Meet the Other Phone. A phone that grows with your child.

Meet the Other Phone.
A phone that grows with your child.

Buy now

Please or to access all these features

Feminism: Sex and gender discussions

See all MNHQ comments on this thread

Data breaches by Mermaids exposed in the Times

703 replies

truthisarevolutionaryact · 15/06/2019 18:46

Mermaids has apparently put lots of confidential data online including private emails, personal data and emails demonstrating the pressure they have put on the Tavistock.
Andrew Gilligan article - share token:

www.thetimes.co.uk/article/parents-anger-as-child-sex-change-charity-puts-private-emails-online-tl0g5hwcg?shareToken=2f8ddc23419c61360023562a62e74d13

OP posts:
Thread gallery
17
Doyoumind · 16/06/2019 14:19

Tbf it's hidden away in Technology but did come up on Twitter.

Needmoresleep · 16/06/2019 14:20

Beaten to it! By their North of England correspondent.

I assume we can now expect a comment piece by OJ.

everythingthelighttouches · 16/06/2019 14:21

What possible reason could they have for sharing this on a personal platform (WhatsApp)?) when everyone involved was in the same charity?? They would have had a charity email address for that.

RedToothBrush · 16/06/2019 14:23

This is a selection of Comments the ICO made in reference to the Bounty case which was under the less strict Data Protection Act which has since been succeed by GDPR

“Bounty were not open or transparent to the millions of people that their personal data may be passed on to such large number of organisations. Any consent given by these people was clearly not informed. Bounty’s actions appear to have been motivated by financial gain, given that data sharing was an integral part of their business model at the time.

“Such careless data sharing is likely to have caused distress to many people, since they did not know that their personal information was being shared multiple times with so many organisations, including information about their pregnancy status and their children”

And

37. The "fairness" requirement under DPP1 also included a substantive duty to treat individuals fairly when using their personal data. In particular, fairness involves adhering to individual's reasonable expectations of how their data will be used and not using their data in ways that risk causing them damage or distress, unless there is some sufficiently weighty justification for doing so. Bounty failed to use the personal data of the affected data subjects fairly in this case. As indicated above, data subjects registering with a pregnancy and parenting clude would not reasonably have expected their personal data to be disclosed to the likes of credit reference, marketing and profiling agencies. Bounty had no adequare justification for acting as it did. Its actions appear to have been motivated by finacial gain, given that data sharing was an integral part of Bounty's business model, and as confirmed by Bounty, cessation of its data sharing practice on 30 April 2018 resulted in significant commerical impact

Under the heading
Seriousness of the contravention
46. The Commissioner is satisfied that the contravention identified above was serious, in that:
(1) The number of affected data subjects was extraordinarily high - in excess of 34 million records having been disclosed, comprising the personal data of over 14 million individuals. This represents an unprecedented number of affected data subjects in the history of the Commissioner's investigations into data broking organisations. As her investigation focussed on only four 4 out of 39 organisation with which Bounty shared data, it is resonable to suppose that the number of records disclosed could have been significantly higher.

(2) In addition, some of the affected individual's data was shared on multiple occasions and with multiple organisations, further impacting on their data rights. Whilst Bounty stated it tracked the data it shared, trading data up to 17 times in a 12 month period is arguably disproportionate, and opened the affected individuals to excessive processing that they did not consent to.

(3) The sustained and prolonged duration of the contravention - approximately 7 months in respect of 'online' member registrations, and 11 months in respect of 'offline member registrations

My bold
(4) The data subjects were not only potentially vulnerable new mothers/mothers-to-be, but also very young children. Furthermore, whilst Bountry advised that its 'philosophy and policy' is never to market to children, and it did not share children's names with third parties, the Commissioner considers that sharing the birth date and gender of a child along with information about its parent, creates the potentia this data to be appended to create a fuller profile of the child, which may then be used for future targeted marketing. In these circumstances a loss of control of data has already taken place before the child has capacity to consent for its data to be used for marketing purposes.

(5) In the Commissioner's assessment, this disclosure went clearly against the terms of the privacy notices in place at the time. As subjects signed up to a parenting club it is considered highly unlikely that individuals would reasonably expect their personal data to be shared with credit referencing, marketing and profiling agencies, unless explicitly informed that it would be.

