top of page

Data Protection in E&S with Danie Strachan

Ildiko Almasi Simsic
1 day ago
35 min read

Watch the episode


Summary

In this episode of The No Nonsense Sustainability Podcast, host Ildiko Almasi Simsic welcomes Danie Strachan, Senior Privacy Counsel at VeraSafe, to discuss data protection in the environmental and social (E&S) sectors. The conversation centers around the legal aspects of data protection and its importance in E&S projects.

The discussion covers a range of topics including the essentials of data protection, common legal pitfalls, and the distinction between legal requirements and best practices. Strachan also addresses the challenges of working in countries with weak privacy laws and the importance of designing systems that support compliance without hindering project progress.

Key insights include the need for clear data protection principles, understanding the legal obligations in different jurisdictions, and the importance of balancing transparency with privacy. The episode emphasizes the role of data protection in safeguarding community data and the ethical considerations involved in handling personal information.


Highlights

  • Danie Strachan explains the broad scope of data protection laws.

  • The difference between data protection and data security is clarified.

  • Common misconceptions about personal data in E&S projects are discussed.

  • The role of transparency and disclosure in data protection is explored.

  • Strachan emphasizes the importance of clear data protection principles.

  • Challenges of working in countries without strong privacy laws are highlighted.

  • The ethical implications of data handling in E&S sectors are examined.


Key takeaways

1. Data protection laws cover a wide range of activities beyond just data security.

2. Understanding legal obligations is crucial for E&S practitioners handling personal data.

3. Transparency must be balanced with privacy to avoid irresponsible data disclosure.

4. Ethical considerations are vital when handling community data in E&S projects.

5. Organizations should establish clear data protection principles and practices.


Timestamped breakdown

[0:09] — Introduction to the Episode: Host Ildiko Almasi Simsic introduces the guest, Danie Strachan, and the topic of data protection.

[2:00] — Defining Data Protection: Strachan explains data protection as a set of rules for handling personal data responsibly.

[3:26] — Data Protection in E&S Projects: Discussion on the application of data protection laws in environmental and social projects.

[5:57] — Misconceptions About Personal Data: Strachan addresses common misconceptions about what constitutes personal data.

[9:34] — Legal Terminology Explained: Clarification of terms like personal data and data processing in legal contexts.

[15:11] — Balancing Legal and Practical Requirements: Exploration of how to balance legal obligations with practical project needs.

[22:39] — Principles of Data Protection: Strachan outlines key principles that guide data protection practices.

[32:56] — Data Retention Challenges: Discussion on how long data should be kept and the legal implications.

[39:01] — Using Personal Devices for Work: Strachan discusses the risks and legality of using personal devices for work purposes.

[48:59] — Conclusion and Future Guidance: The episode concludes with a discussion on developing data protection principles for E&S.


Edited transcript

Welcome to the non nonsense sustainability podcast. I'm Ili Kama Shisimik and today we're looking at data protection from the legal lens. My guest today is Danny Stretchen who's senior privacy council at VeraSafe, also a co-host of another podcast, Privacy and Practice, and he's helping clients across sectors and jurisdictions to make sense of legislation and implement some pragmatic data protection policies. Welcome to the show, Danny.

Thanks so much. I'm really excited to be here and looking forward to our discussion today. To kick things off, what's the most exciting part of your job?

Working with people, working with clients, and learning interesting things about the different kinds of businesses and hearing about their challenges and helping them to solve those problems. I'm really really excited to discuss this topic with a legal expert today. As a reminder, we have some of our house rules. First, my permanent gas bulb, the buzzer, who will give us a gentle reminder if we slip back into the jargon or the buzz words that we usually use. We aim to have an open and honest conversation. We might disagree on certain things. We might delve into the nuance a bit more to unpack the complexity. And of course, having a sense of humor is essential because although we're covering some very serious issues, it's okay to have a sense of humor.

Great. That sounds like fun. Hello, Bob.

Bob is ready for the buzzer battle. So, Denny, you got 60 seconds. What is data protection? In simple terms, it's an obligation that companies that organizations have to look after people's data. Organizations have the privilege of working with people. They have the privilege of being exposed to people's information. But to make sure that there are guard rails and to make sure that that data is handled responsibly, there must be a law that sets rules about the use of data, the processing of the data, the handling of the data. So data protection is basically a set of rules that people must follow, organizations must follow when they work with people's data. you sometimes hear other concepts as well, information processing law or personal information law or data privacy law or privacy law. It's all basically the same thing. I think what we must not confuse it with is one specific thing which is data security. So we're not just talking about the rules and systems that you must have in place to make sure that data is protected from bad actors or whatever. Data protection I think is much wider than that. People will disagree about what the right term is to use, but in Europe, people normally talk about data protection. In the US, you'll often find that they talk about data privacy or just privacy.

