• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

fare dodgers and GDPR - what are the TOCs actually allowed to do?

Status
Not open for further replies.

concerned1

Member
Joined
18 Mar 2012
Messages
40
Just seen a person get PF’d on my train… (Luton Airport Parkway to Farringdon) was the journey they claimed to be making.

Usual excuses and rigmarole, but then the RP said “I can see this is the second time you have done this, and normally this would be a prosecution but …”

And the guy interrupted and said: “how can you see this is the 2nd time? Are you holding my data without my consent, that is a breach of GDPR,…” and it went on. The RP didn’t seem to have a satisfactory reason as to why Thameslink was allowed to hold individuals data without their consent and the argument was still going on when I left at St Pancras.

I’m sure we’ll agree the pax was lucky not to have been given an MG11 but just for my own interest, what is the little bit of the NCoC that allows TOCs to hold fare dodgers data? I can’t see anything
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

Bletchleyite

Veteran Member
Joined
20 Oct 2014
Messages
113,737
Location
"Marston Vale mafia"
And the guy interrupted and said: “how can you see this is the 2nd time? Are you holding my data without my consent, that is a breach of GDPR,…” and it went on. The RP didn’t seem to have a satisfactory reason as to why Thameslink was allowed to hold individuals data without their consent and the argument was still going on when I left at St Pancras.

I’m sure we’ll agree the pax was lucky not to have been given an MG11 but just for my own interest, what is the little bit of the NCoC that allows TOCs to hold fare dodgers data? I can’t see anything

It doesn't need to be in the NRCoT. Consent is not the only GDPR basis to hold personal data (it is by far the weakest basis and is only generally to be used as a last resort where none of the others apply, principally relating to stuff like marketing). There are other bases, in this case the one applicable is holding the data for the prevention or investigation of crime (as travelling without a valid ticket is a criminal offence).

GDPR is and was in many ways an anti-spam law. While it creates paperwork, it doesn't ban very much that was permitted (under the Data Protection Act 1998) to do with data before it existed apart from various forms of marketing.
 

concerned1

Member
Joined
18 Mar 2012
Messages
40
And yet we all still get SPAM?

A lot of people treat GDPR as the right to have consent over third parties holding our data. Would have thought RP training would cover this?
 

Bletchleyite

Veteran Member
Joined
20 Oct 2014
Messages
113,737
Location
"Marston Vale mafia"
And yet we all still get SPAM?

Far, far less than before GDPR. Indeed, pretty much only from countries outside the EU now, and if you click to unsubscribe from anything in the EU it does actually work.

A lot of people treat GDPR as the right to have consent over third parties holding our data.

They are of course wrong. Consent is just one of the bases, the others are better choices if they apply to the reason the data is being held. For example, businesses hold under "legitimate interest", not "consent", if they are holding customer data for the purpose of completing a transaction or carrying out after-sales service. Though it is notable that you can't in most cases change the basis of why a particular piece of data is held (so you can't use your after-sales service database to spam people advertising to upgrade their product, for instance, or to carry out paid servicing on it), you have to re-collect in such cases - but I'd be astonished if when signing up to Trainline the basis of crime prevention isn't mentioned, indeed I'm almost certain it is. And you can collect data on more than one basis as long as you state what the bases are when you collect it and it is genuinely necessary to hold it on those bases.
 

Tetchytyke

Veteran Member
Joined
12 Sep 2013
Messages
17,628
Location
Isle of Man
It's a common misconception that GDPR means that data subjects have to consent to their data being processed. That isn't the case at all.
 

