• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

TOCs and Data Protection/Rights

Status
Not open for further replies.
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

AdamWW

Established Member
Joined
6 Nov 2012
Messages
5,902
I'm all for it, personally.

I'm just setting out what the factual position is.

If I look at the use of my data, or data about me, holistically across all aspects of my life, I think I could have a substantially better quality of life if more data was known about me and used in new, innovative ways, that I likely can't even imagine. AI is developing so quickly, and it's now become mainstream, with most smart devices from 2023/2024 having it embedded in the operating system. In a couple more years, it will be doing things our minds can't comprehend at the moment.

Whilst there are risks when it goes wrong, most of them result in simple, minor inconveniences, rather than anything that can't be unpicked and resolved. I mitigate against these risks with basic things like a VPN on unusual networks, disposable emails for certain services etc.

I do not think that history supports a view that whatever these incomprehendable innovations are, companies will only ever apply them in a benevolent fashion.

I realise this couldn't happen at present, but if it could get away with it I wonder if the industry would resist the temptation of charging fares based on their perception of how much someone would be willing to pay for their ticket?
 

Egg Centric

Established Member
Joined
6 Oct 2018
Messages
2,837
Location
Land of the Prince Bishops
I realise this couldn't happen at present, but if it could get away with it I wonder if the industry would resist the temptation of charging fares based on their perception of how much someone would be willing to pay for their ticket?

Any for profit business would (and should).

I expect the aims after nationalisation to be more about maximising fiefdoms and things. Possibly with occasional short term political objectives. We shall see.

I suppose a public service ethos is possible but not any time in the next decade or two...
 

125Spotter

Member
Joined
7 Aug 2022
Messages
113
Location
South West
Customers connecting to TOC or TfL WiFi networks on board trains and at stations are a case in point.
TfL also talk about using wi-fi device data to provide a more detailed picture of flows through stations and across their network, which they can’t get by tracking journeys by looking at raw scan data. I’ve noticed this on the tube map somewhere before, maybe on Elizabeth line services or stations, with small print saying that opting out means disabling WiFi on your device. Likely not entirely adequate as many devices background scan even with WiFi off for locating the user.

Either way they make a big point that they have designed this process so as to be ‘anonymised’, although that doesn’t mean much if they can still spot trends and correlate the data with other sources (unusual journeys or routings at quiet times of day might easily stand out, for example).

They caught him at canary wharf complete with cameras from fare dodgers at war with the law camera crew… It later turned out he had a paper season ticket from I think manor park which covered him for the romford part of the journey

…a platitude apology was given… it was a pretty disgraceful way to treat someone and the prosecutions department didn't see anything wrong with the way that he was treated.
This is an awful example of a way to treat someone and underscores my concerns about giving more data than is necessary without effective safeguards in place. It also demonstrates that people employed to assess the reliability of data need to both
  1. Understand the pipeline that feeds them the data, and particularly areas where it may be inadequate for the purposes it was originally designed
  2. Think outside the box to consider alternative, rational and plausible explanations for the data they‘re seeing – rather than going in with prejudice and assumptions
It’s easy for (1) to go wrong because people don’t have the experience or tenure to comprehend the limits of the system. And (2) emerges because most humans cannot consider other rational, and perfectly legal, explanations for others’ behaviours where people may differ from them. I expect there are elements of target cultures, and we see all too often the impunity and assumption of wrongdoing on this forum, and we have a perfect storm.

There is a similar trait to the passing of statute, or at least the proper process for doing so when bills are drafted and debated properly. It’s very well for someone to draft and propose a statute that is sufficient to achieve their original objective. It’s far harder to assure that achieves only and precisely that objective, and that it doesn’t interact poorly with other legislation or negatively impact underrepresented groups in society through the making of unintended consequences.

As humans we tend not to be able to consider there are people in very different circumstances to us and that this is okay.
 

paul1609

Established Member
Joined
28 Jan 2006
Messages
7,992
Location
K
That would appear to be from Avanti's privacy policy, so sadly not subject to an FOI.