Okay, that's very clear. So we've come across each other in the IIA that's the international association for impact assessment event in Bologna where you presented about data protection and privacy for social impact assessments and social data specifically. I was so excited to have an actual legal expert come into our field to share probably some of the blind spots. I mean most of us had some of intuition that some of these data we collect should not be disclosed or should not be identifiable but we couldn't quite see if it's something that's illegal or if it's something that's just unethical. What made you focus on data protection in this ENS space?

I think it started off a while back when I had a discussion with one of my friends who's an impact assessment practitioner and we talked about what they do out there in the field and I realized that there's so much data that gets exposed in the process because to do an impact assessment you need to work with people because you're looking at real life impact and you can only measure that if you speak to real life humans and to make the data reliable, you have to speak to many of them and you do community engagements and then I started asking questions about how this happens in practice. So when you go out and you have a meeting with someone in the community, how do you get that meeting organized? Whose contacts detail whose contact details do you use? How do you find the people that will participate in that engagement? Where are their details? And then down the line, if you've done the report and the project has been wrapped up, where do the details go? And if there's any management of a community subsequently, how do you stay in touch with them? So, surely you have their details. And then that got me thinking and I realized there might be some impact assessment practitioners out there that think that data protection laws maybe don't apply to them because they're not a normal business like an e-commerce business that sells widgets online. Sometimes they think that it only applies to businesses. In other words, you're in a consumer business and you have end users or customers and you deliver stuff to them online and those people are covered by data protection law. So I think there is that misconception. But then secondly, I think there are some impact assessment practitioners or many that realize that data protection laws also apply in that context. It's not only if you're in a consumer business. It's in a situation where there's any kind of interaction with people's data. But then I found that there are impact assessment practitioners out there that think that the law doesn't apply because somehow that information isn't someone's personal data. And there are a couple of misconceptions about that. I think the biggest one is that people go out, they do an engagement with a community, they write stuff down in their notes or in a report and then at some stage they remove the names of those people and they think, well, just because I've taken the name out, this is now not personal information anymore. But you are still in control of that process, you still have their names somewhere. So, it's like taking a puzzle and splitting the puzzle up. Maybe each piece of the puzzle when you look at it doesn't make sense anymore, but if you put the puzzle pieces back together again, then you have the picture again. And I think that that is a big issue that we have in lots of industries where there's processing of personal data. In legal terms, this is

But can I

Yeah, please.

Can I just ask processing of personal data because I think what you mentioned in my mind there's a difference between collecting this data and keeping it within my organization so I can write my report and a difference also when I disclose that removing the names as part of the public disclosure requirements.

Yeah, I think it so there's an all-encompassing term of doing anything with personal data. So most data protection laws cover everything. So the whole lifespan of data from the point where you get the data, the collection when you analyze the data, you might merge it with other data, you might store the data up to the point where you delete it or you destroy it or you erase it. All of that is normally covered by data protection law. And the only way to cover all of that in one term is to use some concept. So most I think almost all data protection laws use the term process. In other words, process the verb not a process as in a standard operating procedure but doing something. I see a lot of people have started using the term handling now which is very rarely found in data protection laws. I've seen it in some cases, but I think it's maybe a bit of a planer word if you talk about data handling. But I'm worried that it's not a wide enough concept because if you collect data, I'm not sure if it sounds like you're handling the data, maybe you are. If you're destroying it, I suppose you are handling it. But I think that that's the point. If you're an impact assessment practitioner and you're doing any of those things with data, then the law applies. And you can't get out of it by saying, "Well, it's not personal data because I remove the names before I publish it." That's not true because you still know who the data subject is. You have your little book there on your cupboard or on your computer.

Exactly. So, what is personal data in legal terminology?

No, you're going to baz me, so I'll try and keep this plain. Personal data is basically any data of someone that you can identify. So if you just have if you have a sentence on paper saying I like cheese, that's just random information. But if you know that we did a survey and there you have a clipboard and you fill in a name, you say Donnie and below you say he likes cheese. That fact is my information now because you know something about my preferences and most data protection laws cover people's preferences and opinions and their views. So any information that you can basically link back to someone that you can identify and that's why the scope of personal information is so wide because it is quite easy to link information back to someone. If you did an interview with a community, someone in a community, you're writing it down, it's going to be relatively easy to link that back to them if it's a very unique person or unique situation or small village.

