• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

TOCs sharing out information on passengers

Status
Not open for further replies.

soil

Established Member
Joined
28 May 2012
Messages
2,311
I doubt most people are aware of, or still less claim, for delay compensation.
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

RJ

Established Member
Joined
25 Jun 2005
Messages
8,817
Location
Back office
The amount I spend on rail travel in a year fluctuates wildly. There is no trend. Although I've worked in London constantly since the beginning of my working life in 2007, my commute has varied. There has been a mix of short hop trips and long distance round trips from Canterbury and the East Midlands. Plus I buy tickets to travel around the country several times a year for leisure reasons.

I'm flattered that these people wish to monitor me and gossip about my movements. That said, whatever it is these people are expecting to find, they're not going to find it :)

My offer to put £50 into a fighting fund still stands. I suspect others will do likewise.

Surely it is only a matter of time before they try to cause trouble for you with your employer?

Thanks - at present, after 7 months, it seems my complaints are finally being acknowledged as valid. I'll see how it pans out.
 
Last edited:

Baxenden Bank

Established Member
Joined
23 Oct 2013
Messages
4,743
First Scotrail - "We have no record of any correspondence from this customer ‐ but we have been alerted to him by our Auditor."

Interesting, a secret society of Auditors passing information around the country about people - surely thats a data protection breach if not defamatory (depending upon what the 'alert' says)?

Do a personal information request to Scotrail and when it comes back, see if this 'alert' from an auditor gets picked up. If not, follow it up as to why not, what format the 'alert' took and why it is there. Alternativley just send a general enquiry as to what this alert is.

Depends how much fun / trouble you want to have.
 

Llanigraham

On Moderation
Joined
23 Mar 2013
Messages
6,486
Location
Powys
First Scotrail - "We have no record of any correspondence from this customer ‐ but we have been alerted to him by our Auditor."

Interesting, a secret society of Auditors passing information around the country about people - surely thats a data protection breach if not defamatory (depending upon what the 'alert' says)?

Do a personal information request to Scotrail and when it comes back, see if this 'alert' from an auditor gets picked up. If not, follow it up as to why not, what format the 'alert' took and why it is there. Alternativley just send a general enquiry as to what this alert is.

Depends how much fun / trouble you want to have.

Get real!
Lots of businesses share information on people who they perceive to be a "problem". Insurance companies have a "black list". Finance companies have a "black list". Even retail outlets in town centres share a "black list".
The circulation of a person's name, and his photograph even, is not a breach of Data Protection. That is all that it appears the Auditors have done.

A few people here need to actually read the Data Protection legislation and see what and how information can be legally shared.
 

jon0844

Veteran Member
Joined
1 Feb 2009
Messages
30,865
Location
UK
I agree that information can be shared, but it could be a problem if sharing such details will automatically put someone at an extreme disadvantage.

For example, making a delay repay claim and having to wait weeks/months because the initial reaction is to assume it's fraudulent.

Or, of course, to try and make life as difficult as possible for someone simply because he has a reputation for being too clever for his own good, or similar.
 

Tetchytyke

Veteran Member
Joined
12 Sep 2013
Messages
17,474
Location
Isle of Man
Blacklisting is unlawful, as the construction industry are beginning to belatedly discover.

Schedules One and Two are where the real bits of the DPA are. Data may only be "processed" (that includes sharing data) for a specified and lawful purpose. Fraud prevention can be a specified and lawful purpose. However the reason for processing the data needs to be reasonable. If IPFAS suspected that the Delay Repay voucher was awarded to RJ fraudulently then it would be lawful to process that data.

The other TOCs could argue they processed RJ's data because IPFAS implied that they suspected fraud. However nothing disclosed to IPFAS makes that a reasonable belief on the part of IPFAS, and so they also fall down on the requirement to ensure that all data processed is accurate.

I would suggest to RJ that he looks at s10 of the DPA and writes to the Data Controller demanding that they cease processing data that they hold, as it is likely to cause him "substantial damage or substantial distress". It'll be interesting to see what the Data Controller replies with.

