Even If your business doesn't depend on computer servers you must still be sure that your security is foolproof.
With the vast amount of information/data that you can have on a server,
like cards or your staff info or even your clients personal data,
all of which you are responsible for protecting.
UK SURVEILLANCE LAW
In July 2015 English comedian Michael McIntyre found himself the unexpected subject of a spying row.
The National Police Air Support unit (NPAS) spotted the foppish funnyman crossing the road, snapped his picture from the sky and then posted the image to Twitter, asking followers to guess who it was. Silly move. They swiftly deleted the tweet after vocal criticism from privacy campaigners. However, they didn’t actually break any law. Human rights lawyer Simon McKay explained to the BBC how the police were technically on the right side of the law, but they may have breached a code of practice: "In a nutshell, the taking of the photograph is unlikely to be an invasion of privacy.
However, its needless publication almost certainly is, assuming Michael McIntyre didn't consent, which seems likely.
The Metropolitan Police is a data controller and this is personal data, so there are compliance issues. On the face of it it also breaches the CCTV Code of Practice. The courts have held the arbitrary publication of photographs by the police without a pressing need to do so is unlawful.
A Metropolitan Police spokesperson said in a statement that "this tweet does not, as far as we know, constitute a breach of data protection legislation.” Which brings us neatly onto something we’ve been meaning to address for a while.
How do users of spy equipment stand when it comes to the law? Well, there are two key things to remember when considering whether your actions are legal or illegal; firstly does the subject have a reasonable expectation of privacy and secondly, do they give their consent? The latter typically supersedes the former. You can’t have a reasonable expectation of privacy if you consent to working in an office where your conversations will be recorded, for example.
The key measurement, should you need to defend yourself against accusations of illegal or unethical use of spy equipment, is that the subject had a reasonable expectation of privacy. In short, that’s why it’s legal for you to bug your own office but not the bathroom. There are exceptions to this. For example, it’s legal for the police to bug your house. You may have a reasonable expectation of privacy in your own home but if you’re suspected of criminal activity, the pursuit of justice and protection of the public takes precedence. The concept of consent is very important too. While most people may take issue with having their likeness or voice recorded and stored, they regularly imply consent to this without really considering the implications.
For example, the words “calls are recorded for training and quality purposes” are effectively soliciting implied consent. If you stay on the line, you accept these conditions.
The use of spy equipment falls under one or more of six separate pieces of UK legislation. There is no specific law on privacy like the Privacy Act of 1974 in the States, but our right to privacy is covered mainly by the Human Rights Act.
The Data Protection Act governs how data handlers, for example the local council, police or bank, manage and protect your personal data. If you are a data handler (hint: most employers are data handlers, otherwise how do they pay their employees?), you must comply with the Data Protection Act too, or face heavy fines or even imprisonment. So, if for example, you legally record a conversation taking place during office hours at your business, and then post that online, you could potentially be in breach of the Data Protection Act. The employee may have given consent to be recorded by signing their employment contract, but it’s unlikely they’ll have given their consent to having those conversations made public or shared.
The CCTV Code of Practice is potentially where the use of the police helicopter footage of Michael McIntyre slips up. It’s not illegal to record him but it does breach this non-legislative code of conduct. In order to operate certain pieces of equipment, for example closed circuit networks, one needs to sign up to specific codes of practice.
The 1998 Wireless Telegraphy Act covers the use of discreet or hidden recording devices. Significantly, it’s an idiosyncratic piece of law that actually seems to protect the spy more than the subject.
The Lawful Business Practice Regulations Act covers the monitoring of employee behaviour, typically computer and telephone usage. The relevant parts are in the main there to protect employee privacy and prevent them from being unduly snooped on. Public bodies, such as the police, HMRC or spy agencies are subject to the Regulation of Investigatory Powers Act, which limits and controls their powers to record, monitor and gather information on members of the public.
Under UK law you are generally permitted to use spy cameras, under certain conditions. Elements of the Data Protection Act and the Human Rights Act govern where you can and can’t conduct recording, but in general, their use is legal.