Exactly. If you say on the form, I interviewed the teacher in this town, and we all know there's only one teacher in that town, that information, no matter what you do, if it's published, people will probably be able to link it to that person. So, it's personal data. I think something I must maybe clarify now because otherwise what we say later on might not be so clear. There is a very big misconception out there that data protection laws only apply to information that's not public. So we mustn't confuse personal data with confidential data. You can have a situation where personal data is confidential but you can also have another situation where personal data is publicly known.

All confidential personal data is Yeah. Okay, that's a good Let's do that. So, if you have a directory somewhere that's online or a telephone directory, remember the old days when we start paper directories, that information in the paper directory or in an app or whatever else, it's public. Someone can go into that and find it. Many countries you have online registries where you can search who owns a company or who owns a specific property and you can get their name and their phone number. So technically speaking, it's not confidential. It's not locked up somewhere in a safe. It's publicly available. Even on websites, many people have contact people's numbers and email addresses and other types of personal data on there. So it's public information, but it's still someone's information. It's still personal information. So just because the personal information is available to the public doesn't mean that it's not personal information. How you handle that information might be a little bit different. So obviously if the information is already made public so if I put my phone number on my social media profile I've made it public there. So the obligation on that social media company might be a bit lower because I've given them this information. and I've put it on my profile. I've decided that this is okay. But it's still on there. It's still on their platform. So, they can't then go and take and use that information for any and every other purpose. They still have to follow the rules. Even though it's public information. So, I made my number maybe available on social media for a specific reason. that doesn't mean that they now can take that information and put it for any reason to send me spam messages or sell it to another company for them to send me spam messages. So, I think in the context of impact assessment, it's also important. So, some information is public but maybe not so easy to get hold of and there's been more than one situation in Europe there's actually been rulings about this where authorities there have said that even if information can be accessed even though you can go and find it because it's somewhere accessible. So, let's say you have to log in and go to each and every person's details and get their phone number and then subsequently you recreate a whole searchable database and you put that on the internet. That is a problem. That's wrong. You're not allowed to just go and do anything now with this information just because you could get hold of it. There are still rules about that. So, in the impact assessment context, I think it's also important. Yes, maybe you can find someone's phone number by some kind of process through government to get in touch with that person so you can go and interview them. But that doesn't mean that you can now on your website put it there and say, "Hey everyone, if you need a contact in that village, here is him, his name, her name, phone number." That doesn't work like that. We need to protect people's privacy.

We do that for the community and officer. Yeah. But there we obtain this person's consent.

Yeah. And they know about it at least.

Yeah. Exactly. They know they should expect the calls. But I think what's what would be really interesting to clarify is what is legally required information to collect and how to process and what we do in practice to respond to international standards because we often don't work with legislation. We work with standards and lender requirements that has this aspect of transparency and accountability to share our findings to justify you know the that the process followed their policies etc. And often we work in countries where there's limited or no equivalent to GDPR. How do we find this like balance between requirements to disclose and transparency and the legal minimization of data, personal data we collect?

I think it is a big challenge for organizations to do that because you're basically between two fires. you have to try and in the middle find the perfect spot where you're not invading the person's privacy and breaching their privacy rights but on the other end you're not upsetting your lender or government authority or funer or whoever else sits on the other side so it is difficult to be there in the middle but I think it is possible to find that middle road where you are recognizing the data subject's rights but you're also complying with your obligation to the funer or the government organization or whoever else they might be. It is difficult though because in many instances there are these competing interests and sometimes commercial interests weigh quite hard and I think you're under pressure because someone is funding a project and you have some organizations feel well then they must just do whatever they say and that is why there are these laws and in many countries these laws came about because the problem was that organizations were just doing anything and everything with data. even if they had a legal obligation to do it. Even if there's a financial transaction in the background happening, you need to at least follow principles. And I think that's that's what will help many organizations is if you can crystallize those principles and if you can try and follow those principles, it will probably help you to make sure that you do not invade people's privacy unnecessarily or illegally. But also on the other hand that you can at least try and have that transparency because transparency and disclosure is obviously also important. So you've asked the question about what do you do with countries where there aren't data privacy laws. I think they're actually not that many anymore. It seems that almost it would be interesting to do that count but let's say the vast m vast majority of countries in the world now have data protection laws. Whether they necessarily enforcing them, whether they're actually working in practice on the ground is a different question. But there are laws in many of these countries. But even if there isn't a law, there are principles that you can follow. So people often refer back to the GDPR because the GDPR is this gold standard. It's been around for a while and people look up to that standard. It's not the only one. There are other good or respectable data protection laws out there as well. But I think the GDPR is a good example of a data protection law because it's come a long time. A lot of work has gone into it. There are lots of member countries in the EU. So a lot of input goes into the development of the GDPR. But the GDPR didn't just come out of the blue. It's also based on on other historical principles. So the OECD for example has has PR principles to follow when you're processing personal information. A lot of this actually goes back to the 1970s when organizations realized at that stage that technology is going to create a problem because in the 1970s and I'm trying to I don't know what happened in the 1970s but from what I understand they didn't have the internet they didn't have computers on desktops they didn't have smartphones maybe that fax us I'm not sure if that faxes us or texes but technology was was advancing and they realized with the age of the computer that it's going to be very easy soon to collect lots of data to store lots of data and therefore expose people to bigger risks because before that your privacy was quite protected if you think about it. If you locked your doors and you closed your windows you are private. people won't really have your details because there was no internet to put it on there. It couldn't be stored somewhere. So, it was easy to protect your privacy. But because of the way in which technology started developing, they realized that people won't be able to protect their own privacy anymore. They can't lock their gates anymore. It's out there in the cloud. Well, at that stage, the cloud didn't even exist.

