Haywain
Veteran Member
- Joined
- 3 Feb 2013
- Messages
- 24,526
And the footage wouldn't have been held by TfL.There's an exemption for journalism.
And the footage wouldn't have been held by TfL.There's an exemption for journalism.
There is also an exemption for criminal investigations tooThere's an exemption for journalism.
I'm all for it, personally.
I'm just setting out what the factual position is.
If I look at the use of my data, or data about me, holistically across all aspects of my life, I think I could have a substantially better quality of life if more data was known about me and used in new, innovative ways, that I likely can't even imagine. AI is developing so quickly, and it's now become mainstream, with most smart devices from 2023/2024 having it embedded in the operating system. In a couple more years, it will be doing things our minds can't comprehend at the moment.
Whilst there are risks when it goes wrong, most of them result in simple, minor inconveniences, rather than anything that can't be unpicked and resolved. I mitigate against these risks with basic things like a VPN on unusual networks, disposable emails for certain services etc.
I realise this couldn't happen at present, but if it could get away with it I wonder if the industry would resist the temptation of charging fares based on their perception of how much someone would be willing to pay for their ticket?
TfL also talk about using wi-fi device data to provide a more detailed picture of flows through stations and across their network, which they can’t get by tracking journeys by looking at raw scan data. I’ve noticed this on the tube map somewhere before, maybe on Elizabeth line services or stations, with small print saying that opting out means disabling WiFi on your device. Likely not entirely adequate as many devices background scan even with WiFi off for locating the user.Customers connecting to TOC or TfL WiFi networks on board trains and at stations are a case in point.
This is an awful example of a way to treat someone and underscores my concerns about giving more data than is necessary without effective safeguards in place. It also demonstrates that people employed to assess the reliability of data need to bothThey caught him at canary wharf complete with cameras from fare dodgers at war with the law camera crew… It later turned out he had a paper season ticket from I think manor park which covered him for the romford part of the journey
…a platitude apology was given… it was a pretty disgraceful way to treat someone and the prosecutions department didn't see anything wrong with the way that he was treated.
Arent E tickets only an interim solution on Northern until they role out Moscow metros Face Pay as you go system across their network?That would appear to be from Avanti's privacy policy, so sadly not subject to an FOI.
Indeed, I made such a request to Northern (whom are both retailer of my most used ticket and scanner of same ticket) and they were adamant that they weren't using the scan data for anything and nor could they link it back to anyone anyway. Personally I wasn't entirely convinced but wasn't able to summon the wherewithal to escalate the matter to the ICO. Perhaps I should make a fresh request...

We're not too far off that. It's available now from mainstream suppliers. I was looking at a new gate design in a factory that had overhead biometric sensors installed and worked seamlessly, even trying to trick it with various disguises, sunglasses, hats etc.Arent E tickets only an interim solution on Northern until they role out Moscow metros Face Pay as you go system across their network?![]()
This reminds me of the last time I travelled to the US. As a returning visitor under the Visa Waiver Program (an “alien”, as they like to call us), I used the US citizens’ immigration queue, which is permitted at some airports. I approached the desk expecting to be asked for documents etc. Not so. The agent pointed a cheap USB webcam on a tripod at me, of the sort you might have used in the 2000s, and immediately drew up my name and travel history entirely by facial recognition using a likely ancient photo. I also didn’t need any entry/exit stamps. He never looked at my passport or even checked I was travelling with one.We're not too far off that. It's available now from mainstream suppliers. I was looking at a new gate design in a factory that had overhead biometric sensors installed and worked seamlessly, even trying to trick it with various disguises, sunglasses, hats etc.
