• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Track and Trace - is taking surnames necessary?

Status
Not open for further replies.

AM9

Veteran Member
Joined
13 May 2014
Messages
16,035
Location
St Albans
You clearly don’t live in the same world I do. I have every intention of continuing to visit these establishments, but I *will not* be giving out my personal details.

It’s perfectly possible to visit pubs/restaurants and simply give false details. That way, everyone is a winner: they get my business, I don’t give my details out unnecessarily.

That’s what I do on the (very rare) occasions where I’m asked for details in hospitality venues, and that’s exactly what I will continue to do.
I live in the same world as you but I certainly don't have the same attitude as you.
So by giving a false identity you maintain that "everyone is a winner". Presumably in your world, 'everyone' is restricted to you and the publican/restauranteur. No consideration given to the other customers, your family - possibly the restaurateur when they discover that an outbreak was spread from there. The selfishness of people never fails to surprise.
 
Last edited:
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

island

Veteran Member
Joined
30 Dec 2010
Messages
17,910
Location
0036
GDPR does not prevent gathering and keeping personal data without consent. The basis for gathering personal data is to protect the vital interests of the data subject and/or to comply with legal requirements, depending which part of the country you are in.

However, asking people to write their personal data on a sheet on which others have written their personal data, or leaving said data out and visible to the public, is likely to be a GDPR breach (failing to keep data secure).

== Doublepost prevention - post automatically merged: ==

The difference being that the telephone directory gave a number to a device that was largely not connected to anything other than the telephone network, nor was it a device that might carry sensitive information that might be use to hackers, scammers etc. But all that is beside the point, GDPR requires companies collecting data (note collecting, which is not what the telephone directory did, they simply published information already owned by the telephone company)
This is a red herring. GDPR applies to processing personal data, and processing includes collecting, storing, and publishing. Producing a phone book is certainly governed by GDPR. I don’t know whether phone books are produced any more, but the basis for processing personal data to produce to a phone book is the legitimate interests of the data controller (the phone company) in making available contact details of phone users so that other users can find those details and place phone calls, thereby generating business for the phone company. They offer an opt-out (also known as being ex-directory) for customers who do not want to be so listed.
 

43066

Veteran Member
Joined
24 Nov 2019
Messages
12,089
Location
London
I live in the same world as you but I certainly don't have the same attitude as you.
So by giving a false identity you maintain that "everyone is a winner". Presumably in your world, 'everyone' is restricted to you and the publican/restauranteur. No consideration given to the other customers, your family - possibly the restaurateur when they discover that an outbreak was spread from there. The selfishness of people never fails to surprise.

You may consider me selfish - that’s fine with me - my approach won’t be changing, one iota.

I wish to get back to as normal a life as I can, as quickly as possible. I don’t mix with people who are “high risk”, including a close family member who has been shielding since early March. None of us have enjoyed that, trust me.

I’ve had no choice but to continue going to work, throughout this pandemic. If I’d taken your approach, several thousands of people wouldn’t have got to where they needed to be, over the last few months, and I’d most likely be unemployed by now.

So sue me if I want to go to the pub, occasionally.
 

GusB

Established Member
Joined
9 Jul 2016
Messages
8,141
Location
Elginshire
I don't think giving false details is helpful, especially if you were to come into contact with someone who had the virus and you then went on to pass it on asymptomatically to other people. However, I do completely understand the reservations that people have about giving over contact details. The process by which details are captured and stored should have been mandated early on, along with a reminder of the obligations that establishments have under GDPR legislation. A "visitors' book" which allows anyone to see the contact details of those who went before is completely inappropriate.

I've just come back from having a few pints in my local. There were only a few of us in, but the bar staff pulled the folder out from under the counter, recorded my name and the time I walked in, and put it back beneath the bar. That's enough in my book, but I do live in a fairly small place. I'm not confident that a similar system would work in a pub that's busy.
 

