View Single Post
Old 07-07-2008, 14:03   #11256
Florence
Inactive
 
Florence's Avatar
 
Join Date: Jun 2003
Services: The wonders of Sky TV BT line and Aquiss.net ADSL cable dies on 5th RIP VM.
Posts: 4,004
Florence has a bronzed appealFlorence has a bronzed appeal
Florence has a bronzed appealFlorence has a bronzed appealFlorence has a bronzed appealFlorence has a bronzed appealFlorence has a bronzed appealFlorence has a bronzed appealFlorence has a bronzed appealFlorence has a bronzed appealFlorence has a bronzed appealFlorence has a bronzed appealFlorence has a bronzed appealFlorence has a bronzed appealFlorence has a bronzed appealFlorence has a bronzed appealFlorence has a bronzed appealFlorence has a bronzed appealFlorence has a bronzed appeal
Re: Virgin Media Phorm Webwise Adverts [Updated: See Post No. 1, 77, 102 & 797]

Quote:
Originally Posted by Peter N View Post
Section 7 of the Data Protection Act states that...

Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.

Thiis is qualifies in Schedule 1 part 2 to mean...

12 Where processing of personal data is carried out by a data processor on behalf of a data controller, the data controller is not to be regarded as complying with the seventh principle unless—

(a) the processing is carried out under a contract—

(i) which is made or evidenced in writing, and

(ii) under which the data processor is to act only on instructions from the data controller, and

(b) the contract requires the data processor to comply with obligations equivalent to those imposed on a data controller by the seventh principle.


We need to know whether or not Phorm has a contract with BT because an "agreement" does not satisfy the DPA. The profiling may be done on BT equipment but the data processing isn't.

The Act also states that the follwing criteria MUST apply...

10 The data controller must take reasonable steps to ensure the reliability of any employees of his who have access to the personal data.

11 Where processing of personal data is carried out by a data processor on behalf of a data controller, the data controller must in order to comply with the seventh principle—

(a) choose a data processor providing sufficient guarantees in respect of the technical and organisational security measures governing the processing to be carried out, and

(b) take reasonable steps to ensure compliance with those measures.


Phorm's background and Russian connections suggest that NT could not in all fiath support these terms and the 2006 trials took place whilst BT was not in contract with 121Media and that company was under investigation by the American FTC who were still trying to locate the company following a trail that dried up in Poland.
Very true they seem to have sliped with their due diligence mind they were blinded with greed and dollar signs.
Florence is offline