Indeed, I made such a request to Northern (whom are both retailer of my most used ticket and scanner of same ticket) and they were adamant that they weren't using the scan data for anything and nor could they link it back to anyone anyway. Personally I wasn't entirely convinced but wasn't able to summon the wherewithal to escalate the matter to the ICO. Perhaps I should make a fresh request...
Arent E tickets only an interim solution on Northern until they role out Moscow metros Face Pay as you go system across their network? :)
 

Tazi Hupefi

On Moderation
Joined
1 Apr 2018
Messages
1,838
Location
Nottinghamshire
Arent E tickets only an interim solution on Northern until they role out Moscow metros Face Pay as you go system across their network? :)
We're not too far off that. It's available now from mainstream suppliers. I was looking at a new gate design in a factory that had overhead biometric sensors installed and worked seamlessly, even trying to trick it with various disguises, sunglasses, hats etc.

I believe the other concept of a "gateless gateline" is a genuine aspiration and some trials will appear in the near future. This uses sensors and beacons to identify mobile devices. Chiltern tried something like this with Bluetooth a few years ago, but technology has rapidly evolved since then.
 

125Spotter

Member
Joined
7 Aug 2022
Messages
113
Location
South West
We're not too far off that. It's available now from mainstream suppliers. I was looking at a new gate design in a factory that had overhead biometric sensors installed and worked seamlessly, even trying to trick it with various disguises, sunglasses, hats etc.
This reminds me of the last time I travelled to the US. As a returning visitor under the Visa Waiver Program (an “alien”, as they like to call us), I used the US citizens’ immigration queue, which is permitted at some airports. I approached the desk expecting to be asked for documents etc. Not so. The agent pointed a cheap USB webcam on a tripod at me, of the sort you might have used in the 2000s, and immediately drew up my name and travel history entirely by facial recognition using a likely ancient photo. I also didn’t need any entry/exit stamps. He never looked at my passport or even checked I was travelling with one.

But what staggered me was the comparison between this and the e-gates we see at British airports, which have an array of cameras and lights, a very slow rate for actually passing people through them, and still seem to reject me every few times. Granted, our gates are making an automated decision by machine, whereas in the US a human was still in the loop to sanity check the decision the machine was making. Still, it was pretty unexpected.
 

Tazi Hupefi

On Moderation
Joined
1 Apr 2018
Messages
1,838
Location
Nottinghamshire
This reminds me of the last time I travelled to the US. As a returning visitor under the Visa Waiver Program (an “alien”, as they like to call us), I used the US citizens’ immigration queue, which is permitted at some airports. I approached the desk expecting to be asked for documents etc. Not so. The agent pointed a cheap USB webcam on a tripod at me, of the sort you might have used in the 2000s, and immediately drew up my name and travel history entirely by facial recognition using a likely ancient photo. I also didn’t need any entry/exit stamps. He never looked at my passport or even checked I was travelling with one.

But what staggered me was the comparison between this and the e-gates we see at British airports, which have an array of cameras and lights, a very slow rate for actually passing people through them, and still seem to reject me every few times. Granted, our gates are making an automated decision by machine, whereas in the US a human was still in the loop to sanity check the decision the machine was making. Still, it was pretty unexpected.
The UK e-gates have two modes, depending on how short staffed the Border Force are. In normal circumstances, there's not really any automation at all, and it's someone in a control room doing it all, albeit the gates recommend what the officer should do, to speed things up.

The other mode is full automation - but this can be too strict as it is simple black/white logic, anything remotely grey and you're kicked to a manned immigration officer.

When I travel on Eurostar, there's now a dedicated premium lane for staff / business class travel (albeit it does work for anyone who's registered) whereby you check in online, and upload a photograph and your travel document. At St. Pancras, you just walk through the corridor and no need to use the gates or have your exit data captured/documents examined. Facial recognition sorts it all.