My bold
(6) The nature of the data data involved - this included information relating to number, age and gender of children, and [redacted] pregnancy status. Disclosure of such information in this context created a real risk of distress (see further below).

(7) Individuals were exposed to a significant loss of control over their data, exacerabated by the fact that Bounty did not inform them about this disclosure either before or after it had taken place

Under the heading
Contraventions of a kind likely to cause substantial damage or substantial distress

48. The Commissioner considers that this contravention was of a kind likely to cause substantial damage or substantial distress, in that:

(1) For those data subjects registering online, Bounty's privacy notices contained reasonably clear descriptions of the kinds of third parties who might recieve personal data from Bounty. However, none of the four most supplied organisations were listed, and the broad category types did not clearly indicate the types of organisations with which the data the subject of the Notice was shared. At least some of the affected data subjects are likely to have been distressed by this failure to adhere to their expectations about how their data would have been used. At least some of these data subjects would reasonably feel mislead.

(2) In addition, given that Bounty failed to be transparent with the data subjects about this disclosure, the data subjects may well have been distressed by uncertainty as to how the organisations in this case obtained information with which to target them based on their personal circumstances.

My bold
(3) This sense of distress is likely to have been exacerbated by the fact that it focussed on the affected data subjects' status as new or expectant mothers, as well as on their young children. It is highly likely that at least some data subjects who may not be concerned about their name or email address being shared with a marketing company, would have been distressed by the inclusion of information about their pregnacy status and children without their explicit consent.

(4) At least some of the affected data subjects are likely to be distressed by the percieved loss of control over their data when it was shared without their knowledge with large marketing organisations.

(5) At least some of the affected data subjects are likely to be distressed by the fact that their personal data has been shared on numerous occasions with multiple organisations. Some data records were shared up to 17 times over a 12 month period. This, in the Commissioners view, would exacerbate the level of any distress caused.

(6) The Commissioner has also given weight to the number of affected data subjects: in excess of 14 million. The Commisioner considers that even if the damage or distress likely to have been suffered by each affect individual was less than substantial, the cumulative impact would clearly pass the threshold of "substantial".

(7) In representations made to the Commissioner, Bounty pointed to a lack of complaints about Bounty's processing of data in the circumstances described. Bounty also stated that only a tiny proportion of those registering 'online' went on to view the supplementary list linked to the Privacy Policy, suggesting that very few data subjects were concerned about the 'named list' and so (if any) detriment to those individuals would be minumal.
Bounty relies upon a lack of any evidence of actual distress, stating this case is based upon an assumption of 'risk'. The Commissioner's view is that the above is demonstrative of the 'invisible' nature of the processing whereby individuals are unaware, either before or after, of the processing of their data in these circumstances. She considers that if individuals were aware of the processing of their personal data in these circumstances there would be a real likelihood of substantial damage or distress of the nature described above.

And finally

51. While it may not have set out to contravene the DPA, Bounty's actions in sharing the data were plainly deliberate. In any event, the Commissioner considers that Bounty knew or ought reasonably to have known that there was a risk that the contravention would (a) occur, and (b) be of a kind likely to cause substantial damage or substantial distress. She further considers that Bounty failed to take reasonable steps to prevent such a contravention in that:

(1) Bounty was aware of the terms of its own privacy notices. It should have been readily aware that those terms were inadequate for disclose for these purposes.

(2) Bounty knew its customer base. It knew why they registered with Bounty and what kind of marketing communication they would expect to recieve. It should have been very clear to Bounty that this disclosure contravened those expectations

My bold
(3) Given its own knowledge of its customer base and the common sense considerations summarised at paragraph 48 above, it should have been readily apparent to Bounty that this disclosure was likely to cause substantial distress to at least some of the affect data subjects.

(4) The ICO has published extensive guidance on the importance of valid consent and how to obtain it, and a long established organisation of Bounty's size should have been well aware of the steps it needed to take to ensure its data subjects had all the relevant information at the point of data collection.