35B

Established Member
Joined
19 Dec 2011
Messages
5,552
It's a common misconception that GDPR means that data subjects have to consent to their data being processed. That isn't the case at all.
And one that is used by charmers like the subject of the OP.
 

ainsworth74

Forum Staff
Staff Member
Global Moderator
Joined
16 Nov 2009
Messages
31,125
Location
Redcar
but I'd be astonished if when signing up to Trainline the basis of crime prevention isn't mentioned, indeed I'm almost certain it is.
Indeed:

We work with travel operators who also need your data to create your tickets and provide services in relation to your journey as well as to deal with after-sales matters. Some travel operators may run your data through their own payment and eticket systems in order to issue your tickets or notify you of any travel disruption. We may also share your personal data with travel operators to prevent and detect fraud against either you, Trainline or the travel operator. We only share what is necessary to meet this purpose, and we make it clear to them they must keep your personal data safe.

 

IanD

Established Member
Joined
18 Sep 2011
Messages
2,784
Location
Newport Pagnell
I'm not sure the "public task" argument applies here but you'd still have the right to object to your data being held.

Also, once your data has been used for the purpose it was collected, it should be removed in a timely manner and cannot be used for any other purpose without you being informed and giving your consent.
 

Bletchleyite

Veteran Member
Joined
20 Oct 2014
Messages
113,737
Location
"Marston Vale mafia"
I'm not sure the "public task" argument applies here but you'd still have the right to object to your data being held.

Not in every case.

Also, once your data has been used for the purpose it was collected, it should be removed in a timely manner and cannot be used for any other purpose without you being informed and giving your consent.

If crime prevention was part of why it was originally being held, it can be held for as long as required for crime prevention purposes.
 

35B

Established Member
Joined
19 Dec 2011
Messages
5,552
I'm not sure the "public task" argument applies here but you'd still have the right to object to your data being held.

Also, once your data has been used for the purpose it was collected, it should be removed in a timely manner and cannot be used for any other purpose without you being informed and giving your consent.
Timeliness will depend on the defined retention period, while the grounds under GDPR are relatively broad so may not give the degree of consent you suggest. The ICO guidance page (https://ico.org.uk/for-organisation...sources/lawful-basis/a-guide-to-lawful-basis/) is quite interesting, and it's not difficult to see how data sharing between a ticket retailer and the firm whom they act as an agent for could be justified under legitimate interests, and the data retained for more than just the time taken to make the purchase.
 

concerned1

Member
Joined
18 Mar 2012
Messages
40
Interested in knowing how far you could take this maxim? Pretty sure there will be some loophole lawyers somewhere arguing that prosecutions based on data collected on repeat offenders gathered without their consent is cause to throw out a case.

Is it just names and addresses that the TOCs collect, or does it go further than this, e.g. driving license numbers, etc? Because people change address all the time, and there are lots of Dave Smith’s out there.
 

NorthWestRover

Established Member
Joined
24 Aug 2018
Messages
1,612
I'm not sure the "public task" argument applies here but you'd still have the right to object to your data being held.
Yes, on reflection I agree.

Legitimate Interests will easily cover it though.
 

Bletchleyite

Veteran Member
Joined
20 Oct 2014
Messages
113,737
Location
"Marston Vale mafia"
Interested in knowing how far you could take this maxim? Pretty sure there will be some loophole lawyers somewhere arguing that prosecutions based on data collected on repeat offenders gathered without their consent is cause to throw out a case.

People will argue all sorts, but I don't personally believe there's anything breaching GDPR in what they are doing.
 

IanD

Established Member
Joined
18 Sep 2011
Messages
2,784
Location
Newport Pagnell
If crime prevention was part of why it was originally being held, it can be held for as long as required for crime prevention purposes.

As long as you made it clear when collecting that it was for "future crime prevention" rather than just investigating this particular instance.

On this forum, we are continually being told that being issued a penalty fare is not the same as committing a crime, it's just an acknowledgement that you have made a mistake. So, once the PF has been paid there is no need to keep the information.
 

35B

Established Member
Joined
19 Dec 2011
Messages
5,552
Interested in knowing how far you could take this maxim? Pretty sure there will be some loophole lawyers somewhere arguing that prosecutions based on data collected on repeat offenders gathered without their consent is cause to throw out a case.