I would also do a subject access request to Scotrail as they should disclose that they are processing data shared with them by an auditor, and for what purpose they are processing this data.
 

sheff1

Established Member
Joined
24 Dec 2009
Messages
6,059
Location
Sheffield
The circulation of a person's name, and his photograph even, is not a breach of Data Protection. That is all that it appears the Auditors have done.

An 'alert' suggests that Scotrail is being warned in some way about dealing with correspondence from RJ. i.e. rather more than circulation of a name.

Now, if the warning is that RJ knows his stuff about the Routeing Guide that would be be based on the truth. If, however, the warning is that his Delay Repay claims should be scrutinised more thoroughly than normal, beacuse he is 'trying it on', that would not be based on the truth.
 
Last edited:

Llanigraham

On Moderation
Joined
23 Mar 2013
Messages
6,486
Location
Powys
If you wish to be pedantic then replace my word with "Warning List" because even my local LVA produce one of those with the aid of the local Police! That certainly contains names, nick-names and photos!
 

sheff1

Established Member
Joined
24 Dec 2009
Messages
6,059
Location
Sheffield
What your LVA does has no bearing at all on the legality or otherwise of an Auditors alert to Scotrail.
 

jon0844

Veteran Member
Joined
1 Feb 2009
Messages
30,865
Location
UK
If you wish to be pedantic then replace my word with "Warning List" because even my local LVA produce one of those with the aid of the local Police! That certainly contains names, nick-names and photos!

What does it matter what the London Volleyball Association does? :D
 

Tetchytyke

Veteran Member
Joined
12 Sep 2013
Messages
17,474
Location
Isle of Man
If you wish to be pedantic then replace my word with "Warning List" because even my local LVA produce one of those with the aid of the local Police!

I don't think I am being pedantic. "Warning list" and "blacklist" are not synonyms.

It's reasonable to share details about known offenders- for one thing, criminal proceedings are a matter of public record. Sharing details about people who've been barred from a pub is probably also ok. But it's what you do with the data that makes it lawful or unlawful.

In this case, turning down a Delay Repay claim purely because IPFAS allege RJ is a troublemaker is unlawful. Double checking that his ticket is valid before issuing a voucher? That's probably lawful. Telling RJ's employer about his travel history? Almost certainly unlawful.

I don't think the TOCs replying to IPFAS have broken the DPA because of how IPFAS structured the question. But this means that IPFAS' breach is worse than the apology from SouthEastern seems to imply; what they said is very close to being defamatory.

As I said, it'd be interesting to see SouthEastern's response to a s10 request to cease processing RJ's data.
 

richw

Veteran Member
Joined
10 Jun 2010
Messages
11,528
Location
Liskeard
Sharing someone's name is not a DPA breach, as a full name is not a unique combination to an individual. It is only a DPA breach when shared with information unique to that individual.
 

RJ

Established Member
Joined
25 Jun 2005
Messages
8,817
Location
Back office
Sharing someone's name is not a DPA breach, as a full name is not a unique combination to an individual. It is only a DPA breach when shared with information unique to that individual.

You speak no word of a lie :)
 

Baxenden Bank

Established Member
Joined
23 Oct 2013
Messages
4,743
Get real!
Even retail outlets in town centres share a "black list".

Indeed, and when casual visitors came to our Town Centre Managers office, all the mugshots and names posted up on the wall have to be covered up - for data protection reasons. You need a reason to store data, you need a reason or permission to pass it on. I'm sure the DPA spells this out at great length. However, as I need to 'get real', I'll spend time doing that down the pub instead of reading the act.

I always considered policemen to be less than the sharpest tools in the box. The more I meet the more it is confirmed.
 

Gricerjo

Member
Joined
27 Nov 2013
Messages
15
An internal communication in the nature of business between two employees of the same organisation is very unlikely to be a breach. The external emails are highly likely to be justified by an irregular pattern for an individual, thus making any enquiries to other TOCs justifiable.