(5) Redacted

(6) At the commencement of the Commisioner's investigation in early 2018, Bounty informed the Commissioner that it planned detailed changes to ensure that its marketing practices were compliant with the (then) forthcoming GDPR, including cessation of trading and sharing personal data with third party organisations, updating fair processing notices to ensure data obtained for marketing is fully opted-in, changes to its retention policy, cessation of hard copy claim cards, training of staff and purging its database to reduce the number of records held. Bounty knew that its data sharing practices would likely not be compliant with GDPR and confirmed that it had not carried out impact assessments prior to GDPR. If these appropriate checks had been carried out beforehand than Bounty should have known that its data sharing practices would contravene the DPA.

My bold and remembering that Mermaids have recently had a data breech involving email
(7) As referred to above, the steps it took to prevent further breaches and minimise detriment to data subjects shows that Bounty was alive to the kinds of steps that would be needed to avoid contraventions of the DPA in the circumstances, but it failed to take any such steps. The Commissioner considers there was no good reason for this failure

Now Bounty is a much bigger organisation than Mermaids and the scale of the data sharing was much much bigger, but its interesting to see exactly where the ICO stress severity and emphasis.

One of these is the point that young children involved do not have the capacity to give informed consent to their data being shared!

In this particular case, Mermaids don't make money out of children but there is a clear demonstration that they are using children's data to further their own political aims by using it to apply pressure. This is without the express consent of parents and it should be noted that young children don't have the capacity to consent to their data being used in ways which might have a long term effect on them in terms of their health. The data of the data leaked is particularly sensitive and extensive. Some of this data sharing was very deliberate and there are serious questions over who this benefits and whether doing this without explicit consent could cause serious distress.

Nothing that the ICO operate on the risk of harm, not whether there is proof of harm.

I really do hope that those involved or The Times make sure that the ICO deal with this data breach in the appropriate fashion.

And the Trustee has the nerve to say The Times did an attack piece, for pointing out their legal responsibilities as Trustees in a charity.

Indeed, this in itself is probably worthy of a complaint to the charity's commission for evidence of the charity's failure to understand and take its legal responsibilities to children seriously.

nauticant · 16/06/2019 14:23

I think it's worth reflecting on how you deradicalise people at this point.

You can't do it by being confrontational. It has the opposite effect. You have to do it drip, by drip and let people come to their own conclusions based on their values.

This is spot on. Many of us have seen people in the "you're all bigots" crowd reach a point where they go "sorry? is what you've said actually true?" and from there they start listening with a far more open mind. I can't recall seeing anyone doing the same as a result of stand up rows of "how can you believe something so stupid!"

RedToothBrush · 16/06/2019 14:27

BTW, the above reflection on GDPR responsibilities and Mermaids legal obligations and how a trustee is scoffing publicly about this, which undermines its trusted status as a charity SHOULD be the story and SHOULD be the focus that the likes of the BBC are reporting.

It speaks volumes that we have a real wet "charity says sorry" article instead.

I am fucking sick of crap and soft reporting, which misses the entire fucking point.

RedToothBrush · 16/06/2019 14:30

It maintained there was "no evidence" the information had been retrieved by anyone other than the Sunday Times, or those contacted by their journalist.

Not an excuse in the eyes of the ICO!!!

Dear lord they are out of their depth on this.

nauticant · 16/06/2019 14:30

Also, Mermaids existed before she went there. I think it was a lot smaller, but she didn't establish it.

For some reason this made me think of Patisserie Valerie and how, what they were had worked brilliantly for years until they were taken over and inflated into a very different entity, leading to collapse in financial disgrace.

TheAngryLlama · 16/06/2019 14:34

They are, and the question about the data was ever held in a shared environment is fundamental. I think they may struggle to answer that. The trustees have no need for it to discharge their duties so far as I can tell. Detail about the sorts of cases being dealt with can be provided in a more general, anonymous form.
Lots of questions to answer here. If the only response is going to be “ this is an attack” - well it’s pretty clear no one’s accessed competent legal advice yet, put it that way.

JessicaWakefieldSV · 16/06/2019 14:37

RedToothBrush

Thank you for all that information. Who can make complaints to the ICO?