Is it just names and addresses that the TOCs collect, or does it go further than this, e.g. driving license numbers, etc? Because people change address all the time, and there are lots of Dave Smith’s out there.
Consent which they provide by entering into a contract which specifies how their data will be used as part of a data processing statement. Unless the data controller or processor has been pretty flaky in how they've worked, I'd be very surprised if a court supported a defence that went along the lines of "they can't prosecute me because I didn't give permission for them to prosecute me".

The only area where I might have concerns about how TOCs operate is in their selection of who to investigate, and how they then consider that data. Based on the cases seen here, though, I think they meet the threshold of reasonable suspicion, and the data that then emerges is what follows. The TOCs interpretation of their rights once they have that data is perhaps a more questionable area.

== Doublepost prevention - post automatically merged: ==

As long as you made it clear when collecting that it was for "future crime prevention" rather than just investigating this particular instance.

On this forum, we are continually being told that being issued a penalty fare is not the same as committing a crime, it's just an acknowledgement that you have made a mistake. So, once the PF has been paid there is no need to keep the information.
Hard disagree. For a firm to keep a record of whom they have dealt with is a basic administrative requirement, required to keep a contract with a named individual. It is clearly within a company's legitimate interests when settling a matter to retain a record of whom they have settled with, and to be able to refer back to that record to see whether there is actually a pattern of behaviour that is criminal in nature.

Given the legal requirements that consent be freely given, consent provided on a "give us consent or we'll prosecute you" basis could never be validly obtained.
 

Tetchytyke

Veteran Member
Joined
12 Sep 2013
Messages
17,628
Location
Isle of Man
Crime prevention isn't a lawful basis under UK GDPR.
It's complicated.

'The prevention or detection of crime' is an exemption from some parts of GDPR. This is not a blanket exemption though. The exemption is limited to the extent that application of GDPR would otherwise prejudice the prevention or detection of crime.

An example is where I disclose something to the Financial Intelligence Unit (FIU). I am allowed to disclose a data subject's data under this exemption. I am also allowed to not tell the data subject that I have made that disclosure, again because of this exemption. The FIU can also disclose that data subject's data under this exemption.

Separately, there is a lawful basis under GDPR for processing data because of 'legitimate interests'. This can include the prevention and detection of crime.

The TOC retaining the details of people who have previously been issued a Penalty Fare or who have been the subject of a Travel Irregularity Report would be a legitimate interest, in my opinion.

However, I am less persuaded that the 'fishing expeditions' that TOCs engage in with Trainline data are quite so compliant with GDPR. The data being shared should be proportional to the legitimate interest and the bulk-download of ticket retailer data wouldn't, in my opinion, be compliant with that. But it is nuanced- if someone's been stopped for not having a railcard, the TOCs would undoubtedly argue they then have a legitimate purpose in finding out how many other times they've bought tickets with a railcard. 'Fishing expeditions' by downloading the data of anyone who buys tickets between [known short-faring station pairs] would, in my opinion, be a step further again from legitimate interest.

I'd be very interested in what the Information Commissioner would decide should it ever be referred to them in a complaint. It's nuanced.
 

IanD

Established Member
Joined
18 Sep 2011
Messages
2,784
Location
Newport Pagnell
For a firm to keep a record of whom they have dealt with is a basic administrative requirement, required to keep a contract with a named individual. It is clearly within a company's legitimate interests when settling a matter to retain a record of whom they have settled with, and to be able to refer back to that record to see whether there is actually a pattern of behaviour that is criminal in nature.
And they should be allowed to keep this information forever?
 

35B

Established Member
Joined
19 Dec 2011
Messages
5,552
And they should be allowed to keep this information forever?
As I've already said, no - they need to define a retention period for that data, which would need to be proportionate to the purpose for which the data was being kept. Instinctively, I'd expect it to be somewhere between one month after the ticket ceases to be valid (i.e. to support possible Delay Repay) and 7 years following the end of the tax year in which the record was created (to align with the statutory retention period for accounting records). The precise length will be a trade off between the cost of retaining the records and the likely need for the data - though I notice that a number of the railcard related cases seem to be pushing to the longer end of that range.