By all means try a complaint to the ICO about SET (not the police its not their matter), it wont be upheld.

If someone exploits loopholes, don't be suprised if TOCs start investigating and data sharing just as we all would expect TOCs (and more obviously other industries like insurance) to do with fraudsters, and fare evaders which maybe detected with similar patterns, with one key difference, nothing will be found if all the loopholes are bona fide, then nothing more will come of it. I'm sure nobody here will object to data sharing between TOCs regarding delay repay, or ticket fraud, which result in somebody being brought before the courts.

My wife works in the claims sections of a major insurance company and I’m afraid its standard practice to circulate details of claims and claimants to other companies in the industry. If challenged under the Data Protection Act their defence is that they are justified in doing so as a precaution against potential fraud.

I assume that TOCs have a similar policy?
 

IanXC

Emeritus Moderator
Joined
18 Dec 2009
Messages
6,611
I have to agree with Arctic Troll - there are various conditions that these firms would be obliged to evidence they have met, and its far from clear that they (a) have met those conditions (b) know how to answer to confirm their compliance.

My wife works in the claims sections of a major insurance company and I’m afraid its standard practice to circulate details of claims and claimants to other companies in the industry. If challenged under the Data Protection Act their defence is that they are justified in doing so as a precaution against potential fraud.

I assume that TOCs have a similar policy?

It is standard practice in financial services, however you'll get a warning of how your data may be used - I certainly don't recall any TOC stating that they may (eg) "share personal data for the purpose of fraud prevention" and the NRCoC doesn't seem to mention it.
 

Solent&Wessex

Established Member
Joined
9 Jul 2009
Messages
2,745
I know that some TOCs use Section 29 of the Data Protection Act 1998 to gain personal information on people from outside sources such as employers, local authorities who issue travel cards and ENCTS passes etc.

Section 29 basically seems to state that

.....Personal data processed for any of the following purposes—

(a)the prevention or detection of crime,

(b)the apprehension or prosecution of offenders, or

(c)the assessment or collection of any tax or duty or of any imposition of a similar nature,

are exempt....

This could be quite useful to verify information on somebody who they may believe has provided false information when questioned, but they have some information available such as a ENCTS pass number number, or employers details.
 

cjmillsnun

Established Member
Joined
13 Feb 2011
Messages
3,275
Get real!
Lots of businesses share information on people who they perceive to be a "problem". Insurance companies have a "black list". Finance companies have a "black list". Even retail outlets in town centres share a "black list".
The circulation of a person's name, and his photograph even, is not a breach of Data Protection. That is all that it appears the Auditors have done.

A few people here need to actually read the Data Protection legislation and see what and how information can be legally shared.

As someone who deals with sensitive personal information as defined by the DPA, I can say with authority that you are wrong.

Finance companies do not possess a blacklist. They do however have access the credit history of a person going back six years (10 years in the case of discharged bankrupts). They obtain this from one of three credit reference agencies. They must however inform the customer prior to doing any credit search. The credit search will never say don't give this person finance. It will however give an account of how the customer has conducted themselves financially. A score is worked out by the finance company based on this and some other factors.

Insurance companies do share information on claimants and who has committed insurance fraud. However some of this information is available from the courts and as such, is in the public domain. Again, they must clearly state that they do this to the customer before any quote is given.

With retail outlets you're on dodgy ground. They must again state that they do this. 99.99% of them don't. And should an innocent person be discriminated against, the retailer who did so, and the one who spread the incorrect information can be prosecuted.
 
Last edited:

Crossover

Established Member
Joined
4 Jun 2009
Messages
9,493
Location
Yorkshire
I have been filling out some compensation claims for First TPE and I noted the small print at the bottom of the page made mention of TPE may share information with other TOC's for the purpose of detecting fraud etc. I have just sealed up the last of the forms so I can't recount the exact wording but it was something to that effect nonetheless
 

bb21

Emeritus Moderator
Joined
4 Feb 2010
Messages
24,451
Where is it?
 