The UK e-gates have two modes, depending on how short staffed the Border Force are. In normal circumstances, there's not really any automation at all, and it's someone in a control room doing it all, albeit the gates recommend what the officer should do, to speed things up.This reminds me of the last time I travelled to the US. As a returning visitor under the Visa Waiver Program (an “alien”, as they like to call us), I used the US citizens’ immigration queue, which is permitted at some airports. I approached the desk expecting to be asked for documents etc. Not so. The agent pointed a cheap USB webcam on a tripod at me, of the sort you might have used in the 2000s, and immediately drew up my name and travel history entirely by facial recognition using a likely ancient photo. I also didn’t need any entry/exit stamps. He never looked at my passport or even checked I was travelling with one.
But what staggered me was the comparison between this and the e-gates we see at British airports, which have an array of cameras and lights, a very slow rate for actually passing people through them, and still seem to reject me every few times. Granted, our gates are making an automated decision by machine, whereas in the US a human was still in the loop to sanity check the decision the machine was making. Still, it was pretty unexpected.
I do exactly that regularly. In my case it's using an Over-60s Oyster card to the full extent of it's validity and then a pre-purchased paper ticket for the remainder of the journey. It means that l don't need to exit the train.Quite.
As somebody who quite regularly touches in on a Travelcard but doesn't touch out, because I also have another ticket that I bought from somebody else and am making a non-stop split, it's not a massive stretch of the imagination that this is going to be flagged by whoever sold me the Travelcard. I'm not even convinced everyone at the top of the industry has much interest in the important (to me) distinction between not overpaying on the one hand, and fare evasion on the other. Will a school of thought develop that if you're using a ticket in a way that gets flagged because not many people use it that way, you're the one being awkward?
I wonder how well the massive growth in cosmetic surgery interfaces with that....This reminds me of the last time I travelled to the US. As a returning visitor under the Visa Waiver Program (an “alien”, as they like to call us), I used the US citizens’ immigration queue, which is permitted at some airports. I approached the desk expecting to be asked for documents etc. Not so. The agent pointed a cheap USB webcam on a tripod at me, of the sort you might have used in the 2000s, and immediately drew up my name and travel history entirely by facial recognition using a likely ancient photo. I also didn’t need any entry/exit stamps. He never looked at my passport or even checked I was travelling with one.
But what staggered me was the comparison between this and the e-gates we see at British airports, which have an array of cameras and lights, a very slow rate for actually passing people through them, and still seem to reject me every few times. Granted, our gates are making an automated decision by machine, whereas in the US a human was still in the loop to sanity check the decision the machine was making. Still, it was pretty unexpected.
Having spent my whole career working with National Security/law enforcement (including Border Force) that's a "hell no" from me! I know what can already be done.The UK e-gates have two modes, depending on how short staffed the Border Force are. In normal circumstances, there's not really any automation at all, and it's someone in a control room doing it all, albeit the gates recommend what the officer should do, to speed things up.
The other mode is full automation - but this can be too strict as it is simple black/white logic, anything remotely grey and you're kicked to a manned immigration officer.
When I travel on Eurostar, there's now a dedicated premium lane for staff / business class travel (albeit it does work for anyone who's registered) whereby you check in online, and upload a photograph and your travel document. At St. Pancras, you just walk through the corridor and no need to use the gates or have your exit data captured/documents examined. Facial recognition sorts it all.
I don't think we are too far off seeing passengers volunteer for trials with faces connected to credit/debit cards or seasons, but there will be considerable opposition from certain pockets of society, and will need a TOC who is prepared to stick their neck out on the line from a data protection perspective.
It should be noted that this is possible because (1) the US has photos on file of all previous visitors, and (2) they know from API who's coming today, so there's a pretty short number of entries to be searched on the database.This reminds me of the last time I travelled to the US. As a returning visitor under the Visa Waiver Program (an “alien”, as they like to call us), I used the US citizens’ immigration queue, which is permitted at some airports. I approached the desk expecting to be asked for documents etc. Not so. The agent pointed a cheap USB webcam on a tripod at me, of the sort you might have used in the 2000s, and immediately drew up my name and travel history entirely by facial recognition using a likely ancient photo. I also didn’t need any entry/exit stamps. He never looked at my passport or even checked I was travelling with one.