I don't think we are too far off seeing passengers volunteer for trials with faces connected to credit/debit cards or seasons, but there will be considerable opposition from certain pockets of society, and will need a TOC who is prepared to stick their neck out on the line from a data protection perspective.
 

Wolfie

Established Member
Joined
17 Aug 2010
Messages
7,395
Quite.

As somebody who quite regularly touches in on a Travelcard but doesn't touch out, because I also have another ticket that I bought from somebody else and am making a non-stop split, it's not a massive stretch of the imagination that this is going to be flagged by whoever sold me the Travelcard. I'm not even convinced everyone at the top of the industry has much interest in the important (to me) distinction between not overpaying on the one hand, and fare evasion on the other. Will a school of thought develop that if you're using a ticket in a way that gets flagged because not many people use it that way, you're the one being awkward?
I do exactly that regularly. In my case it's using an Over-60s Oyster card to the full extent of it's validity and then a pre-purchased paper ticket for the remainder of the journey. It means that l don't need to exit the train.

== Doublepost prevention - post automatically merged: ==

This reminds me of the last time I travelled to the US. As a returning visitor under the Visa Waiver Program (an “alien”, as they like to call us), I used the US citizens’ immigration queue, which is permitted at some airports. I approached the desk expecting to be asked for documents etc. Not so. The agent pointed a cheap USB webcam on a tripod at me, of the sort you might have used in the 2000s, and immediately drew up my name and travel history entirely by facial recognition using a likely ancient photo. I also didn’t need any entry/exit stamps. He never looked at my passport or even checked I was travelling with one.

But what staggered me was the comparison between this and the e-gates we see at British airports, which have an array of cameras and lights, a very slow rate for actually passing people through them, and still seem to reject me every few times. Granted, our gates are making an automated decision by machine, whereas in the US a human was still in the loop to sanity check the decision the machine was making. Still, it was pretty unexpected.
I wonder how well the massive growth in cosmetic surgery interfaces with that....

== Doublepost prevention - post automatically merged: ==

The UK e-gates have two modes, depending on how short staffed the Border Force are. In normal circumstances, there's not really any automation at all, and it's someone in a control room doing it all, albeit the gates recommend what the officer should do, to speed things up.

The other mode is full automation - but this can be too strict as it is simple black/white logic, anything remotely grey and you're kicked to a manned immigration officer.

When I travel on Eurostar, there's now a dedicated premium lane for staff / business class travel (albeit it does work for anyone who's registered) whereby you check in online, and upload a photograph and your travel document. At St. Pancras, you just walk through the corridor and no need to use the gates or have your exit data captured/documents examined. Facial recognition sorts it all.

I don't think we are too far off seeing passengers volunteer for trials with faces connected to credit/debit cards or seasons, but there will be considerable opposition from certain pockets of society, and will need a TOC who is prepared to stick their neck out on the line from a data protection perspective.
Having spent my whole career working with National Security/law enforcement (including Border Force) that's a "hell no" from me! I know what can already be done.
 
Last edited:

island

Veteran Member
Joined
30 Dec 2010
Messages
17,907
Location
0036
This reminds me of the last time I travelled to the US. As a returning visitor under the Visa Waiver Program (an “alien”, as they like to call us), I used the US citizens’ immigration queue, which is permitted at some airports. I approached the desk expecting to be asked for documents etc. Not so. The agent pointed a cheap USB webcam on a tripod at me, of the sort you might have used in the 2000s, and immediately drew up my name and travel history entirely by facial recognition using a likely ancient photo. I also didn’t need any entry/exit stamps. He never looked at my passport or even checked I was travelling with one.
It should be noted that this is possible because (1) the US has photos on file of all previous visitors, and (2) they know from API who's coming today, so there's a pretty short number of entries to be searched on the database.
 

