
My offer to put £50 into a fighting fund still stands. I suspect others will do likewise.
Surely it is only a matter of time before they try to cause trouble for you with your employer?
First Scotrail - "We have no record of any correspondence from this customer ‐ but we have been alerted to him by our Auditor."
Interesting, a secret society of Auditors passing information around the country about people - surely thats a data protection breach if not defamatory (depending upon what the 'alert' says)?
Do a personal information request to Scotrail and when it comes back, see if this 'alert' from an auditor gets picked up. If not, follow it up as to why not, what format the 'alert' took and why it is there. Alternativley just send a general enquiry as to what this alert is.
Depends how much fun / trouble you want to have.
The circulation of a person's name, and his photograph even, is not a breach of Data Protection. That is all that it appears the Auditors have done.
If you wish to be pedantic then replace my word with "Warning List" because even my local LVA produce one of those with the aid of the local Police! That certainly contains names, nick-names and photos!
If you wish to be pedantic then replace my word with "Warning List" because even my local LVA produce one of those with the aid of the local Police!
Sharing someone's name is not a DPA breach, as a full name is not a unique combination to an individual. It is only a DPA breach when shared with information unique to that individual.

Get real!
Even retail outlets in town centres share a "black list".
An internal communication in the nature of business between two employees of the same organisation is very unlikely to be a breach. The external emails are highly likely to be justified by an irregular pattern for an individual, thus making any enquiries to other TOCs justifiable.
By all means try a complaint to the ICO about SET (not the police its not their matter), it wont be upheld.
If someone exploits loopholes, don't be suprised if TOCs start investigating and data sharing just as we all would expect TOCs (and more obviously other industries like insurance) to do with fraudsters, and fare evaders which maybe detected with similar patterns, with one key difference, nothing will be found if all the loopholes are bona fide, then nothing more will come of it. I'm sure nobody here will object to data sharing between TOCs regarding delay repay, or ticket fraud, which result in somebody being brought before the courts.
My wife works in the claims sections of a major insurance company and Im afraid its standard practice to circulate details of claims and claimants to other companies in the industry. If challenged under the Data Protection Act their defence is that they are justified in doing so as a precaution against potential fraud.
I assume that TOCs have a similar policy?
Get real!
Lots of businesses share information on people who they perceive to be a "problem". Insurance companies have a "black list". Finance companies have a "black list". Even retail outlets in town centres share a "black list".
The circulation of a person's name, and his photograph even, is not a breach of Data Protection. That is all that it appears the Auditors have done.
A few people here need to actually read the Data Protection legislation and see what and how information can be legally shared.
Where is it?
That is normally through the Claims and Underwriting Exchange, set up in 1994. Its web page saysInsurance companies do share information on claimants and who has committed insurance fraud.
The information contained in the database will comprise that supplied by the policyholder or claimant on their application or claim form, together with other information relating to the incident or claim. It does not hold sensitive information or details relating to the amount of premium paid.
This reminds me - I put in a SAR to Scotrail on the 28th November 2013. I got an auto acknowledgement and reference number, but no reply as yet. They're running out of time if they are intending to respond within the legal timeframe.
When I emailed Scotrail on 15 November about a Delay Repay claim it took them until 19 December, 34 days, to get back to me saying they were inundated with correspondence.
ICO said:The organisation has to reply within 40 days, starting from the day they receive both the fee and the information they need to identify you and the information you need...
Yes, although under the Data Protection legislation, a Subject Access Request must be dealt with within 40 days, whereas there are no statutory time limits on delay repay (other than perhaps contract law).
The ICO website says:
I'm fully aware of DSAR rules. Was just saying that Scotrail were, 3 weeks ago, saying that they were drowning under a sea of correspondence.
If their resources are inadequate to meet statutory deadlines then they should get some more (lack of resources is NOT an excuse for failing to comply with the law!)!
Have they sent you the FSR SAR form?This reminds me - I put in a SAR to Scotrail on the 28th November 2013. I got an auto acknowledgement and reference number, but no reply as yet. They're running out of time if they are intending to respond within the legal timeframe.