• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Requesting GDPR Right to be Forgotten from a TOC

Status
Not open for further replies.

gray1404

Established Member
Joined
3 Mar 2014
Messages
7,616
Location
Merseyside
There was recently a thread where somebody's name and address has been falsely provided to LNER and they requested that the innocent person sent them a copy of their ID before the case was closed as far as the involvement of our poster here was concerned. This is very sensitive data so it made me wonder would they now be able to request the right to be forgotten under GDPR. I personally would not want an organisation holding onto a copy of my passport moreover when I'd provided it under such circumstances in the hope of avoiding court action.
 
Last edited:
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

Cowley

Forum Staff
Staff Member
Global Moderator
Joined
15 Apr 2016
Messages
18,901
Location
Devon
Just to add to the above. This was the thread referenced by @gray1404
 

Dai Corner

Established Member
Joined
20 Jul 2015
Messages
6,990
There was recently a thread where somebody's name and address has been falsely provided to LNER and they requested that the innocent person sent them a copy of their ID before the case was closed as far as the involvement of our poster here was concerned. This is very sensitive data so it made me wonder would they now be able to request the right to be forgotten under GDPR. I personally would not want an organisation holding onto a copy of my passport moreover when I'd provided it under such circumstances in the hope of avoiding court action.
I think the rules forbid the retention of personal data for longer than necessary or for purposes other than those for which it was collected. In this case it should be destroyed on closure of the case.
 

silexa

Member
Joined
26 Jan 2022
Messages
110
Location
East Midlands
It should be destroyed on closure of the case, but it might be worth that the original poster make sure of this. I'd personally be concerned knowing they might be storing it
 

Surreytraveller

On Moderation
Joined
21 Oct 2009
Messages
3,905
There was recently a thread where somebody's name and address has been falsely provided to LNER and they requested that the innocent person sent them a copy of their ID before the case was closed as far as the involvement of our poster here was concerned. This is very sensitive data so it made me wonder would they now be able to request the right to be forgotten under GDPR. I personally would not want an organisation holding onto a copy of my passport moreover when I'd provided it under such circumstances in the hope of avoiding court action.
Its not sensitive data as defined under DPA 2018. Sensitive data would be medical, and certain other categories.

== Doublepost prevention - post automatically merged: ==

It should be destroyed on closure of the case, but it might be worth that the original poster make sure of this. I'd personally be concerned knowing they might be storing it
But it could be justified to store it to use as evidence should the same person provide those details in future to avoid payment of fares
 

Haywain

Veteran Member
Joined
3 Feb 2013
Messages
24,609
But it could be justified to store it to use as evidence should the same person provide those details in future to avoid payment of fares
In such circumstances I would have thought the OP of the other thread might prefer that LNER retain some basic information rather than have to go through the same thing again.
 
Joined
26 Aug 2022
Messages
28
Location
Buckingham
GDPR doesn't permit LNER to do so. There is no reason to retain the data after the OP's ID has been established so -
From ICO guidance
"You must not keep personal data for longer than you need it.You should also periodically review the data you hold, and erase or anonymise it when you no longer need it."
 

AlterEgo

Verified Rep - Wingin' It! Paul Lucas
Joined
30 Dec 2008
Messages
29,365
Location
LBK
I agree the principle should apply here. “Someone used this innocent real person’s name to evade fares” isn’t a good reason to hold onto their personal data, and the data should be deleted, especially so if requested.
 

andrew749

Member
Joined
25 Oct 2021
Messages
64
Location
Essex
I think it should be retained under the UKGDPR exemption "for the prevention or detection of a crime" - the crime in question being fraud by impersonation.
 

Dai Corner

Established Member
Joined
20 Jul 2015
Messages
6,990
I think it should be retained under the UKGDPR exemption "for the prevention or detection of a crime" - the crime in question being fraud by impersonation.
Are you going to send all the TOCs copies of your passport just in case somebody falsely gives them your details in the future?
 

AlterEgo

Verified Rep - Wingin' It! Paul Lucas
Joined
30 Dec 2008
Messages
29,365
Location
LBK
I think it should be retained under the UKGDPR exemption "for the prevention or detection of a crime" - the crime in question being fraud by impersonation.
How will storing the OP’s name and address prevent any crime?
 