And I think what they thought of as too much data back then is even like multiplied by today, right?

Exactly. I don't think they they could have dreamed well I don't know maybe some of them could have seen what was going to happen where we now but then they came up with these principles it was in the late 1970s and they said let's come up with a few principles that must apply if organizations handle personal data and those principles you keep on seeing in many laws out there they definitely reflected in the GDPR and the law before the GDPR because Europe had something else before the GDPR GDPR is that that old actually and many other countries have decided to adopt those laws as well which makes it easy for organizations I think because it's not like other types of laws like banking law or wills and estates or family law where every country has a very unique law and it might be totally different to another country's law when it comes to data protection law I I I can't do this analysis but I would guess that all of them are about 75% the same because they'll they'll have similar principles and we can go through those principles but to get back to your question because it's now becoming a long answer. I think it's possible for organizations to look at those principles and try and develop a way in which they will handle privacy no matter where they operating because that's obviously the problem. If you have a company and they they're they have a project in three countries in Africa, two countries in Europe and something in APEC, it's going to be very difficult to comply with all those laws. But if you at least have a baseline and you say, "Okay, these five or eight or 10 principles are the principles that we think are really important. We see that they're in most privacy laws. Let's try and follow them." And those principles will then also help you. So if you if you know that a an a funer or a governor organization requires disclosure or transparency then you can think okay well I have these principles so let's just first see what my principles say about disclosing this to them. So maybe I can disclose.

Yeah. So a couple things. So in ENS when we have multi-country operations we have one standard that kind of trickles down and our main like decision making processes is the law more stringent or is our requirement more stringent whichever is more stringent we will follow that but then the second thing is like you're talking about principles that means that it's up to the company's interpretation how to meet these principles or how to apply. It's not like, yeah, it's the law, but it's not like the law where it's prescribed this is what you must do if this happens, right? It's just like, yeah, you try to minimize personal information. How do you do that? What does that mean? like in reality how you how you build this system that is actually helping you go down this decision tree and come up with the most pragmatic solution for each of the countries where you operate.

That is a challenge. So, so many of these principles because they've they've become quite entrenched, it's easy to interpret some of them because in many countries they've already now we can go and name name actually name the

Yeah. Yeah. So, I'm just going to throw some of them out because it otherwise it becomes a whole lectury here. But so one of the the most common principles that you'll find everywhere is is the notice trans principle or the transparency principle. So the idea there is that you have to make sure that people out there know that you have their data and you're doing something with the data why you're doing something with that data who you're sharing with with the data. So the idea there is that people must know that you have their data. So that's the notice and transparency principle. But that one for example I think

But then we kind of fulfill right because we invite them to the consultation we tell them we need their data for the studies.