Bantamzen

Established Member
Joined
4 Dec 2013
Messages
10,503
Location
Cheshire
GDPR does not prevent gathering and keeping personal data without consent. The basis for gathering personal data is to protect the vital interests of the data subject and/or to comply with legal requirements, depending which part of the country you are in.

However, asking people to write their personal data on a sheet on which others have written their personal data, or leaving said data out and visible to the public, is likely to be a GDPR breach (failing to keep data secure).

== Doublepost prevention - post automatically merged: ==


This is a red herring. GDPR applies to processing personal data, and processing includes collecting, storing, and publishing. Producing a phone book is certainly governed by GDPR. I don’t know whether phone books are produced any more, but the basis for processing personal data to produce to a phone book is the legitimate interests of the data controller (the phone company) in making available contact details of phone users so that other users can find those details and place phone calls, thereby generating business for the phone company. They offer an opt-out (also known as being ex-directory) for customers who do not want to be so listed.

Well that was an excellent example of swerving around the point. A company collecting such data, note I say collecting meaning they did not previously own the data, must ensure the data is secure, i.e. not written in a book that other customers can read & copy freely. It is a breach of GDPR pure and simple. There is no arguing that point.

And to get back to my point why it is a serious breach, mobile phones for the most part are far more than a line line handset. Even a moderately competent hacker would delight in having a list of names & mobile numbers freely available to them, even more so when those people might actually be in the same premises as them. But don't take my word for it, you can try it out for yourself by simply leaving a card with your name & current mobile number wherever you go, and wait to see how it will take before you start to get phising texts or calls, and maybe worse.
 

Bletchleyite

Veteran Member
Joined
20 Oct 2014
Messages
113,443
Location
"Marston Vale mafia"
So sue me if I want to go to the pub, occasionally.

I don't think anyone is saying you shouldn't go to the pub, but rather you should play along with Test and Trace when you do.

While the new NHS app will hopefully provide a solution to this (it has a QR code scanner for a simple "just scan" tracking approach) I must admit I prefer the "name and phone number on a list with a pen" arrangement, because it takes 5 seconds, whereas all the QR code based things seem to take ages, asking for far more than they need (simply name and telephone number, nothing else; even asking the time you were in the pub is silly as the answer is "now, because I've just scanned your QR code!").

I do agree it's a clear GDPR breach, but it's also the best option for me because it's the least hassle. If the list is kept with a member of staff e.g. at the bar, people aren't going to be walking up and noting down the names and numbers or photographing it.
 

adc82140

Established Member
Joined
10 May 2008
Messages
3,407
I go with a halfway house solution. I put down an assumed name but correct phone number. If anyone calls asking for Dave, I know it's track and trace, and will cooperate.

If you go in to my local more than once, you are given a customer number to sign in with. Only the landlord knows which customer is allocated that number.
 

GusB

Established Member
Joined
9 Jul 2016
Messages
8,141
Location
Elginshire
I go with a halfway house solution. I put down an assumed name but correct phone number. If anyone calls asking for Dave, I know it's track and trace, and will cooperate.

If you go in to my local more than once, you are given a customer number to sign in with. Only the landlord knows which customer is allocated that number.
^^^ This. The only crucial piece of information required in this case is a contact number. It doesn't really matter which name you give at the time
 

island

Veteran Member
Joined
30 Dec 2010
Messages
17,910
Location
0036
Well that was an excellent example of swerving around the point. A company collecting such data, note I say collecting meaning they did not previously own the data, must ensure the data is secure, i.e. not written in a book that other customers can read & copy freely. It is a breach of GDPR pure and simple. There is no arguing that point.
How have I “swerved around the point”? My post, which you quoted, contained the sentence:
asking people to write their personal data on a sheet on which others have written their personal data, or leaving said data out and visible to the public, is likely to be a GDPR breach (failing to keep data secure).
which nobody, other than possibly your straw-man, appears to be arguing against.
 

