GDPR for the private investigator

On the 25th May 2018 the way we go about storing and sharing data got a major upheaval. Since 1998 anyone that stored data had to adhere to the DPA 1998 (Data protection act) when it came to handling anyones details.
A lot has changed in 20 years in the way we and when I say we, I don’t just mean private investigators, I mean any organisation, company, business or entity, store or share data.
Technology has moved on a lot since 1998. In those days we did not have smart phones or tablets and on line and personal databases had moved on drastically and it was realised that the DPA 1998 was a spent force and toothless in many respects.
When GDPR was mentioned it sent shockwaves not only through the private investigation industry but for all businesses as it soon became apparent that there would be far more severe cosequences of any breach of data.
Private investigators obviously handle and store data in their day to day activities. Under GDPR a client passes over the name, address and other relevant details to you of a person they wish you to investigate in an email. From this point on you are in possession of someones data and you have to be accountable as to how you handle the data. Such as how long you store the data and why you have stored the data for so long.
Also if we share the details with anyone then we have to share it securely via encrypted emails, secure file transfer sites, password protected word or pdf document and secure chat apps on phones such as whatsapp.
There is a lot more to it that is far too long for this page, so if you want to read some more look here for some more in depth reading on the topic.
Is GDPR good for the private investigator?
I like everyone else had a few ruffled feathers when I heard about GDPR from a friend who heard from a colleague (Chinese whispers) of the implications of this new legislation. Word got around that it would make it impossible for PI’s to work legally etc. In fact I had not seen such hysteria for some time and it was synonymous with the “We’re all doomed” hoo har of the dreaded millenium bug experienced at the turn of the century.
As the murky waters cleared it became obvious that yes initially it would create extra work such as securing websites and putting up proper privacy and cookie policies etc. The principal of M.R. Investigations attended an ABI GDPR workshop and came away happy that GDPR was really a good thing and it is the way we should have been operating all along.
Pre GDPR we would share information with other investigators that would be assisting on say a surveillance operation via unsecure email, which we did without a thought in the world but what happened if that email was sent inadvertently to the wrong recipient? The answer is simple. The wrong person would be aware of the whole operation including when, where and more importantly whom!
We are only human, mistakes will happen and indeed emails with sensitive information was sent to the wrong person on occasions. I would be a liar if I said I hadn’t been guilty of it too but fortunately I sent it to another PI that I get on very well with so the information went no further.
Post GDPR if I password protect any document and it gets sent to the wrong person it’s no big deal as they wont be able to open it anyway. So straight away you can hopefully see that it is a good thing.
Working with other sectors
As private investigators we are asked to assist employers, HR departments councils and legal clients such as solicitors.
In my experience most of these services have got their houses in order when it comes to adhering to GDPR. Councils in my experience implemented secure email methods long before GDPR came in. HR departments are fully versed in GDPR and have sent me forms to fill in to make sure that we too comply.
However, a lot of solicitor clients in our experience have totally ignored it. I have been blatantly told by more than one solicitor “that it does not apply to us”. One even went so far as to say that “our business is all about peoples data so it does not effect us”! Really?
Credit where it is due Askews Legal in Coventry emailed me asking for a copy of our own GDPR policy, stating that they had been told not to use anyone who is not GDPR compliant. Well done to them.
18 months in
So it’s nearly 18 months down the line, are most people adhering to GDPR or have they chose to ignore it? All I will say is that some people are going to trip up and will feel the wrath of the ICO at some point or other.
Unsecured emails containing personal details are still rife, not only from the one man band type of investigator but some of the bigger firms as well, still regularly send job instructions via unsecure email. Most solicitors still send instructions in the clear in their bubble that they are exempt.
However, a lot of other private investigators I deal with have taken it very seriously and require us to send a certificate showing how the data they have shared was handled and when it was destructed.
To be GDPR Compliant
To be GDPR compliant we had to implement and update the following..
1.Website Privacy Notice
2. Data Protection Policy
3. Data Retention Policy
4. Data Processing Policy
5. Data Sharing Policy
6. Privacy Impact Assessments
7. Destruction of data Certificates (Can be downloaded here)
For some interesting reading on what the ICO has been doing to punish those that breach GDPR see here.
September 2019