185

On Moderation
Joined
29 Aug 2010
Messages
5,709
Slightly off subject, I was yesterday asked to have a look a quite ranty email from an HR director of a major TOC. In it, she referred to a former manager from fifteen years ago and some employment details of that person, which when checked were accurate. The manager was not from the current TOC, or the one before, but the one before that - ie they left three TOCs ago. The HR director joined the firm long after the manager left, so I wonder where she obtained the employment record from.

When writing investigative reports, lets pretend for a safety of the line incident, I was always told that after six months, if the report is to be retained for legitimate reasons, you must anonymise - remove & replace the subject's name (eg, Mr Smith becomes Mr A). I understand that for journalism, criminal investigation etc there are certain exemptions on GDPR, but for Human Resources issues, unless someone has burnt the building down you'd assume the law would be strictest when concerning the relationship between employer and employee.

I've witnessed some major faux pas at Train Operating Companies with GDPR:

- HR manager of one TOC didn't want to print a string of 32 letters so emailed them to candidates. All 32 letters - sent to every job applicant, internal and external. She sent employee names and home addresses to members of the public. When questioned she made it sound like the candidates were to blame.

- Planning Manager of TOC A, desperate to prove who owned a (pseudonym) facebook profile, scrolled through seventeen months of family photographs to find what he thought was conclusive proof of ownership, an employee of TOC B. Aside the legality, TOC A's social media policy didn't apply to TOC B's employees, regardless of the parent company.
 

Haywain

Veteran Member
Joined
3 Feb 2013
Messages
24,526
Planning Manager of TOC A, desperate to prove who owned a (pseudonym) facebook profile, scrolled through seventeen months of family photographs to find what he thought was conclusive proof of ownership, an employee of TOC B. Aside the legality, TOC A's social media policy didn't apply to TOC B's employees, regardless of the parent company.
What has this got to do with GDPR and how is it a "major faux pas"? Social media is in the public domain.
 

185

On Moderation
Joined
29 Aug 2010
Messages
5,709
Social media is in the public domain.
It is. But for a business to dig through that data, contact another business, transfer that data to them and demand they discipline their employee surely requires consent of the employee to both use and transfer that data. As abhorrent as the religious / political views of the employee may have been, on principle - if they weren't committing any criminal offence, it's really none of the TOCs business. Employment tribunals have made clear judgements reflecting misuse of (TOC) employee social media data, however it seems the captain doesn't learn enjoys hitting the same iceberg.
 

Haywain

Veteran Member
Joined
3 Feb 2013
Messages
24,526
consent of the employee to both use and transfer that data.
The data (are words and photos really 'data'?) is in the public domain and has presumably been placed there by, or with the implied consent of, the employee. In being there they must accept the risk that it will be seen by their employer and that they will have to bear the consequences if they breach their employer's social media or other policies.
 

Bletchleyite

Veteran Member
Joined
20 Oct 2014
Messages
113,058
Location
"Marston Vale mafia"
The data (are words and photos really 'data'?) is in the public domain and has presumably been placed there by, or with the implied consent of, the employee. In being there they must accept the risk that it will be seen by their employer and that they will have to bear the consequences if they breach their employer's social media or other policies.

I think this rather depends on what was done. If TOC A said to TOC B "Look at this URL, this contains details of <named person>", then that fact would be Personally Identifiable Information under the remit of GDPR whether the actual Facebook profile was public or not. You've got an identifiable person and you've got a fact about them.

That doesn't mean to say it can't be transferred or requires consent - establishing that is much more complex.

It's the transfer to another legal entity that is the issue here. If TOC B established on its own who it was and used that for disciplinary proceedings against their own employee, then that would be fine.
 

Haywain

Veteran Member
Joined
3 Feb 2013
Messages
24,526
If TOC A said to TOC B "Look at this URL, this contains details of <named person>", then that fact would be Personally Identifiable Information under the remit of GDPR whether the actual Facebook profile was public or not. You've got an identifiable person and you've got a fact about them.
I get that, but if they just sent a URL and said "Have you seen this?" without naming the person it would be fine?
 

