned? It’s in the Pubwatch schemes interest to have some measure of audit process to oversee the sharing of personal data.
Members need to have signed and understand the schemes data integrity agreement and if they allow staff members to access this information on a ‘read only’ basis then they also need to understand their personal responsibilities.
Finally I need to say that the above observations are based on my own personal views of GDPR in the context of running a Pubwatch scheme. Whilst I have many years’ experience of Pubwatch I am not a legal or data protection expert so I can only offer this as my interpretation of the regulations and not conclusive legal advice.
In undertaking the review of our Good Practice Guide and other documentation we have sought legal advice from Three Raymond Buildings, a highly reputable legal practice, which should provide some certainty for implementing consistent practice across UK Pubwatch schemes. The updated documents will be published when they become available. In the meantime if you have any concerns about the legal implications for your scheme I would urge you to visit the ICO website www.ico.org.uk where you will find comprehensive advice on the GDPR.