Going back to the OP, my feeling is good on the RPI for being so clear that the data was being used in this way, as a warning shot to the evader that they do leave a trace. The mistake was in a) TL not giving him a script to follow for when someone pushes back and b) getting drawn into the conversation - the reply should very simply have been "if you have a concern, please write to our Data Protection Officer who will be able to answer your question".
 

NorthWestRover

Established Member
Joined
24 Aug 2018
Messages
1,612
It''s complicated.

'The prevention or detection of crime' is an exemption from some parts of GDPR. This is not a blanket exemption though. The exemption is limited to the extent that application of GDPR would otherwise prejudice the prevention or detection of crime.

Agreed it's complicated and as GDPR is principles based, then the first answer to any question should always be "it depends...".

The exemption, as I know you'll know, does not remove the need for a lawful basis.

I also agree with your doubts that the fishing expeditions are compliant with the GDPR principles and I could argue it either way, depending on who was asking lol.
 

Trainbike46

Established Member
Joined
18 Sep 2021
Messages
4,376
Location
belfast
LNER customer account deletion requests won't be actioned until 60 days after the last ticket bought with it expires, explicitly to allow for dealing with any complaints, delay repay, etc., so the minimum retention time of ticket purchases appears to be that long.

Of course, I doubt you can request a penalty fare record is deleted!
 

Fawkes Cat

Established Member
Joined
8 May 2017
Messages
5,324
Interested in knowing how far you could take this maxim? Pretty sure there will be some loophole lawyers somewhere arguing that prosecutions based on data collected on repeat offenders gathered without their consent is cause to throw out a case.

Is it just names and addresses that the TOCs collect, or does it go further than this, e.g. driving license numbers, etc? Because people change address all the time, and there are lots of Dave Smith’s out there.
On a rough and ready basis, it's perhaps worth noting that EU GDPR came in in 2018, and (as I understand it) became UK GDPR with few changes at the start of 2021. I would have thought that if there was a viable challenge to databeing held for the prevention of crime, we'd have seen it by now.

Or maybe things are moving slower than I expect.

(Edit typo: thins > things)
 
Last edited:

saismee

Established Member
Joined
20 Oct 2023
Messages
1,747
Location
UK
I'd be very surprised if a court supported a defence that went along the lines of "they can't prosecute me because I didn't give permission for them to prosecute me".
The TOC/prosecutor wouldn't even bring a case to court that relies on this data. They just use it to find trends and catch people in the act, where they then get hard evidence to prosecute.

The likes of threatening emails and out of court settlements do seem to fall closer to extortion than crime prevention in my eyes, though.
 

35B

Established Member
Joined
19 Dec 2011
Messages
5,552
The TOC/prosecutor wouldn't even bring a case to court that relies on this data. They just use it to find trends and catch people in the act, where they then get hard evidence to prosecute.

The likes of threatening emails and out of court settlements do seem to fall closer to extortion than crime prevention in my eyes, though.
I don't think that view of the use of out of court settlements against a backdrop of criminal prosecution is especially controversial here.
 

concerned1

Member
Joined
18 Mar 2012
Messages
40
I don't think that view of the use of out of court settlements against a backdrop of criminal prosecution is especially controversial here.
Well, it arguably gives people the opportunity to avoid a criminal record by paying a fine.

I’m sure some people on here would agree that it is more of a deterrent than a few hundred quid to your average white collar fare dodger. I’m thinking of the infamous Mr Stonegate here
 

The exile

Established Member
Joined
31 Mar 2010
Messages
9,455
Location
Somerset
The TOC retaining the details of people who have previously been issued a Penalty Fare or who have been the subject of a Travel Irregularity Report would be a legitimate interest, in my opinion.
Indeed - to distinguish between genuine mistakes (which is what they are there for) and people who coincidentally make the same "mistake" on the same day every week.
 
Status
Not open for further replies.

Top