Information Commissioner's Office
When is a breach not a breach?
The ICO has ruled that Virgin Trains East Coast did not break data protection law when it published CCTV footage of Jeremy Corbyn looking for a seat on a service from London.
But the company did breach the law when it published images of other passengers on the same service. The ICO found that Virgin should have taken better care to obscure the faces of other people on the train. Publication of their images was unfair and a breach of the first principle of the Data Protection Act.
Why was it okay to publish pictures of Mr Corbyn?
All organisations are bound to publish details of how they’ll handle personal data. If they don’t process it in the way people would expect, they could be breaking the law.
But there are exceptions.
The Data Protection Act allows an organisation to process personal data outside its published conditions as long as it has a “legitimate interest” to do so.
In this case, the ICO’s view was that Virgin had a legitimate interest, namely correcting what it deemed to be misleading news reports that were potentially damaging to its reputation and commercial interests.
It would not have been possible to achieve Virgin’s legitimate interests without publishing Mr Corbyn’s image. Virgin could only show that there were empty seats on Mr Corbyn’s journey if they showed Mr Corbyn on that journey.
In addition, the ICO believed that Mr Corbyn would have had different expectations than other passengers as to his privacy whilst on this journey because:
- he had already made a video which showed him making that journey, and
- it would be reasonable for him to expect that once he had raised issues about his train journey in a video released to the media, Virgin would respond in kind.
What about the other passengers?
In order to give its side of the story, Virgin had no reason to publish pictures of anyone else on the train.
By doing so, it infringed on the privacy of passengers who were simply minding their own business and would not reasonably have expected their pictures to be published.
What happens next?
We’ve stopped short of formal regulatory action to reflect the exceptional circumstances of the breach. In particular that this was a one-off incident, and the people identified were unlikely to suffer serious distress or detriment.
Only three people were recognisable in the footage – most were pixelated – and while some people complained to us about how CCTV had been used, none of the affected passengers contacted us.
But Virgin has not been let off the hook. Our investigation was rigorous and compelled the company to provide us with details of its practices, policies and procedures. The company was under no illusion of the seriousness of our involvement.
Virgin will strengthen its data protection training for everyone from new starters to the top tier executives. It will amend its CCTV policy to take account of exceptional circumstances and ensure it has easy access to pixelation services should the need arise again.
We did not deem it proportionate to use our regulatory stick on this occasion. But, as always, we will use our enforcement powers to protect the information and privacy rights of UK citizens when necessary.
Latest News from
Information Commissioner's Office
Man prosecuted and police force given undertaking after sensitive data leak on Twitter19/01/2018 09:10:00
A Kent man who posted sensitive police information on Twitter has appeared in court after he admitted breaking the Data Protection Act.
Company which made 75 million nuisance automated calls in four months is fined by the ICO18/01/2018 09:10:00
A company which made 75 million nuisance calls in four months has been fined £350,000 by the Information Commissioner’s Office (ICO).
Statement in response to reports of Just Eat story17/01/2018 10:20:00
An ICO spokesperson yesterday gave a statement in response to reports of Just Eat story.
Firms behind 44 million spam emails, 15 million nuisance calls and one million spam texts fined by the Information Commissioner’s Office12/01/2018 11:10:00
Four companies that disrupted people with nuisance marketing have been fined a total of £600,000 by the Information Commissioner’s Office (ICO).
Carphone Warehouse fined £400,000 after serious failures placed customer and employee data at risk11/01/2018 09:10:00
Carphone Warehouse has been issued with one of the largest fines by the Information Commissioner’s Office (ICO), after one of their computer systems was compromised as a result of a cyber-attack in 2015.