Bantamzen

Established Member
Joined
4 Dec 2013
Messages
10,503
Location
Cheshire
How have I “swerved around the point”? My post, which you quoted, contained the sentence:

which nobody, other than possibly your straw-man, appears to be arguing against.

As I said, there is no arguing the point. I'm glad you agree. However your comparison with the telephone books of yesteryear and mobile phones is not accurate, which was my point and what you dodged.
 

87 027

Member
Joined
1 Sep 2010
Messages
735
Location
London
So I have observed that very few of these lists in cafes and restaurants ask for the arrival and departure time as well as contact details. Therefore people could be asked to self quarantine and miss school/work etc on the basis of being on a list even if they departed before the infected person arrived. It’s making me think twice about the details I give
 

Bletchleyite

Veteran Member
Joined
20 Oct 2014
Messages
113,443
Location
"Marston Vale mafia"
So I have observed that very few of these lists in cafes and restaurants ask for the arrival and departure time as well as contact details. Therefore people could be asked to self quarantine and miss school/work etc on the basis of being on a list even if they departed before the infected person arrived.

I doubt it. You'd be contacted and asked when you were there and where you were sitting, and that would inform whether you had to isolate or not.
 

87 027

Member
Joined
1 Sep 2010
Messages
735
Location
London
I doubt it. You'd be contacted and asked when you were there and where you were sitting, and that would inform whether you had to isolate or not.
But if in and out times aren’t recorded how can you be sure if it’s several days after the event? E.g. I leave at 12:58 and the infected person arrives 13:02. The list at the cafe where I had lunch today was a non-GDPR simple book where everyone writes their name and phone number. No times, no seating plan. Seems very hit-and-miss to me!
 

Islineclear3_1

Established Member
Joined
24 Apr 2014
Messages
6,592
Location
PTSO or platform depending on the weather
I visited a seaside pier over the weekend and was asked for my details by a unsupervised school-age child(!). The only way of access was through the indoor arcades

I gave a false name/mobile number and the child happily just tapped it in on her mobile device and waved us through

I also visited a restaurant with my family and grandma and nobody asked for details
 

route101

Veteran Member
Joined
16 May 2010
Messages
12,281
Glasgow St Enochs Shopping Centre, they ask you to do it as you enter the food court and they also check you leaving with surname,where you ate and time left.
 

mmh

Established Member
Joined
13 Aug 2016
Messages
4,274
On the GDPR issue, I don't believe it will be an issue when done properly, that being done in a secure way. One venue I frequented just had an open book at the entrance and a shared pen (plus sanitiser) - I did put correct details in that case but in hindsight if I came across similar again I may not do (or, of course, not frequent such a venue in the first place)

What makes you feel that someone taking details on an electronic device is more secure than a paper book?
I've just come back from having a few pints in my local. There were only a few of us in, but the bar staff pulled the folder out from under the counter, recorded my name and the time I walked in, and put it back beneath the bar. That's enough in my book, but I do live in a fairly small place. I'm not confident that a similar system would work in a pub that's busy.

Since pubs have reopened I only really go to two places. One, my local pub where they take my name, number and postcode on an ipad. Or rather, they take my number and postcode because being my local, they know my name. The other is a Conservative Club where they have an insecure book open on the bar to fill in yourself, it asks for your name and number. I can't say filling it in has particularly worried me, nor have I taken any notice of the names and numbers before mine.

And to get back to my point why it is a serious breach, mobile phones for the most part are far more than a line line handset. Even a moderately competent hacker would delight in having a list of names & mobile numbers freely available to them, even more so when those people might actually be in the same premises as them. But don't take my word for it, you can try it out for yourself by simply leaving a card with your name & current mobile number wherever you go, and wait to see how it will take before you start to get phising texts or calls, and maybe worse.

You mean a business card? Thousands of people have been leaving those with their name and number all over the place for years.