Yeah. The issue there and here so this is when it becomes more problematic. So I think what you must inform people of is is relatively easy because there are sort of standard things that people should know if you if you have their data or if you want their data and they need to think about it before they give it to you. The problem is how you give them that notice. So some countries require you to to give that notice to them at the time when you're collecting it. So that's that's nice if you have a proper structure where there's a form and it's an in informed consent form for example and you can say here is the form that you must sign so that I can use your data for this study. Here is the notice that tells you everything about the data and what I'm doing with it and who I'm sharing with it. So those are easy to interpret when it becomes problematic is your people that you're working with. What if they are illiterate and they can't read your notice? What if they speak only one language and your notice is in English or in French? How do you address that? What if it's a vulnerable person, for example, an elderly person or a child that might not have the right capabilities to understand what you're trying to tell them? and I think especially in the case of impact assessment, you have to be more careful about this because you're not dealing with business people that sign contracts every day and that speak three or five languages. So there you have to make sure that there are other ways to try and express this information to them. So one way or another, you just need to make sure that they are notified. So, as you've mentioned, you normally tell people that you're collecting their data and why it's being collected. But to be legally compliant, most countries laws require to have some kind of notice. So, some kind of document. And that's why when you visit websites, you almost always see a privacy policy or a privacy notice. Sometimes they have other names. But the whole idea there is to at least have a place somewhere where all this information is on one document because it does become a bit confusing if you tell someone some someone a little bit about the processing now and then a little bit more on the form and then a little bit more in an email or in a text message. It's not all in one place. And I think that's why it's best practice especially when you're getting people's consent to have that notice available to them. If it's if you're dealing with a situation where people have access to the internet, then it's easier because you can even then just give them a link and the form is probably online anyway. It becomes problematic if you're out there in the field and people don't have devices, they don't have the internet, then you'll have to give them a notice that they can understand. And that I think is where impact assessment practitioners can play a big role because many of them come from disciplines where they where they work with people and and understanding their needs and accommodating their needs and and I think one can get quite creative here. You can you can make it much simpler and use pictures to try and explain it. If there's no way that the person can understand the notice, you'll have to have a person there that sits down and explain it with to them in understandable language that that that in a language that they speak.

Yeah. I think when we're doing the site site visits and these consultations in person, we're often faced with a lot of serious decisions that we just have to make on the spot. and we're often unsure if it's lawful or is it just risky. Could we are we going to be able to use this information later on? So, I brought some examples and I want you to share your opinion legal opinion. Is it lawful? Is it risky or is it illegal? Let's say you have the NGO partner that collects this community data and shares it with other NOS's potentially lenders without informing the community.

I would say illegal. It's maybe some people will say it's it's risky. So I suppose if if the community is in a country where there is no law that says you cannot do it, well then obviously I can't say it's illegal. But in most countries that that won't be sufficient. People need to know that you have their data and that you're going to share it with with with other organizations. But even then, there are other reasons why this could be illegal. You get this information for a specific purpose, for a specific project. You tell the community members that you're going to use this data only to look into this specific project. that doesn't allow you to then compile a whole directory and share it with the whole impact assessment community and say I've created this really cool database that everyone can now search if they need to get hold of someone in that community for any new project that that that goes

but okay

let's say it's an NGO that goes to the people we've heard your complaints we want to support you to talk to the lenders and the developer let let us collect your data and talk to them how does That change your opinion?

That does change it because in that case, if they tell the community, this is our purpose. We're going to advocate for you. We're going to try and improve your conditions or we're going to try and sort out this problem that you have with the mine or the facility or whatever in your region. That's okay because you've explained the purpose to them. They've agreed to do it for that purpose. It's a legitimate, it's a legal purpose as long as your purpose makes sense. as long as it's an understandable acceptable purpose that doesn't go against laws or what people would expect or want then then it's okay. It really depends on the context obviously

and what happens in another real situation where NGO goes on the site hears complaints from people takes notes and then emails the lenders.

Yeah. See that is also an issue because firstly does the community know that this information is going to end up with the lenders or do they do they think that you only

we don't know.

Yeah. And that that is the problem and I think that's where the NGO has to be more careful because often your community isn't that involved in how these things actually work. They don't understand the bigger framework around this. They don't they might not know what the impact could be on them if their data ends up with the lender. They might be removed from from their house and moved because because they're difficult and maybe you know someone involved in the process is just not happy with this community that's now become outspoken. So and you have to be careful and I think there sometimes it goes even beyond legal requirements there it's it's more about what is ethical for that organization to do with people's data thinking about broader things than just data protection law but what what is the impact of this go of this disclosure of the information going to be on that person bearing in mind that it could have a real effect on that specific person if the information ends up with a lender and the lender doesn't realize that this information was maybe obtained in a context where the person didn't know that the information is going to end up anywhere. So if you now give it to the lender, the lender thinks I I have consent to to use this information in a court case or give it to government authority, what are the consequences? Where is it going to end up? So there the onus is is on the NGO. the responsibility is with them to make sure that they that they do the right thing and that is difficult I think and that's you've correctly pointed out we have these principles but it's how you apply them in practice and I think some organizations are more principled than other organizations

we briefly touched on keeping the data for longer periods I've I mean I hate to admit this on camera, but I probably have on old laptops grievance forms, photographs, draft information, signed participation forms for projects going back to like 2008. And that's partly because the of the system failure that no one asked me to delete it and it's it's just there. How long how long is it lawful to keep the data? Is there a legal cut off?