RedToothBrush · 16/06/2019 14:44

Well it’s pretty clear no one’s accessed competent legal advice yet, put it that way.

Isn't it just?

I think complaints generally need to be made by an individual affected, however anyone can theoretically do it if they have particular concerns (this being a charity dealing with children and health and the manner of the data breach probably would be sufficient grounds).

RoyalCorgi · 16/06/2019 15:11

The Graun's opening paragraph:

"A charity that supports transgender children has apologised and referred itself to the information commissioner’s office following a data breach that led to the publication of parents’ personal emails online."

Yes, let's get the minimisation in straight away, shall we?

LordProfFekkoThePenguinPhD · 16/06/2019 15:21

You couldn’t gold plate that turd.

HandsOffMyRights · 16/06/2019 15:29

Gotta love Andrew responding to Alex Sharpe's loop de loopy...

Andrew Gilligan (@mragilligan) Tweeted:
Tweet of the day, perhaps the year t.co/Qb0NogzcNJ twitter.com/mragilligan/status/1140260853616381952?s=17

Data breaches by Mermaids exposed in the Times
CaptainKirksSpookyghost · 16/06/2019 15:33

It's actually a pretty apt analogy, Susie Green sending the kids in spitfires to their death....

theytheythey · 16/06/2019 15:33

A question. Are The Times within their rights to publish any examples or excerpts of any of the content of the breached data they’ve seen? They’ve obviously given some examples of the content. What’s stopping them revealing any further content? Is any exposure of the content covered by ‘public interest’ or would it be unethical to use such information as its ‘supposed’ to be confidential?

AlwaysComingHome · 16/06/2019 15:37

It's actually a pretty apt analogy, Susie Green sending the kids in spitfires to their death....

I love the response to Gilligan’s retweet:

‘A couple of fockers if you ask me’

AlwaysComingHome · 16/06/2019 15:40

The Times came by the information legally. The really important stuff is the correspondence with other agencies that proves complicity.

It’s not violating the parents or children’s privacy to publish that material.

PerspicaciaTick · 16/06/2019 15:45

I think the Times are making very sure that they stay firmly in the right, morally, legally, ethically. They will not want to appear to be exacerbating the harm done to vulnerable children.
However, if Mermaids persist in lying (which they seem to find as easy and necessary as breathing), then I'm sure the Times will share what it has found with ICO.

ItsAllGoingToBeFine · 16/06/2019 15:52

I think the Times are making very sure that they stay firmly in the right, morally, legally, ethically.

I also hope they read through all of the material and publish more based on it

ItsAllGoingToBeFine · 16/06/2019 15:58

It would seem from twitter that Mermaids have changed their statement. Did anyone screenshot the original?

TeamUnicorn · 16/06/2019 15:59

Mermaids really need to learn that sometimes saying as little as possible is the best way forwards. 'We've messed up, we're sorry, we have reported ourselves and we have started a review of our procedures' is what they needed to say, not 'everyone is so mean'

As the phase goes ' when you are in a hole, stop digging '

EmpressLesbianInChair · 16/06/2019 16:12

I think that SG’s only motivation nowadays must be to keep reassuring herself that she did the right thing.

If that’s the premise you’re starting from then any admission of fallibility at all could feel threatening.

ItsAllGoingToBeFine · 16/06/2019 16:31

Did anyone screenshot the original?

Evidently someone did...

archive.li/foz11

nauticant · 16/06/2019 16:46

Original:

Again, Mermaids apologises for the breach. Regardless of circumstances, context or misrepresentation in this latest hostile and transphobic article, we are deeply sorry. At the time of 2016-2017, Mermaids was a smaller organisation, growing quickly and facing the pressure of resistance from those who deny the existence of transgender children or who would refuse them the respect and support they deserve. Mermaids now has the internal processes and access to technical support which should mean such breaches cannot now occur.

Current:

Finally, Mermaids apologises for the breach. Even though we have acted promptly and thoroughly, we are sorry. At the time of 2016-2017, Mermaids was a smaller but growing organisation. Mermaids now has the internal processes and access to technical support which should mean such breaches cannot now occur.

Swipe left for the next trending thread