As I said, there is no arguing the point. I'm glad you agree. However your comparison with the telephone books of yesteryear and mobile phones is not accurate, which was my point and what you dodged.

The phone book used to have my full name, address and number in it, just like for millions of other people. It also, last time I had one at least, contained some people's mobile numbers. Why is that different?

Then there are all the people with their names and mobile numbers on their van, on the back of their sweatshirt, on their leaflets, business cards...
 

Crossover

Established Member
Joined
4 Jun 2009
Messages
9,493
Location
Yorkshire
What makes you feel that someone taking details on an electronic device is more secure than a paper book?

No way is ideal. However an open book on a reception or bar is asking for trouble. Less so if the staff have it and fill it in keeping it behind the bar
 

mmh

Established Member
Joined
13 Aug 2016
Messages
4,274
No way is ideal. However an open book on a reception or bar is asking for trouble. Less so if the staff have it and fill it in keeping it behind the bar

What trouble is it asking for, and again why is a tablet computer, say, less worrying?
 

Crossover

Established Member
Joined
4 Jun 2009
Messages
9,493
Location
Yorkshire
What trouble is it asking for, and again why is a tablet computer, say, less worrying?
Granted, one is trusting details being taken electronically being kept securely and of course they could be open to the world. However, an open book is very much open to anyone who happens to pass by. Just because (going back to your earlier point) of you having not taken notice of any other details in there (nor did I, on the one I did fill in) isn't to say everyone else seeing it is quite so well intentioned!
 

221129

Established Member
Joined
21 Mar 2011
Messages
6,515
Location
Sunny Scotland
Granted, one is trusting details being taken electronically being kept securely and of course they could be open to the world. However, an open book is very much open to anyone who happens to pass by. Just because (going back to your earlier point) of you having not taken notice of any other details in there (nor did I, on the one I did fill in) isn't to say everyone else seeing it is quite so well intentioned!
Exactly. It's an identity thief's dream! False name, false number. The whole situation is a massive privacy concern.
 

87 027

Member
Joined
1 Sep 2010
Messages
735
Location
London
Exactly. It's an identity thief's dream! False name, false number. The whole situation is a massive privacy concern.
I think the question is what value would that information have to someone who intends to cause you harm. I am personally relaxed about leaving my name, email and phone number on a paper list. As others have said, it's on hundreds of business cards I've given out over the years. As well as the cafe I had lunch at I have done so again in the restaurant where I had dinner this evening.

From a GDPR perspective, good practice would be for each customer to write their details on a separate piece of paper, then put them in a sealed envelope, lock away in the safe and destroy after a couple of weeks if not needed. This is what I heard at a conference recently from a contributing author of proposed coronavirus safeguards legislation.

My issue as per post 43 above is potentially unnecessary quarantine because the authorities think I have been in contact with an infected person on the basis of a report they were in the same venue as me at 'around 1 o'clock'. Sorry @Bletchleyite, precision matters!
 

Crossover

Established Member
Joined
4 Jun 2009
Messages
9,493
Location
Yorkshire
From a GDPR perspective, good practice would be for each customer to write their details on a separate piece of paper, then put them in a sealed envelope, lock away in the safe and destroy after a couple of weeks if not needed. This is what I heard at a conference recently from a contributing author of proposed coronavirus safeguards legislation.

This would be the correct way to do it. An open book (sometimes seen them 'unguarded') is a huge no-no. Identity theft isn't top of my concerns list (though could in part be used for it) but the information could definitely be traded on and used for nefarious purposes.
 

Bantamzen

Established Member
Joined
4 Dec 2013
Messages
10,503
Location
Cheshire
You mean a business card? Thousands of people have been leaving those with their name and number all over the place for years.



The phone book used to have my full name, address and number in it, just like for millions of other people. It also, last time I had one at least, contained some people's mobile numbers. Why is that different?

Then there are all the people with their names and mobile numbers on their van, on the back of their sweatshirt, on their leaflets, business cards...