It's it's a big it's a big problem. It's I think when it comes to data protection, that's the biggest head back that most organizations have because they sit with lots of data and they don't know how long they can keep it and when must they delete it. So the the keeping it is is easier because most laws will say you can keep information for as long as there's a legal duty on you to keep it. So let's keep it simple in an in a in a context that we all probably understand. If you have to pay tax in a country, most of the country's tax laws will tell you, you must keep the information for at least five years or six years depending on what you know what the country's laws say because we the tax authority want to audit you and make sure that you paid enough tax for example. So on companies there's the same duty. So there's normally a duty to keep your tax and your financial records for a specific period of time. So how to make this practical? What most organizations do is they like

for ENS.

Yeah. Yeah.

And for for ENS Yeah. you have these projects that are under consideration or in preparation 3 years then there's 5 years construction and like for example grievance log like we might need it for auditing purposes 5 years 7 years down the line.

So the the rule is actually in most countries you can keep information for as long as you have a valid reason for keeping that information. So if the project is still ongoing obviously you still have a reason because otherwise how are you going to keep on working on this project if you've now deleted the data but your reason falls away at some stage. So once the project is closed, nothing further has has to be done subsequently to manage any outcomes or impacts. If that is all over then you need to delete the data. But it does become complex because you look need to look at this data at the different levels and there might be microlevel data. In other words, a specific person's address or cell phone number that you might not even need to the the very end of the project because you've already obtained their input. Everyone has looked at it. They've nothing else needs to be done. They don't need to be relocated or whatever else. At that point, you don't need their data anymore. There might still be other details that you still need on a higher level to keep on man managing the project. So the easiest that I think people need to do is first find out what your legal duty is. So get to a minimum period.

Okay,

there will be some kind of period for which you must keep information. And unfortunately this is often per type of information. So in your organization and I think although we're talking obviously you do your operations span more than just interacting with communities. You have your own employees, you have your own contractors, you have your own vendors. So you need to think about all of their data as well and figure out if you have to pay your employees and tax needs to be paid on that. Obviously there's a legal duty on you to keep that information for a certain period. So

yeah,

you'll have to make a schedule. I think that's why I said it's the biggest headache because what creates the biggest net headache is for organizations to create a schedule and say this is all the type of data that I have. This is the legal duty. If this is the minimum period, this is the maximum period. And sometimes there is a maximum period and a minimum period. Some laws will say this is you must keep it for so long and then you have to delete it at that stage. Or they will tell you this information you cannot keep for longer than that period. But that's normally the exception. It's normally a minimum period. So they'll normally tell you you must keep this at least for so long.

Yeah. I'm often involved in in clinical trial studies and there there are strict rules like in Europe it's normally a 25 year period. So if it's a pharmaceutical product, a medication that's being tested, you need to keep that data for a very long period because even if the medication is improved, they could something could go wrong and someone might have to go back into the study details details to see were there serious adverse events that happened because this was tested on people and how was it handled. So, so there are normally minimum periods and in ENS there will be at least in environmental management for example there are requirements of keeping registers for certain periods in in a healthcare the same kind of thing. So it is work unfortunately it's and and the law does create work for people and it takes time and it takes effort to to go and look at your own data but I think you can't even get there unless you don't even know what data you have. So there's this there's this saying I can't remember who said it but someone said that if you can't if you can't measure something you can't manage it. And I think in data protection we have I have a similar rule. If you can't map your data, you can't manage your data because how are you going to figure out what data you must delete or how long you can keep if you don't even know that you have the data. So

yeah and I guess we talk about ENS data but even within the ENS data you could come up with different categories and some might be with a lower um you know on the lower end in terms of number of years to keep some might be required for longer and I think there's no like exact science for it or even the law is not explicit especially for us

no that that isn't

and now a very real question everyone will be able to identify with. We're very often working as subcontractors. Yeah. So, we're working for a larger organization and we have our own personal laptops, phones, iPads. That might be a business asset. They might not be. You might be a self self-employed soloreneur type person. Is it legal or is it risky to use your personal slash soloreneur devices for work?

