Hello! (Sign in or sign up)

Track this request

Act on what you've learnt

Similar requests

Phorm/Second Phase of European Commission Infringement Case 64/08/INSO Dear Mr John, Please find attached our response to your internal review request. Regards, Information Access Team Communications via... Refused.
Refused by Home Office to P. John on 2 March 2010.
British Telecom, 121Media (Phorm), and Apropos/ContextPlus/PeopleonPage Link: [1]File-List 22nd June 2009 Case Reference Number IRQ0249537 Dear Mr John I am writing in response to your request for the inform... Information not held.
Information not held by Information Commissioner’s Office to P. John on 22 June 2009.
121Media, Phorm, and Covert Trials In 2006 and 2007, British Telecom conducted covert mass trials of a communication surveillance system supplied by 121Media. The system intercepted t... Awaiting internal review.
Request sent to Prime Minister's Office by P. John on 26 March 2009.

More similar requests

Event history details

Are you the owner of any commercial copyright on this page?

T-Mobile

P. John made this Freedom of Information request to Information Commissioner’s Office

The request was partially successful.

P. John

17 November 2009

Dear Sir or Madam,

according to reports today, the Information Commissioners Office
were alerted by T-Mobile to an unlawful leak of personal
information.

"When it became apparent that contract renewal information was
being passed on to third parties without our knowledge, we alerted
the Information Commissioner's Office"

Please will you tell me;

- when did T-Mobile alert the Information Commissioners Office?
- please will you disclose the correspondence items (email, fax,
letter etc) from T-Mobile associated with that alert, with dates
- please will you disclose the correspondence items (email, fax,
letter etc) sent in response by the ICO, with dates
- please will you disclose the number of people who have been
interviewed in connection with this matter
- please will you disclose the number of warrants obtained, and the
number of warrants executed on premises

In passing, you'll understand my amazement that you would take such
drastic action against T-Mobile, yet take no action at all with
respect to the BT/Phorm scandal.

Please could you also take this opportunity to assure me that
T-Mobile will not escape compliance with the Data Protection Act
because this was a functional and technical trial of an advertising
idea, it was small scale and technical in nature, and it would have
been difficult to frame any advice for customers about the nature
of the leaked information and obtain any relevant consents for the
processing of personal data with a wording that would have any
resonance at all for theory customers?

Because it would be a scandal if they did.

Yours faithfully,

P John

Link to this | Send follow up

P. John

28 November 2009

Dear Sir or Madam,

please acknowledge receipt of this Freedom of Information request
(now a week elapsed);

http://www.whatdotheyknow.com/request/t_...

Please indicate when I will receive the information requested from
you.

Yours faithfully,

P. John

Link to this | Send follow up

Information Commissioner’s Office

29 November 2009

Link: [1]File-List

29th November 2009

Case Reference Number IRQ0280558

Dear Mr John

Thank you for your e-mail dated 17 November 2009 and subsequent e-mail
which we received today.

Your request is being dealt with in accordance with the Freedom of
Information Act 2000. We will respond by 15 December 2009 which is 20
working days from the day after we received your request.

Yours sincerely

Charlotte Powell

Internal Compliance Manager

show quoted sections

Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow,
Cheshire, SK9 5AF
Tel: 01625 545 700 Fax: 01625 524 510 Web: www.ico.gov.uk

References

Visible links
1. file:///tmp/rad4A552_files/filelist.xml

Link to this | Reply to this message

Information Commissioner’s Office

7 December 2009


Attachment ICOReviewProcedure V7.doc
147K Download View as HTML


Link: [1]File-List

7th December 2009

Case Reference Number IRQ0280558

Dear Mr John

I am writing further to our email dated 29 November 2009 in which we
acknowledged your request for information to the Information
Commissioner’s Office (ICO).

Specifically you referred to “an unlawful leak of personal
information” by T-Mobile and requested;

“- when did T-Mobile alert the Information Commissioners Office?
- please will you disclose the correspondence items (email, fax, letter
etc) from T-Mobile associated with that alert, with dates
- please will you disclose the correspondence items (email, fax, letter
etc) sent in response by the ICO, with dates
- please will you disclose the number of people who have been interviewed
in connection with this matter
- please will you disclose the number of warrants obtained, and the number
of warrants executed on premises”.

As explained in our acknowledgment we are treating your request as a
request for information under the Freedom of Information Act 2000 (the
FOIA).

In answer to the first part of your request please be advised that the
date upon which the ICO was made aware by T-Mobile of the issue was 16
December 2008.

In regard to the other four parts of your request unfortunately we are
unable to provide you with the information which you seek.  This is
because this information is exempt under Section 30 of the FOIA which
concerns investigations and proceedings conducted by public authorities.

Section 30(2) of the FOIA states;

“Information held by a public authority is exempt information if –

(a) it was obtained or recorded by the authority for the purposes of its
functions relating to -

(i) investigations falling within subsection (1)(a) or (b)”

The investigations outlined in section 30(1)(a)

“(a) any investigation which the public authority has a duty to conduct
with a view to it being ascertained -

(i) whether a person should be charged with an offence, or

(ii) whether a person charged with an offence is guilty of it,

(b) any investigation which is conducted by the authority and in the
circumstances may lead to a decision by the authority to institute
criminal proceedings which the authority has power to conduct”

These purposes apply when the Information Commissioner is determining
whether a criminal offence has been committed under the Data Protection
Act 1998 (the DPA), and whether to take action.