And if anyone who is advertising a mobile number either should be using another device other than their personal one for both security and accounting reasons, or if they use their personal should not be using it for personal transactions and / or be very careful what texts / messages / emails they view. Otherwise they are seriously increasing the risk of a phising attack.

What trouble is it asking for, and again why is a tablet computer, say, less worrying?

An open book can be copied in a moment, and a hacker lurking in a cafe or bar is on their way to getting much closer to getting someone's identity. I'm not going to get into details here for obvious reasons, but just spend a little time reading up on how hackers exploit public WiFi networks in public areas, then imagine them already having potential customer name & phone numbers.
 

DelayRepay

Established Member
Joined
21 May 2011
Messages
2,929
So I have observed that very few of these lists in cafes and restaurants ask for the arrival and departure time as well as contact details. Therefore people could be asked to self quarantine and miss school/work etc on the basis of being on a list even if they departed before the infected person arrived. It’s making me think twice about the details I give
I noticed that on Saturday. I got to the cafe just after they opened, there were perhaps 3 other customers inside. I was given a book full of names/phone numbers and asked to add mine to the bottom. There was no record of the time, or date, or even a line to show where Friday's list finished and Saturday's started. Which begs two questions - firstly how do know where to start with the list, if they do have to contact people and secondly how do they know when the 21 day period has passed so details can be destroyed.

On Saturday afternoon I went to a different place and was asked to complete a very detailed form. Full name, address, email address, contact number, alternative contact number... And unlike most places, they wanted this for each person in the group (they had a special form printed with space for up to four people's details).

The whole thing is a mess.
 

greyman42

Established Member
Joined
14 Aug 2017
Messages
5,368
On Saturday afternoon I went to a different place and was asked to complete a very detailed form. Full name, address, email address, contact number, alternative contact number... And unlike most places, they wanted this for each person in the group (they had a special form printed with space for up to four people's details).
This is unnecessary. Just give them your name and number, true or false. If that causes them a problem then move on. I have not encountered a pub like this yet and would think they are few and far between.
 

Andy Pacer

Established Member
Joined
11 Jul 2017
Messages
3,504
Location
Leicestershire
I'm sure as long as they can actually contact you then that should be sufficient. Name and contact number should be ample.
 

NorthOxonian

Established Member
Associate Staff
Buses & Coaches
Joined
5 Jul 2018
Messages
1,670
Location
Oxford/Newcastle
I'm sure as long as they can actually contact you then that should be sufficient. Name and contact number should be ample.

Perhaps surprisingly, the business who seem to have the best approach is Wetherspoons, or at least the two or three I've been to recently. The forms ask for name, contact number, time of arrival, and time of departure. The only thing possibly missing is floor/location - probably useful in their larger pubs especially those with multiple bars. All forms are deposited in a sealed box rather like a ballot box - some place these on the bar while others put them on a dedicated table (I prefer the latter approach because it means you don't get in the way of the bar when putting your forms in).

At first they were quite lax, but they are now quite good at making sure people fill the forms in (though unfortunately one of the ones near me seem to prefer the QR code approach to paper forms, which I'm not so happy about).
 

DelayRepay

Established Member
Joined
21 May 2011
Messages
2,929
This is unnecessary. Just give them your name and number, true or false. If that causes them a problem then move on. I have not encountered a pub like this yet and would think they are few and far between.

Indeed. It wasn't a pub, it was the cafe in a garden centre. I just gave my first name and phone number (real ones, not made up) and the time of my visit, and left the rest of the form blank. They didn't say anything. I think they might have printed the forms a long time ago before they really understood what they had to do.

Edit: A friend has just mentioned that his barber used the details from the Track and Trace form to ring him because he'd left a bag of shopping behind after his hair cut. Probably a breach of GDPR but the friend was very appreciative!
 
Last edited:
Status
Not open for further replies.

Top