What has this got to do with GDPR and how is it a "major faux pas"? Social media is in the public domain.Planning Manager of TOC A, desperate to prove who owned a (pseudonym) facebook profile, scrolled through seventeen months of family photographs to find what he thought was conclusive proof of ownership, an employee of TOC B. Aside the legality, TOC A's social media policy didn't apply to TOC B's employees, regardless of the parent company.
It is. But for a business to dig through that data, contact another business, transfer that data to them and demand they discipline their employee surely requires consent of the employee to both use and transfer that data. As abhorrent as the religious / political views of the employee may have been, on principle - if they weren't committing any criminal offence, it's really none of the TOCs business. Employment tribunals have made clear judgements reflecting misuse of (TOC) employee social media data, however it seems the captain doesn't learn enjoys hitting the same iceberg.Social media is in the public domain.
The data (are words and photos really 'data'?) is in the public domain and has presumably been placed there by, or with the implied consent of, the employee. In being there they must accept the risk that it will be seen by their employer and that they will have to bear the consequences if they breach their employer's social media or other policies.consent of the employee to both use and transfer that data.
The data (are words and photos really 'data'?) is in the public domain and has presumably been placed there by, or with the implied consent of, the employee. In being there they must accept the risk that it will be seen by their employer and that they will have to bear the consequences if they breach their employer's social media or other policies.
I get that, but if they just sent a URL and said "Have you seen this?" without naming the person it would be fine?If TOC A said to TOC B "Look at this URL, this contains details of <named person>", then that fact would be Personally Identifiable Information under the remit of GDPR whether the actual Facebook profile was public or not. You've got an identifiable person and you've got a fact about them.
Common sense would prevail. But not at a TOC, sadly.I get that, but if they just sent a URL and said "Have you seen this?" without naming the person it would be fine?
I get that, but if they just sent a URL and said "Have you seen this?" without naming the person it would be fine?
This fell apart when TOC B printed off the chain of emails sent from TOC A manager to TOC B HR, to TOC B's staff manager, which included screenshots of the facebook wall. The employee was brought in without notice or the option of organising a rep, however they set their phone to record video and discretely obtained a copy of the two offending A4 pages which clearly named them and identified their location of employment and grade.
The first case at least is legal action waiting to happen....Slightly off subject, I was yesterday asked to have a look a quite ranty email from an HR director of a major TOC. In it, she referred to a former manager from fifteen years ago and some employment details of that person, which when checked were accurate. The manager was not from the current TOC, or the one before, but the one before that - ie they left three TOCs ago. The HR director joined the firm long after the manager left, so I wonder where she obtained the employment record from.
When writing investigative reports, lets pretend for a safety of the line incident, I was always told that after six months, if the report is to be retained for legitimate reasons, you must anonymise - remove & replace the subject's name (eg, Mr Smith becomes Mr A). I understand that for journalism, criminal investigation etc there are certain exemptions on GDPR, but for Human Resources issues, unless someone has burnt the building down you'd assume the law would be strictest when concerning the relationship between employer and employee.
I've witnessed some major faux pas at Train Operating Companies with GDPR:
- HR manager of one TOC didn't want to print a string of 32 letters so emailed them to candidates. All 32 letters - sent to every job applicant, internal and external. She sent employee names and home addresses to members of the public. When questioned she made it sound like the candidates were to blame.
- Planning Manager of TOC A, desperate to prove who owned a (pseudonym) facebook profile, scrolled through seventeen months of family photographs to find what he thought was conclusive proof of ownership, an employee of TOC B. Aside the legality, TOC A's social media policy didn't apply to TOC B's employees, regardless of the parent company.
This may have been your employer's policy or process, but is not a requirement that is to be found anywhere in legislation.When writing investigative reports, lets pretend for a safety of the line incident, I was always told that after six months, if the report is to be retained for legitimate reasons, you must anonymise - remove & replace the subject's name (eg, Mr Smith becomes Mr A)