Attachments

  • img1514.jpg
    img1514.jpg
    567.6 KB · Views: 150
  • img1515.jpg
    img1515.jpg
    427.5 KB · Views: 106

RJ

Established Member
Joined
25 Jun 2005
Messages
8,817
Location
Back office
This reminds me - I put in a SAR to Scotrail on the 28th November 2013. I got an auto acknowledgement and reference number, but no reply as yet. They're running out of time if they are intending to respond within the legal timeframe.
 
Last edited:

snail

Established Member
Joined
16 Jun 2011
Messages
1,910
Location
t'North
Insurance companies do share information on claimants and who has committed insurance fraud.
That is normally through the Claims and Underwriting Exchange, set up in 1994. Its web page says
The information contained in the database will comprise that supplied by the policyholder or claimant on their application or claim form, together with other information relating to the incident or claim. It does not hold sensitive information or details relating to the amount of premium paid.

Proposal and claim forms of insurers participating in the exchange will have something to explain this.
 

Chew Chew

Member
Joined
29 Aug 2010
Messages
519
This reminds me - I put in a SAR to Scotrail on the 28th November 2013. I got an auto acknowledgement and reference number, but no reply as yet. They're running out of time if they are intending to respond within the legal timeframe.

When I emailed Scotrail on 15 November about a Delay Repay claim it took them until 19 December, 34 days, to get back to me saying they were inundated with correspondence.
 
Last edited:

SickyNicky

Verified Rep - FastJP
Joined
8 Sep 2010
Messages
2,842
Location
Ledbury
When I emailed Scotrail on 15 November about a Delay Repay claim it took them until 19 December, 34 days, to get back to me saying they were inundated with correspondence.

Yes, although under the Data Protection legislation, a Subject Access Request must be dealt with within 40 days, whereas there are no statutory time limits on delay repay (other than perhaps contract law).

The ICO website says:

ICO said:
The organisation has to reply within 40 days, starting from the day they receive both the fee and the information they need to identify you and the information you need...
 

Chew Chew

Member
Joined
29 Aug 2010
Messages
519
Yes, although under the Data Protection legislation, a Subject Access Request must be dealt with within 40 days, whereas there are no statutory time limits on delay repay (other than perhaps contract law).

The ICO website says:

I'm fully aware of DSAR rules. Was just saying that Scotrail were, 3 weeks ago, saying that they were drowning under a sea of correspondence.
 

Wolfie

Established Member
Joined
17 Aug 2010
Messages
7,397
I'm fully aware of DSAR rules. Was just saying that Scotrail were, 3 weeks ago, saying that they were drowning under a sea of correspondence.

If ScotRail are daft enough not to sort through and prioritise correspondence, dealing with that which has a statutory timeline first, than they deserve everything that they might get in terms of punsihment from the Information Commisioner. If their resources are inadequate to meet statutory deadlines then they should get some more (lack of resources is NOT an excuse for failing to comply with the law!)!
 

Baxenden Bank

Established Member
Joined
23 Oct 2013
Messages
4,743
If their resources are inadequate to meet statutory deadlines then they should get some more (lack of resources is NOT an excuse for failing to comply with the law!)!

Which is what they would say to you if you failed to comply with their interpretation of the law whenever it suits them e.g. having the right ticket.
 

BrownE

Member
Joined
9 Apr 2012
Messages
184
This reminds me - I put in a SAR to Scotrail on the 28th November 2013. I got an auto acknowledgement and reference number, but no reply as yet. They're running out of time if they are intending to respond within the legal timeframe.
Have they sent you the FSR SAR form?
 

RJ

Established Member
Joined
25 Jun 2005
Messages
8,817
Location
Back office
Nope. I don't fill those in anyway when dealing with TOCs. I tell them what they need to know, they can then work with that.
 
Status
Not open for further replies.

Top