Here are a number of key considerations for legally using spy cameras in the UK:
The laws surrounding phone monitoring in the UK aren’t as cut and dried as those surrounding spy cameras. The biggest grey area has to do with the definition of the word ‘legitimate.’ It varies according to who is doing the listening. The police, spy agencies, intelligence services and even HM Revenue and Customs are considered legitimate users of phone tapping without notice, but they are subject to Regulation of Investigatory Powers Act (RIPA) standards. So if you’re suspected of not paying the right amount of tax, HMRC may legitimately tap your phone. But they’ll need a warrant signed by the Home Secretary. As a private citizen or business owner, you are also allowed to monitor phone calls, but under stricter conditions.
Here are the key things to remember if you’re planning on using call monitoring devices:
If you have concerns that your computer use, phone calls, movements or other behaviour are being monitored, you’re entitled to put in place a series of counter-intelligence measures. This is for your own safety, privacy and commercial protection. As far as the law goes, problems only arise when your legitimate counter-intelligence activities begin to infringe on the privacy and other rights of people around you. For example, hacking into someone else’s computer or otherwise unlawfully monitoring their computer usage to check if they’ve been spying on you is illegal.
Here are some key things to remember with regards to counter surveillance and the law in the UK:
There are a number of legitimate uses for using GPS car trackers in the UK. The most typical uses for vehicle tracking are commercial, to ensure that employees are driving safely, efficiently and aren’t wasting company time and resources on unnecessary detours or diversions. It is a business fact that employee productivity increases with the presence of management. However, it’s not possible to be present in every car with every employee. GPS trackers mitigate this business risk by enabling you and your colleagues to keep employees motivated by knowing their movements are being lawfully monitored. A high proportion of road accidents involve people who drive for a living, so there are safety benefits to in-car tracking too. It may even result in lower insurance premiums for your business, providing a tangible cost saving.
GPS workplace vehicle tracking is generally legal, provided you follow a few important steps:
As with commercial vehicle tracking, domestic and private vehicle tracking is generally legal provided you don’t breach the Data Protection Act. In most cases, domestic vehicle tracking is conducted on family cars, or cars driven by sons or daughters, with all parties aware. This can provide an insurance benefit and also builds trust between parents (often the people responsible for paying for the car insurance) and inexperienced young drivers. Because GPS vehicle trackers may be deployed to track any vehicle (some trackers are magnetic to permit ease of fitting to the vehicle’s exterior), it’s extremely important that you pay close attention to the law.
Here’s a rundown of the key things to remember when using GPS vehicle trackers:
You may wish to monitor computer usage for a number of legitimate reasons, including fraud prevention, business and risk compliance or monitoring and protecting your children using a home computer from accessing inappropriate material. Due to the potential for abuse, computer monitoring by members of the public is subject to the Data Protection Act. The overarching principle governing computer monitoring and computer forensics centres around the concept of possession. You are generally permitted to install whatever devices or software onto your own computer that you wish. Persons then using your computer may be monitored, but if you intend to use the data that you gather, for example as part of investigation or civil case, you must first warn the person that their use of your computer may be being monitored.
While this does somewhat defeat the object if you are monitoring computer usage to identify criminal or unethical use, it is important to comply. Not complying may put you in breach of the Data Protection Act. Employers have special responsibilities under the Data Protection Act to get consent from their employees if they plan to monitor their usage. Once consent is given, employers may monitor Internet usage, record keystrokes and store any data pertaining to the use of computers that they own. However, the use of that data is subject to the Data Protection Act.
Here are the key things to remember for employers monitoring employee computer usage:
Here are the key things to remember on the legalities of domestic computer monitoring and forensics:
The vast majority around the legalities of using spy equipment is common sense. Don’t breach privacy, don’t put people’s personal information at risk and don’t spy on people who you have no legitimate reason to spy on. However, the law is complex and seemingly legitimate actions can land you in legal trouble, so it’s smart to keep as up-to-date as possible.
at times we work or recommend our partner Cyber Security Agencies ,