This exemption is a “class based exemption” which means that it is not
necessary to identify some harm or prejudice that may arise as a result of
the disclosure.  However, this exemption is not absolute.  When
considering whether to apply it in response to a request for information,
there is a ‘public interest test’.  That is, we must consider whether
the public interest favours withholding or disclosing the information. 
  

In this case the public interest factors in disclosing the information
within the scope of the request are –

o increased transparency in the way in which the ICO conducts its
investigations

The factors in withholding the information are –

o the public interest in not prejudicing the ICO’s ongoing
investigation into a possible criminal offence under the DPA
o the public interest in maintenance of independence of the judicial and
prosecution processes
o the public interest in not prejudicing any prosecution which may arise
out of the ICO’s investigation.

Having considered all of these factors we have taken the decision that the
public interest in withholding the information outweighs the public
interest in disclosing it.  I am sorry, therefore, that in this instance
we are unable to provide you with the information from the investigation
that you have requested. 

Finally I note that you appear to have concerns that the ICO “would take
such
drastic action against T-Mobile, yet take no action at all with respect to
the BT/Phorm scandal”.  As you will appreciate the issues involved in
these two matters are very different.  In respect of the T-Mobile issue
the ICO is looking into possible criminal offences committed under the DPA
whereas the matter of BT and Phorm regarding targeted online marketing did
not involve any criminal offences under the DPA but raised issues of fair
processing and compliance with the first Data Protection principle.  It
may be useful for you to refer to the link below to the press release
issued by the ICO on 17 November 2009 which provides more information.

[2]http://www.ico.gov.uk/upload/documents/p...

Your email of 17 November 2009 also contains the following statement;

“Please could you also take this opportunity to assure me that T-Mobile
will not escape compliance with the Data Protection Act because this was a
functional and technical trial of an advertising idea, it was small scale
and technical in nature, and it would have been difficult to frame any
advice for customers about the nature of the leaked information and obtain
any relevant consents for the processing of personal data with a wording
that would have any resonance at all for theory customers?”

As you will appreciate this is not a Freedom of Information request as you
are seeking an “assurance” rather than recorded information.  However
we are not clear what “assurance” you are seeking as we are not
investigating T-Mobile in relation to “a functional and technical trial
of an advertising idea”.

If you are dissatisfied with the response you have received in relation to
your Freedom of Information request and wish to request a review of our
decision or make a complaint about how your request has been handled you
should write to the Internal Compliance Team at the address below or
e-mail [3][email address]

Your request for internal review should be submitted to us within 40
working days of receipt by you of this response. Any such request
received after this time will only be considered at the discretion of the
Commissioner.

If having exhausted the review process you are not content that your
request or review has been dealt with correctly, you have a further right
of appeal to this office in our capacity as the statutory complaint
handler under the legislation.  To make such an application, please write
to the Case Reception Team, at the address below or visit the
‘Complaints’ section of our website to make a Freedom of Information
Act or Environmental Information Regulations complaint online.

 

A copy of our review procedure is attached.

Yours sincerely

Joanne Crowley

Assistant Internal Compliance Manager

show quoted sections

Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow,
Cheshire, SK9 5AF
Tel: 01625 545 700 Fax: 01625 524 510 Web: www.ico.gov.uk

References

Visible links
1. file:///tmp/radDC357_files/filelist.xml
2. http://www.ico.gov.uk/upload/documents/p...
3. mailto:[email address]

Link to this | Reply to this message

P. John

7 December 2009

Dear Ms Crowley,

many thanks for your reply.

I'm disappointed to learn that this matter has been outstanding for
approximately a year, and concerned that you are still unable to
indicate 12 months later whether anyone has been prosecuted as a
consequence.

Regards the Phorm affair, 121Media failed to register as Data
Controllers under the Data Protection Act, while operating the
'ContextPlus' spyware network prior to 2006, and while conducting
mass trials of the PageSense/ ProxySense/ Webwise application
during 2006, 2007 and 2008.

Apart from other alleged offences of illegal interception, computer
misuse, fraud, trademark and copyright infringement, and failing to
comply with the requirements of the Companies Act... under section
21 of the DPA failing to register as a Data Controller is also a
serious criminal offence.

Given the ICO conducted no substantial investigation into the Phorm
affair, or the ContextPlus system, particularly the large scale
offences committed in 2007, including the processing of sensitive
personal communication data without explicit consent... it is
obviously not surprising that a cursory, shoddy, haphazard, and
inadequate investigation by people who are 'not technical experts'
might reach a substantially inaccurate conclusion.

Presently, I struggle to understand what purpose the ICO serves.

Yours faithfully,

P. John

Link to this | Send follow up

P. John left an annotation (6 January 2010)

Follow up request; asking the Information Commissioner's Office to account for the effort expended over the last 12 months in pursuit of the offenders, and the preparation of the putative prosecution...

http://www.whatdotheyknow.com/request/t_...

Link to this

Things to do with this request

Anyone:
Information Commissioner’s Office only: