• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

TOCs and Data Protection/Rights

Status
Not open for further replies.

Tazi Hupefi

On Moderation
Joined
1 Apr 2018
Messages
1,838
Location
Nottinghamshire
Mod Note: Posts #1 - #17 originally in this thread.

The concern is about TOC prosecution departments going on a fishing trip. A CCST bought in cash leaves no easy accessible record to the train company, buying e-tickets from Trainline gives them easy access to all your purchases as well as your name and address. TOCs won't have access to phone signal data and banking history, and are unlikely to go looking through CCTV when there is so much low hanging fruit.

If you're trying to hide your travel history from MI5, good luck even with paper tickets and cash.
TOCs do have access to far more data than you think.

Customers connecting to TOC or TfL WiFi networks on board trains and at stations are a case in point.

If you connect to a WiFi Network on a train, some TOCs check the email address and other meta data like Device ID to try to reconcile that against bookings made with them directly, so that they know who to market to when it appears the customer has potentially booked elsewhere. It is also used for some fraud prevention purposes as it can provide an indication of who was on a particular service at a particular time, even down to what carriage.

Huge amounts of mobile phone data is also purchased by most TOCs, as well as the DfT and similar organisations, but this is sold as irreversibly disguised so it isn't possible to use for fraud prevention, prosecutions etc. However, it is possible for a TOC to see how a unique subscriber ID travels across the network, how frequent etc, along with high level information about the device, e.g. iOS, Android etc. They just can't reverse engineer who that subscriber is. It's mainly used to model footfall, heat maps, and plays a particularly important role in assessing the value of commercial retail units at stations. TfL do something similar to monitor overcrowding.

You might think that mobile networks make their money from selling phones and data plans - I suspect a not insignificant, and increasingly important amount is actually derived from the data they have on how they're used.
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

signed

Established Member
Joined
13 May 2024
Messages
2,374
Location
ROI
Customers connecting to TOC or TfL WiFi networks on board trains and at stations are a case in point.
Which, unless you give the information yourself has only access to the MAC (hardware network address) which is nowadays generated on the fly and random per network so irrelevant for identification. Some devices even generate a new MAC address at every connexion to a network.
 

crablab

Established Member
Joined
8 Feb 2020
Messages
1,292
Location
UK
These days, we all have a huge digital footprint whether it be shopping in a supermarket, attending a sporting event, using public transport, or eben visiting a National Trust property!
TOCs do have access to far more data than you think.
...which is why it's not 'paranoid' for people to care about their privacy and what data is being collected, and how's it being used.

Friends who visit from Europe are amazed at how 'in your face' some of this is; with CCTV everywhere and signs telling you what you must or must not do, repeated announcements about reporting things to the police... It's quite a culture shock for them.
 

Tazi Hupefi

On Moderation
Joined
1 Apr 2018
Messages
1,838
Location
Nottinghamshire
Which, unless you give the information yourself has only access to the MAC (hardware network address) which is nowadays generated on the fly and random per network so irrelevant for identification. Some devices even generate a new MAC address at every connexion to a network.
MAC address isn't widely used. There's far better ways of creating a unique device ID or fingerprint these days.

Just visiting a mobile browser WiFi landing page in itself reveals a significant amount of data about your device, often with enough data points to make it unique, or as close to unique as you need it to be.
 

crablab

Established Member
Joined
8 Feb 2020
Messages
1,292
Location
UK
The issue I have from a railway point of view is where the data is stored, what it might be used for, who has access to it and for how long is it stored for.
Indeed and, as @Bletchleyite mentioned, whether the passenger gets to see any of this. Some people have submitted SARs (Subject Access Request) to get scan data before - I believe it was a little fraught.

If the TOCs are going to keep their corpus of scan history so they can data mine it for revenue protection, there needs to be more public assurances about how long it's being kept, who has access, how that's audited etc.

You can imagine how useful some of this data would be to nefarious persons.
 

Tazi Hupefi

On Moderation
Joined
1 Apr 2018
Messages
1,838
Location
Nottinghamshire
...which is why it's not 'paranoid' for people to care about their privacy and what data is being collected, and how's it being used.

Friends who visit from Europe are amazed at how 'in your face' some of this is; with CCTV everywhere and signs telling you what you must or must not do, repeated announcements about reporting things to the police... It's quite a culture shock for them.
The only difference in most other countries is that it is often hidden or less obvious. At least you know you're being watched in the UK.

It's still paranoid behaviour because it implies there's a fear of it being used for nefarious purposes, when the reality is that most of the data points like that are used to try to improve our lives in some way, e.g. personalisation, or for commercial purposes like marketing, which whilst annoying occasionally, is benign.
 

crablab

Established Member
Joined
8 Feb 2020
Messages
1,292
Location
UK
Just visiting a mobile browser WiFi landing page in itself reveals a significant amount of data about your device, often with enough data points to make it unique, or as close to unique as you need it to be
Yeah, unfortunately a combination of device and browser traits can make 'you' very identifiable and reliably trackable across sessions, even with cookies disabled etc.

Have a look at https://coveryourtracks.eff.org to understand more about how this works.

== Doublepost prevention - post automatically merged: ==

It's still paranoid behaviour because it implies there's a fear of it being used for nefarious purposes
I guess I'm "paranoid" because I don't like Meta knowing who my friends are and selling a list of things I'm interested in to advertisers. And because I'd rather Google didn't use the contents of my inbox & personal photo collection for their training models.

I don't think they're going to use it for anything "nefarious" - the NSA already has a copy stored away for when they can get quantum computers good enough to break RSA & ECDH.

I just don't see why I need to sell my identity to them, so I don't.
 
Last edited:

miklcct

Established Member
Joined
2 May 2021
Messages
5,017
Location
Cricklewood
Yeah, unfortunately a combination of device and browser traits can make 'you' very identifiable and reliably trackable across sessions, even with cookies disabled etc.

Have a look at https://coveryourtracks.eff.org to understand more about how this works.
I have tested and, to my surprise, the language list contains the most information in my browser fingerprint, followed by screen size.
 

Bletchleyite

Veteran Member
Joined
20 Oct 2014
Messages
113,062
Location
"Marston Vale mafia"
If you connect to a WiFi Network on a train, some TOCs check the email address and other meta data like Device ID to try to reconcile that against bookings made with them directly, so that they know who to market to when it appears the customer has potentially booked elsewhere.

That would appear to be a GDPR breach unless one has consented to marketing use (marketing use is permitted under GDPR only under the basis of consent, which cannot be assumed). If I found evidence of that occurring I would be reporting it to the Information Commissioner's Office.
 

OscarH

Established Member
Joined
15 Sep 2020
Messages
1,262
Location
Crawley
when the reality is that most of the data points like that are used to try to improve our lives in some way, e.g. personalisation, or for commercial purposes like marketing, which whilst annoying occasionally, is benign
I'm very unconvinced that marketing is benign

But I think many people would say I'm paranoid generally, so perhaps not a useful data point :D
 

Tazi Hupefi

On Moderation
Joined
1 Apr 2018
Messages
1,838
Location
Nottinghamshire
That would appear to be a GDPR breach unless one has consented to marketing use (marketing use is permitted under GDPR only under the basis of consent, which cannot be assumed). If I found evidence of that occurring I would be reporting it to the Information Commissioner's Office.
Taking a random TOC (deliberately not naming or singling one out).
Automated technologies or interactions:

If you use our Website or Wi-Fi network, we automatically collect the following information:

Website

• web usage information (e.g. IP address), your login information, browser type and version, time zone setting, operating system and platform; and

• information about your visit, including the full Uniform Resource Locators (URLs) clickstream to, through and from our Website (including date and time); time on page, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks and mouse-overs).

Wi-Fi

• Session data to understand your geographical location when you started and stopped using the Wi-Fi. If you use our on-board Wi-Fi, this data will also include which service you were on and in which class (e.g. First/Standard Premium or standard) and how frequently you use the Wi-Fi by date and time.
Invitations to provide marketing preferences through the log-in process if your device and account information is not recognised by our systems. For more information on marketing messages and advertising please refer to section 6.
They go on to say that the basis is legitimate interest.
Where we collect information about you in the ways described above, we do so on the basis that it is in our legitimate interests to collect and process this data.
 

redreni

Established Member
Joined
24 Sep 2010
Messages
2,670
Location
Slade Green
I'm very unconvinced that marketing is benign

But I think many people would say I'm paranoid generally, so perhaps not a useful data point :D
I don't think many people think marketing is benign, do they?

I've always thought it ranked alongside tax inspector as one of those occupations one daren't admit to being in at social occasions?
 

crablab

Established Member
Joined
8 Feb 2020
Messages
1,292
Location
UK
They go on to say that the basis is legitimate interest.
That isn't the 'get out of jail free' they presumably believe it is...

Perhaps someone should FOI them (assuming it's a OLR TOC) for their legitimate interests assessment.
 

Starmill

Veteran Member
Joined
18 May 2012
Messages
27,189
Location
Bolton
Unless you're engaged in some form of fare evasion, or give the TOC reason to suspect you of such, this really isn't something I can see being an issue.
Unfortunately this is quite an idealistic approach.
 

Bletchleyite

Veteran Member
Joined
20 Oct 2014
Messages
113,062
Location
"Marston Vale mafia"
Taking a random TOC (deliberately not naming or singling one out).

They go on to say that the basis is legitimate interest.

Legitimate interest is not a basis under which data can legally be collected for marketing purposes or used for marketing. Marketing can exclusively be carried out under the "consent" basis.

They may have other purposes for the data which is acceptable under legitimate interest, such as monitoring the use of the wifi itself, such as for the purposes of crime prevention. However, data collected for one purpose cannot just be transferred to use for another, particularly not where that requires a different basis.

If a TOC is actually doing what you suggested where the passenger did not explicitly opt in to marketing contact, they are potentially going to be at the thick end of some legal cases.
 

Starmill

Veteran Member
Joined
18 May 2012
Messages
27,189
Location
Bolton
That isn't the 'get out of jail free' they presumably believe it is...

Perhaps someone should FOI them (assuming it's a OLR TOC) for their legitimate interests assessment.
Hard to see a legitimate interest if the customer hasn't used the retail channels that TOC controls, and just happens to have an account with them and logs into their WiFi, but paid for their ticket at a machine at the station run by another company. Unless I'm misreading that privacy policy.

Perhaps a new thread to dig into a few privacy policies would help?
 

Tazi Hupefi

On Moderation
Joined
1 Apr 2018
Messages
1,838
Location
Nottinghamshire
Legitimate interest is not a basis under which data can legally be collected for marketing purposes or used for marketing. Marketing can exclusively be carried out under the "consent" basis.

They may have other purposes for the data which is acceptable under legitimate interest, such as monitoring the use of the wifi itself, such as for the purposes of crime prevention. However, data collected for one purpose cannot just be transferred to use for another, particularly not where that requires a different basis.

If a TOC is actually doing what you suggested where the passenger did not explicitly opt in to marketing contact, they are potentially going to be at the thick end of some legal cases.
You can rely on legitimate interest for marketing activities if you can show that how you use people's data is proportionate, has a minimal privacy impact, and people would not be surprised or likely to object.

What the ICO is clear about is that you should avoid using legitimate interest if you're using personal data in ways that people don't understand and would not reasonably expect, or if you think people would object if you explained it to them.

The GDPR (Recital 47) says, “the processing of Personal Data for direct marketing purposes may be regarded as carried out for a legitimate interest.” An organisation may wish to rely upon legitimate interest where consent is not viable or not preferred and the relevant balance of interest condition can be met.

(Agree, new thread!)
 

ainsworth74

Forum Staff
Staff Member
Global Moderator
Joined
16 Nov 2009
Messages
31,069
Location
Redcar
Taking a random TOC (deliberately not naming or singling one out).


They go on to say that the basis is legitimate interest.
That would appear to be from Avanti's privacy policy, so sadly not subject to an FOI.
Indeed and, as @Bletchleyite mentioned, whether the passenger gets to see any of this. Some people have submitted SARs (Subject Access Request) to get scan data before - I believe it was a little fraught.

Indeed, I made such a request to Northern (whom are both retailer of my most used ticket and scanner of same ticket) and they were adamant that they weren't using the scan data for anything and nor could they link it back to anyone anyway. Personally I wasn't entirely convinced but wasn't able to summon the wherewithal to escalate the matter to the ICO. Perhaps I should make a fresh request...
 

Tazi Hupefi

On Moderation
Joined
1 Apr 2018
Messages
1,838
Location
Nottinghamshire
That would appear to be from Avanti's privacy policy, so sadly not subject to an FOI.


Indeed, I made such a request to Northern (whom are both retailer of my most used ticket and scanner of same ticket) and they were adamant that they weren't using the scan data for anything and nor could they link it back to anyone anyway. Personally I wasn't entirely convinced but wasn't able to summon the wherewithal to escalate the matter to the ICO. Perhaps I should make a fresh request...
I'm assuming they didn't quite say that they weren't using it for anything.

I suspect they're probably saying they don't believe they are using any of your personal data - as clearly they do analysis of barcode tickets for both staff performance/commission purposes as well as proactive fraud detection, prevention and investigation / prosecution.

The mindset is probably that that sort of information doesn't have any of the typical personal information, name, address, DOB etc - and they'd only reconcile the barcode ticket with that richer dataset from the retailer (or that other part of the business if internal) if they had a lawful reason to do so. So not automatically joined/linked.

I suspect they have an interpretation that the eTVD records and ticket payload itself (so UTN, origin, destination , price etc) doesn't necessarily automatically equate to it being personally identifiable information - not by itself anyway. So in their view they are doing things with this data, but not your data.

There's a number of counter points you can make to challenge that, but I suspect is what the thinking is.
 

island

Veteran Member
Joined
30 Dec 2010
Messages
17,907
Location
0036
That would appear to be a GDPR breach unless one has consented to marketing use (marketing use is permitted under GDPR only under the basis of consent, which cannot be assumed).
That's not correct.

GDPR permits marketing activities to occur under the legitimate interests lawful basis as well as the consent lawful basis. The data subject has an absolute right to object.

You may be thinking of UK domestic law, the Privacy and Electronic Communications Regulations (PECR), which has a stronger opt-in requirement for marketing, but only by email, text message, and automated call.

Marketing by other channels, such as web advertisement, app push notification, live phone calls, letter in the post, following you around on social media etc. is not covered under PECR.

The relevant disclosures would need to be made in the data controller's privacy statement, and a data protection impact assessment and legitimate interest assessment would likely need to be made and followed.
 

AdamWW

Established Member
Joined
6 Nov 2012
Messages
5,902
Unless you're engaged in some form of fare evasion, or give the TOC reason to suspect you of such, this really isn't something I can see being an issue.

Ah. If you haven't done anything wrong, you've nothing to hide?

Any attempt to trawl through data looking for suspicious patterns is inevitably going to generate false positives.

Now, depending on how they go about things, it might be reasonable for a TOC to investigate people who turn out to have done nothing wrong.

Buit even if we assume that in every case of a false positive the victim will be able to sccessfully defend themselves, it doesn't mean that the stress and time involved in doing so isn't an issue for them.
 

ainsworth74

Forum Staff
Staff Member
Global Moderator
Joined
16 Nov 2009
Messages
31,069
Location
Redcar
I'm assuming they didn't quite say that they weren't using it for anything.
Yes to be fair it was in the context of my personal data they were referring to rather than it being absolutely nothing at all.
 

redreni

Established Member
Joined
24 Sep 2010
Messages
2,670
Location
Slade Green
Ah. If you haven't done anything wrong, you've nothing to hide?

Any attempt to trawl through data looking for suspicious patterns is inevitably going to generate false positives.

Now, depending on how they go about things, it might be reasonable for a TOC to investigate people who turn out to have done nothing wrong.

Buit even if we assume that in every case of a false positive the victim will be able to sccessfully defend themselves, it doesn't mean that the stress and time involved in doing so isn't an issue for them.
Quite.

As somebody who quite regularly touches in on a Travelcard but doesn't touch out, because I also have another ticket that I bought from somebody else and am making a non-stop split, it's not a massive stretch of the imagination that this is going to be flagged by whoever sold me the Travelcard. I'm not even convinced everyone at the top of the industry has much interest in the important (to me) distinction between not overpaying on the one hand, and fare evasion on the other. Will a school of thought develop that if you're using a ticket in a way that gets flagged because not many people use it that way, you're the one being awkward?
 

125Spotter

Member
Joined
7 Aug 2022
Messages
113
Location
South West
Ah. If you haven't done anything wrong, you've nothing to hide?

Any attempt to trawl through data looking for suspicious patterns is inevitably going to generate false positives.

Now, depending on how they go about things, it might be reasonable for a TOC to investigate people who turn out to have done nothing wrong.

Buit even if we assume that in every case of a false positive the victim will be able to sccessfully defend themselves, it doesn't mean that the stress and time involved in doing so isn't an issue for them.
Similar arguments can be made about dragnet surveillance.

I have no real issue with the police or other authorities having information about me that they've put the legwork in to collect. I trust the system in most cases to protect us with due process (in the UK, anyway), although miscarriages of justice do sadly occur.

The problem comes when digital methods provide easier ways to blanket collect data, followed by someone smart deciding to earn a ton of money using some 'AI' to audit it to find interesting trends. These methods intrinsically have less overhead and that creates moral hazards on both sides before even considering what is done with it. We're not limited by the availability of staff, or budgets to pay them, to hoover up data digitally and search it. Combine this with the railway having private prosecution powers and all the ways these are often misused by those who don't understand the labyrinthine ticketing system, I believe this isn't in my interest.

And there is, of course, also the problem that with a bigger haystack the needles are far harder to find.
 

Sonic1234

Member
Joined
25 Apr 2021
Messages
791
Location
Croydon
Buit even if we assume that in every case of a false positive the victim will be able to sccessfully defend themselves, it doesn't mean that the stress and time involved in doing so isn't an issue for them.
And the image/customer relations issue - that customer is never coming back to the railway and their story will scare off a few more.
 

TUC

Established Member
Joined
11 Nov 2010
Messages
5,031
Mod Note: Posts #1 - #17 originally in this thread.


TOCs do have access to far more data than you think.

Customers connecting to TOC or TfL WiFi networks on board trains and at stations are a case in point.

If you connect to a WiFi Network on a train, some TOCs check the email address and other meta data like Device ID to try to reconcile that against bookings made with them directly, so that they know who to market to when it appears the customer has potentially booked elsewhere. It is also used for some fraud prevention purposes as it can provide an indication of who was on a particular service at a particular time, even down to what carriage.

Huge amounts of mobile phone data is also purchased by most TOCs, as well as the DfT and similar organisations, but this is sold as irreversibly disguised so it isn't possible to use for fraud prevention, prosecutions etc. However, it is possible for a TOC to see how a unique subscriber ID travels across the network, how frequent etc, along with high level information about the device, e.g. iOS, Android etc. They just can't reverse engineer who that subscriber is. It's mainly used to model footfall, heat maps, and plays a particularly important role in assessing the value of commercial retail units at stations. TfL do something similar to monitor overcrowding.

You might think that mobile networks make their money from selling phones and data plans - I suspect a not insignificant, and increasingly important amount is actually derived from the data they have on how they're used.
Do I care? If this means I get offers that are well targeted at me so much the better. I have no reason to keep secret where I'm travelling to. Do you?
 

Bletchleyite

Veteran Member
Joined
20 Oct 2014
Messages
113,062
Location
"Marston Vale mafia"
Do I care? If this means I get offers that are well targeted at me so much the better. I have no reason to keep secret where I'm travelling to. Do you?

In my experience I get targetted with offers on something I've already bought...most recently (a vacuum cleaner), something I hope not to need to buy again for at least ten years, so it's not like throwing up an advert for Coke might make me want one now rather than the one I had yesterday.
 

Tazi Hupefi

On Moderation
Joined
1 Apr 2018
Messages
1,838
Location
Nottinghamshire
Do I care? If this means I get offers that are well targeted at me so much the better. I have no reason to keep secret where I'm travelling to. Do you?
I'm all for it, personally.

I'm just setting out what the factual position is.

If I look at the use of my data, or data about me, holistically across all aspects of my life, I think I could have a substantially better quality of life if more data was known about me and used in new, innovative ways, that I likely can't even imagine. AI is developing so quickly, and it's now become mainstream, with most smart devices from 2023/2024 having it embedded in the operating system. In a couple more years, it will be doing things our minds can't comprehend at the moment.

Whilst there are risks when it goes wrong, most of them result in simple, minor inconveniences, rather than anything that can't be unpicked and resolved. I mitigate against these risks with basic things like a VPN on unusual networks, disposable emails for certain services etc.
 
Last edited:

matt_world2004

Established Member
Joined
5 Nov 2014
Messages
4,581
Quite.

As somebody who quite regularly touches in on a Travelcard but doesn't touch out, because I also have another ticket that I bought from somebody else and am making a non-stop split, it's not a massive stretch of the imagination that this is going to be flagged by whoever sold me the Travelcard. I'm not even convinced everyone at the top of the industry has much interest in the important (to me) distinction between not overpaying on the one hand, and fare evasion on the other. Will a school of thought develop that if you're using a ticket in a way that gets flagged because not many people use it that way, you're the one being awkward?
There was one incident I know of anecdotally where someone was touching out at canary wharf with an zone 2-3 travelcard . But not in TfL got data that showed he lived somewhere in the romford area and believed he was short faring . (Bus touch in?)

They caught him at canary wharf complete with cameras from fare dodgers at war with the law camera crew, he became quite flustered and stressed at being accused of being a fare dodger on national television and couldn't articulate properly, and the ticket inspectors let's say hyped up the situation for television . It later turned out he had a paper season ticket from I think manor park which covered him for the romford part of the journey

Anyway he makes a complaint about the way he is treated . The presence of camera crew (I think he tried to make a subject access request for footage) there was some back and forth between the prosecutions department about the customer services department . With internal emails blaming the customer for having "poor touching in hygene" a platitude apology was given but he didn't get access to the footage and the footage was never shown on television . It was a pretty disgraceful way to treat someone and the prosecutions department didn't see anything wrong with the way that he was treated.

I forget what the excuse was provided for why he couldn't get access to the camera footage . But it was something as stupid as the prosecutions department claiming that the camera crew were private citizens just filming the encounter and not subject to regulations governing subject access requests
 
Status
Not open for further replies.

Top