It's risky, but it's it's not necessarily illegal. I can't think of a law that says that your employees can't use their own devices. I think that's why many organizations have BYOD policies. bring your own device policies to regulate it because I think you can't ignore the fact that for many people it is easier to use their own phone as part of their lives and sometimes they use that phone to contact a client or to if they on the ground in a community to store their details so they can phone them and make arrangements for tomorrow's engagement session or to follow up with them a few months later. So devices are part of our lives. So I think we just have to deal with that but you need to manage that and that is where the security risks come in. There's actually a couple of issues that come in here. Let's maybe first just talk about using devices generally and then about contractors because when you use these devices there are risks of the devices getting stolen or lost. People then get into the device they can get all sorts of data on there. So that's why you need practical measures to try and limit that. So, you need a passcode on your phone. You need a password for your email. You might need face IDs, those kind of practical things. And that's normally what you do if you allow people to use their own devices. You'll say, "Okay, well, you can use your device, but there are ground rules. Then you need a passcode, you need passwords, you certain things you cannot use on your phone." And you'll maybe also prove what kind of apps or services they can use because there are some services that are safer than others. It's just a fact of life. Some services are free because they share that data and they make money out of it. Some services are dangerous because it's processed or stored somewhere in a country where there's government surveillance and people's data could get exposed that way and it could lead to problematic situations for them because we know in some countries they are quite ownorous laws and some people are vulnerable. they have some kind of disease that has a big stigma attached to it and if that data leaks out the community could reject them because that information is out there. So you have to manage how people use devices. But then you've now mentioned something else as well is if it's a contractor. So, if that's not your device or if it's not your employees device, but you're employing another company or another contractor that's a third party, an external party, they're basically a service provider to you. And under almost all data protection laws, there's an obligation on you to then make sure that you have some kind of paperwork in place with that contractor to make sure that there's a confidentiality clause, for example, in that contract to say that you're going to be helping me here. You're a contractor for me to help me to do this assessment, to do this study, but you will look after all the data at the end of the project. You'll give it all back to me. If you lose the data somewhere,

that's the thing. I've never had that. You give it all back to me and delete. Never heard that.

Yeah. And that's that's it is that is scary to put it mildly. It's probably actually very shocking. But that is a big risk and and it's in all business and sectors, not just and ENS. You'll you'll I've seen it so many cases where people use a company, they do their accounting, they do the payroll of the employees or they use a software service provider, they their subscription ends, but they don't know what's happened to that data. Has it been deleted? Is it still sitting somewhere? Basic things. I mean it gets really worrying if you think about if so let's you say you allow your your contractor to use a scanner or a printer that that device has a hard disk on it normally so if they need to scan stuff in they take it out and use it there in the field I don't know people still use scanners probably not but if you had to take that scanner and you gave it gave it to them and now the project comes to an end and you say just keep the scanner I don't really care it's old, I don't need it. That you can't do that. You need to go and get that scanner back. If you give them a laptop, take it back because there's still data on there. You need to wipe it. And can you really trust them that they will do it? Some organizations are probably reputable and you know that they will do it and you can maybe get an outside IT company to go and wipe it and write you letter and say, "Okay, we've cleaned it up." But in most cases, that doesn't happen. So, you have to take that back. And the reason why this is important is because you're responsible for that what that contractor is doing because that contractor is just handling this data for you. You've signed up to do this project. You're responsible to the community. You're answerable to the authorities if something does go wrong. If that data gets leaked or used by bad actors. So it's unfortunately part of life these days because we have nice technologies out there. the risks are just bigger and you have to just be more careful with who you use as a contractor also. You need to do a due diligence on them. You need to check them out and see

and you know the supply chain and contractor management that we do with with our clients or recommend and execute on their behalfs. We should practice what we preach more often.

Yeah, you need a checklist and principles. And I think that's why we came up with this idea that potentially this international association for impact assessment is a good place to have a more formal set of principles for data protection specifically for ENS indoors by this like network so that it reaches everyone and they could learn from the data protection principles and how that applies to their work and support these these highle principles with the very very practical guidance note because these these examples that we've discussed today these are things that most of us face every day every week so how to put these principles into context for us and then into the practice of ENS work whether that's impact assessment or due diligence so I think as part of that maybe as as a conclusion usion. What were the some of the gaps or some of the sort of like inconsistencies that you've observed with the disclosure requirements, the access to information policies that are things that clearly govern how how we disclose and process data.