Skymonster

Established Member
Joined
7 Feb 2012
Messages
2,061
If a TOC only needs ID to establish whether someone who is accused matches the description / CCTV of the offender, why not send the passport scan with the passport number, DOB, issue / expiry date and OCR bar redacted?
 

AlterEgo

Verified Rep - Wingin' It! Paul Lucas
Joined
30 Dec 2008
Messages
29,365
Location
LBK
By helping to establish that someone giving those details who is not the OP is committing a crime.
So it doesn't prevent crime then - just "helps to establish whether one has been committed". Just as it was possible to establish one had been committed by LNER contacting the OP in the original thread.

Should the company have everyone in the country's details then, or just the unlucky people who've been the innocent victims of crime?
 

Haywain

Veteran Member
Joined
3 Feb 2013
Messages
24,609
So it doesn't prevent crime then - just "helps to establish whether one has been committed". Just as it was possible to establish one had been committed by LNER contacting the OP in the original thread.
The exemption is for prevention and detection of crime, so it is appropriate in my view.
 

AlterEgo

Verified Rep - Wingin' It! Paul Lucas
Joined
30 Dec 2008
Messages
29,365
Location
LBK
The exemption is for prevention and detection of crime, so it is appropriate in my view.
In your view, how would retaining the victim’s name and address help with that?
 

AlterEgo

Verified Rep - Wingin' It! Paul Lucas
Joined
30 Dec 2008
Messages
29,365
Location
LBK
If you can't figure it out there's no point in me trying to explain it.
No, you say you'd retain the data, so explain how having the OP's name and address in the back office somewhere will help someone in the revenue protection team decide if that was the person stopped, without contacting them.
 

Haywain

Veteran Member
Joined
3 Feb 2013
Messages
24,609
No, you say you'd retain the data, so explain how having the OP's name and address in the back office somewhere will help someone in the revenue protection team decide if that was the person stopped, without contacting them.
OK, so having the OP's name on file could cause a prompt when the check is carried out that it could be false, so CCTV is obtained and potentially BTP are involved. I know nothing about actual revenue protection procedures so don't know if this would actually happen or if the OP's data would actually be retained.
 

SussexSeagull

Member
Joined
13 Aug 2021
Messages
208
Location
Worthing
They can keep the data as long as they like but they have to justify retaining it. On face value I would say it should be destroyed once the case us resolved unless they have a reason none of us can think of.

Would certainly request it deleted upon resolution and see what they have to say.
 

madjack

Member
Joined
27 Jul 2012
Messages
83
Location
Ealing, London
It took me 3 seconds on google to find that LNER do have a clear and what looks to me to be a compliant privacy policy, including the right to be forgotten and a reminder that anyone can complain to the Information Commissioner's Office (ICO). From my previous career I can confirm that the ICO does have teeth. We don't know what ID the original poster sent in but I would expect no justification for keeping e.g. a copy of their passport and I would not expect LNER to actually be interested in keeping it. This all sounds like a straw man to me.

I think the likely scenario is given in posts 4 and 23, i.e. that once the case is closed the accompanying paperwork will be destroyed.
 

Fawkes Cat

Established Member
Joined
8 May 2017
Messages
5,278
I'm not doubting anyone's view of the law here, but what mischief by LNER are we anticipating if the data is retained? And - even if retained - is there a realistic chance of this mischief occurring?
 

Dai Corner

Established Member
Joined
20 Jul 2015
Messages
6,990
I'm not doubting anyone's view of the law here, but what mischief by LNER are we anticipating if the data is retained? And - even if retained - is there a realistic chance of this mischief occurring?
For example, a dishonest person with access to the data could steal and misuse it.
 

AlterEgo

Verified Rep - Wingin' It! Paul Lucas
Joined
30 Dec 2008
Messages
29,365
Location
LBK
I'm not doubting anyone's view of the law here, but what mischief by LNER are we anticipating if the data is retained? And - even if retained - is there a realistic chance of this mischief occurring?
The likelihood of mischief is very small but that notwithstanding, there is the right to have the data deleted.
 
Status
Not open for further replies.

Top