185

On Moderation
Joined
29 Aug 2010
Messages
5,709
I get that, but if they just sent a URL and said "Have you seen this?" without naming the person it would be fine?
Common sense would prevail. But not at a TOC, sadly.

This fell apart when TOC B printed off the chain of emails sent from TOC A manager to TOC B HR, to TOC B's staff manager, which included screenshots of the facebook wall. The employee was brought in without notice or the option of organising a rep, however they set their phone to record video and discretely obtained a copy of the two offending A4 pages which clearly named them and identified their location of employment and grade.

It's not quite as naughty as Northern vs Man Vic Guard not taking ticket machine out (2022). At tribunal, Northern bosses were caught out in a lie by the union who produced covertly collected evidence. The union revealed that during the appeal hearing 'somebody' placed a recording device under the desk to record the deliberations of Guards Manager and HR Lady whilst staff were out the room. Guards manager said words to the effect of "they were told not to take a machine out, as more than half were broken". HR lady said "yeah, but they can't prove that." As disgraceful as their conduct was, the judge heard, but threw out the evidence.
 

Bletchleyite

Veteran Member
Joined
20 Oct 2014
Messages
113,058
Location
"Marston Vale mafia"
I get that, but if they just sent a URL and said "Have you seen this?" without naming the person it would be fine?

I can't see that that would be a problem, but the URL alone isn't going to prove it's that person, is it, if TOC A had to spend hours trawling photos to prove that it was?

== Doublepost prevention - post automatically merged: ==

This fell apart when TOC B printed off the chain of emails sent from TOC A manager to TOC B HR, to TOC B's staff manager, which included screenshots of the facebook wall. The employee was brought in without notice or the option of organising a rep, however they set their phone to record video and discretely obtained a copy of the two offending A4 pages which clearly named them and identified their location of employment and grade.

If that's what happened it absolutely would come under the remit of GDPR, including those e-mails whether printed or not.

A very, very important thing to do if you're going to have any kind of discussion about an individual you don't want on record is only to have that conversation either in person or by telephone so records of it neither exist nor ever have.
 
Last edited:

Wolfie

Established Member
Joined
17 Aug 2010
Messages
7,395
Slightly off subject, I was yesterday asked to have a look a quite ranty email from an HR director of a major TOC. In it, she referred to a former manager from fifteen years ago and some employment details of that person, which when checked were accurate. The manager was not from the current TOC, or the one before, but the one before that - ie they left three TOCs ago. The HR director joined the firm long after the manager left, so I wonder where she obtained the employment record from.

When writing investigative reports, lets pretend for a safety of the line incident, I was always told that after six months, if the report is to be retained for legitimate reasons, you must anonymise - remove & replace the subject's name (eg, Mr Smith becomes Mr A). I understand that for journalism, criminal investigation etc there are certain exemptions on GDPR, but for Human Resources issues, unless someone has burnt the building down you'd assume the law would be strictest when concerning the relationship between employer and employee.

I've witnessed some major faux pas at Train Operating Companies with GDPR:

- HR manager of one TOC didn't want to print a string of 32 letters so emailed them to candidates. All 32 letters - sent to every job applicant, internal and external. She sent employee names and home addresses to members of the public. When questioned she made it sound like the candidates were to blame.

- Planning Manager of TOC A, desperate to prove who owned a (pseudonym) facebook profile, scrolled through seventeen months of family photographs to find what he thought was conclusive proof of ownership, an employee of TOC B. Aside the legality, TOC A's social media policy didn't apply to TOC B's employees, regardless of the parent company.
The first case at least is legal action waiting to happen....
 

island

Veteran Member
Joined
30 Dec 2010
Messages
17,907
Location
0036
When writing investigative reports, lets pretend for a safety of the line incident, I was always told that after six months, if the report is to be retained for legitimate reasons, you must anonymise - remove & replace the subject's name (eg, Mr Smith becomes Mr A)
This may have been your employer's policy or process, but is not a requirement that is to be found anywhere in legislation.
 
Status
Not open for further replies.

Top