I think there are there are a couple of issues. I think one of the biggest issues is that too much information is expected and too much information is disclosed. People I think it might also just be the way in which people interpret this. But you can't just give all your raw data and say well that is in the interest of transparency and disclosure. The impact assessment practitioner even though there might be a duty on them to disclose and to be transparent you need to first sit back and think well what I would say what is the minimum information that you can disclose to still achieve transparency just putting an information dump out there and say okay now it's been transparent that's not transparency that's irresponsible and and I know many of these organizations expect transparency and they expect disclosure and that is important but it it needs to be tempered. So we have the two fires you need to try and find your way in the middle of that fire and and decide okay I am going to disclose but is there a way to disclose this information without putting the relevant people at risk. So if if someone questions whether you've actually done the study, well you you have the information. If a government wants to come and investigate, then you can give it to them. But that doesn't mean that you now go overboard and put it all out there in on the internet in the interests of transparency. That's not transparency. That that's irresponsibility if there's such a word.

Yeah. And I guess a lot of these access to information policies, even outside of ENS, they would allow any random person to access other people's personal information without their consent or even knowledge.

Yeah. And the purpose of transparency is obviously to to investigate things and to people to keep people accountable and honest. And you can do that without without having all of the data. And if you then pick something up and see, well, this does not make sense. Something is wrong here. Something is unethical. Something is illegal. Well, then the government authorities have the power to then go and dig deeper and look at the actual data and see what went wrong. But it's I don't think it's it's fair or reasonable to expect impact assessment practitioners to take all their data and and just make it public just bec because this is transparency. you need to think about the repercussions and going back to the suggestion for the IIA IIA I think it will be useful for people to have certain principles and to make them aware of these principles because I think some people are maybe not aware of these principles because they didn't study about them in in university it's maybe not something that they've encountered previously it's definitely not something that people learn about at school so I to have the principles there and and principles are infectious to a certain extent. The moment that a community adopts them, they they start spreading and everyone starts accepting that as best practice. So I think it will be a nice thing to spread and then to have practical guidance that goes with that that that where you can have case studies where you can have examples and say well in this kind of situation how do you handle that? But I think the other thing that is tied to awareness is also the risks because sometimes people don't want to follow the law because they just don't have the time or the money or the effort or the energy to do it. But if you figure out that there are actually consequences to this and this is what I've also encountered many organizations don't realize that there are laws or they as I've explained previously think that they are not covered by these laws but they also forget that well it is a law so you can get fined but there are also other consequences. It's if this study gets blown open and it's a lot of things went wrong and that information is now out there. it's really going to affect your reputation and maybe you'll lose business. You'll lose clients because they don't want to be associated with you or they don't trust you because you managed to use a contractor who had an unsecure laptop and they left the laptop in the field. Just as a very very simple example, but there's also the community there. There are the the vulnerable people that we're actually supposed to protect. I think many impact impact assessment practitioners realize that they have an ethical duty to work with people and make life better for them. Now you go and collect their data and make it worse for them. That's that's not the right thing. So I think

it it often helps to realize why you you're doing things. And I think there are reasons you want to maybe avoid fines. You want to manage a good reputation. you want to ensure that that people are kept safe and secure and that their well-being is okay. If you keep those things in mind, you might realize that you need to follow these laws and you need to apply these principles because of of the good consequences. And there are advantages to complying with these laws as well. I've I've heard of many organizations where they where they've started implementing a privacy program or privacy management framework or a process or something and they've realized oh gosh we have way too much data we have to delete this we can save space we can destroy those files we have bit better business

optimize the costs

yeah there are advantages to this so and I think it's it's a lot of this is about awareness it about knowing about the risks about the advantages But I think it's also about being aware of what data you have. I really think it's it's an organization that any kind of business or professional no matter what sector or industry you're in, you need to do do this. Make your little data map and start by saying whose data are we processing? What kind of data is it? Which systems are we using and what data goes into that system? Because if you if you cannot put that alls on a page or a spreadsheet or some kind of diagram, how are you going to even comply with your obligations? Because you can only comply with your obligations if you know what you're handling. Otherwise, you you can't even start at step one.

Thank you so much. I've learned a lot this past hour and I'm so excited to start working on these principles and the guidance note. I have a lot of ideas and a lot of questions about the practical implications of having these set of principles. So, thank you so much Danny for being here today.

Thanks so much. It's been really great.

I hope you also got inspired on data protection, especially on what's legal and what's unethical. And we'll be back next time with more. Thank you.

Comments


bottom of page